_ZN5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EED2Ev:
   65|      1|      ~AlignmentBuffer() { secure_scrub_memory(m_buffer.data(), m_buffer.size()); }
_ZN5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EEC2Ev:
   63|      1|      AlignmentBuffer() : m_position(0) {}
_ZN5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE5clearEv:
   72|      7|      void clear() {
   73|      7|         clear_mem(m_buffer.data(), m_buffer.size());
   74|      7|         m_position = 0;
   75|      7|      }
_ZN5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE21handle_unaligned_dataERNS_12BufferSlicerE:
  167|      9|      [[nodiscard]] std::optional<std::span<const T>> handle_unaligned_data(BufferSlicer& slicer) {
  168|       |         // When the final block is to be deferred, we would need to store and
  169|       |         // hold a buffer that contains exactly one block until more data is
  170|       |         // passed or it is explicitly consumed.
  171|      9|         const size_t defer = (defers_final_block()) ? 1 : 0;
  ------------------
  |  Branch (171:31): [True: 0, False: 9]
  ------------------
  172|       |
  173|      9|         if(in_alignment() && slicer.remaining() >= m_buffer.size() + defer) {
  ------------------
  |  Branch (173:13): [True: 9, False: 0]
  |  Branch (173:31): [True: 6, False: 3]
  ------------------
  174|       |            // We are currently in alignment and the passed-in data source
  175|       |            // contains enough data to benefit from aligned processing.
  176|       |            // Therefore, we don't copy anything into the intermittent buffer.
  177|      6|            return std::nullopt;
  178|      6|         }
  179|       |
  180|       |         // Fill the buffer with as much input data as needed to reach alignment
  181|       |         // or until the input source is depleted.
  182|      3|         const auto elements_to_consume = std::min(m_buffer.size() - m_position, slicer.remaining());
  183|      3|         append(slicer.take(elements_to_consume));
  184|       |
  185|       |         // If we collected enough data, we push out one full block. When
  186|       |         // deferring the final block is enabled, we additionally check that
  187|       |         // more input data is available to continue processing a consecutive
  188|       |         // block.
  189|      3|         if(ready_to_consume() && (!defers_final_block() || !slicer.empty())) {
  ------------------
  |  Branch (189:13): [True: 0, False: 3]
  |  Branch (189:36): [True: 0, False: 0]
  |  Branch (189:61): [True: 0, False: 0]
  ------------------
  190|      0|            return consume();
  191|      3|         } else {
  192|      3|            return std::nullopt;
  193|      3|         }
  194|      3|      }
_ZNK5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE18defers_final_blockEv:
  234|     15|      constexpr bool defers_final_block() const {
  235|     15|         return FINAL_BLOCK_STRATEGY == AlignmentBufferFinalBlock::must_be_deferred;
  236|     15|      }
_ZN5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE6appendENSt3__14spanIKhLm18446744073709551615EEE:
   91|      7|      void append(std::span<const T> elements) {
   92|      7|         BOTAN_ASSERT_NOMSG(elements.size() <= elements_until_alignment());
  ------------------
  |  |   60|      7|   do {                                                                     \
  |  |   61|      7|      if(!(expr))                                                           \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 7]
  |  |  ------------------
  |  |   62|      7|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   63|      7|   } while(0)
  |  |  ------------------
  |  |  |  Branch (63:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   93|      7|         std::copy(elements.begin(), elements.end(), m_buffer.begin() + m_position);
   94|      7|         m_position += elements.size();
   95|      7|      }
_ZNK5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE24elements_until_alignmentEv:
  222|     19|      size_t elements_until_alignment() const { return m_buffer.size() - m_position; }
_ZNK5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE16ready_to_consumeEv:
  232|     15|      bool ready_to_consume() const { return m_position == m_buffer.size(); }
_ZN5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE7consumeEv:
  201|      4|      [[nodiscard]] std::span<const T> consume() {
  202|      4|         BOTAN_ASSERT_NOMSG(ready_to_consume());
  ------------------
  |  |   60|      4|   do {                                                                     \
  |  |   61|      4|      if(!(expr))                                                           \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 4]
  |  |  ------------------
  |  |   62|      4|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   63|      4|   } while(0)
  |  |  ------------------
  |  |  |  Branch (63:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  203|      4|         m_position = 0;
  204|      4|         return m_buffer;
  205|      4|      }
_ZNK5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE12in_alignmentEv:
  227|     24|      bool in_alignment() const { return m_position == 0; }
_ZNK5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE23aligned_data_to_processERNS_12BufferSlicerE:
  127|      6|      [[nodiscard]] std::tuple<std::span<const uint8_t>, size_t> aligned_data_to_process(BufferSlicer& slicer) const {
  128|      6|         BOTAN_ASSERT_NOMSG(in_alignment());
  ------------------
  |  |   60|      6|   do {                                                                     \
  |  |   61|      6|      if(!(expr))                                                           \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 6]
  |  |  ------------------
  |  |   62|      6|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   63|      6|   } while(0)
  |  |  ------------------
  |  |  |  Branch (63:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  129|       |
  130|       |         // When the final block is to be deferred, the last block must not be
  131|       |         // selected for processing if there is no (unaligned) extra input data.
  132|      6|         const size_t defer = (defers_final_block()) ? 1 : 0;
  ------------------
  |  Branch (132:31): [True: 0, False: 6]
  ------------------
  133|      6|         const size_t full_blocks_to_process = (slicer.remaining() - defer) / m_buffer.size();
  134|      6|         return {slicer.take(full_blocks_to_process * m_buffer.size()), full_blocks_to_process};
  135|      6|      }
_ZN5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE18fill_up_with_zerosEv:
   80|      4|      void fill_up_with_zeros() {
   81|      4|         if(!ready_to_consume()) {
  ------------------
  |  Branch (81:13): [True: 4, False: 0]
  ------------------
   82|      4|            clear_mem(&m_buffer[m_position], elements_until_alignment());
   83|      4|            m_position = m_buffer.size();
   84|      4|         }
   85|      4|      }
_ZN5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE20directly_modify_lastEm:
  114|      4|      std::span<T> directly_modify_last(size_t elements) {
  115|      4|         BOTAN_ASSERT_NOMSG(size() >= elements);
  ------------------
  |  |   60|      4|   do {                                                                     \
  |  |   61|      4|      if(!(expr))                                                           \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 4]
  |  |  ------------------
  |  |   62|      4|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   63|      4|   } while(0)
  |  |  ------------------
  |  |  |  Branch (63:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  116|      4|         return std::span(m_buffer).last(elements);
  117|      4|      }
_ZNK5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE4sizeEv:
  218|      4|      constexpr size_t size() const { return m_buffer.size(); }

_ZN5Botan14expand_top_bitImEET_S1_:
   25|   685M|{
   26|   685M|   return static_cast<T>(0) - (a >> (sizeof(T) * 8 - 1));
   27|   685M|}
_ZN5Botan6chooseImEET_S1_S1_S1_:
  180|   869M|inline constexpr T choose(T mask, T a, T b) {
  181|       |   //return (mask & a) | (~mask & b);
  182|   869M|   return (b ^ (mask & (a ^ b)));
  183|   869M|}
_ZN5Botan10ct_is_zeroImEET_S1_:
   35|   492M|{
   36|   492M|   return expand_top_bit<T>(~x & (x - 1));
   37|   492M|}
_ZN5Botan13is_power_of_2ImEEbT_:
   47|   370k|{
   48|   370k|   return (arg != 0) && (arg != 1) && ((arg & static_cast<T>(arg - 1)) == 0);
  ------------------
  |  Branch (48:11): [True: 370k, False: 0]
  |  Branch (48:25): [True: 370k, False: 0]
  |  Branch (48:39): [True: 345k, False: 24.7k]
  ------------------
   49|   370k|}
_ZN5Botan8high_bitImEEmT_:
   60|   565k|{
   61|   565k|   size_t hb = 0;
   62|       |
   63|  3.95M|   for(size_t s = 8 * sizeof(T) / 2; s > 0; s /= 2) {
  ------------------
  |  Branch (63:38): [True: 3.39M, False: 565k]
  ------------------
   64|  3.39M|      const size_t z = s * ((~ct_is_zero(n >> s)) & 1);
   65|  3.39M|      hb += z;
   66|  3.39M|      n >>= z;
   67|  3.39M|   }
   68|       |
   69|   565k|   hb += n;
   70|       |
   71|   565k|   return hb;
   72|   565k|}
_ZN5Botan10ct_is_zeroIhEET_S1_:
   35|   158k|{
   36|   158k|   return expand_top_bit<T>(~x & (x - 1));
   37|   158k|}
_ZN5Botan14expand_top_bitIhEET_S1_:
   25|   162k|{
   26|   162k|   return static_cast<T>(0) - (a >> (sizeof(T) * 8 - 1));
   27|   162k|}
_ZN5Botan6chooseIhEET_S1_S1_S1_:
  180|   162k|inline constexpr T choose(T mask, T a, T b) {
  181|       |   //return (mask & a) | (~mask & b);
  182|   162k|   return (b ^ (mask & (a ^ b)));
  183|   162k|}
_ZN5Botan3ctzImEEmT_:
  104|  1.20M|{
  105|       |   /*
  106|       |   * If n == 0 then this function will compute 8*sizeof(T)-1, so
  107|       |   * initialize lb to 1 if n == 0 to produce the expected result.
  108|       |   */
  109|  1.20M|   size_t lb = ct_is_zero(n) & 1;
  110|       |
  111|  8.44M|   for(size_t s = 8 * sizeof(T) / 2; s > 0; s /= 2) {
  ------------------
  |  Branch (111:38): [True: 7.23M, False: 1.20M]
  ------------------
  112|  7.23M|      const T mask = (static_cast<T>(1) << s) - 1;
  113|  7.23M|      const size_t z = s * (ct_is_zero(n & mask) & 1);
  114|  7.23M|      lb += z;
  115|  7.23M|      n >>= z;
  116|  7.23M|   }
  117|       |
  118|  1.20M|   return lb;
  119|  1.20M|}
_ZN5Botan6chooseIjEET_S1_S1_S1_:
  180|  1.28k|inline constexpr T choose(T mask, T a, T b) {
  181|       |   //return (mask & a) | (~mask & b);
  182|  1.28k|   return (b ^ (mask & (a ^ b)));
  183|  1.28k|}
_ZN5Botan8majorityIjEET_S1_S1_S1_:
  186|    640|inline constexpr T majority(T a, T b, T c) {
  187|       |   /*
  188|       |   Considering each bit of a, b, c individually
  189|       |
  190|       |   If a xor b is set, then c is the deciding vote.
  191|       |
  192|       |   If a xor b is not set then either a and b are both set or both unset.
  193|       |   In either case the value of c doesn't matter, and examining b (or a)
  194|       |   allows us to determine which case we are in.
  195|       |   */
  196|    640|   return choose(a ^ b, c, b);
  197|    640|}

_ZN5Botan13reverse_bytesEm:
   48|   525k|inline constexpr uint64_t reverse_bytes(uint64_t x) {
   49|   525k|#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap64)
   50|   525k|   return __builtin_bswap64(x);
   51|       |#else
   52|       |   uint32_t hi = static_cast<uint32_t>(x >> 32);
   53|       |   uint32_t lo = static_cast<uint32_t>(x);
   54|       |
   55|       |   hi = reverse_bytes(hi);
   56|       |   lo = reverse_bytes(lo);
   57|       |
   58|       |   return (static_cast<uint64_t>(lo) << 32) | hi;
   59|       |#endif
   60|   525k|}
_ZN5Botan13reverse_bytesEj:
   33|    192|inline constexpr uint32_t reverse_bytes(uint32_t x) {
   34|    192|#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap32)
   35|    192|   return __builtin_bswap32(x);
   36|       |#else
   37|       |   // MSVC at least recognizes this as a bswap
   38|       |   return ((x & 0x000000FF) << 24) | ((x & 0x0000FF00) << 8) | ((x & 0x00FF0000) >> 8) | ((x & 0xFF000000) >> 24);
   39|       |#endif
   40|    192|}

_ZN5Botan5CPUID13has_cpuid_bitENS0_10CPUID_bitsE:
  333|  24.5k|      static bool has_cpuid_bit(CPUID_bits elem) {
  334|  24.5k|         const uint32_t elem32 = static_cast<uint32_t>(elem);
  335|  24.5k|         return state().has_bit(elem32);
  336|  24.5k|      }
_ZN5Botan5CPUID5stateEv:
  362|  24.5k|      static CPUID_Data& state() {
  363|  24.5k|         static CPUID::CPUID_Data g_cpuid;
  364|  24.5k|         return g_cpuid;
  365|  24.5k|      }
_ZNK5Botan5CPUID10CPUID_Data7has_bitEj:
  350|  24.5k|            bool has_bit(uint32_t bit) const { return (m_processor_features & bit) == bit; }
_ZN5Botan5CPUID8has_sse2Ev:
  208|  8.19k|      static bool has_sse2() { return has_cpuid_bit(CPUID_SSE2_BIT); }
_ZN5Botan5CPUID8has_avx2Ev:
  218|  8.19k|      static bool has_avx2() { return has_cpuid_bit(CPUID_AVX2_BIT); }
_ZN5Botan5CPUID10has_avx512Ev:
  225|  8.19k|      static bool has_avx512() { return has_cpuid_bit(CPUID_AVX512_BIT); }
_ZN5Botan5CPUID8has_bmi2Ev:
  240|     10|      static bool has_bmi2() { return has_cpuid_bit(CPUID_BMI_BIT); }
_ZN5Botan5CPUID13has_intel_shaEv:
  255|     10|      static bool has_intel_sha() { return has_sse2() && has_cpuid_bit(CPUID_SHA_BIT); }
  ------------------
  |  Branch (255:44): [True: 10, False: 0]
  |  Branch (255:58): [True: 0, False: 10]
  ------------------

_ZN5Botan2CT4MaskImE8is_equalEmm:
  128|   180M|      static Mask<T> is_equal(T x, T y) { return Mask<T>::is_zero(static_cast<T>(x ^ y)); }
_ZN5Botan2CT4MaskImE5is_ltEmm:
  133|   193M|      static Mask<T> is_lt(T x, T y) { return Mask<T>(expand_top_bit<T>(x ^ ((x ^ y) | ((x - y) ^ x)))); }
_ZN5Botan2CT4MaskImEC2Em:
  280|   855M|      Mask(T m) : m_mask(m) {}
_ZNK5Botan2CT4MaskImE6selectEmm:
  228|   869M|      T select(T x, T y) const { return choose(value(), x, y); }
_ZNK5Botan2CT4MaskImE5valueEv:
  277|  1.44G|      T value() const { return m_mask; }
_ZN5Botan2CT4MaskImE7is_zeroEm:
  123|   311M|      static Mask<T> is_zero(T x) { return Mask<T>(ct_is_zero<T>(x)); }
_ZN5Botan2CT8unpoisonImEEvRT_:
   64|  42.9M|inline void unpoison(T& p) {
   65|       |#if defined(BOTAN_HAS_VALGRIND)
   66|       |   VALGRIND_MAKE_MEM_DEFINED(&p, sizeof(T));
   67|       |#else
   68|  42.9M|   BOTAN_UNUSED(p);
  ------------------
  |  |  118|  42.9M|#define BOTAN_UNUSED Botan::ignore_params
  ------------------
   69|  42.9M|#endif
   70|  42.9M|}
_ZN5Botan2CT4MaskImE6expandEm:
  109|   127M|      static Mask<T> expand(T v) { return ~Mask<T>::is_zero(v); }
_ZNK5Botan2CT4MaskImEcoEv:
  213|   156M|      Mask<T> operator~() const { return Mask<T>(~value()); }
_ZNK5Botan2CT4MaskImE11select_maskES2_S2_:
  239|   162M|      Mask<T> select_mask(Mask<T> x, Mask<T> y) const { return Mask<T>(select(x.value(), y.value())); }
_ZN5Botan2CT4MaskImEoRES2_:
  190|  1.20M|      Mask<T>& operator|=(Mask<T> o) {
  191|  1.20M|         m_mask |= o.value();
  192|  1.20M|         return (*this);
  193|  1.20M|      }
_ZN5Botan2CT4MaskImEaNES2_:
  174|  18.5k|      Mask<T>& operator&=(Mask<T> o) {
  175|  18.5k|         m_mask &= o.value();
  176|  18.5k|         return (*this);
  177|  18.5k|      }
_ZN5Botan2CT20conditional_swap_ptrIPKmEEvbRT_S5_:
  315|  93.9k|inline void conditional_swap_ptr(bool cnd, T& x, T& y) {
  316|  93.9k|   uintptr_t xp = reinterpret_cast<uintptr_t>(x);
  317|  93.9k|   uintptr_t yp = reinterpret_cast<uintptr_t>(y);
  318|       |
  319|  93.9k|   conditional_swap<uintptr_t>(cnd, xp, yp);
  320|       |
  321|  93.9k|   x = reinterpret_cast<T>(xp);
  322|  93.9k|   y = reinterpret_cast<T>(yp);
  323|  93.9k|}
_ZN5Botan2CT16conditional_swapImEEvbRT_S3_:
  305|   187k|inline void conditional_swap(bool cnd, T& x, T& y) {
  306|   187k|   const auto swap = CT::Mask<T>::expand(cnd);
  307|       |
  308|   187k|   T t0 = swap.select(y, x);
  309|   187k|   T t1 = swap.select(x, y);
  310|   187k|   x = t0;
  311|   187k|   y = t1;
  312|   187k|}
_ZNK5Botan2CT4MaskImE13if_set_returnEm:
  218|   328M|      T if_set_return(T x) const { return m_mask & x; }
_ZN5Botan2CT20conditional_copy_memImEENS0_4MaskIT_EES3_PS3_PKS3_S7_m:
  292|  3.09M|inline Mask<T> conditional_copy_mem(T cnd, T* to, const T* from0, const T* from1, size_t elems) {
  293|  3.09M|   const auto mask = CT::Mask<T>::expand(cnd);
  294|  3.09M|   return CT::conditional_copy_mem(mask, to, from0, from1, elems);
  295|  3.09M|}
_ZN5Botan2CT20conditional_copy_memImEENS0_4MaskIT_EES4_PS3_PKS3_S7_m:
  286|  3.09M|inline Mask<T> conditional_copy_mem(Mask<T> mask, T* to, const T* from0, const T* from1, size_t elems) {
  287|  3.09M|   mask.select_n(to, from0, from1, elems);
  288|  3.09M|   return mask;
  289|  3.09M|}
_ZNK5Botan2CT4MaskImE8select_nEPmPKmS5_m:
  245|  3.49M|      void select_n(T output[], const T x[], const T y[], size_t len) const {
  246|  24.5M|         for(size_t i = 0; i != len; ++i) {
  ------------------
  |  Branch (246:28): [True: 21.0M, False: 3.49M]
  ------------------
  247|  21.0M|            output[i] = this->select(x[i], y[i]);
  248|  21.0M|         }
  249|  3.49M|      }
_ZNK5Botan2CT4MaskImE7as_boolEv:
  272|  31.4M|      bool as_bool() const { return unpoisoned_value() != 0; }
_ZNK5Botan2CT4MaskImE16unpoisoned_valueEv:
  263|  31.4M|      T unpoisoned_value() const {
  264|  31.4M|         T r = value();
  265|  31.4M|         CT::unpoison(r);
  266|  31.4M|         return r;
  267|  31.4M|      }
_ZN5Botan2CT8unpoisonIKmEEvRT_:
   64|   565k|inline void unpoison(T& p) {
   65|       |#if defined(BOTAN_HAS_VALGRIND)
   66|       |   VALGRIND_MAKE_MEM_DEFINED(&p, sizeof(T));
   67|       |#else
   68|   565k|   BOTAN_UNUSED(p);
  ------------------
  |  |  118|   565k|#define BOTAN_UNUSED Botan::ignore_params
  ------------------
   69|   565k|#endif
   70|   565k|}
_ZN5Botan2CT4MaskIhE6expandEh:
  109|   158k|      static Mask<T> expand(T v) { return ~Mask<T>::is_zero(v); }
_ZN5Botan2CT4MaskIhE7is_zeroEh:
  123|   158k|      static Mask<T> is_zero(T x) { return Mask<T>(ct_is_zero<T>(x)); }
_ZN5Botan2CT4MaskIhEC2Eh:
  280|   323k|      Mask(T m) : m_mask(m) {}
_ZNK5Botan2CT4MaskIhEcoEv:
  213|   161k|      Mask<T> operator~() const { return Mask<T>(~value()); }
_ZNK5Botan2CT4MaskIhE5valueEv:
  277|   323k|      T value() const { return m_mask; }
_ZNK5Botan2CT4MaskIhE6selectEhh:
  228|   162k|      T select(T x, T y) const { return choose(value(), x, y); }
_ZN5Botan2CT4MaskImE6is_gteEmm:
  148|  29.0M|      static Mask<T> is_gte(T x, T y) { return ~Mask<T>::is_lt(x, y); }
_ZN5Botan2CTorENS0_4MaskImEES2_:
  208|  29.0M|      friend Mask<T> operator|(Mask<T> x, Mask<T> y) { return Mask<T>(x.value() | y.value()); }
_ZN5Botan2CT4MaskImE7clearedEv:
  104|   150k|      static Mask<T> cleared() { return Mask<T>(0); }
_ZNK5Botan2CT4MaskImE17if_not_set_returnEm:
  223|  1.20M|      T if_not_set_return(T x) const { return ~m_mask & x; }
_ZN5Botan2CTanENS0_4MaskImEES2_:
  198|  1.77M|      friend Mask<T> operator&(Mask<T> x, Mask<T> y) { return Mask<T>(x.value() & y.value()); }
_ZN5Botan2CT9all_zerosImEENS0_4MaskIT_EEPKS3_m:
  326|  3.55M|inline CT::Mask<T> all_zeros(const T elem[], size_t len) {
  327|  3.55M|   T sum = 0;
  328|  24.9M|   for(size_t i = 0; i != len; ++i) {
  ------------------
  |  Branch (328:22): [True: 21.3M, False: 3.55M]
  ------------------
  329|  21.3M|      sum |= elem[i];
  330|  21.3M|   }
  331|  3.55M|   return CT::Mask<T>::is_zero(sum);
  332|  3.55M|}
_ZN5Botan2CT4MaskIhE15is_within_rangeEhhh:
  150|  2.52k|      static Mask<T> is_within_range(T v, T l, T u) {
  151|       |         //return Mask<T>::is_gte(v, l) & Mask<T>::is_lte(v, u);
  152|       |
  153|  2.52k|         const T v_lt_l = v ^ ((v ^ l) | ((v - l) ^ v));
  154|  2.52k|         const T v_gt_u = u ^ ((u ^ v) | ((u - v) ^ u));
  155|  2.52k|         const T either = v_lt_l | v_gt_u;
  156|  2.52k|         return ~Mask<T>(expand_top_bit(either));
  157|  2.52k|      }
_ZN5Botan2CT4MaskIhE9is_any_ofEhSt16initializer_listIhE:
  159|    840|      static Mask<T> is_any_of(T v, std::initializer_list<T> accepted) {
  160|    840|         T accept = 0;
  161|       |
  162|  3.36k|         for(auto a : accepted) {
  ------------------
  |  Branch (162:21): [True: 3.36k, False: 840]
  ------------------
  163|  3.36k|            const T diff = a ^ v;
  164|  3.36k|            const T eq_zero = ~diff & (diff - 1);
  165|  3.36k|            accept |= eq_zero;
  166|  3.36k|         }
  167|       |
  168|    840|         return Mask<T>(expand_top_bit(accept));
  169|    840|      }
_ZN5Botan2CT4MaskImE6is_lteEmm:
  143|    128|      static Mask<T> is_lte(T x, T y) { return ~Mask<T>::is_gt(x, y); }
_ZN5Botan2CT4MaskImE5is_gtEmm:
  138|    128|      static Mask<T> is_gt(T x, T y) { return Mask<T>::is_lt(y, x); }
_ZN5Botan2CT22conditional_assign_memImEENS0_4MaskIT_EES3_PS3_PKS3_m:
  298|   392k|inline Mask<T> conditional_assign_mem(T cnd, T* sink, const T* src, size_t elems) {
  299|   392k|   const auto mask = CT::Mask<T>::expand(cnd);
  300|   392k|   mask.select_n(sink, src, sink, elems);
  301|   392k|   return mask;
  302|   392k|}
_ZN5Botan2CT8unpoisonIlEEvRT_:
   64|  65.1M|inline void unpoison(T& p) {
   65|       |#if defined(BOTAN_HAS_VALGRIND)
   66|       |   VALGRIND_MAKE_MEM_DEFINED(&p, sizeof(T));
   67|       |#else
   68|  65.1M|   BOTAN_UNUSED(p);
  ------------------
  |  |  118|  65.1M|#define BOTAN_UNUSED Botan::ignore_params
  ------------------
   69|  65.1M|#endif
   70|  65.1M|}

_ZN5Botan9ct_divideERKNS_6BigIntES2_:
   49|    838|inline BigInt ct_divide(const BigInt& x, const BigInt& y) {
   50|    838|   BigInt q, r;
   51|    838|   ct_divide(x, y, q, r);
   52|    838|   return q;
   53|    838|}

_ZN5Botan8store_beImEEvT_Ph:
  408|      4|inline constexpr void store_be(T in, uint8_t out[sizeof(T)]) {
  409|      4|   store_be(in, std::span<uint8_t, sizeof(T)>(out, sizeof(T)));
  410|      4|}
_ZN5Botan8store_beImNSt3__14spanIhLm8EEEEEvT_OT0_:
  358|      4|inline constexpr void store_be(T in, OutR&& out_range) {
  359|      4|   ranges::assert_exact_byte_length<sizeof(T)>(out_range);
  360|      4|   std::span out{out_range};
  361|      4|   if constexpr(sizeof(T) == 1) {
  ------------------
  |  Branch (361:17): [Folded - Ignored]
  ------------------
  362|      4|      out[0] = static_cast<uint8_t>(in);
  363|      4|   } else {
  364|       |#if defined(BOTAN_TARGET_CPU_IS_BIG_ENDIAN)
  365|       |      typecast_copy(out, in);
  366|       |#elif defined(BOTAN_TARGET_CPU_IS_LITTLE_ENDIAN)
  367|      4|      typecast_copy(out, reverse_bytes(in));
  368|       |#else
  369|       |      [&]<size_t... i>(std::index_sequence<i...>) {
  370|       |         ((out[i] = get_byte<i>(in)), ...);
  371|       |      }
  372|       |      (std::make_index_sequence<sizeof(T)>());
  373|       |#endif
  374|      4|   }
  375|      4|}
_ZN5Botan7load_beImEET_PKhm:
  226|   525k|inline constexpr T load_be(const uint8_t in[], size_t off) {
  227|       |   // asserts that *in points to the correct amount of memory
  228|   525k|   return load_be<T>(std::span<const uint8_t, sizeof(T)>(in + off * sizeof(T), sizeof(T)));
  229|   525k|}
_ZN5Botan7load_beImNSt3__14spanIKhLm8EEEEET_OT0_:
   92|   525k|inline constexpr T load_be(InR&& in_range) {
   93|   525k|   ranges::assert_exact_byte_length<sizeof(T)>(in_range);
   94|   525k|   std::span in{in_range};
   95|   525k|   if constexpr(sizeof(T) == 1) {
  ------------------
  |  Branch (95:17): [Folded - Ignored]
  ------------------
   96|   525k|      return static_cast<T>(in[0]);
   97|   525k|   } else {
   98|       |#if defined(BOTAN_TARGET_CPU_IS_BIG_ENDIAN)
   99|       |      return typecast_copy<T>(in);
  100|       |#elif defined(BOTAN_TARGET_CPU_IS_LITTLE_ENDIAN)
  101|   525k|      return reverse_bytes(typecast_copy<T>(in));
  102|       |#else
  103|       |      return [&]<size_t... i>(std::index_sequence<i...>) {
  104|       |         return ((static_cast<T>(in[i]) << ((sizeof(T) - i - 1) * 8)) | ...);
  105|       |      }
  106|       |      (std::make_index_sequence<sizeof(T)>());
  107|       |#endif
  108|   525k|   }
  109|   525k|}
_ZN5Botan8store_beIjEEvT_Ph:
  408|     32|inline constexpr void store_be(T in, uint8_t out[sizeof(T)]) {
  409|     32|   store_be(in, std::span<uint8_t, sizeof(T)>(out, sizeof(T)));
  410|     32|}
_ZN5Botan8store_beIjNSt3__14spanIhLm4EEEEEvT_OT0_:
  358|     32|inline constexpr void store_be(T in, OutR&& out_range) {
  359|     32|   ranges::assert_exact_byte_length<sizeof(T)>(out_range);
  360|     32|   std::span out{out_range};
  361|     32|   if constexpr(sizeof(T) == 1) {
  ------------------
  |  Branch (361:17): [Folded - Ignored]
  ------------------
  362|     32|      out[0] = static_cast<uint8_t>(in);
  363|     32|   } else {
  364|       |#if defined(BOTAN_TARGET_CPU_IS_BIG_ENDIAN)
  365|       |      typecast_copy(out, in);
  366|       |#elif defined(BOTAN_TARGET_CPU_IS_LITTLE_ENDIAN)
  367|     32|      typecast_copy(out, reverse_bytes(in));
  368|       |#else
  369|       |      [&]<size_t... i>(std::index_sequence<i...>) {
  370|       |         ((out[i] = get_byte<i>(in)), ...);
  371|       |      }
  372|       |      (std::make_index_sequence<sizeof(T)>());
  373|       |#endif
  374|     32|   }
  375|     32|}
_ZN5Botan7load_beIjNSt3__14spanIKhLm4EEEEET_OT0_:
   92|    160|inline constexpr T load_be(InR&& in_range) {
   93|    160|   ranges::assert_exact_byte_length<sizeof(T)>(in_range);
   94|    160|   std::span in{in_range};
   95|    160|   if constexpr(sizeof(T) == 1) {
  ------------------
  |  Branch (95:17): [Folded - Ignored]
  ------------------
   96|    160|      return static_cast<T>(in[0]);
   97|    160|   } else {
   98|       |#if defined(BOTAN_TARGET_CPU_IS_BIG_ENDIAN)
   99|       |      return typecast_copy<T>(in);
  100|       |#elif defined(BOTAN_TARGET_CPU_IS_LITTLE_ENDIAN)
  101|    160|      return reverse_bytes(typecast_copy<T>(in));
  102|       |#else
  103|       |      return [&]<size_t... i>(std::index_sequence<i...>) {
  104|       |         return ((static_cast<T>(in[i]) << ((sizeof(T) - i - 1) * 8)) | ...);
  105|       |      }
  106|       |      (std::make_index_sequence<sizeof(T)>());
  107|       |#endif
  108|    160|   }
  109|    160|}
_ZN5Botan7load_beIjEET_PKhm:
  226|    160|inline constexpr T load_be(const uint8_t in[], size_t off) {
  227|       |   // asserts that *in points to the correct amount of memory
  228|    160|   return load_be<T>(std::span<const uint8_t, sizeof(T)>(in + off * sizeof(T), sizeof(T)));
  229|    160|}
_ZN5Botan7load_leIjEEvPT_PKhm:
  310|      2|inline constexpr void load_le(T out[], const uint8_t in[], size_t count) {
  311|      2|   if(count > 0) {
  ------------------
  |  Branch (311:7): [True: 2, False: 0]
  ------------------
  312|      2|#if defined(BOTAN_TARGET_CPU_IS_LITTLE_ENDIAN)
  313|      2|      typecast_copy(out, in, count);
  314|       |
  315|       |#elif defined(BOTAN_TARGET_CPU_IS_BIG_ENDIAN)
  316|       |      typecast_copy(out, in, count);
  317|       |
  318|       |      for(size_t i = 0; i != count; ++i)
  319|       |         out[i] = reverse_bytes(out[i]);
  320|       |#else
  321|       |      for(size_t i = 0; i != count; ++i)
  322|       |         out[i] = load_le<T>(in, i);
  323|       |#endif
  324|      2|   }
  325|      2|}
_ZN5Botan15copy_out_vec_beIjNS_16secure_allocatorIjEEEEvPhmRKNSt3__16vectorIT_T0_EE:
  521|      4|void copy_out_vec_be(uint8_t out[], size_t out_bytes, const std::vector<T, Alloc>& in) {
  522|      4|   copy_out_be(out, out_bytes, in.data());
  523|      4|}
_ZN5Botan11copy_out_beIjEEvPhmPKT_:
  507|      4|void copy_out_be(uint8_t out[], size_t out_bytes, const T in[]) {
  508|     36|   while(out_bytes >= sizeof(T)) {
  ------------------
  |  Branch (508:10): [True: 32, False: 4]
  ------------------
  509|     32|      store_be(in[0], out);
  510|     32|      out += sizeof(T);
  511|     32|      out_bytes -= sizeof(T);
  512|     32|      in += 1;
  513|     32|   }
  514|       |
  515|      4|   for(size_t i = 0; i != out_bytes; ++i) {
  ------------------
  |  Branch (515:22): [True: 0, False: 4]
  ------------------
  516|      0|      out[i] = get_byte_var(i % 8, in[0]);
  517|      0|   }
  518|      4|}

_ZN5Botan18MerkleDamgard_HashINS_7SHA_256EEC2Ev:
   42|      1|      MerkleDamgard_Hash() { clear(); }
_ZN5Botan18MerkleDamgard_HashINS_7SHA_256EE5clearEv:
   70|      7|      void clear() {
   71|      7|         MD::init(m_digest);
   72|      7|         m_buffer.clear();
   73|      7|         m_count = 0;
   74|      7|      }
_ZN5Botan18MerkleDamgard_HashINS_7SHA_256EE6updateENSt3__14spanIKhLm18446744073709551615EEE:
   44|      9|      void update(std::span<const uint8_t> input) {
   45|      9|         BufferSlicer in(input);
   46|       |
   47|     18|         while(!in.empty()) {
  ------------------
  |  Branch (47:16): [True: 9, False: 9]
  ------------------
   48|      9|            if(const auto one_block = m_buffer.handle_unaligned_data(in)) {
  ------------------
  |  Branch (48:27): [True: 0, False: 9]
  ------------------
   49|      0|               MD::compress_n(m_digest, one_block.value(), 1);
   50|      0|            }
   51|       |
   52|      9|            if(m_buffer.in_alignment()) {
  ------------------
  |  Branch (52:16): [True: 6, False: 3]
  ------------------
   53|      6|               const auto [aligned_data, full_blocks] = m_buffer.aligned_data_to_process(in);
   54|      6|               if(full_blocks > 0) {
  ------------------
  |  Branch (54:19): [True: 6, False: 0]
  ------------------
   55|      6|                  MD::compress_n(m_digest, aligned_data, full_blocks);
   56|      6|               }
   57|      6|            }
   58|      9|         }
   59|       |
   60|      9|         m_count += input.size();
   61|      9|      }
_ZN5Botan18MerkleDamgard_HashINS_7SHA_256EE5finalENSt3__14spanIhLm18446744073709551615EEE:
   63|      4|      void final(std::span<uint8_t> output) {
   64|      4|         append_padding_bit();
   65|      4|         append_counter_and_finalize();
   66|      4|         copy_output(output);
   67|      4|         clear();
   68|      4|      }
_ZN5Botan18MerkleDamgard_HashINS_7SHA_256EE18append_padding_bitEv:
   77|      4|      void append_padding_bit() {
   78|      4|         BOTAN_ASSERT_NOMSG(!m_buffer.ready_to_consume());
  ------------------
  |  |   60|      4|   do {                                                                     \
  |  |   61|      4|      if(!(expr))                                                           \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 4]
  |  |  ------------------
  |  |   62|      4|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   63|      4|   } while(0)
  |  |  ------------------
  |  |  |  Branch (63:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   79|      4|         if constexpr(MD::bit_endianness == MD_Endian::Big) {
  ------------------
  |  Branch (79:23): [Folded - Ignored]
  ------------------
   80|      4|            const uint8_t final_byte = 0x80;
   81|      4|            m_buffer.append({&final_byte, 1});
   82|      4|         } else {
   83|      4|            const uint8_t final_byte = 0x01;
   84|      4|            m_buffer.append({&final_byte, 1});
   85|      4|         }
   86|      4|      }
_ZN5Botan18MerkleDamgard_HashINS_7SHA_256EE27append_counter_and_finalizeEv:
   88|      4|      void append_counter_and_finalize() {
   89|       |         // Compress the remaining data if the final data block does not provide
   90|       |         // enough space for the counter bytes.
   91|      4|         if(m_buffer.elements_until_alignment() < MD::ctr_bytes) {
  ------------------
  |  Branch (91:13): [True: 0, False: 4]
  ------------------
   92|      0|            m_buffer.fill_up_with_zeros();
   93|      0|            MD::compress_n(m_digest, m_buffer.consume(), 1);
   94|      0|         }
   95|       |
   96|       |         // Make sure that any remaining bytes in the very last block are zero.
   97|      4|         BOTAN_ASSERT_NOMSG(m_buffer.elements_until_alignment() >= MD::ctr_bytes);
  ------------------
  |  |   60|      4|   do {                                                                     \
  |  |   61|      4|      if(!(expr))                                                           \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 4]
  |  |  ------------------
  |  |   62|      4|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   63|      4|   } while(0)
  |  |  ------------------
  |  |  |  Branch (63:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   98|      4|         m_buffer.fill_up_with_zeros();
   99|       |
  100|       |         // Replace a bunch of the right-most zero-padding with the counter bytes.
  101|      4|         const uint64_t bit_count = m_count * 8;
  102|      4|         auto last_bytes = m_buffer.directly_modify_last(sizeof(bit_count));
  103|      4|         if constexpr(MD::byte_endianness == MD_Endian::Big) {
  ------------------
  |  Branch (103:23): [Folded - Ignored]
  ------------------
  104|      4|            store_be(bit_count, last_bytes.data());
  105|      4|         } else {
  106|      4|            store_le(bit_count, last_bytes.data());
  107|      4|         }
  108|       |
  109|       |         // Compress the very last block.
  110|      4|         MD::compress_n(m_digest, m_buffer.consume(), 1);
  111|      4|      }
_ZN5Botan18MerkleDamgard_HashINS_7SHA_256EE11copy_outputENSt3__14spanIhLm18446744073709551615EEE:
  113|      4|      void copy_output(std::span<uint8_t> output) {
  114|      4|         BOTAN_ASSERT_NOMSG(output.size() >= MD::output_bytes);
  ------------------
  |  |   60|      4|   do {                                                                     \
  |  |   61|      4|      if(!(expr))                                                           \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 4]
  |  |  ------------------
  |  |   62|      4|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   63|      4|   } while(0)
  |  |  ------------------
  |  |  |  Branch (63:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  115|       |
  116|      4|         if constexpr(MD::byte_endianness == MD_Endian::Big) {
  ------------------
  |  Branch (116:23): [Folded - Ignored]
  ------------------
  117|      4|            copy_out_vec_be(output.data(), MD::output_bytes, m_digest);
  118|      4|         } else {
  119|      4|            copy_out_vec_le(output.data(), MD::output_bytes, m_digest);
  120|      4|         }
  121|      4|      }

_ZNK5Botan14Montgomery_Int19const_time_unpoisonEv:
  124|    837|      void const_time_unpoison() const { return m_v.const_time_unpoison(); }
_ZNK5Botan17Montgomery_Params1pEv:
  148|  1.67k|      const BigInt& p() const { return m_p; }
_ZNK5Botan17Montgomery_Params2R1Ev:
  150|    837|      const BigInt& R1() const { return m_r1; }
_ZNK5Botan17Montgomery_Params2R2Ev:
  152|    837|      const BigInt& R2() const { return m_r2; }
_ZNK5Botan17Montgomery_Params7p_wordsEv:
  158|  13.3k|      size_t p_words() const { return m_p_words; }

_ZN5Botan17monty_exp_vartimeERKNSt3__110shared_ptrIKNS_17Montgomery_ParamsEEERKNS_6BigIntES9_:
   51|    837|                                const BigInt& k) {
   52|    837|   auto precomputed = monty_precompute(params_p, g, 4, false);
   53|    837|   return monty_execute_vartime(*precomputed, k);
   54|    837|}

_ZN5Botan10word8_add2EPmPKmm:
  265|  10.8k|inline word word8_add2(word x[8], const word y[8], word carry) {
  266|       |#if defined(BOTAN_MP_USE_X86_32_ASM)
  267|       |   asm(ADD_OR_SUBTRACT(DO_8_TIMES(ADDSUB2_OP, "adcl"))
  268|       |       : [carry] "=r"(carry)
  269|       |       : [x] "r"(x), [y] "r"(y), "0"(carry)
  270|       |       : "cc", "memory");
  271|       |
  272|       |#elif defined(BOTAN_MP_USE_X86_64_ASM)
  273|       |
  274|  10.8k|   asm(ADD_OR_SUBTRACT(DO_8_TIMES(ADDSUB2_OP, "adcq"))
  275|  10.8k|       : [carry] "=r"(carry)
  276|  10.8k|       : [x] "r"(x), [y] "r"(y), "0"(carry)
  277|  10.8k|       : "cc", "memory");
  278|       |
  279|       |#else
  280|       |   x[0] = word_add(x[0], y[0], &carry);
  281|       |   x[1] = word_add(x[1], y[1], &carry);
  282|       |   x[2] = word_add(x[2], y[2], &carry);
  283|       |   x[3] = word_add(x[3], y[3], &carry);
  284|       |   x[4] = word_add(x[4], y[4], &carry);
  285|       |   x[5] = word_add(x[5], y[5], &carry);
  286|       |   x[6] = word_add(x[6], y[6], &carry);
  287|       |   x[7] = word_add(x[7], y[7], &carry);
  288|       |#endif
  289|       |
  290|  10.8k|   return carry;
  291|  10.8k|}
_ZN5Botan8word_addEmmPm:
  237|   636M|inline word word_add(word x, word y, word* carry) {
  238|       |#if defined(BOTAN_MP_USE_X86_32_ASM)
  239|       |   asm(ADD_OR_SUBTRACT(ASM("adcl %[y],%[x]"))
  240|       |       : [x] "=r"(x), [carry] "=r"(*carry)
  241|       |       : "0"(x), [y] "rm"(y), "1"(*carry)
  242|       |       : "cc");
  243|       |   return x;
  244|       |
  245|       |#elif defined(BOTAN_MP_USE_X86_64_ASM)
  246|       |
  247|   636M|   asm(ADD_OR_SUBTRACT(ASM("adcq %[y],%[x]"))
  248|   636M|       : [x] "=r"(x), [carry] "=r"(*carry)
  249|   636M|       : "0"(x), [y] "rm"(y), "1"(*carry)
  250|   636M|       : "cc");
  251|   636M|   return x;
  252|       |
  253|       |#else
  254|       |   word z = x + y;
  255|       |   word c1 = (z < x);
  256|       |   z += *carry;
  257|       |   *carry = c1 | (z < *carry);
  258|       |   return z;
  259|       |#endif
  260|   636M|}
_ZN5Botan10word8_sub2EPmPKmm:
  353|    835|inline word word8_sub2(word x[8], const word y[8], word carry) {
  354|       |#if defined(BOTAN_MP_USE_X86_32_ASM)
  355|       |   asm(ADD_OR_SUBTRACT(DO_8_TIMES(ADDSUB2_OP, "sbbl"))
  356|       |       : [carry] "=r"(carry)
  357|       |       : [x] "r"(x), [y] "r"(y), "0"(carry)
  358|       |       : "cc", "memory");
  359|       |
  360|       |#elif defined(BOTAN_MP_USE_X86_64_ASM)
  361|    835|   asm(ADD_OR_SUBTRACT(DO_8_TIMES(ADDSUB2_OP, "sbbq"))
  362|    835|       : [carry] "=r"(carry)
  363|    835|       : [x] "r"(x), [y] "r"(y), "0"(carry)
  364|    835|       : "cc", "memory");
  365|       |
  366|       |#else
  367|       |   x[0] = word_sub(x[0], y[0], &carry);
  368|       |   x[1] = word_sub(x[1], y[1], &carry);
  369|       |   x[2] = word_sub(x[2], y[2], &carry);
  370|       |   x[3] = word_sub(x[3], y[3], &carry);
  371|       |   x[4] = word_sub(x[4], y[4], &carry);
  372|       |   x[5] = word_sub(x[5], y[5], &carry);
  373|       |   x[6] = word_sub(x[6], y[6], &carry);
  374|       |   x[7] = word_sub(x[7], y[7], &carry);
  375|       |#endif
  376|       |
  377|    835|   return carry;
  378|    835|}
_ZN5Botan8word_subEmmPm:
  326|  1.05G|inline word word_sub(word x, word y, word* carry) {
  327|       |#if defined(BOTAN_MP_USE_X86_32_ASM)
  328|       |   asm(ADD_OR_SUBTRACT(ASM("sbbl %[y],%[x]"))
  329|       |       : [x] "=r"(x), [carry] "=r"(*carry)
  330|       |       : "0"(x), [y] "rm"(y), "1"(*carry)
  331|       |       : "cc");
  332|       |   return x;
  333|       |
  334|       |#elif defined(BOTAN_MP_USE_X86_64_ASM)
  335|  1.05G|   asm(ADD_OR_SUBTRACT(ASM("sbbq %[y],%[x]"))
  336|  1.05G|       : [x] "=r"(x), [carry] "=r"(*carry)
  337|  1.05G|       : "0"(x), [y] "rm"(y), "1"(*carry)
  338|  1.05G|       : "cc");
  339|  1.05G|   return x;
  340|       |
  341|       |#else
  342|       |   word t0 = x - y;
  343|       |   word c1 = (t0 > x);
  344|       |   word z = t0 - *carry;
  345|       |   *carry = c1 | (z > t0);
  346|       |   return z;
  347|       |#endif
  348|  1.05G|}
_ZN5Botan14word8_sub2_revEPmPKmm:
  383|     82|inline word word8_sub2_rev(word x[8], const word y[8], word carry) {
  384|       |#if defined(BOTAN_MP_USE_X86_32_ASM)
  385|       |   asm(ADD_OR_SUBTRACT(DO_8_TIMES(ADDSUB3_OP, "sbbl"))
  386|       |       : [carry] "=r"(carry)
  387|       |       : [x] "r"(y), [y] "r"(x), [z] "r"(x), "0"(carry)
  388|       |       : "cc", "memory");
  389|       |
  390|       |#elif defined(BOTAN_MP_USE_X86_64_ASM)
  391|     82|   asm(ADD_OR_SUBTRACT(DO_8_TIMES(ADDSUB3_OP, "sbbq"))
  392|     82|       : [carry] "=r"(carry)
  393|     82|       : [x] "r"(y), [y] "r"(x), [z] "r"(x), "0"(carry)
  394|     82|       : "cc", "memory");
  395|       |
  396|       |#else
  397|       |   x[0] = word_sub(y[0], x[0], &carry);
  398|       |   x[1] = word_sub(y[1], x[1], &carry);
  399|       |   x[2] = word_sub(y[2], x[2], &carry);
  400|       |   x[3] = word_sub(y[3], x[3], &carry);
  401|       |   x[4] = word_sub(y[4], x[4], &carry);
  402|       |   x[5] = word_sub(y[5], x[5], &carry);
  403|       |   x[6] = word_sub(y[6], x[6], &carry);
  404|       |   x[7] = word_sub(y[7], x[7], &carry);
  405|       |#endif
  406|       |
  407|     82|   return carry;
  408|     82|}
_ZN5Botan10word8_sub3EPmPKmS2_m:
  413|    380|inline word word8_sub3(word z[8], const word x[8], const word y[8], word carry) {
  414|       |#if defined(BOTAN_MP_USE_X86_32_ASM)
  415|       |   asm(ADD_OR_SUBTRACT(DO_8_TIMES(ADDSUB3_OP, "sbbl"))
  416|       |       : [carry] "=r"(carry)
  417|       |       : [x] "r"(x), [y] "r"(y), [z] "r"(z), "0"(carry)
  418|       |       : "cc", "memory");
  419|       |
  420|       |#elif defined(BOTAN_MP_USE_X86_64_ASM)
  421|    380|   asm(ADD_OR_SUBTRACT(DO_8_TIMES(ADDSUB3_OP, "sbbq"))
  422|    380|       : [carry] "=r"(carry)
  423|    380|       : [x] "r"(x), [y] "r"(y), [z] "r"(z), "0"(carry)
  424|    380|       : "cc", "memory");
  425|       |
  426|       |#else
  427|       |   z[0] = word_sub(x[0], y[0], &carry);
  428|       |   z[1] = word_sub(x[1], y[1], &carry);
  429|       |   z[2] = word_sub(x[2], y[2], &carry);
  430|       |   z[3] = word_sub(x[3], y[3], &carry);
  431|       |   z[4] = word_sub(x[4], y[4], &carry);
  432|       |   z[5] = word_sub(x[5], y[5], &carry);
  433|       |   z[6] = word_sub(x[6], y[6], &carry);
  434|       |   z[7] = word_sub(x[7], y[7], &carry);
  435|       |#endif
  436|       |
  437|    380|   return carry;
  438|    380|}
_ZN5Botan13word8_linmul3EPmPKmmm:
  467|    599|inline word word8_linmul3(word z[8], const word x[8], word y, word carry) {
  468|       |#if defined(BOTAN_MP_USE_X86_32_ASM)
  469|       |   asm(DO_8_TIMES(LINMUL_OP, "z")
  470|       |       : [carry] "=r"(carry)
  471|       |       : [z] "r"(z), [x] "r"(x), [y] "rm"(y), "0"(carry)
  472|       |       : "cc", "%eax", "%edx");
  473|       |
  474|       |#elif defined(BOTAN_MP_USE_X86_64_ASM)
  475|    599|   asm(DO_8_TIMES(LINMUL_OP, "z")
  476|    599|       : [carry] "=r"(carry)
  477|    599|       : [z] "r"(z), [x] "r"(x), [y] "rm"(y), "0"(carry)
  478|    599|       : "cc", "%rax", "%rdx");
  479|       |
  480|       |#else
  481|       |   z[0] = word_madd2(x[0], y, &carry);
  482|       |   z[1] = word_madd2(x[1], y, &carry);
  483|       |   z[2] = word_madd2(x[2], y, &carry);
  484|       |   z[3] = word_madd2(x[3], y, &carry);
  485|       |   z[4] = word_madd2(x[4], y, &carry);
  486|       |   z[5] = word_madd2(x[5], y, &carry);
  487|       |   z[6] = word_madd2(x[6], y, &carry);
  488|       |   z[7] = word_madd2(x[7], y, &carry);
  489|       |#endif
  490|       |
  491|    599|   return carry;
  492|    599|}
_ZN5Botan10word_madd2EmmPm:
   44|  24.5M|inline word word_madd2(word a, word b, word* c) {
   45|       |#if defined(BOTAN_MP_USE_X86_32_ASM)
   46|       |   asm(R"(
   47|       |      mull %[b]
   48|       |      addl %[c],%[a]
   49|       |      adcl $0,%[carry]
   50|       |      )"
   51|       |       : [a] "=a"(a), [b] "=rm"(b), [carry] "=&d"(*c)
   52|       |       : "0"(a), "1"(b), [c] "g"(*c)
   53|       |       : "cc");
   54|       |
   55|       |   return a;
   56|       |
   57|       |#elif defined(BOTAN_MP_USE_X86_64_ASM)
   58|  24.5M|   asm(R"(
   59|  24.5M|      mulq %[b]
   60|  24.5M|      addq %[c],%[a]
   61|  24.5M|      adcq $0,%[carry]
   62|  24.5M|      )"
   63|  24.5M|       : [a] "=a"(a), [b] "=rm"(b), [carry] "=&d"(*c)
   64|  24.5M|       : "0"(a), "1"(b), [c] "g"(*c)
   65|  24.5M|       : "cc");
   66|       |
   67|  24.5M|   return a;
   68|       |
   69|       |#elif defined(BOTAN_MP_DWORD)
   70|       |   const BOTAN_MP_DWORD s = static_cast<BOTAN_MP_DWORD>(a) * b + *c;
   71|       |   *c = static_cast<word>(s >> BOTAN_MP_WORD_BITS);
   72|       |   return static_cast<word>(s);
   73|       |#else
   74|       |   static_assert(BOTAN_MP_WORD_BITS == 64, "Unexpected word size");
   75|       |
   76|       |   word hi = 0, lo = 0;
   77|       |
   78|       |   mul64x64_128(a, b, &lo, &hi);
   79|       |
   80|       |   lo += *c;
   81|       |   hi += (lo < *c);  // carry?
   82|       |
   83|       |   *c = hi;
   84|       |   return lo;
   85|       |#endif
   86|  24.5M|}
_ZN5Botan13word8_linmul2EPmmm:
  443|  21.4M|inline word word8_linmul2(word x[8], word y, word carry) {
  444|       |#if defined(BOTAN_MP_USE_X86_32_ASM)
  445|       |   asm(DO_8_TIMES(LINMUL_OP, "x") : [carry] "=r"(carry) : [x] "r"(x), [y] "rm"(y), "0"(carry) : "cc", "%eax", "%edx");
  446|       |
  447|       |#elif defined(BOTAN_MP_USE_X86_64_ASM)
  448|  21.4M|   asm(DO_8_TIMES(LINMUL_OP, "x") : [carry] "=r"(carry) : [x] "r"(x), [y] "rm"(y), "0"(carry) : "cc", "%rax", "%rdx");
  449|       |
  450|       |#else
  451|       |   x[0] = word_madd2(x[0], y, &carry);
  452|       |   x[1] = word_madd2(x[1], y, &carry);
  453|       |   x[2] = word_madd2(x[2], y, &carry);
  454|       |   x[3] = word_madd2(x[3], y, &carry);
  455|       |   x[4] = word_madd2(x[4], y, &carry);
  456|       |   x[5] = word_madd2(x[5], y, &carry);
  457|       |   x[6] = word_madd2(x[6], y, &carry);
  458|       |   x[7] = word_madd2(x[7], y, &carry);
  459|       |#endif
  460|       |
  461|  21.4M|   return carry;
  462|  21.4M|}
_ZN5Botan10word_madd3EmmmPm:
   91|  31.8k|inline word word_madd3(word a, word b, word c, word* d) {
   92|       |#if defined(BOTAN_MP_USE_X86_32_ASM)
   93|       |   asm(R"(
   94|       |      mull %[b]
   95|       |
   96|       |      addl %[c],%[a]
   97|       |      adcl $0,%[carry]
   98|       |
   99|       |      addl %[d],%[a]
  100|       |      adcl $0,%[carry]
  101|       |      )"
  102|       |       : [a] "=a"(a), [b] "=rm"(b), [carry] "=&d"(*d)
  103|       |       : "0"(a), "1"(b), [c] "g"(c), [d] "g"(*d)
  104|       |       : "cc");
  105|       |
  106|       |   return a;
  107|       |
  108|       |#elif defined(BOTAN_MP_USE_X86_64_ASM)
  109|  31.8k|   asm(R"(
  110|  31.8k|      mulq %[b]
  111|  31.8k|
  112|  31.8k|      addq %[c],%[a]
  113|  31.8k|      adcq $0,%[carry]
  114|  31.8k|
  115|  31.8k|      addq %[d],%[a]
  116|  31.8k|      adcq $0,%[carry]
  117|  31.8k|      )"
  118|  31.8k|       : [a] "=a"(a), [b] "=rm"(b), [carry] "=&d"(*d)
  119|  31.8k|       : "0"(a), "1"(b), [c] "g"(c), [d] "g"(*d)
  120|  31.8k|       : "cc");
  121|       |
  122|  31.8k|   return a;
  123|       |
  124|       |#elif defined(BOTAN_MP_DWORD)
  125|       |   const BOTAN_MP_DWORD s = static_cast<BOTAN_MP_DWORD>(a) * b + c + *d;
  126|       |   *d = static_cast<word>(s >> BOTAN_MP_WORD_BITS);
  127|       |   return static_cast<word>(s);
  128|       |#else
  129|       |   static_assert(BOTAN_MP_WORD_BITS == 64, "Unexpected word size");
  130|       |
  131|       |   word hi = 0, lo = 0;
  132|       |
  133|       |   mul64x64_128(a, b, &lo, &hi);
  134|       |
  135|       |   lo += c;
  136|       |   hi += (lo < c);  // carry?
  137|       |
  138|       |   lo += *d;
  139|       |   hi += (lo < *d);  // carry?
  140|       |
  141|       |   *d = hi;
  142|       |   return lo;
  143|       |#endif
  144|  31.8k|}
_ZN5Botan11word8_madd3EPmPKmmm:
  497|    265|inline word word8_madd3(word z[8], const word x[8], word y, word carry) {
  498|       |#if defined(BOTAN_MP_USE_X86_32_ASM)
  499|       |   asm(DO_8_TIMES(MULADD_OP, "")
  500|       |       : [carry] "=r"(carry)
  501|       |       : [z] "r"(z), [x] "r"(x), [y] "rm"(y), "0"(carry)
  502|       |       : "cc", "%eax", "%edx");
  503|       |
  504|       |#elif defined(BOTAN_MP_USE_X86_64_ASM)
  505|    265|   asm(DO_8_TIMES(MULADD_OP, "")
  506|    265|       : [carry] "=r"(carry)
  507|    265|       : [z] "r"(z), [x] "r"(x), [y] "rm"(y), "0"(carry)
  508|    265|       : "cc", "%rax", "%rdx");
  509|       |
  510|       |#else
  511|       |   z[0] = word_madd3(x[0], y, z[0], &carry);
  512|       |   z[1] = word_madd3(x[1], y, z[1], &carry);
  513|       |   z[2] = word_madd3(x[2], y, z[2], &carry);
  514|       |   z[3] = word_madd3(x[3], y, z[3], &carry);
  515|       |   z[4] = word_madd3(x[4], y, z[4], &carry);
  516|       |   z[5] = word_madd3(x[5], y, z[5], &carry);
  517|       |   z[6] = word_madd3(x[6], y, z[6], &carry);
  518|       |   z[7] = word_madd3(x[7], y, z[7], &carry);
  519|       |#endif
  520|       |
  521|    265|   return carry;
  522|    265|}
_ZN5Botan12word3_muladdEPmS0_S0_mm:
  528|  1.31G|inline void word3_muladd(word* w2, word* w1, word* w0, word x, word y) {
  529|       |#if defined(BOTAN_MP_USE_X86_32_ASM)
  530|       |   word z0 = 0, z1 = 0;
  531|       |
  532|       |   asm("mull %[y]" : "=a"(z0), "=d"(z1) : "a"(x), [y] "rm"(y) : "cc");
  533|       |
  534|       |   asm(R"(
  535|       |       addl %[z0],%[w0]
  536|       |       adcl %[z1],%[w1]
  537|       |       adcl $0,%[w2]
  538|       |       )"
  539|       |       : [w0] "=r"(*w0), [w1] "=r"(*w1), [w2] "=r"(*w2)
  540|       |       : [z0] "r"(z0), [z1] "r"(z1), "0"(*w0), "1"(*w1), "2"(*w2)
  541|       |       : "cc");
  542|       |
  543|       |#elif defined(BOTAN_MP_USE_X86_64_ASM)
  544|  1.31G|   word z0 = 0, z1 = 0;
  545|       |
  546|  1.31G|   asm("mulq %[y]" : "=a"(z0), "=d"(z1) : "a"(x), [y] "rm"(y) : "cc");
  547|       |
  548|  1.31G|   asm(R"(
  549|  1.31G|       addq %[z0],%[w0]
  550|  1.31G|       adcq %[z1],%[w1]
  551|  1.31G|       adcq $0,%[w2]
  552|  1.31G|       )"
  553|  1.31G|       : [w0] "=r"(*w0), [w1] "=r"(*w1), [w2] "=r"(*w2)
  554|  1.31G|       : [z0] "r"(z0), [z1] "r"(z1), "0"(*w0), "1"(*w1), "2"(*w2)
  555|  1.31G|       : "cc");
  556|       |
  557|       |#else
  558|       |   word carry = *w0;
  559|       |   *w0 = word_madd2(x, y, &carry);
  560|       |   *w1 += carry;
  561|       |   *w2 += (*w1 < carry);
  562|       |#endif
  563|  1.31G|}
_ZN5Botan9word3_addEPmS0_S0_m:
  569|  4.31M|inline void word3_add(word* w2, word* w1, word* w0, word x) {
  570|       |#if defined(BOTAN_MP_USE_X86_32_ASM)
  571|       |   asm(R"(
  572|       |      addl %[x],%[w0]
  573|       |      adcl $0,%[w1]
  574|       |      adcl $0,%[w2]
  575|       |      )"
  576|       |       : [w0] "=r"(*w0), [w1] "=r"(*w1), [w2] "=r"(*w2)
  577|       |       : [x] "r"(x), "0"(*w0), "1"(*w1), "2"(*w2)
  578|       |       : "cc");
  579|       |
  580|       |#elif defined(BOTAN_MP_USE_X86_64_ASM)
  581|  4.31M|   asm(R"(
  582|  4.31M|      addq %[x],%[w0]
  583|  4.31M|      adcq $0,%[w1]
  584|  4.31M|      adcq $0,%[w2]
  585|  4.31M|      )"
  586|  4.31M|       : [w0] "=r"(*w0), [w1] "=r"(*w1), [w2] "=r"(*w2)
  587|  4.31M|       : [x] "r"(x), "0"(*w0), "1"(*w1), "2"(*w2)
  588|  4.31M|       : "cc");
  589|       |
  590|       |#else
  591|       |   *w0 += x;
  592|       |   word c1 = (*w0 < x);
  593|       |   *w1 += c1;
  594|       |   word c2 = (*w1 < c1);
  595|       |   *w2 += c2;
  596|       |#endif
  597|  4.31M|}
_ZN5Botan14word3_muladd_2EPmS0_S0_mm:
  603|   528M|inline void word3_muladd_2(word* w2, word* w1, word* w0, word x, word y) {
  604|       |#if defined(BOTAN_MP_USE_X86_32_ASM)
  605|       |   word z0 = 0, z1 = 0;
  606|       |
  607|       |   asm("mull %[y]" : "=a"(z0), "=d"(z1) : "a"(x), [y] "rm"(y) : "cc");
  608|       |
  609|       |   asm(R"(
  610|       |      addl %[z0],%[w0]
  611|       |      adcl %[z1],%[w1]
  612|       |      adcl $0,%[w2]
  613|       |
  614|       |      addl %[z0],%[w0]
  615|       |      adcl %[z1],%[w1]
  616|       |      adcl $0,%[w2]
  617|       |      )"
  618|       |       : [w0] "=r"(*w0), [w1] "=r"(*w1), [w2] "=r"(*w2)
  619|       |       : [z0] "r"(z0), [z1] "r"(z1), "0"(*w0), "1"(*w1), "2"(*w2)
  620|       |       : "cc");
  621|       |
  622|       |#elif defined(BOTAN_MP_USE_X86_64_ASM)
  623|   528M|   word z0 = 0, z1 = 0;
  624|       |
  625|   528M|   asm("mulq %[y]" : "=a"(z0), "=d"(z1) : "a"(x), [y] "rm"(y) : "cc");
  626|       |
  627|   528M|   asm(R"(
  628|   528M|      addq %[z0],%[w0]
  629|   528M|      adcq %[z1],%[w1]
  630|   528M|      adcq $0,%[w2]
  631|   528M|
  632|   528M|      addq %[z0],%[w0]
  633|   528M|      adcq %[z1],%[w1]
  634|   528M|      adcq $0,%[w2]
  635|   528M|      )"
  636|   528M|       : [w0] "=r"(*w0), [w1] "=r"(*w1), [w2] "=r"(*w2)
  637|   528M|       : [z0] "r"(z0), [z1] "r"(z1), "0"(*w0), "1"(*w1), "2"(*w2)
  638|   528M|       : "cc");
  639|       |
  640|       |#else
  641|       |   word carry = 0;
  642|       |   x = word_madd2(x, y, &carry);
  643|       |   y = carry;
  644|       |
  645|       |   word top = (y >> (BOTAN_MP_WORD_BITS - 1));
  646|       |   y <<= 1;
  647|       |   y |= (x >> (BOTAN_MP_WORD_BITS - 1));
  648|       |   x <<= 1;
  649|       |
  650|       |   carry = 0;
  651|       |   *w0 = word_add(*w0, x, &carry);
  652|       |   *w1 = word_add(*w1, y, &carry);
  653|       |   *w2 = word_add(*w2, top, &carry);
  654|       |#endif
  655|   528M|}

_ZN5Botan11bigint_add2EPmmPKmm:
  259|   140k|inline void bigint_add2(word x[], size_t x_size, const word y[], size_t y_size) {
  260|   140k|   x[x_size] += bigint_add2_nc(x, x_size, y, y_size);
  261|   140k|}
_ZN5Botan14bigint_add2_ncEPmmPKmm:
  203|   140k|inline word bigint_add2_nc(word x[], size_t x_size, const word y[], size_t y_size) {
  204|   140k|   word carry = 0;
  205|       |
  206|   140k|   BOTAN_ASSERT(x_size >= y_size, "Expected sizes");
  ------------------
  |  |   51|   140k|   do {                                                                                 \
  |  |   52|   140k|      if(!(expr))                                                                       \
  |  |  ------------------
  |  |  |  Branch (52:10): [True: 0, False: 140k]
  |  |  ------------------
  |  |   53|   140k|         Botan::assertion_failure(#expr, assertion_made, __func__, __FILE__, __LINE__); \
  |  |   54|   140k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (54:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  207|       |
  208|   140k|   const size_t blocks = y_size - (y_size % 8);
  209|       |
  210|   150k|   for(size_t i = 0; i != blocks; i += 8) {
  ------------------
  |  Branch (210:22): [True: 10.8k, False: 140k]
  ------------------
  211|  10.8k|      carry = word8_add2(x + i, y + i, carry);
  212|  10.8k|   }
  213|       |
  214|   155k|   for(size_t i = blocks; i != y_size; ++i) {
  ------------------
  |  Branch (214:27): [True: 15.4k, False: 140k]
  ------------------
  215|  15.4k|      x[i] = word_add(x[i], y[i], &carry);
  216|  15.4k|   }
  217|       |
  218|  1.16M|   for(size_t i = y_size; i != x_size; ++i) {
  ------------------
  |  Branch (218:27): [True: 1.02M, False: 140k]
  ------------------
  219|  1.02M|      x[i] = word_add(x[i], 0, &carry);
  220|  1.02M|   }
  221|       |
  222|   140k|   return carry;
  223|   140k|}
_ZN5Botan10bigint_cmpEPKmmS1_m:
  490|   295k|inline int32_t bigint_cmp(const word x[], size_t x_size, const word y[], size_t y_size) {
  491|   295k|   static_assert(sizeof(word) >= sizeof(uint32_t), "Size assumption");
  492|       |
  493|   295k|   const word LT = static_cast<word>(-1);
  494|   295k|   const word EQ = 0;
  495|   295k|   const word GT = 1;
  496|       |
  497|   295k|   const size_t common_elems = std::min(x_size, y_size);
  498|       |
  499|   295k|   word result = EQ;  // until found otherwise
  500|       |
  501|  1.42M|   for(size_t i = 0; i != common_elems; i++) {
  ------------------
  |  Branch (501:22): [True: 1.12M, False: 295k]
  ------------------
  502|  1.12M|      const auto is_eq = CT::Mask<word>::is_equal(x[i], y[i]);
  503|  1.12M|      const auto is_lt = CT::Mask<word>::is_lt(x[i], y[i]);
  504|       |
  505|  1.12M|      result = is_eq.select(result, is_lt.select(LT, GT));
  506|  1.12M|   }
  507|       |
  508|   295k|   if(x_size < y_size) {
  ------------------
  |  Branch (508:7): [True: 22.5k, False: 273k]
  ------------------
  509|  22.5k|      word mask = 0;
  510|  80.5k|      for(size_t i = x_size; i != y_size; i++) {
  ------------------
  |  Branch (510:30): [True: 57.9k, False: 22.5k]
  ------------------
  511|  57.9k|         mask |= y[i];
  512|  57.9k|      }
  513|       |
  514|       |      // If any bits were set in high part of y, then x < y
  515|  22.5k|      result = CT::Mask<word>::is_zero(mask).select(result, LT);
  516|   273k|   } else if(y_size < x_size) {
  ------------------
  |  Branch (516:14): [True: 19.1k, False: 253k]
  ------------------
  517|  19.1k|      word mask = 0;
  518|   141k|      for(size_t i = y_size; i != x_size; i++) {
  ------------------
  |  Branch (518:30): [True: 122k, False: 19.1k]
  ------------------
  519|   122k|         mask |= x[i];
  520|   122k|      }
  521|       |
  522|       |      // If any bits were set in high part of x, then x > y
  523|  19.1k|      result = CT::Mask<word>::is_zero(mask).select(result, GT);
  524|  19.1k|   }
  525|       |
  526|   295k|   CT::unpoison(result);
  527|   295k|   BOTAN_DEBUG_ASSERT(result == LT || result == GT || result == EQ);
  ------------------
  |  |   99|   295k|      do {                          \
  |  |  100|   295k|      } while(0)
  |  |  ------------------
  |  |  |  Branch (100:15): [Folded - Ignored]
  |  |  ------------------
  ------------------
  528|   295k|   return static_cast<int32_t>(result);
  529|   295k|}
_ZN5Botan11bigint_sub2EPmmPKmm:
  273|  65.2M|inline word bigint_sub2(word x[], size_t x_size, const word y[], size_t y_size) {
  274|  65.2M|   word borrow = 0;
  275|       |
  276|  65.2M|   BOTAN_ASSERT(x_size >= y_size, "Expected sizes");
  ------------------
  |  |   51|  65.2M|   do {                                                                                 \
  |  |   52|  65.2M|      if(!(expr))                                                                       \
  |  |  ------------------
  |  |  |  Branch (52:10): [True: 0, False: 65.2M]
  |  |  ------------------
  |  |   53|  65.2M|         Botan::assertion_failure(#expr, assertion_made, __func__, __FILE__, __LINE__); \
  |  |   54|  65.2M|   } while(0)
  |  |  ------------------
  |  |  |  Branch (54:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  277|       |
  278|  65.2M|   const size_t blocks = y_size - (y_size % 8);
  279|       |
  280|  65.2M|   for(size_t i = 0; i != blocks; i += 8) {
  ------------------
  |  Branch (280:22): [True: 835, False: 65.2M]
  ------------------
  281|    835|      borrow = word8_sub2(x + i, y + i, borrow);
  282|    835|   }
  283|       |
  284|   456M|   for(size_t i = blocks; i != y_size; ++i) {
  ------------------
  |  Branch (284:27): [True: 391M, False: 65.2M]
  ------------------
  285|   391M|      x[i] = word_sub(x[i], y[i], &borrow);
  286|   391M|   }
  287|       |
  288|   130M|   for(size_t i = y_size; i != x_size; ++i) {
  ------------------
  |  Branch (288:27): [True: 65.1M, False: 65.2M]
  ------------------
  289|  65.1M|      x[i] = word_sub(x[i], 0, &borrow);
  290|  65.1M|   }
  291|       |
  292|  65.2M|   return borrow;
  293|  65.2M|}
_ZN5Botan15bigint_sub2_revEPmPKmm:
  298|     66|inline void bigint_sub2_rev(word x[], const word y[], size_t y_size) {
  299|     66|   word borrow = 0;
  300|       |
  301|     66|   const size_t blocks = y_size - (y_size % 8);
  302|       |
  303|    148|   for(size_t i = 0; i != blocks; i += 8) {
  ------------------
  |  Branch (303:22): [True: 82, False: 66]
  ------------------
  304|     82|      borrow = word8_sub2_rev(x + i, y + i, borrow);
  305|     82|   }
  306|       |
  307|    215|   for(size_t i = blocks; i != y_size; ++i) {
  ------------------
  |  Branch (307:27): [True: 149, False: 66]
  ------------------
  308|    149|      x[i] = word_sub(y[i], x[i], &borrow);
  309|    149|   }
  310|       |
  311|     66|   BOTAN_ASSERT(borrow == 0, "y must be greater than x");
  ------------------
  |  |   51|     66|   do {                                                                                 \
  |  |   52|     66|      if(!(expr))                                                                       \
  |  |  ------------------
  |  |  |  Branch (52:10): [True: 0, False: 66]
  |  |  ------------------
  |  |   53|     66|         Botan::assertion_failure(#expr, assertion_made, __func__, __FILE__, __LINE__); \
  |  |   54|     66|   } while(0)
  |  |  ------------------
  |  |  |  Branch (54:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  312|     66|}
_ZN5Botan11bigint_sub3EPmPKmmS2_m:
  321|  66.8M|inline word bigint_sub3(word z[], const word x[], size_t x_size, const word y[], size_t y_size) {
  322|  66.8M|   word borrow = 0;
  323|       |
  324|  66.8M|   BOTAN_ASSERT(x_size >= y_size, "Expected sizes");
  ------------------
  |  |   51|  66.8M|   do {                                                                                 \
  |  |   52|  66.8M|      if(!(expr))                                                                       \
  |  |  ------------------
  |  |  |  Branch (52:10): [True: 0, False: 66.8M]
  |  |  ------------------
  |  |   53|  66.8M|         Botan::assertion_failure(#expr, assertion_made, __func__, __FILE__, __LINE__); \
  |  |   54|  66.8M|   } while(0)
  |  |  ------------------
  |  |  |  Branch (54:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  325|       |
  326|  66.8M|   const size_t blocks = y_size - (y_size % 8);
  327|       |
  328|  66.8M|   for(size_t i = 0; i != blocks; i += 8) {
  ------------------
  |  Branch (328:22): [True: 380, False: 66.8M]
  ------------------
  329|    380|      borrow = word8_sub3(z + i, x + i, y + i, borrow);
  330|    380|   }
  331|       |
  332|   467M|   for(size_t i = blocks; i != y_size; ++i) {
  ------------------
  |  Branch (332:27): [True: 400M, False: 66.8M]
  ------------------
  333|   400M|      z[i] = word_sub(x[i], y[i], &borrow);
  334|   400M|   }
  335|       |
  336|   101M|   for(size_t i = y_size; i != x_size; ++i) {
  ------------------
  |  Branch (336:27): [True: 34.5M, False: 66.8M]
  ------------------
  337|  34.5M|      z[i] = word_sub(x[i], 0, &borrow);
  338|  34.5M|   }
  339|       |
  340|  66.8M|   return borrow;
  341|  66.8M|}
_ZN5Botan14bigint_add3_ncEPmPKmmS2_m:
  228|  3.12M|inline word bigint_add3_nc(word z[], const word x[], size_t x_size, const word y[], size_t y_size) {
  229|  3.12M|   if(x_size < y_size) {
  ------------------
  |  Branch (229:7): [True: 14.0k, False: 3.10M]
  ------------------
  230|  14.0k|      return bigint_add3_nc(z, y, y_size, x, x_size);
  231|  14.0k|   }
  232|       |
  233|  3.10M|   word carry = 0;
  234|       |
  235|  3.10M|   const size_t blocks = y_size - (y_size % 8);
  236|       |
  237|  3.10M|   for(size_t i = 0; i != blocks; i += 8) {
  ------------------
  |  Branch (237:22): [True: 0, False: 3.10M]
  ------------------
  238|      0|      carry = word8_add3(z + i, x + i, y + i, carry);
  239|      0|   }
  240|       |
  241|  21.6M|   for(size_t i = blocks; i != y_size; ++i) {
  ------------------
  |  Branch (241:27): [True: 18.5M, False: 3.10M]
  ------------------
  242|  18.5M|      z[i] = word_add(x[i], y[i], &carry);
  243|  18.5M|   }
  244|       |
  245|  3.19M|   for(size_t i = y_size; i != x_size; ++i) {
  ------------------
  |  Branch (245:27): [True: 86.4k, False: 3.10M]
  ------------------
  246|  86.4k|      z[i] = word_add(x[i], 0, &carry);
  247|  86.4k|   }
  248|       |
  249|  3.10M|   return carry;
  250|  3.12M|}
_ZN5Botan15bigint_ct_is_ltEPKmmS1_mb:
  537|  27.4M|   const word x[], size_t x_size, const word y[], size_t y_size, bool lt_or_equal = false) {
  538|  27.4M|   const size_t common_elems = std::min(x_size, y_size);
  539|       |
  540|  27.4M|   auto is_lt = CT::Mask<word>::expand(lt_or_equal);
  541|       |
  542|   190M|   for(size_t i = 0; i != common_elems; i++) {
  ------------------
  |  Branch (542:22): [True: 162M, False: 27.4M]
  ------------------
  543|   162M|      const auto eq = CT::Mask<word>::is_equal(x[i], y[i]);
  544|   162M|      const auto lt = CT::Mask<word>::is_lt(x[i], y[i]);
  545|   162M|      is_lt = eq.select_mask(is_lt, lt);
  546|   162M|   }
  547|       |
  548|  27.4M|   if(x_size < y_size) {
  ------------------
  |  Branch (548:7): [True: 1.27k, False: 27.4M]
  ------------------
  549|  1.27k|      word mask = 0;
  550|  6.74k|      for(size_t i = x_size; i != y_size; i++) {
  ------------------
  |  Branch (550:30): [True: 5.46k, False: 1.27k]
  ------------------
  551|  5.46k|         mask |= y[i];
  552|  5.46k|      }
  553|       |      // If any bits were set in high part of y, then is_lt should be forced true
  554|  1.27k|      is_lt |= CT::Mask<word>::expand(mask);
  555|  27.4M|   } else if(y_size < x_size) {
  ------------------
  |  Branch (555:14): [True: 18.5k, False: 27.3M]
  ------------------
  556|  18.5k|      word mask = 0;
  557|  83.0k|      for(size_t i = y_size; i != x_size; i++) {
  ------------------
  |  Branch (557:30): [True: 64.5k, False: 18.5k]
  ------------------
  558|  64.5k|         mask |= x[i];
  559|  64.5k|      }
  560|       |
  561|       |      // If any bits were set in high part of x, then is_lt should be false
  562|  18.5k|      is_lt &= CT::Mask<word>::is_zero(mask);
  563|  18.5k|   }
  564|       |
  565|  27.4M|   return is_lt;
  566|  27.4M|}
_ZN5Botan17bigint_cnd_addsubENS_2CT4MaskImEEPmPKmS5_m:
  158|  26.8M|inline word bigint_cnd_addsub(CT::Mask<word> mask, word x[], const word y[], const word z[], size_t size) {
  159|  26.8M|   const size_t blocks = size - (size % 8);
  160|       |
  161|  26.8M|   word carry = 0;
  162|  26.8M|   word borrow = 0;
  163|       |
  164|  26.8M|   word t0[8] = {0};
  165|  26.8M|   word t1[8] = {0};
  166|       |
  167|  26.8M|   for(size_t i = 0; i != blocks; i += 8) {
  ------------------
  |  Branch (167:22): [True: 0, False: 26.8M]
  ------------------
  168|      0|      carry = word8_add3(t0, x + i, y + i, carry);
  169|      0|      borrow = word8_sub3(t1, x + i, z + i, borrow);
  170|       |
  171|      0|      for(size_t j = 0; j != 8; ++j) {
  ------------------
  |  Branch (171:25): [True: 0, False: 0]
  ------------------
  172|      0|         x[i + j] = mask.select(t0[j], t1[j]);
  173|      0|      }
  174|      0|   }
  175|       |
  176|   187M|   for(size_t i = blocks; i != size; ++i) {
  ------------------
  |  Branch (176:27): [True: 161M, False: 26.8M]
  ------------------
  177|   161M|      t0[0] = word_add(x[i], y[i], &carry);
  178|   161M|      t1[0] = word_sub(x[i], z[i], &borrow);
  179|   161M|      x[i] = mask.select(t0[0], t1[0]);
  180|   161M|   }
  181|       |
  182|  26.8M|   return mask.select(carry, borrow);
  183|  26.8M|}
_ZN5Botan14bigint_sub_absEPmPKmmS2_m:
  604|  93.9k|inline int32_t bigint_sub_abs(word z[], const word x[], size_t x_size, const word y[], size_t y_size) {
  605|  93.9k|   const int32_t relative_size = bigint_cmp(x, x_size, y, y_size);
  606|       |
  607|       |   // Swap if relative_size == -1
  608|  93.9k|   const bool need_swap = relative_size < 0;
  609|  93.9k|   CT::conditional_swap_ptr(need_swap, x, y);
  610|  93.9k|   CT::conditional_swap(need_swap, x_size, y_size);
  611|       |
  612|       |   /*
  613|       |   * We know at this point that x >= y so if y_size is larger than
  614|       |   * x_size, we are guaranteed they are just leading zeros which can
  615|       |   * be ignored
  616|       |   */
  617|  93.9k|   y_size = std::min(x_size, y_size);
  618|       |
  619|  93.9k|   bigint_sub3(z, x, x_size, y, y_size);
  620|       |
  621|  93.9k|   return relative_size;
  622|  93.9k|}
_ZN5Botan14bigint_linmul3EPmPKmmm:
  468|   135k|inline void bigint_linmul3(word z[], const word x[], size_t x_size, word y) {
  469|   135k|   const size_t blocks = x_size - (x_size % 8);
  470|       |
  471|   135k|   word carry = 0;
  472|       |
  473|   136k|   for(size_t i = 0; i != blocks; i += 8) {
  ------------------
  |  Branch (473:22): [True: 599, False: 135k]
  ------------------
  474|    599|      carry = word8_linmul3(z + i, x + i, y, carry);
  475|    599|   }
  476|       |
  477|   688k|   for(size_t i = blocks; i != x_size; ++i) {
  ------------------
  |  Branch (477:27): [True: 552k, False: 135k]
  ------------------
  478|   552k|      z[i] = word_madd2(x[i], y, &carry);
  479|   552k|   }
  480|       |
  481|   135k|   z[x_size] = carry;
  482|   135k|}
_ZN5Botan14bigint_linmul2EPmmm:
  452|  13.0M|[[nodiscard]] inline word bigint_linmul2(word x[], size_t x_size, word y) {
  453|  13.0M|   const size_t blocks = x_size - (x_size % 8);
  454|       |
  455|  13.0M|   word carry = 0;
  456|       |
  457|  34.4M|   for(size_t i = 0; i != blocks; i += 8) {
  ------------------
  |  Branch (457:22): [True: 21.4M, False: 13.0M]
  ------------------
  458|  21.4M|      carry = word8_linmul2(x + i, y, carry);
  459|  21.4M|   }
  460|       |
  461|  36.5M|   for(size_t i = blocks; i != x_size; ++i) {
  ------------------
  |  Branch (461:27): [True: 23.4M, False: 13.0M]
  ------------------
  462|  23.4M|      x[i] = word_madd2(x[i], y, &carry);
  463|  23.4M|   }
  464|       |
  465|  13.0M|   return carry;
  466|  13.0M|}
_ZN5Botan20bigint_modop_vartimeEmmm:
  697|  26.1k|inline word bigint_modop_vartime(word n1, word n0, word d) {
  698|  26.1k|   if(d == 0) {
  ------------------
  |  Branch (698:7): [True: 0, False: 26.1k]
  ------------------
  699|      0|      throw Invalid_Argument("bigint_modop_vartime divide by zero");
  700|      0|   }
  701|       |
  702|  26.1k|#if defined(BOTAN_MP_DWORD)
  703|  26.1k|   return ((static_cast<BOTAN_MP_DWORD>(n1) << BOTAN_MP_WORD_BITS) | n0) % d;
  ------------------
  |  |   50|  26.1k|#define BOTAN_MP_WORD_BITS 64
  ------------------
  704|       |#else
  705|       |   word z = bigint_divop_vartime(n1, n0, d);
  706|       |   word dummy = 0;
  707|       |   z = word_madd2(z, d, &dummy);
  708|       |   return (n0 - z);
  709|       |#endif
  710|  26.1k|}
_ZN5Botan11bigint_shl1EPmmmmm:
  382|   251k|inline void bigint_shl1(word x[], size_t x_size, size_t x_words, size_t word_shift, size_t bit_shift) {
  383|   251k|   copy_mem(x + word_shift, x, x_words);
  384|   251k|   clear_mem(x, word_shift);
  385|       |
  386|   251k|   const auto carry_mask = CT::Mask<word>::expand(bit_shift);
  387|   251k|   const word carry_shift = carry_mask.if_set_return(BOTAN_MP_WORD_BITS - bit_shift);
  ------------------
  |  |   50|   251k|#define BOTAN_MP_WORD_BITS 64
  ------------------
  388|       |
  389|   251k|   word carry = 0;
  390|  1.38M|   for(size_t i = word_shift; i != x_size; ++i) {
  ------------------
  |  Branch (390:31): [True: 1.12M, False: 251k]
  ------------------
  391|  1.12M|      const word w = x[i];
  392|  1.12M|      x[i] = (w << bit_shift) | carry;
  393|  1.12M|      carry = carry_mask.if_set_return(w >> carry_shift);
  394|  1.12M|   }
  395|   251k|}
_ZN5Botan11bigint_shr1EPmmmm:
  397|   416k|inline void bigint_shr1(word x[], size_t x_size, size_t word_shift, size_t bit_shift) {
  398|   416k|   const size_t top = x_size >= word_shift ? (x_size - word_shift) : 0;
  ------------------
  |  Branch (398:23): [True: 415k, False: 1.06k]
  ------------------
  399|       |
  400|   416k|   if(top > 0) {
  ------------------
  |  Branch (400:7): [True: 415k, False: 1.06k]
  ------------------
  401|   415k|      copy_mem(x, x + word_shift, top);
  402|   415k|   }
  403|   416k|   clear_mem(x + top, std::min(word_shift, x_size));
  404|       |
  405|   416k|   const auto carry_mask = CT::Mask<word>::expand(bit_shift);
  406|   416k|   const word carry_shift = carry_mask.if_set_return(BOTAN_MP_WORD_BITS - bit_shift);
  ------------------
  |  |   50|   416k|#define BOTAN_MP_WORD_BITS 64
  ------------------
  407|       |
  408|   416k|   word carry = 0;
  409|       |
  410|  3.59M|   for(size_t i = 0; i != top; ++i) {
  ------------------
  |  Branch (410:22): [True: 3.18M, False: 416k]
  ------------------
  411|  3.18M|      const word w = x[top - i - 1];
  412|  3.18M|      x[top - i - 1] = (w >> bit_shift) | carry;
  413|  3.18M|      carry = carry_mask.if_set_return(w << carry_shift);
  414|  3.18M|   }
  415|   416k|}
_ZN5Botan16bigint_mod_sub_nILm6EEEvPmPKmS3_S1_:
  648|  26.8M|inline void bigint_mod_sub_n(word t[], const word s[], const word mod[], word ws[]) {
  649|       |   // is t < s or not?
  650|  26.8M|   const auto is_lt = bigint_ct_is_lt(t, N, s, N);
  651|       |
  652|       |   // ws = p - s
  653|  26.8M|   const word borrow = bigint_sub3(ws, mod, N, s, N);
  654|       |
  655|       |   // Compute either (t - s) or (t + (p - s)) depending on mask
  656|  26.8M|   const word carry = bigint_cnd_addsub(is_lt, t, ws, s, N);
  657|       |
  658|  26.8M|   BOTAN_DEBUG_ASSERT(borrow == 0 && carry == 0);
  ------------------
  |  |   99|  26.8M|      do {                          \
  |  |  100|  26.8M|      } while(0)
  |  |  ------------------
  |  |  |  Branch (100:15): [Folded - Ignored]
  |  |  ------------------
  ------------------
  659|  26.8M|   BOTAN_UNUSED(carry, borrow);
  ------------------
  |  |  118|  26.8M|#define BOTAN_UNUSED Botan::ignore_params
  ------------------
  660|  26.8M|}
_ZN5Botan15bigint_cnd_swapEmPmS0_m:
   29|   651k|inline void bigint_cnd_swap(word cnd, word x[], word y[], size_t size) {
   30|   651k|   const auto mask = CT::Mask<word>::expand(cnd);
   31|       |
   32|  5.85M|   for(size_t i = 0; i != size; ++i) {
  ------------------
  |  Branch (32:22): [True: 5.20M, False: 651k]
  ------------------
   33|  5.20M|      const word a = x[i];
   34|  5.20M|      const word b = y[i];
   35|  5.20M|      x[i] = mask.select(b, a);
   36|  5.20M|      y[i] = mask.select(a, b);
   37|  5.20M|   }
   38|   651k|}
_ZN5Botan14bigint_cnd_addEmPmmPKmm:
   40|  65.1M|inline word bigint_cnd_add(word cnd, word x[], word x_size, const word y[], size_t y_size) {
   41|  65.1M|   BOTAN_ASSERT(x_size >= y_size, "Expected sizes");
  ------------------
  |  |   51|  65.1M|   do {                                                                                 \
  |  |   52|  65.1M|      if(!(expr))                                                                       \
  |  |  ------------------
  |  |  |  Branch (52:10): [True: 0, False: 65.1M]
  |  |  ------------------
  |  |   53|  65.1M|         Botan::assertion_failure(#expr, assertion_made, __func__, __FILE__, __LINE__); \
  |  |   54|  65.1M|   } while(0)
  |  |  ------------------
  |  |  |  Branch (54:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   42|       |
   43|  65.1M|   const auto mask = CT::Mask<word>::expand(cnd);
   44|       |
   45|  65.1M|   word carry = 0;
   46|       |
   47|  65.1M|   const size_t blocks = y_size - (y_size % 8);
   48|  65.1M|   word z[8] = {0};
   49|       |
   50|  65.1M|   for(size_t i = 0; i != blocks; i += 8) {
  ------------------
  |  Branch (50:22): [True: 0, False: 65.1M]
  ------------------
   51|      0|      carry = word8_add3(z, x + i, y + i, carry);
   52|      0|      mask.select_n(x + i, z, x + i, 8);
   53|      0|   }
   54|       |
   55|   455M|   for(size_t i = blocks; i != y_size; ++i) {
  ------------------
  |  Branch (55:27): [True: 390M, False: 65.1M]
  ------------------
   56|   390M|      z[0] = word_add(x[i], y[i], &carry);
   57|   390M|      x[i] = mask.select(z[0], x[i]);
   58|   390M|   }
   59|       |
   60|   130M|   for(size_t i = y_size; i != x_size; ++i) {
  ------------------
  |  Branch (60:27): [True: 65.1M, False: 65.1M]
  ------------------
   61|  65.1M|      z[0] = word_add(x[i], 0, &carry);
   62|  65.1M|      x[i] = mask.select(z[0], x[i]);
   63|  65.1M|   }
   64|       |
   65|  65.1M|   return mask.if_set_return(carry);
   66|  65.1M|}
_ZN5Botan11bigint_add3EPmPKmmS2_m:
  266|  16.1k|inline void bigint_add3(word z[], const word x[], size_t x_size, const word y[], size_t y_size) {
  267|  16.1k|   z[x_size > y_size ? x_size : y_size] += bigint_add3_nc(z, x, x_size, y, y_size);
  ------------------
  |  Branch (267:6): [True: 906, False: 15.2k]
  ------------------
  268|  16.1k|}
_ZN5Botan11bigint_shl2EPmPKmmmm:
  417|   125k|inline void bigint_shl2(word y[], const word x[], size_t x_size, size_t word_shift, size_t bit_shift) {
  418|   125k|   copy_mem(y + word_shift, x, x_size);
  419|       |
  420|   125k|   const auto carry_mask = CT::Mask<word>::expand(bit_shift);
  421|   125k|   const word carry_shift = carry_mask.if_set_return(BOTAN_MP_WORD_BITS - bit_shift);
  ------------------
  |  |   50|   125k|#define BOTAN_MP_WORD_BITS 64
  ------------------
  422|       |
  423|   125k|   word carry = 0;
  424|   752k|   for(size_t i = word_shift; i != x_size + word_shift + 1; ++i) {
  ------------------
  |  Branch (424:31): [True: 627k, False: 125k]
  ------------------
  425|   627k|      const word w = y[i];
  426|   627k|      y[i] = (w << bit_shift) | carry;
  427|   627k|      carry = carry_mask.if_set_return(w >> carry_shift);
  428|   627k|   }
  429|   125k|}
_ZN5Botan11bigint_shr2EPmPKmmmm:
  431|    837|inline void bigint_shr2(word y[], const word x[], size_t x_size, size_t word_shift, size_t bit_shift) {
  432|    837|   const size_t new_size = x_size < word_shift ? 0 : (x_size - word_shift);
  ------------------
  |  Branch (432:28): [True: 0, False: 837]
  ------------------
  433|       |
  434|    837|   if(new_size > 0) {
  ------------------
  |  Branch (434:7): [True: 837, False: 0]
  ------------------
  435|    837|      copy_mem(y, x + word_shift, new_size);
  436|    837|   }
  437|       |
  438|    837|   const auto carry_mask = CT::Mask<word>::expand(bit_shift);
  439|    837|   const word carry_shift = carry_mask.if_set_return(BOTAN_MP_WORD_BITS - bit_shift);
  ------------------
  |  |   50|    837|#define BOTAN_MP_WORD_BITS 64
  ------------------
  440|       |
  441|    837|   word carry = 0;
  442|  5.85k|   for(size_t i = new_size; i > 0; --i) {
  ------------------
  |  Branch (442:29): [True: 5.02k, False: 837]
  ------------------
  443|  5.02k|      word w = y[i - 1];
  444|  5.02k|      y[i - 1] = (w >> bit_shift) | carry;
  445|  5.02k|      carry = carry_mask.if_set_return(w << carry_shift);
  446|  5.02k|   }
  447|    837|}
_ZN5Botan15bigint_ct_is_eqEPKmmS1_m:
  568|  21.7k|inline CT::Mask<word> bigint_ct_is_eq(const word x[], size_t x_size, const word y[], size_t y_size) {
  569|  21.7k|   const size_t common_elems = std::min(x_size, y_size);
  570|       |
  571|  21.7k|   word diff = 0;
  572|       |
  573|   152k|   for(size_t i = 0; i != common_elems; i++) {
  ------------------
  |  Branch (573:22): [True: 130k, False: 21.7k]
  ------------------
  574|   130k|      diff |= (x[i] ^ y[i]);
  575|   130k|   }
  576|       |
  577|       |   // If any bits were set in high part of x/y, then they are not equal
  578|  21.7k|   if(x_size < y_size) {
  ------------------
  |  Branch (578:7): [True: 0, False: 21.7k]
  ------------------
  579|      0|      for(size_t i = x_size; i != y_size; i++) {
  ------------------
  |  Branch (579:30): [True: 0, False: 0]
  ------------------
  580|      0|         diff |= y[i];
  581|      0|      }
  582|  21.7k|   } else if(y_size < x_size) {
  ------------------
  |  Branch (582:14): [True: 3, False: 21.7k]
  ------------------
  583|     10|      for(size_t i = y_size; i != x_size; i++) {
  ------------------
  |  Branch (583:30): [True: 7, False: 3]
  ------------------
  584|      7|         diff |= x[i];
  585|      7|      }
  586|      3|   }
  587|       |
  588|  21.7k|   return CT::Mask<word>::is_zero(diff);
  589|  21.7k|}
_ZN5Botan20bigint_divop_vartimeEmmm:
  665|   126k|inline word bigint_divop_vartime(word n1, word n0, word d) {
  666|   126k|   if(d == 0) {
  ------------------
  |  Branch (666:7): [True: 0, False: 126k]
  ------------------
  667|      0|      throw Invalid_Argument("bigint_divop_vartime divide by zero");
  668|      0|   }
  669|       |
  670|   126k|#if defined(BOTAN_MP_DWORD)
  671|   126k|   return static_cast<word>(((static_cast<BOTAN_MP_DWORD>(n1) << BOTAN_MP_WORD_BITS) | n0) / d);
  ------------------
  |  |   50|   126k|#define BOTAN_MP_WORD_BITS 64
  ------------------
  672|       |#else
  673|       |
  674|       |   word high = n1 % d;
  675|       |   word quotient = 0;
  676|       |
  677|       |   for(size_t i = 0; i != BOTAN_MP_WORD_BITS; ++i) {
  678|       |      const word high_top_bit = high >> (BOTAN_MP_WORD_BITS - 1);
  679|       |
  680|       |      high <<= 1;
  681|       |      high |= (n0 >> (BOTAN_MP_WORD_BITS - 1 - i)) & 1;
  682|       |      quotient <<= 1;
  683|       |
  684|       |      if(high_top_bit || high >= d) {
  685|       |         high -= d;
  686|       |         quotient |= 1;
  687|       |      }
  688|       |   }
  689|       |
  690|       |   return quotient;
  691|       |#endif
  692|   126k|}
_ZN5Botan17bigint_monty_redcEPmPKmmmS0_m:
  757|   392k|inline void bigint_monty_redc(word z[], const word p[], size_t p_size, word p_dash, word ws[], size_t ws_size) {
  758|   392k|   const size_t z_size = 2 * p_size;
  759|       |
  760|   392k|   BOTAN_ARG_CHECK(ws_size >= p_size + 1, "Montgomery workspace too small");
  ------------------
  |  |   30|   392k|   do {                                                          \
  |  |   31|   392k|      if(!(expr))                                                \
  |  |  ------------------
  |  |  |  Branch (31:10): [True: 0, False: 392k]
  |  |  ------------------
  |  |   32|   392k|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   33|   392k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (33:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  761|       |
  762|   392k|   if(p_size == 4) {
  ------------------
  |  Branch (762:7): [True: 0, False: 392k]
  ------------------
  763|      0|      bigint_monty_redc_4(z, p, p_dash, ws);
  764|   392k|   } else if(p_size == 6) {
  ------------------
  |  Branch (764:14): [True: 392k, False: 0]
  ------------------
  765|   392k|      bigint_monty_redc_6(z, p, p_dash, ws);
  766|   392k|   } else if(p_size == 8) {
  ------------------
  |  Branch (766:14): [True: 0, False: 0]
  ------------------
  767|      0|      bigint_monty_redc_8(z, p, p_dash, ws);
  768|      0|   } else if(p_size == 16) {
  ------------------
  |  Branch (768:14): [True: 0, False: 0]
  ------------------
  769|      0|      bigint_monty_redc_16(z, p, p_dash, ws);
  770|      0|   } else if(p_size == 24) {
  ------------------
  |  Branch (770:14): [True: 0, False: 0]
  ------------------
  771|      0|      bigint_monty_redc_24(z, p, p_dash, ws);
  772|      0|   } else if(p_size == 32) {
  ------------------
  |  Branch (772:14): [True: 0, False: 0]
  ------------------
  773|      0|      bigint_monty_redc_32(z, p, p_dash, ws);
  774|      0|   } else {
  775|      0|      bigint_monty_redc_generic(z, z_size, p, p_size, p_dash, ws);
  776|      0|   }
  777|   392k|}

_ZN5Botan4rotrILm18EjEET0_S1_:
   35|    640|{
   36|    640|   return static_cast<T>((input >> ROT) | (input << (8 * sizeof(T) - ROT)));
   37|    640|}
_ZN5Botan4rotrILm6EjEET0_S1_:
   35|    640|{
   36|    640|   return static_cast<T>((input >> ROT) | (input << (8 * sizeof(T) - ROT)));
   37|    640|}
_ZN5Botan4rotrILm2EjEET0_S1_:
   35|    640|{
   36|    640|   return static_cast<T>((input >> ROT) | (input << (8 * sizeof(T) - ROT)));
   37|    640|}
_ZN5Botan4rotrILm22EjEET0_S1_:
   35|    640|{
   36|    640|   return static_cast<T>((input >> ROT) | (input << (8 * sizeof(T) - ROT)));
   37|    640|}
_ZN5Botan4rotrILm7EjEET0_S1_:
   35|    640|{
   36|    640|   return static_cast<T>((input >> ROT) | (input << (8 * sizeof(T) - ROT)));
   37|    640|}
_ZN5Botan4rotrILm13EjEET0_S1_:
   35|    640|{
   36|    640|   return static_cast<T>((input >> ROT) | (input << (8 * sizeof(T) - ROT)));
   37|    640|}
_ZN5Botan3rhoILm2ELm13ELm22EjEET2_S1_:
   51|    640|inline constexpr T rho(T x) {
   52|    640|   return rotr<R1>(x) ^ rotr<R2>(x) ^ rotr<R3>(x);
   53|    640|}
_ZN5Botan3rhoILm6ELm11ELm25EjEET2_S1_:
   51|    640|inline constexpr T rho(T x) {
   52|    640|   return rotr<R1>(x) ^ rotr<R2>(x) ^ rotr<R3>(x);
   53|    640|}
_ZN5Botan4rotrILm11EjEET0_S1_:
   35|    640|{
   36|    640|   return static_cast<T>((input >> ROT) | (input << (8 * sizeof(T) - ROT)));
   37|    640|}
_ZN5Botan4rotrILm25EjEET0_S1_:
   35|    640|{
   36|    640|   return static_cast<T>((input >> ROT) | (input << (8 * sizeof(T) - ROT)));
   37|    640|}
_ZN5Botan5sigmaILm7ELm18ELm3EjEET2_S1_:
   43|    640|inline constexpr T sigma(T x) {
   44|    640|   return rotr<R1>(x) ^ rotr<R2>(x) ^ (x >> S);
   45|    640|}
_ZN5Botan5sigmaILm17ELm19ELm10EjEET2_S1_:
   43|    640|inline constexpr T sigma(T x) {
   44|    640|   return rotr<R1>(x) ^ rotr<R2>(x) ^ (x >> S);
   45|    640|}
_ZN5Botan4rotrILm17EjEET0_S1_:
   35|    640|{
   36|    640|   return static_cast<T>((input >> ROT) | (input << (8 * sizeof(T) - ROT)));
   37|    640|}
_ZN5Botan4rotrILm19EjEET0_S1_:
   35|    640|{
   36|    640|   return static_cast<T>((input >> ROT) | (input << (8 * sizeof(T) - ROT)));
   37|    640|}

_ZN5Botan8round_upEmm:
   21|   195k|inline size_t round_up(size_t n, size_t align_to) {
   22|   195k|   BOTAN_ARG_CHECK(align_to != 0, "align_to must not be 0");
  ------------------
  |  |   30|   195k|   do {                                                          \
  |  |   31|   195k|      if(!(expr))                                                \
  |  |  ------------------
  |  |  |  Branch (31:10): [True: 0, False: 195k]
  |  |  ------------------
  |  |   32|   195k|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   33|   195k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (33:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   23|       |
   24|   195k|   if(n % align_to) {
  ------------------
  |  Branch (24:7): [True: 170k, False: 24.8k]
  ------------------
   25|   170k|      n += align_to - (n % align_to);
   26|   170k|   }
   27|   195k|   return n;
   28|   195k|}

_ZN5Botan11checked_mulEmm:
   47|  2.93M|inline std::optional<size_t> checked_mul(size_t x, size_t y) {
   48|  2.93M|#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_add_overflow)
   49|  2.93M|   size_t z;
   50|  2.93M|   if(__builtin_mul_overflow(x, y, &z)) [[unlikely]]
  ------------------
  |  Branch (50:7): [True: 0, False: 2.93M]
  ------------------
   51|       |#elif defined(_MSC_VER)
   52|       |   size_t z;
   53|       |   if(SizeTMult(x, y, &z) != S_OK) [[unlikely]]
   54|       |#else
   55|       |   size_t z = x * y;
   56|       |   if(y && z / y != x) [[unlikely]]
   57|       |#endif
   58|      0|   {
   59|      0|      return std::nullopt;
   60|      0|   }
   61|  2.93M|   return z;
   62|  2.93M|}

_ZNK5Botan9SCAN_Name9algo_nameEv:
   44|      7|      const std::string& algo_name() const { return m_alg_name; }
_ZNK5Botan9SCAN_Name9arg_countEv:
   49|      3|      size_t arg_count() const { return m_args.size(); }

_ZNK5Botan7SHA_25613output_lengthEv:
   75|      5|      size_t output_length() const override { return output_bytes; }
_ZNK5Botan7SHA_25615hash_block_sizeEv:
   77|      1|      size_t hash_block_size() const override { return block_bytes; }
_ZN5Botan7SHA_2565clearEv:
   83|      2|      void clear() override { m_md.clear(); }

_ZN5Botan9SHA2_32_FEjjjRjjjjS0_S0_jjjj:
   31|    640|                                  uint32_t magic) {
   32|    640|   uint32_t A_rho = rho<2, 13, 22>(A);
   33|    640|   uint32_t E_rho = rho<6, 11, 25>(E);
   34|    640|   uint32_t M2_sigma = sigma<17, 19, 10>(M2);
   35|    640|   uint32_t M4_sigma = sigma<7, 18, 3>(M4);
   36|    640|   H += magic + E_rho + choose(E, F, G) + M1;
   37|    640|   D += H;
   38|    640|   H += A_rho + majority(A, B, C);
   39|    640|   M1 += M2_sigma + M3 + M4_sigma;
   40|    640|}

_ZN5Botan9SIMD_4x32C2EDv2_x:
  597|      2|      explicit SIMD_4x32(native_simd_type x) noexcept : m_simd(x) {}
_ZN5Botan9SIMD_4x32C2Ejjjj:
  113|     96|      SIMD_4x32(uint32_t B0, uint32_t B1, uint32_t B2, uint32_t B3) noexcept {
  114|     96|#if defined(BOTAN_SIMD_USE_SSE2)
  115|     96|         m_simd = _mm_set_epi32(B3, B2, B1, B0);
  116|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  117|       |         __vector unsigned int val = {B0, B1, B2, B3};
  118|       |         m_simd = val;
  119|       |#elif defined(BOTAN_SIMD_USE_NEON)
  120|       |         // Better way to do this?
  121|       |         const uint32_t B[4] = {B0, B1, B2, B3};
  122|       |         m_simd = vld1q_u32(B);
  123|       |#endif
  124|     96|      }
_ZN5Botan9SIMD_4x328splat_u8Eh:
  142|      2|      static SIMD_4x32 splat_u8(uint8_t B) noexcept {
  143|      2|#if defined(BOTAN_SIMD_USE_SSE2)
  144|      2|         return SIMD_4x32(_mm_set1_epi8(B));
  145|       |#elif defined(BOTAN_SIMD_USE_NEON)
  146|       |         return SIMD_4x32(vreinterpretq_u32_u8(vdupq_n_u8(B)));
  147|       |#else
  148|       |         const uint32_t B4 = make_uint32(B, B, B, B);
  149|       |         return SIMD_4x32(B4, B4, B4, B4);
  150|       |#endif
  151|      2|      }

_ZN5Botan9SIMD_8x3215reset_registersEv:
  243|  8.18k|      static void reset_registers() noexcept { _mm256_zeroupper(); }
_ZN5Botan9SIMD_8x32C2EDv4_x:
  251|  3.01M|      SIMD_8x32(__m256i x) noexcept : m_avx2(x) {}
_ZN5Botan9SIMD_8x329transposeERS0_S1_S1_S1_:
  194|  32.7k|      static void transpose(SIMD_8x32& B0, SIMD_8x32& B1, SIMD_8x32& B2, SIMD_8x32& B3) noexcept {
  195|  32.7k|         const __m256i T0 = _mm256_unpacklo_epi32(B0.m_avx2, B1.m_avx2);
  196|  32.7k|         const __m256i T1 = _mm256_unpacklo_epi32(B2.m_avx2, B3.m_avx2);
  197|  32.7k|         const __m256i T2 = _mm256_unpackhi_epi32(B0.m_avx2, B1.m_avx2);
  198|  32.7k|         const __m256i T3 = _mm256_unpackhi_epi32(B2.m_avx2, B3.m_avx2);
  199|       |
  200|  32.7k|         B0.m_avx2 = _mm256_unpacklo_epi64(T0, T1);
  201|  32.7k|         B1.m_avx2 = _mm256_unpackhi_epi64(T0, T1);
  202|  32.7k|         B2.m_avx2 = _mm256_unpacklo_epi64(T2, T3);
  203|  32.7k|         B3.m_avx2 = _mm256_unpackhi_epi64(T2, T3);
  204|  32.7k|      }
_ZNK5Botan9SIMD_8x328store_leEPh:
   59|   131k|      void store_le(uint8_t out[]) const noexcept { _mm256_storeu_si256(reinterpret_cast<__m256i*>(out), m_avx2); }
_ZN5Botan9SIMD_8x3214zero_registersEv:
  246|  8.18k|      static void zero_registers() noexcept { _mm256_zeroall(); }
_ZN5Botan9SIMD_8x325splatEj:
   48|   262k|      static SIMD_8x32 splat(uint32_t B) noexcept { return SIMD_8x32(_mm256_set1_epi32(B)); }
_ZN5Botan9SIMD_8x32eOERKS0_:
  149|  2.62M|      void operator^=(const SIMD_8x32& other) { m_avx2 = _mm256_xor_si256(m_avx2, other.m_avx2); }
_ZNK5Botan9SIMD_8x324rotlILm7EEES0_v:
   67|   655k|      {
   68|       |#if defined(__AVX512VL__)
   69|       |         return SIMD_8x32(_mm256_rol_epi32(m_avx2, ROT));
   70|       |#else
   71|   655k|         if constexpr(ROT == 8) {
  ------------------
  |  Branch (71:23): [Folded - Ignored]
  ------------------
   72|   655k|            const __m256i shuf_rotl_8 =
   73|   655k|               _mm256_set_epi64x(0x0e0d0c0f'0a09080b, 0x06050407'02010003, 0x0e0d0c0f'0a09080b, 0x06050407'02010003);
   74|       |
   75|   655k|            return SIMD_8x32(_mm256_shuffle_epi8(m_avx2, shuf_rotl_8));
   76|   655k|         } else if constexpr(ROT == 16) {
  ------------------
  |  Branch (76:30): [Folded - Ignored]
  ------------------
   77|   655k|            const __m256i shuf_rotl_16 =
   78|   655k|               _mm256_set_epi64x(0x0d0c0f0e'09080b0a, 0x05040706'01000302, 0x0d0c0f0e'09080b0a, 0x05040706'01000302);
   79|       |
   80|   655k|            return SIMD_8x32(_mm256_shuffle_epi8(m_avx2, shuf_rotl_16));
   81|   655k|         } else {
   82|   655k|            return SIMD_8x32(_mm256_or_si256(_mm256_slli_epi32(m_avx2, static_cast<int>(ROT)),
   83|   655k|                                             _mm256_srli_epi32(m_avx2, static_cast<int>(32 - ROT))));
   84|   655k|         }
   85|   655k|#endif
   86|   655k|      }
_ZN5Botan9SIMD_8x32C2Ejjjjjjjj:
   43|  16.3k|                         uint32_t B7) noexcept {
   44|  16.3k|         m_avx2 = _mm256_set_epi32(B7, B6, B5, B4, B3, B2, B1, B0);
   45|  16.3k|      }
_ZNK5Botan9SIMD_8x32plERKS0_:
  108|  32.7k|      SIMD_8x32 operator+(const SIMD_8x32& other) const noexcept {
  109|  32.7k|         SIMD_8x32 retval(*this);
  110|  32.7k|         retval += other;
  111|  32.7k|         return retval;
  112|  32.7k|      }
_ZN5Botan9SIMD_8x32pLERKS0_:
  143|  2.78M|      void operator+=(const SIMD_8x32& other) { m_avx2 = _mm256_add_epi32(m_avx2, other.m_avx2); }
_ZN5Botan9SIMD_8x329transposeERS0_S1_S1_S1_S1_S1_S1_S1_:
  214|  16.3k|                            SIMD_8x32& B7) noexcept {
  215|  16.3k|         transpose(B0, B1, B2, B3);
  216|  16.3k|         transpose(B4, B5, B6, B7);
  217|       |
  218|  16.3k|         swap_tops(B0, B4);
  219|  16.3k|         swap_tops(B1, B5);
  220|  16.3k|         swap_tops(B2, B6);
  221|  16.3k|         swap_tops(B3, B7);
  222|  16.3k|      }
_ZNK5Botan9SIMD_8x326handleEv:
  248|   262k|      __m256i BOTAN_AVX2_FN handle() const noexcept { return m_avx2; }
_ZN5Botan9SIMD_8x329swap_topsERS0_S1_:
  255|  65.5k|      static void swap_tops(SIMD_8x32& A, SIMD_8x32& B) {
  256|  65.5k|         SIMD_8x32 T0 = _mm256_permute2x128_si256(A.handle(), B.handle(), 0 + (2 << 4));
  257|  65.5k|         SIMD_8x32 T1 = _mm256_permute2x128_si256(A.handle(), B.handle(), 1 + (3 << 4));
  258|  65.5k|         A = T0;
  259|  65.5k|         B = T1;
  260|  65.5k|      }
_ZNK5Botan9SIMD_8x324rotlILm16EEES0_v:
   67|   655k|      {
   68|       |#if defined(__AVX512VL__)
   69|       |         return SIMD_8x32(_mm256_rol_epi32(m_avx2, ROT));
   70|       |#else
   71|   655k|         if constexpr(ROT == 8) {
  ------------------
  |  Branch (71:23): [Folded - Ignored]
  ------------------
   72|   655k|            const __m256i shuf_rotl_8 =
   73|   655k|               _mm256_set_epi64x(0x0e0d0c0f'0a09080b, 0x06050407'02010003, 0x0e0d0c0f'0a09080b, 0x06050407'02010003);
   74|       |
   75|   655k|            return SIMD_8x32(_mm256_shuffle_epi8(m_avx2, shuf_rotl_8));
   76|   655k|         } else if constexpr(ROT == 16) {
  ------------------
  |  Branch (76:30): [Folded - Ignored]
  ------------------
   77|   655k|            const __m256i shuf_rotl_16 =
   78|   655k|               _mm256_set_epi64x(0x0d0c0f0e'09080b0a, 0x05040706'01000302, 0x0d0c0f0e'09080b0a, 0x05040706'01000302);
   79|       |
   80|   655k|            return SIMD_8x32(_mm256_shuffle_epi8(m_avx2, shuf_rotl_16));
   81|   655k|         } else {
   82|   655k|            return SIMD_8x32(_mm256_or_si256(_mm256_slli_epi32(m_avx2, static_cast<int>(ROT)),
   83|   655k|                                             _mm256_srli_epi32(m_avx2, static_cast<int>(32 - ROT))));
   84|   655k|         }
   85|   655k|#endif
   86|   655k|      }
_ZNK5Botan9SIMD_8x324rotlILm12EEES0_v:
   67|   655k|      {
   68|       |#if defined(__AVX512VL__)
   69|       |         return SIMD_8x32(_mm256_rol_epi32(m_avx2, ROT));
   70|       |#else
   71|   655k|         if constexpr(ROT == 8) {
  ------------------
  |  Branch (71:23): [Folded - Ignored]
  ------------------
   72|   655k|            const __m256i shuf_rotl_8 =
   73|   655k|               _mm256_set_epi64x(0x0e0d0c0f'0a09080b, 0x06050407'02010003, 0x0e0d0c0f'0a09080b, 0x06050407'02010003);
   74|       |
   75|   655k|            return SIMD_8x32(_mm256_shuffle_epi8(m_avx2, shuf_rotl_8));
   76|   655k|         } else if constexpr(ROT == 16) {
  ------------------
  |  Branch (76:30): [Folded - Ignored]
  ------------------
   77|   655k|            const __m256i shuf_rotl_16 =
   78|   655k|               _mm256_set_epi64x(0x0d0c0f0e'09080b0a, 0x05040706'01000302, 0x0d0c0f0e'09080b0a, 0x05040706'01000302);
   79|       |
   80|   655k|            return SIMD_8x32(_mm256_shuffle_epi8(m_avx2, shuf_rotl_16));
   81|   655k|         } else {
   82|   655k|            return SIMD_8x32(_mm256_or_si256(_mm256_slli_epi32(m_avx2, static_cast<int>(ROT)),
   83|   655k|                                             _mm256_srli_epi32(m_avx2, static_cast<int>(32 - ROT))));
   84|   655k|         }
   85|   655k|#endif
   86|   655k|      }
_ZNK5Botan9SIMD_8x324rotlILm8EEES0_v:
   67|   655k|      {
   68|       |#if defined(__AVX512VL__)
   69|       |         return SIMD_8x32(_mm256_rol_epi32(m_avx2, ROT));
   70|       |#else
   71|   655k|         if constexpr(ROT == 8) {
  ------------------
  |  Branch (71:23): [Folded - Ignored]
  ------------------
   72|   655k|            const __m256i shuf_rotl_8 =
   73|   655k|               _mm256_set_epi64x(0x0e0d0c0f'0a09080b, 0x06050407'02010003, 0x0e0d0c0f'0a09080b, 0x06050407'02010003);
   74|       |
   75|   655k|            return SIMD_8x32(_mm256_shuffle_epi8(m_avx2, shuf_rotl_8));
   76|   655k|         } else if constexpr(ROT == 16) {
   77|   655k|            const __m256i shuf_rotl_16 =
   78|   655k|               _mm256_set_epi64x(0x0d0c0f0e'09080b0a, 0x05040706'01000302, 0x0d0c0f0e'09080b0a, 0x05040706'01000302);
   79|       |
   80|   655k|            return SIMD_8x32(_mm256_shuffle_epi8(m_avx2, shuf_rotl_16));
   81|   655k|         } else {
   82|   655k|            return SIMD_8x32(_mm256_or_si256(_mm256_slli_epi32(m_avx2, static_cast<int>(ROT)),
   83|   655k|                                             _mm256_srli_epi32(m_avx2, static_cast<int>(32 - ROT))));
   84|   655k|         }
   85|   655k|#endif
   86|   655k|      }

_ZN5Botan12BufferSlicerC2ENSt3__14spanIKhLm18446744073709551615EEE:
  143|     19|      BufferSlicer(std::span<const uint8_t> buffer) : m_remaining(buffer) {}
_ZN5Botan12BufferSlicer4takeEm:
  155|     19|      std::span<const uint8_t> take(const size_t count) {
  156|     19|         BOTAN_STATE_CHECK(remaining() >= count);
  ------------------
  |  |   42|     19|   do {                                                         \
  |  |   43|     19|      if(!(expr))                                               \
  |  |  ------------------
  |  |  |  Branch (43:10): [True: 0, False: 19]
  |  |  ------------------
  |  |   44|     19|         Botan::throw_invalid_state(#expr, __func__, __FILE__); \
  |  |   45|     19|   } while(0)
  |  |  ------------------
  |  |  |  Branch (45:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  157|     19|         auto result = m_remaining.first(count);
  158|     19|         m_remaining = m_remaining.subspan(count);
  159|     19|         return result;
  160|     19|      }
_ZNK5Botan12BufferSlicer9remainingEv:
  184|     37|      size_t remaining() const { return m_remaining.size(); }
_ZNK5Botan12BufferSlicer5emptyEv:
  186|     18|      bool empty() const { return m_remaining.empty(); }

_ZN5Botan21Allocator_InitializerC2Ev:
   40|      1|      Allocator_Initializer() { initialize_allocator(); }

_ZN5Botan3OIDC2ESt16initializer_listIjE:
  229|    283|      explicit OID(std::initializer_list<uint32_t> init) : m_id(init) {
  230|    283|         BOTAN_ARG_CHECK(m_id.size() > 2 && m_id[0] <= 2 && (m_id[0] != 2 || m_id[1] <= 39), "Invalid OID");
  ------------------
  |  |   30|    283|   do {                                                          \
  |  |   31|  1.48k|      if(!(expr))                                                \
  |  |  ------------------
  |  |  |  Branch (31:12): [True: 283, False: 0]
  |  |  |  Branch (31:12): [True: 283, False: 0]
  |  |  |  Branch (31:12): [True: 210, False: 73]
  |  |  |  Branch (31:12): [True: 73, False: 0]
  |  |  ------------------
  |  |   32|    283|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   33|    283|   } while(0)
  |  |  ------------------
  |  |  |  Branch (33:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  231|    283|      }
_ZNK5Botan3OID9has_valueEv:
  271|      2|      bool has_value() const { return (m_id.empty() == false); }
_ZNK5Botan3OIDeqERKS0_:
  309|      2|      bool operator==(const OID& other) const { return m_id == other.m_id; }
_ZN5Botan11ASN1_ObjectC2Ev:
  117|    283|      ASN1_Object() = default;
_ZN5Botan11ASN1_ObjectD2Ev:
  120|    848|      virtual ~ASN1_Object() = default;
_ZN5Botan11ASN1_ObjectC2ERKS0_:
  118|    565|      ASN1_Object(const ASN1_Object&) = default;

_ZN5Botan13ignore_paramsIJRKmS2_EEEvDpOT_:
  114|  26.8M|void ignore_params(T&&... args) {
  115|  26.8M|   (ignore_param(args), ...);
  116|  26.8M|}
_ZN5Botan12ignore_paramIRKmEEvOT_:
  111|  54.2M|void ignore_param(T&&) {}
_ZN5Botan13ignore_paramsIJRmEEEvDpOT_:
  114|  46.0M|void ignore_params(T&&... args) {
  115|  46.0M|   (ignore_param(args), ...);
  116|  46.0M|}
_ZN5Botan12ignore_paramIRmEEvOT_:
  111|  46.0M|void ignore_param(T&&) {}
_ZN5Botan13ignore_paramsIJRKmEEEvDpOT_:
  114|   565k|void ignore_params(T&&... args) {
  115|   565k|   (ignore_param(args), ...);
  116|   565k|}
_ZN5Botan13ignore_paramsIJRNSt3__16vectorImNS_16secure_allocatorImEEEEEEEvDpOT_:
  114|  65.1M|void ignore_params(T&&... args) {
  115|  65.1M|   (ignore_param(args), ...);
  116|  65.1M|}
_ZN5Botan12ignore_paramIRNSt3__16vectorImNS_16secure_allocatorImEEEEEEvOT_:
  111|  65.1M|void ignore_param(T&&) {}
_ZN5Botan13ignore_paramsIJRlEEEvDpOT_:
  114|  65.1M|void ignore_params(T&&... args) {
  115|  65.1M|   (ignore_param(args), ...);
  116|  65.1M|}
_ZN5Botan12ignore_paramIRlEEvOT_:
  111|  65.1M|void ignore_param(T&&) {}

_ZN5Botan6BigIntC2ERKS0_:
   80|   565k|      BigInt(const BigInt& other) = default;
_ZN5Botan6BigIntC2Ev:
   40|  2.06M|      BigInt() = default;
_ZN5Botan6BigInt6decodeEPKhm:
  776|  2.72k|      static BigInt decode(const uint8_t buf[], size_t length) { return BigInt(buf, length); }
_ZN5BotanplERKNS_6BigIntES2_:
  958|  15.2k|inline BigInt operator+(const BigInt& x, const BigInt& y) {
  959|  15.2k|   return BigInt::add2(x, y.data(), y.sig_words(), y.sign());
  960|  15.2k|}
_ZNK5Botan6BigInt4dataEv:
  615|   228M|      const word* data() const { return m_data.const_data(); }
_ZNK5Botan6BigInt4Data10const_dataEv:
  839|   228M|            const word* const_data() const { return m_reg.data(); }
_ZNK5Botan6BigInt9sig_wordsEv:
  584|  57.0M|      size_t sig_words() const { return m_data.sig_words(); }
_ZNK5Botan6BigInt4Data9sig_wordsEv:
  933|  57.0M|            size_t sig_words() const {
  934|  57.0M|               if(m_sig_words == sig_words_npos) {
  ------------------
  |  Branch (934:19): [True: 11.2M, False: 45.7M]
  ------------------
  935|  11.2M|                  m_sig_words = calc_sig_words();
  936|  45.7M|               } else {
  937|  45.7M|                  BOTAN_DEBUG_ASSERT(m_sig_words == calc_sig_words());
  ------------------
  |  |   99|  45.7M|      do {                          \
  |  |  100|  45.7M|      } while(0)
  |  |  ------------------
  |  |  |  Branch (100:15): [Folded - Ignored]
  |  |  ------------------
  ------------------
  938|  45.7M|               }
  939|  57.0M|               return m_sig_words;
  940|  57.0M|            }
_ZNK5Botan6BigInt4signEv:
  540|   132M|      Sign sign() const { return (m_signedness); }
_ZN5Botan6BigIntpLERKS0_:
  186|   133k|      BigInt& operator+=(const BigInt& y) { return add(y.data(), y.sig_words(), y.sign()); }
_ZN5Botan6BigIntaSEOS0_:
  153|   581k|      BigInt& operator=(BigInt&& other) {
  154|   581k|         if(this != &other) {
  ------------------
  |  Branch (154:13): [True: 581k, False: 0]
  ------------------
  155|   581k|            this->swap(other);
  156|   581k|         }
  157|       |
  158|   581k|         return (*this);
  159|   581k|      }
_ZN5Botan6BigInt4swapERS0_:
  170|  29.2M|      void swap(BigInt& other) {
  171|  29.2M|         m_data.swap(other.m_data);
  172|  29.2M|         std::swap(m_signedness, other.m_signedness);
  173|  29.2M|      }
_ZN5Botan6BigInt4Data4swapERS1_:
  921|  29.2M|            void swap(Data& other) {
  922|  29.2M|               m_reg.swap(other.m_reg);
  923|  29.2M|               std::swap(m_sig_words, other.m_sig_words);
  924|  29.2M|            }
_ZN5BotanltERKNS_6BigIntEm:
 1035|  7.74k|inline bool operator<(const BigInt& a, word b) {
 1036|  7.74k|   return (a.cmp_word(b) < 0);
 1037|  7.74k|}
_ZNK5Botan6BigInt7get_bitEm:
  467|  29.9M|      bool get_bit(size_t n) const { return ((word_at(n / BOTAN_MP_WORD_BITS) >> (n % BOTAN_MP_WORD_BITS)) & 1); }
  ------------------
  |  |   50|  29.9M|#define BOTAN_MP_WORD_BITS 64
  ------------------
                    bool get_bit(size_t n) const { return ((word_at(n / BOTAN_MP_WORD_BITS) >> (n % BOTAN_MP_WORD_BITS)) & 1); }
  ------------------
  |  |   50|  29.9M|#define BOTAN_MP_WORD_BITS 64
  ------------------
_ZNK5Botan6BigInt7word_atEm:
  518|  64.7M|      word word_at(size_t n) const { return m_data.get_word_at(n); }
_ZNK5Botan6BigInt4Data11get_word_atEm:
  848|  64.7M|            word get_word_at(size_t n) const {
  849|  64.7M|               if(n < m_reg.size()) {
  ------------------
  |  Branch (849:19): [True: 64.7M, False: 1.67k]
  ------------------
  850|  64.7M|                  return m_reg[n];
  851|  64.7M|               }
  852|  1.67k|               return 0;
  853|  64.7M|            }
_ZN5BotanmiERKNS_6BigIntES2_:
  970|  80.7k|inline BigInt operator-(const BigInt& x, const BigInt& y) {
  971|  80.7k|   return BigInt::add2(x, y.data(), y.sig_words(), y.reverse_sign());
  972|  80.7k|}
_ZNK5Botan6BigInt12reverse_signEv:
  545|  82.0k|      Sign reverse_sign() const {
  546|  82.0k|         if(sign() == Positive) {
  ------------------
  |  Branch (546:13): [True: 82.0k, False: 0]
  ------------------
  547|  82.0k|            return Negative;
  548|  82.0k|         }
  549|      0|         return Positive;
  550|  82.0k|      }
_ZNK5Botan6BigInt7is_zeroEv:
  428|  10.6M|      bool is_zero() const { return (sig_words() == 0); }
_ZN5Botan6BigIntD2Ev:
  148|  3.02M|      ~BigInt() { const_time_unpoison(); }
_ZNK5Botan6BigInt19const_time_unpoisonEv:
  726|  3.02M|      void const_time_unpoison() const {}
_ZN5Botan6BigInt4zeroEv:
   45|   134k|      static BigInt zero() { return BigInt(); }
_ZN5Botan6BigIntC2EOS0_:
  146|   343k|      BigInt(BigInt&& other) { this->swap(other); }
_ZN5Botan6BigInt8swap_regERNSt3__16vectorImNS_16secure_allocatorImEEEE:
  177|  20.1M|      void swap_reg(secure_vector<word>& reg) {
  178|  20.1M|         m_data.swap(reg);
  179|       |         // sign left unchanged
  180|  20.1M|      }
_ZN5Botan6BigIntmIERKS0_:
  198|   126k|      BigInt& operator-=(const BigInt& y) { return sub(y.data(), y.sig_words(), y.sign()); }
_ZN5Botan6BigInt3subEPKmmNS0_4SignE:
  292|   126k|      BigInt& sub(const word y[], size_t y_words, Sign sign) {
  293|   126k|         return add(y, y_words, sign == Positive ? Negative : Positive);
  ------------------
  |  Branch (293:33): [True: 126k, False: 0]
  ------------------
  294|   126k|      }
_ZN5Botan6BigInt5clearEv:
  370|   105k|      void clear() {
  371|   105k|         m_data.set_to_zero();
  372|   105k|         m_signedness = Positive;
  373|   105k|      }
_ZNK5Botan6BigInt7is_evenEv:
  410|  2.19k|      bool is_even() const { return (get_bit(0) == 0); }
_ZNK5Botan6BigInt6is_oddEv:
  416|  1.36k|      bool is_odd() const { return (get_bit(0) == 1); }
_ZNK5Botan6BigInt10is_nonzeroEv:
  422|  6.59k|      bool is_nonzero() const { return (!is_zero()); }
_ZN5Botan6BigInt7set_bitEm:
  434|  75.4k|      void set_bit(size_t n) { conditionally_set_bit(n, true); }
_ZN5Botan6BigInt21conditionally_set_bitEmb:
  444|  30.3M|      void conditionally_set_bit(size_t n, bool set_it) {
  445|  30.3M|         const size_t which = n / BOTAN_MP_WORD_BITS;
  ------------------
  |  |   50|  30.3M|#define BOTAN_MP_WORD_BITS 64
  ------------------
  446|  30.3M|         const word mask = static_cast<word>(set_it) << (n % BOTAN_MP_WORD_BITS);
  ------------------
  |  |   50|  30.3M|#define BOTAN_MP_WORD_BITS 64
  ------------------
  447|  30.3M|         m_data.set_word_at(which, word_at(which) | mask);
  448|  30.3M|      }
_ZN5Botan6BigInt9mask_bitsEm:
  460|  65.1M|      void mask_bits(size_t n) { m_data.mask_bits(n); }
_ZN5Botan6BigInt11set_word_atEmm:
  520|  13.0M|      void set_word_at(size_t i, word w) { m_data.set_word_at(i, w); }
_ZN5Botan6BigInt9set_wordsEPKmm:
  522|  3.12M|      void set_words(const word w[], size_t len) { m_data.set_words(w, len); }
_ZNK5Botan6BigInt11is_negativeEv:
  528|   129M|      bool is_negative() const { return (sign() == Negative); }
_ZNK5Botan6BigInt11is_positiveEv:
  534|   652k|      bool is_positive() const { return (sign() == Positive); }
_ZN5Botan6BigInt9flip_signEv:
  555|  1.36k|      void flip_sign() { set_sign(reverse_sign()); }
_ZN5Botan6BigInt8set_signENS0_4SignE:
  561|   883k|      void set_sign(Sign sign) {
  562|   883k|         if(sign == Negative && is_zero()) {
  ------------------
  |  Branch (562:13): [True: 1.39k, False: 882k]
  |  Branch (562:33): [True: 0, False: 1.39k]
  ------------------
  563|      0|            sign = Positive;
  564|      0|         }
  565|       |
  566|   883k|         m_signedness = sign;
  567|   883k|      }
_ZNK5Botan6BigInt4sizeEv:
  578|   361M|      size_t size() const { return m_data.size(); }
_ZN5Botan6BigInt12mutable_dataEv:
  609|   303M|      word* mutable_data() { return m_data.mutable_data(); }
_ZN5Botan6BigInt15get_word_vectorEv:
  620|  9.55M|      secure_vector<word>& get_word_vector() { return m_data.mutable_vector(); }
_ZNK5Botan6BigInt7grow_toEm:
  631|   130M|      void grow_to(size_t n) const { m_data.grow_to(n); }
_ZN5Botan6BigInt10power_of_2Em:
  742|    837|      static BigInt power_of_2(size_t n) {
  743|    837|         BigInt b;
  744|    837|         b.set_bit(n);
  745|    837|         return b;
  746|    837|      }
_ZN5Botan6BigInt4Data12mutable_dataEv:
  834|   304M|            word* mutable_data() {
  835|   304M|               invalidate_sig_words();
  836|   304M|               return m_reg.data();
  837|   304M|            }
_ZN5Botan6BigInt4Data14mutable_vectorEv:
  841|  9.55M|            secure_vector<word>& mutable_vector() {
  842|  9.55M|               invalidate_sig_words();
  843|  9.55M|               return m_reg;
  844|  9.55M|            }
_ZN5Botan6BigInt4Data11set_word_atEmm:
  855|  43.4M|            void set_word_at(size_t i, word w) {
  856|  43.4M|               invalidate_sig_words();
  857|  43.4M|               if(i >= m_reg.size()) {
  ------------------
  |  Branch (857:19): [True: 13.0M, False: 30.3M]
  ------------------
  858|  13.0M|                  if(w == 0) {
  ------------------
  |  Branch (858:22): [True: 13.0M, False: 35.9k]
  ------------------
  859|  13.0M|                     return;
  860|  13.0M|                  }
  861|  35.9k|                  grow_to(i + 1);
  862|  35.9k|               }
  863|  30.4M|               m_reg[i] = w;
  864|  30.4M|            }
_ZN5Botan6BigInt4Data9set_wordsEPKmm:
  866|  3.12M|            void set_words(const word w[], size_t len) {
  867|  3.12M|               invalidate_sig_words();
  868|  3.12M|               m_reg.assign(w, w + len);
  869|  3.12M|            }
_ZN5Botan6BigInt4Data11set_to_zeroEv:
  871|   105k|            void set_to_zero() {
  872|   105k|               m_reg.resize(m_reg.capacity());
  873|   105k|               clear_mem(m_reg.data(), m_reg.size());
  874|   105k|               m_sig_words = 0;
  875|   105k|            }
_ZN5Botan6BigInt4Data9mask_bitsEm:
  883|  65.1M|            void mask_bits(size_t n) {
  884|  65.1M|               if(n == 0) {
  ------------------
  |  Branch (884:19): [True: 0, False: 65.1M]
  ------------------
  885|      0|                  return set_to_zero();
  886|      0|               }
  887|       |
  888|  65.1M|               const size_t top_word = n / BOTAN_MP_WORD_BITS;
  ------------------
  |  |   50|  65.1M|#define BOTAN_MP_WORD_BITS 64
  ------------------
  889|       |
  890|       |               // if(top_word < sig_words()) ?
  891|  65.1M|               if(top_word < size()) {
  ------------------
  |  Branch (891:19): [True: 65.1M, False: 950]
  ------------------
  892|  65.1M|                  const word mask = (static_cast<word>(1) << (n % BOTAN_MP_WORD_BITS)) - 1;
  ------------------
  |  |   50|  65.1M|#define BOTAN_MP_WORD_BITS 64
  ------------------
  893|  65.1M|                  const size_t len = size() - (top_word + 1);
  894|  65.1M|                  if(len > 0) {
  ------------------
  |  Branch (894:22): [True: 65.1M, False: 3.96k]
  ------------------
  895|  65.1M|                     clear_mem(&m_reg[top_word + 1], len);
  896|  65.1M|                  }
  897|  65.1M|                  m_reg[top_word] &= mask;
  898|  65.1M|                  invalidate_sig_words();
  899|  65.1M|               }
  900|  65.1M|            }
_ZNK5Botan6BigInt4Data7grow_toEm:
  902|   130M|            void grow_to(size_t n) const {
  903|   130M|               if(n > size()) {
  ------------------
  |  Branch (903:19): [True: 4.14M, False: 126M]
  ------------------
  904|  4.14M|                  if(n <= m_reg.capacity()) {
  ------------------
  |  Branch (904:22): [True: 3.09M, False: 1.04M]
  ------------------
  905|  3.09M|                     m_reg.resize(n);
  906|  3.09M|                  } else {
  907|  1.04M|                     m_reg.resize(n + (8 - (n % 8)));
  908|  1.04M|                  }
  909|  4.14M|               }
  910|   130M|            }
_ZNK5Botan6BigInt4Data4sizeEv:
  912|   623M|            size_t size() const { return m_reg.size(); }
_ZN5Botan6BigInt4Data4swapERNSt3__16vectorImNS_16secure_allocatorImEEEE:
  926|  20.2M|            void swap(secure_vector<word>& reg) {
  927|  20.2M|               m_reg.swap(reg);
  928|  20.2M|               invalidate_sig_words();
  929|  20.2M|            }
_ZNK5Botan6BigInt4Data20invalidate_sig_wordsEv:
  931|   445M|            void invalidate_sig_words() const { m_sig_words = sig_words_npos; }
_ZN5BotanplERKNS_6BigIntEm:
  962|    837|inline BigInt operator+(const BigInt& x, word y) {
  963|    837|   return BigInt::add2(x, &y, 1, BigInt::Positive);
  964|    837|}
_ZN5BotanmiERKNS_6BigIntEm:
  974|      1|inline BigInt operator-(const BigInt& x, word y) {
  975|      1|   return BigInt::add2(x, &y, 1, BigInt::Negative);
  976|      1|}
_ZN5BotanmlEmRKNS_6BigIntE:
  981|   253k|inline BigInt operator*(word x, const BigInt& y) {
  982|   253k|   return y * x;
  983|   253k|}
_ZN5BotaneqERKNS_6BigIntES2_:
  995|  21.7k|inline bool operator==(const BigInt& a, const BigInt& b) {
  996|  21.7k|   return a.is_equal(b);
  997|  21.7k|}
_ZN5BotanleERKNS_6BigIntES2_:
 1003|  18.0k|inline bool operator<=(const BigInt& a, const BigInt& b) {
 1004|  18.0k|   return (a.cmp(b) <= 0);
 1005|  18.0k|}
_ZN5BotangeERKNS_6BigIntES2_:
 1007|  11.5k|inline bool operator>=(const BigInt& a, const BigInt& b) {
 1008|  11.5k|   return (a.cmp(b) >= 0);
 1009|  11.5k|}
_ZN5BotanltERKNS_6BigIntES2_:
 1011|   165k|inline bool operator<(const BigInt& a, const BigInt& b) {
 1012|   165k|   return a.is_less_than(b);
 1013|   165k|}
_ZN5BotangtERKNS_6BigIntES2_:
 1015|   150k|inline bool operator>(const BigInt& a, const BigInt& b) {
 1016|   150k|   return b.is_less_than(a);
 1017|   150k|}
_ZN5BotaneqERKNS_6BigIntEm:
 1019|  44.8k|inline bool operator==(const BigInt& a, word b) {
 1020|  44.8k|   return (a.cmp_word(b) == 0);
 1021|  44.8k|}
_ZN5BotanleERKNS_6BigIntEm:
 1027|  1.36k|inline bool operator<=(const BigInt& a, word b) {
 1028|  1.36k|   return (a.cmp_word(b) <= 0);
 1029|  1.36k|}
_ZN5BotangeERKNS_6BigIntEm:
 1031|  1.36k|inline bool operator>=(const BigInt& a, word b) {
 1032|  1.36k|   return (a.cmp_word(b) >= 0);
 1033|  1.36k|}
_ZN5BotangtERKNS_6BigIntEm:
 1039|   172k|inline bool operator>(const BigInt& a, word b) {
 1040|   172k|   return (a.cmp_word(b) > 0);
 1041|   172k|}
_ZN5Botan6BigIntaSERKS0_:
  164|  3.88M|      BigInt& operator=(const BigInt&) = default;
_ZN5Botan6BigInt13binary_decodeINS_16secure_allocatorIhEEEEvRKNSt3__16vectorIhT_EE:
  682|  91.8k|      void binary_decode(const std::vector<uint8_t, Alloc>& buf) {
  683|  91.8k|         binary_decode(buf.data(), buf.size());
  684|  91.8k|      }

_ZN5Botan20Buffered_Computation6updateENSt3__14spanIKhLm18446744073709551615EEE:
   41|     10|      void update(std::span<const uint8_t> in) { add_data(in); }
_ZN5Botan20Buffered_Computation5finalENSt3__14spanIhLm18446744073709551615EEE:
   86|      4|      void final(std::span<uint8_t> out) {
   87|      4|         BOTAN_ARG_CHECK(out.size() >= output_length(), "provided output buffer has insufficient capacity");
  ------------------
  |  |   30|      4|   do {                                                          \
  |  |   31|      4|      if(!(expr))                                                \
  |  |  ------------------
  |  |  |  Branch (31:10): [True: 0, False: 4]
  |  |  ------------------
  |  |   32|      4|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   33|      4|   } while(0)
  |  |  ------------------
  |  |  |  Branch (33:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   88|      4|         final_result(out);
   89|      4|      }
_ZN5Botan20Buffered_Computation5finalINSt3__16vectorIhNS_16secure_allocatorIhEEEEEET_v:
   78|      2|      T final() {
   79|      2|         T output(output_length());
   80|      2|         final_result(output);
   81|      2|         return output;
   82|      2|      }
_ZN5Botan20Buffered_ComputationD2Ev:
  134|      2|      virtual ~Buffered_Computation() = default;

_ZNK5Botan10ChaCha_RNG31max_number_of_bytes_per_requestEv:
  106|  91.8k|      size_t max_number_of_bytes_per_request() const override { return 0; }

_ZN5Botan6ranges24assert_exact_byte_lengthILm8ERNSt3__14spanIhLm8EEEEEvOT0_:
   86|      4|inline constexpr void assert_exact_byte_length(R&& r) {
   87|      4|   const std::span s{r};
   88|      4|   if constexpr(decltype(s)::extent != std::dynamic_extent) {
  ------------------
  |  Branch (88:17): [Folded - Ignored]
  ------------------
   89|      4|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   90|      4|   } else {
   91|      4|      BOTAN_ASSERT(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   92|      4|   }
   93|      4|}
_ZN5Botan6ranges25assert_equal_byte_lengthsIRNSt3__14spanIhLm8EEEJRNS3_IKmLm1EEEEEEvOT_DpOT0_:
  107|      4|{
  108|      4|   const std::span s0{r0};
  109|       |
  110|      4|   if constexpr(decltype(s0)::extent != std::dynamic_extent) {
  ------------------
  |  Branch (110:17): [Folded - Ignored]
  ------------------
  111|      4|      constexpr size_t expected_size = s0.size_bytes();
  112|      4|      (assert_exact_byte_length<expected_size>(rs), ...);
  113|      4|   } else {
  114|      4|      const size_t expected_size = s0.size_bytes();
  115|      4|      BOTAN_ARG_CHECK(((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...),
  116|      4|                      "memory regions don't have equal lengths");
  117|      4|   }
  118|      4|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm8ERNSt3__14spanIKmLm1EEEEEvOT0_:
   86|      4|inline constexpr void assert_exact_byte_length(R&& r) {
   87|      4|   const std::span s{r};
   88|      4|   if constexpr(decltype(s)::extent != std::dynamic_extent) {
  ------------------
  |  Branch (88:17): [Folded - Ignored]
  ------------------
   89|      4|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   90|      4|   } else {
   91|      4|      BOTAN_ASSERT(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   92|      4|   }
   93|      4|}
_ZN5Botan6ranges10size_bytesIRNSt3__14spanIhLm8EEEEEmOT_:
   73|      4|inline constexpr size_t size_bytes(spanable_range auto&& r) {
   74|      4|   return std::span{r}.size_bytes();
   75|      4|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm8ERNSt3__14spanIKhLm8EEEEEvOT0_:
   86|  1.05M|inline constexpr void assert_exact_byte_length(R&& r) {
   87|  1.05M|   const std::span s{r};
   88|  1.05M|   if constexpr(decltype(s)::extent != std::dynamic_extent) {
  ------------------
  |  Branch (88:17): [Folded - Ignored]
  ------------------
   89|  1.05M|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   90|  1.05M|   } else {
   91|  1.05M|      BOTAN_ASSERT(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   92|  1.05M|   }
   93|  1.05M|}
_ZN5Botan6ranges25assert_equal_byte_lengthsIRNSt3__14spanImLm1EEEJRNS3_IKhLm8EEEEEEvOT_DpOT0_:
  107|   525k|{
  108|   525k|   const std::span s0{r0};
  109|       |
  110|   525k|   if constexpr(decltype(s0)::extent != std::dynamic_extent) {
  ------------------
  |  Branch (110:17): [Folded - Ignored]
  ------------------
  111|   525k|      constexpr size_t expected_size = s0.size_bytes();
  112|   525k|      (assert_exact_byte_length<expected_size>(rs), ...);
  113|   525k|   } else {
  114|   525k|      const size_t expected_size = s0.size_bytes();
  115|   525k|      BOTAN_ARG_CHECK(((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...),
  116|   525k|                      "memory regions don't have equal lengths");
  117|   525k|   }
  118|   525k|}
_ZN5Botan6ranges10size_bytesIRNSt3__14spanImLm1EEEEEmOT_:
   73|   525k|inline constexpr size_t size_bytes(spanable_range auto&& r) {
   74|   525k|   return std::span{r}.size_bytes();
   75|   525k|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm4ERNSt3__14spanIhLm4EEEEEvOT0_:
   86|     32|inline constexpr void assert_exact_byte_length(R&& r) {
   87|     32|   const std::span s{r};
   88|     32|   if constexpr(decltype(s)::extent != std::dynamic_extent) {
  ------------------
  |  Branch (88:17): [Folded - Ignored]
  ------------------
   89|     32|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   90|     32|   } else {
   91|     32|      BOTAN_ASSERT(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   92|     32|   }
   93|     32|}
_ZN5Botan6ranges25assert_equal_byte_lengthsIRNSt3__14spanIhLm4EEEJRNS3_IKjLm1EEEEEEvOT_DpOT0_:
  107|     32|{
  108|     32|   const std::span s0{r0};
  109|       |
  110|     32|   if constexpr(decltype(s0)::extent != std::dynamic_extent) {
  ------------------
  |  Branch (110:17): [Folded - Ignored]
  ------------------
  111|     32|      constexpr size_t expected_size = s0.size_bytes();
  112|     32|      (assert_exact_byte_length<expected_size>(rs), ...);
  113|     32|   } else {
  114|     32|      const size_t expected_size = s0.size_bytes();
  115|     32|      BOTAN_ARG_CHECK(((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...),
  116|     32|                      "memory regions don't have equal lengths");
  117|     32|   }
  118|     32|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm4ERNSt3__14spanIKjLm1EEEEEvOT0_:
   86|     32|inline constexpr void assert_exact_byte_length(R&& r) {
   87|     32|   const std::span s{r};
   88|     32|   if constexpr(decltype(s)::extent != std::dynamic_extent) {
  ------------------
  |  Branch (88:17): [Folded - Ignored]
  ------------------
   89|     32|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   90|     32|   } else {
   91|     32|      BOTAN_ASSERT(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   92|     32|   }
   93|     32|}
_ZN5Botan6ranges10size_bytesIRNSt3__14spanIhLm4EEEEEmOT_:
   73|     32|inline constexpr size_t size_bytes(spanable_range auto&& r) {
   74|     32|   return std::span{r}.size_bytes();
   75|     32|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm4ERNSt3__14spanIKhLm4EEEEEvOT0_:
   86|    320|inline constexpr void assert_exact_byte_length(R&& r) {
   87|    320|   const std::span s{r};
   88|    320|   if constexpr(decltype(s)::extent != std::dynamic_extent) {
  ------------------
  |  Branch (88:17): [Folded - Ignored]
  ------------------
   89|    320|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   90|    320|   } else {
   91|    320|      BOTAN_ASSERT(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   92|    320|   }
   93|    320|}
_ZN5Botan6ranges25assert_equal_byte_lengthsIRNSt3__14spanIjLm1EEEJRNS3_IKhLm4EEEEEEvOT_DpOT0_:
  107|    160|{
  108|    160|   const std::span s0{r0};
  109|       |
  110|    160|   if constexpr(decltype(s0)::extent != std::dynamic_extent) {
  ------------------
  |  Branch (110:17): [Folded - Ignored]
  ------------------
  111|    160|      constexpr size_t expected_size = s0.size_bytes();
  112|    160|      (assert_exact_byte_length<expected_size>(rs), ...);
  113|    160|   } else {
  114|    160|      const size_t expected_size = s0.size_bytes();
  115|    160|      BOTAN_ARG_CHECK(((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...),
  116|    160|                      "memory regions don't have equal lengths");
  117|    160|   }
  118|    160|}
_ZN5Botan6ranges10size_bytesIRNSt3__14spanIjLm1EEEEEmOT_:
   73|    160|inline constexpr size_t size_bytes(spanable_range auto&& r) {
   74|    160|   return std::span{r}.size_bytes();
   75|    160|}
_ZN5Botan6ranges25assert_equal_byte_lengthsIRNSt3__14spanIjLm18446744073709551615EEEJRNS3_IKhLm18446744073709551615EEEEEEvOT_DpOT0_:
  107|      2|{
  108|      2|   const std::span s0{r0};
  109|       |
  110|      2|   if constexpr(decltype(s0)::extent != std::dynamic_extent) {
  ------------------
  |  Branch (110:17): [Folded - Ignored]
  ------------------
  111|      2|      constexpr size_t expected_size = s0.size_bytes();
  112|      2|      (assert_exact_byte_length<expected_size>(rs), ...);
  113|      2|   } else {
  114|      2|      const size_t expected_size = s0.size_bytes();
  115|      2|      BOTAN_ARG_CHECK(((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...),
  ------------------
  |  |   30|      2|   do {                                                          \
  |  |   31|      2|      if(!(expr))                                                \
  |  |  ------------------
  |  |  |  Branch (31:10): [True: 0, False: 2]
  |  |  ------------------
  |  |   32|      2|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   33|      2|   } while(0)
  |  |  ------------------
  |  |  |  Branch (33:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  116|      2|                      "memory regions don't have equal lengths");
  117|      2|   }
  118|      2|}
_ZN5Botan6ranges10size_bytesIRNSt3__14spanIjLm18446744073709551615EEEEEmOT_:
   73|      2|inline constexpr size_t size_bytes(spanable_range auto&& r) {
   74|      2|   return std::span{r}.size_bytes();
   75|      2|}

_ZN5Botan8CurveGFpC2ERKS0_:
  100|   118k|      CurveGFp(const CurveGFp&) = default;
_ZNK5Botan8CurveGFp5get_pEv:
  118|  4.74M|      const BigInt& get_p() const { return m_repr->get_p(); }
_ZNK5Botan13CurveGFp_Repr9curve_mulERNS_6BigIntERKS1_S4_RNSt3__16vectorImNS_16secure_allocatorImEEEE:
   60|  25.0M|      void curve_mul(BigInt& z, const BigInt& x, const BigInt& y, secure_vector<word>& ws) const {
   61|  25.0M|         BOTAN_DEBUG_ASSERT(x.sig_words() <= get_p_words());
  ------------------
  |  |   99|  25.0M|      do {                          \
  |  |  100|  25.0M|      } while(0)
  |  |  ------------------
  |  |  |  Branch (100:15): [Folded - Ignored]
  |  |  ------------------
  ------------------
   62|  25.0M|         curve_mul_words(z, x.data(), x.size(), y, ws);
   63|  25.0M|      }
_ZNK5Botan13CurveGFp_Repr9curve_sqrERNS_6BigIntERKS1_RNSt3__16vectorImNS_16secure_allocatorImEEEE:
   68|  34.0M|      void curve_sqr(BigInt& z, const BigInt& x, secure_vector<word>& ws) const {
   69|  34.0M|         BOTAN_DEBUG_ASSERT(x.sig_words() <= get_p_words());
  ------------------
  |  |   99|  34.0M|      do {                          \
  |  |  100|  34.0M|      } while(0)
  |  |  ------------------
  |  |  |  Branch (100:15): [Folded - Ignored]
  |  |  ------------------
  ------------------
   70|  34.0M|         curve_sqr_words(z, x.data(), x.size(), ws);
   71|  34.0M|      }
_ZN5Botan8CurveGFpC2ERKNS_6BigIntES3_S3_:
   98|      1|      CurveGFp(const BigInt& p, const BigInt& a, const BigInt& b) : m_repr(choose_repr(p, a, b)) {}
_ZNK5Botan8CurveGFp5get_aEv:
  107|  1.36k|      const BigInt& get_a() const { return m_repr->get_a(); }
_ZNK5Botan8CurveGFp5get_bEv:
  112|  1.36k|      const BigInt& get_b() const { return m_repr->get_b(); }
_ZNK5Botan8CurveGFp11get_p_wordsEv:
  120|   287k|      size_t get_p_words() const { return m_repr->get_p_words(); }
_ZNK5Botan8CurveGFp11get_ws_sizeEv:
  122|  4.71M|      size_t get_ws_size() const { return m_repr->get_ws_size(); }
_ZNK5Botan8CurveGFp9get_1_repEv:
  128|  24.1k|      const BigInt& get_1_rep() const { return m_repr->get_1_rep(); }
_ZNK5Botan8CurveGFp12a_is_minus_3Ev:
  130|  3.09M|      bool a_is_minus_3() const { return m_repr->a_is_minus_3(); }
_ZNK5Botan8CurveGFp9a_is_zeroEv:
  132|  3.09M|      bool a_is_zero() const { return m_repr->a_is_zero(); }
_ZNK5Botan8CurveGFp6is_oneERKNS_6BigIntE:
  134|  43.4k|      bool is_one(const BigInt& x) const { return m_repr->is_one(x); }
_ZNK5Botan8CurveGFp14invert_elementERKNS_6BigIntERNSt3__16vectorImNS_16secure_allocatorImEEEE:
  136|  43.4k|      BigInt invert_element(const BigInt& x, secure_vector<word>& ws) const { return m_repr->invert_element(x, ws); }
_ZNK5Botan8CurveGFp6to_repERNS_6BigIntERNSt3__16vectorImNS_16secure_allocatorImEEEE:
  138|  1.67k|      void to_rep(BigInt& x, secure_vector<word>& ws) const { m_repr->to_curve_rep(x, ws); }
_ZNK5Botan8CurveGFp8from_repERNS_6BigIntERNSt3__16vectorImNS_16secure_allocatorImEEEE:
  140|  43.4k|      void from_rep(BigInt& x, secure_vector<word>& ws) const { m_repr->from_curve_rep(x, ws); }
_ZNK5Botan8CurveGFp15from_rep_to_tmpERKNS_6BigIntERNSt3__16vectorImNS_16secure_allocatorImEEEE:
  142|     72|      BigInt from_rep_to_tmp(const BigInt& x, secure_vector<word>& ws) const {
  143|     72|         BigInt xt(x);
  144|     72|         m_repr->from_curve_rep(xt, ws);
  145|     72|         return xt;
  146|     72|      }
_ZNK5Botan8CurveGFp3mulERNS_6BigIntERKS1_S4_RNSt3__16vectorImNS_16secure_allocatorImEEEE:
  150|  24.3M|      void mul(BigInt& z, const BigInt& x, const BigInt& y, secure_vector<word>& ws) const {
  151|  24.3M|         m_repr->curve_mul(z, x, y, ws);
  152|  24.3M|      }
_ZNK5Botan8CurveGFp3mulERNS_6BigIntEPKmmRKS1_RNSt3__16vectorImNS_16secure_allocatorImEEEE:
  154|  5.13M|      void mul(BigInt& z, const word x_w[], size_t x_size, const BigInt& y, secure_vector<word>& ws) const {
  155|  5.13M|         m_repr->curve_mul_words(z, x_w, x_size, y, ws);
  156|  5.13M|      }
_ZNK5Botan8CurveGFp3sqrERNS_6BigIntERKS1_RNSt3__16vectorImNS_16secure_allocatorImEEEE:
  158|  17.3M|      void sqr(BigInt& z, const BigInt& x, secure_vector<word>& ws) const { m_repr->curve_sqr(z, x, ws); }
_ZNK5Botan8CurveGFp3sqrERNS_6BigIntEPKmmRNSt3__16vectorImNS_16secure_allocatorImEEEE:
  160|   941k|      void sqr(BigInt& z, const word x_w[], size_t x_size, secure_vector<word>& ws) const {
  161|   941k|         m_repr->curve_sqr_words(z, x_w, x_size, ws);
  162|   941k|      }
_ZNK5Botan8CurveGFp10mul_to_tmpERKNS_6BigIntES3_RNSt3__16vectorImNS_16secure_allocatorImEEEE:
  168|  61.7k|      BigInt mul_to_tmp(const BigInt& x, const BigInt& y, secure_vector<word>& ws) const {
  169|  61.7k|         BigInt z;
  170|  61.7k|         m_repr->curve_mul(z, x, y, ws);
  171|  61.7k|         return z;
  172|  61.7k|      }
_ZNK5Botan8CurveGFp10sqr_to_tmpERKNS_6BigIntERNSt3__16vectorImNS_16secure_allocatorImEEEE:
  174|  52.4k|      BigInt sqr_to_tmp(const BigInt& x, secure_vector<word>& ws) const {
  175|  52.4k|         BigInt z;
  176|  52.4k|         m_repr->curve_sqr(z, x, ws);
  177|  52.4k|         return z;
  178|  52.4k|      }
_ZN5Botan8CurveGFp4swapERS0_:
  180|  74.9k|      void swap(CurveGFp& other) { std::swap(m_repr, other.m_repr); }
_ZNK5Botan8CurveGFpeqERKS0_:
  189|   298k|      inline bool operator==(const CurveGFp& other) const {
  190|   298k|         if(m_repr.get() == other.m_repr.get()) {
  ------------------
  |  Branch (190:13): [True: 298k, False: 0]
  ------------------
  191|   298k|            return true;
  192|   298k|         }
  193|       |
  194|      0|         return (get_p() == other.get_p()) && (get_a() == other.get_a()) && (get_b() == other.get_b());
  ------------------
  |  Branch (194:17): [True: 0, False: 0]
  |  Branch (194:47): [True: 0, False: 0]
  |  Branch (194:77): [True: 0, False: 0]
  ------------------
  195|   298k|      }
_ZN5BotanneERKNS_8CurveGFpES2_:
  203|  10.8k|inline bool operator!=(const CurveGFp& lhs, const CurveGFp& rhs) {
  204|  10.8k|   return !(lhs == rhs);
  205|  10.8k|}
_ZN5Botan8CurveGFpaSERKS0_:
  102|  5.69k|      CurveGFp& operator=(const CurveGFp&) = default;
_ZN5Botan8CurveGFpC2Ev:
   90|  80.0k|      CurveGFp() = default;
_ZN5Botan13CurveGFp_ReprD2Ev:
   23|      1|      virtual ~CurveGFp_Repr() = default;

_ZN5Botan8EC_PointC2ERKS0_:
   53|  94.1k|      EC_Point(const EC_Point&) = default;
_ZN5BotanmlERKNS_8EC_PointERKNS_6BigIntE:
  371|  4.08k|inline EC_Point operator*(const EC_Point& point, const BigInt& scalar) {
  372|  4.08k|   return scalar * point;
  373|  4.08k|}
_ZN5BotanplERKNS_8EC_PointES2_:
  361|  8.17k|inline EC_Point operator+(const EC_Point& lhs, const EC_Point& rhs) {
  362|  8.17k|   EC_Point tmp(lhs);
  363|  8.17k|   return tmp += rhs;
  364|  8.17k|}
_ZN5BotanneERKNS_8EC_PointES2_:
  352|  10.8k|inline bool operator!=(const EC_Point& lhs, const EC_Point& rhs) {
  353|  10.8k|   return !(rhs == lhs);
  354|  10.8k|}
_ZNK5Botan8EC_Point7is_zeroEv:
  177|  4.78M|      bool is_zero() const { return m_coord_z.is_zero(); }
_ZN5Botan8EC_PointaSEOS0_:
   68|  74.7k|      EC_Point& operator=(EC_Point&& other) {
   69|  74.7k|         if(this != &other) {
  ------------------
  |  Branch (69:13): [True: 74.7k, False: 0]
  ------------------
   70|  74.7k|            this->swap(other);
   71|  74.7k|         }
   72|  74.7k|         return (*this);
   73|  74.7k|      }
_ZNK5Botan8EC_Point5get_xEv:
  139|   153k|      const BigInt& get_x() const { return m_coord_x; }
_ZNK5Botan8EC_Point5get_yEv:
  146|   153k|      const BigInt& get_y() const { return m_coord_y; }
_ZNK5Botan8EC_Point5get_zEv:
  153|   152k|      const BigInt& get_z() const { return m_coord_z; }
_ZN5Botan8EC_Point11swap_coordsERNS_6BigIntES2_S2_:
  155|  73.8k|      void swap_coords(BigInt& new_x, BigInt& new_y, BigInt& new_z) {
  156|  73.8k|         m_coord_x.swap(new_x);
  157|  73.8k|         m_coord_y.swap(new_y);
  158|  73.8k|         m_coord_z.swap(new_z);
  159|  73.8k|      }
_ZN5Botan8EC_Point3addERKS0_RNSt3__16vectorINS_6BigIntENS3_9allocatorIS5_EEEE:
  216|   287k|      void add(const EC_Point& other, std::vector<BigInt>& workspace) {
  217|   287k|         BOTAN_ARG_CHECK(m_curve == other.m_curve, "cannot add points on different curves");
  ------------------
  |  |   30|   287k|   do {                                                          \
  |  |   31|   287k|      if(!(expr))                                                \
  |  |  ------------------
  |  |  |  Branch (31:10): [True: 0, False: 287k]
  |  |  ------------------
  |  |   32|   287k|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   33|   287k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (33:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  218|       |
  219|   287k|         const size_t p_words = m_curve.get_p_words();
  220|       |
  221|   287k|         add(other.m_coord_x.data(),
  222|   287k|             std::min(p_words, other.m_coord_x.size()),
  223|   287k|             other.m_coord_y.data(),
  224|   287k|             std::min(p_words, other.m_coord_y.size()),
  225|   287k|             other.m_coord_z.data(),
  226|   287k|             std::min(p_words, other.m_coord_z.size()),
  227|   287k|             workspace);
  228|   287k|      }
_ZNK5Botan8EC_Point4plusERKS0_RNSt3__16vectorINS_6BigIntENS3_9allocatorIS5_EEEE:
  297|  35.2k|      EC_Point plus(const EC_Point& other, std::vector<BigInt>& workspace) const {
  298|  35.2k|         EC_Point x = (*this);
  299|  35.2k|         x.add(other, workspace);
  300|  35.2k|         return x;
  301|  35.2k|      }
_ZNK5Botan8EC_Point9double_ofERNSt3__16vectorINS_6BigIntENS1_9allocatorIS3_EEEE:
  308|  34.4k|      EC_Point double_of(std::vector<BigInt>& workspace) const {
  309|  34.4k|         EC_Point x = (*this);
  310|  34.4k|         x.mult2(workspace);
  311|  34.4k|         return x;
  312|  34.4k|      }
_ZNK5Botan8EC_Point4zeroEv:
  317|  13.0k|      EC_Point zero() const { return EC_Point(m_curve); }
_ZNK5Botan8EC_Point9get_curveEv:
  325|  9.84k|      const CurveGFp& get_curve() const { return m_curve; }
_ZN5Botan8EC_PointaSERKS0_:
   63|  5.69k|      EC_Point& operator=(const EC_Point&) = default;
_ZN5Botan8EC_PointC2Ev:
   42|  80.0k|      EC_Point() = default;

_ZN5Botan25MessageAuthenticationCodeD2Ev:
   50|      1|      ~MessageAuthenticationCode() override = default;

_ZN5Botan11clear_bytesEPvm:
  103|   145M|inline constexpr void clear_bytes(void* ptr, size_t bytes) {
  104|   145M|   if(bytes > 0) {
  ------------------
  |  Branch (104:7): [True: 144M, False: 549k]
  ------------------
  105|   144M|      std::memset(ptr, 0, bytes);
  106|   144M|   }
  107|   145M|}
_ZN5Botan22cast_char_ptr_to_uint8EPKc:
  272|     10|inline const uint8_t* cast_char_ptr_to_uint8(const char* s) {
  273|     10|   return reinterpret_cast<const uint8_t*>(s);
  274|     10|}
_ZN5Botan22cast_uint8_ptr_to_charEPKh:
  276|     10|inline const char* cast_uint8_ptr_to_char(const uint8_t* b) {
  277|     10|   return reinterpret_cast<const char*>(b);
  278|     10|}
_ZN5Botan9clear_memImEEvPT_m:
  120|   145M|inline constexpr void clear_mem(T* ptr, size_t n) {
  121|   145M|   clear_bytes(ptr, sizeof(T) * n);
  122|   145M|}
_ZN5Botan8copy_memImEEvPT_PKS1_m:
  146|  1.41M|inline constexpr void copy_mem(T* out, const T* in, size_t n) {
  147|  1.41M|   BOTAN_ASSERT_IMPLICATION(n > 0, in != nullptr && out != nullptr, "If n > 0 then args are not null");
  ------------------
  |  |   78|  1.41M|   do {                                                                                          \
  |  |   79|  2.80M|      if((expr1) && !(expr2))                                                                    \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 1.40M, False: 9.96k]
  |  |  |  Branch (79:23): [True: 1.40M, False: 0]
  |  |  |  Branch (79:23): [True: 1.40M, False: 0]
  |  |  ------------------
  |  |   80|  1.41M|         Botan::assertion_failure(#expr1 " implies " #expr2, msg, __func__, __FILE__, __LINE__); \
  |  |   81|  1.41M|   } while(0)
  |  |  ------------------
  |  |  |  Branch (81:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  148|       |
  149|  1.41M|   if(in != nullptr && out != nullptr && n > 0) {
  ------------------
  |  Branch (149:7): [True: 1.40M, False: 9.84k]
  |  Branch (149:24): [True: 1.40M, False: 0]
  |  Branch (149:42): [True: 1.40M, False: 118]
  ------------------
  150|  1.40M|      std::memmove(out, in, sizeof(T) * n);
  151|  1.40M|   }
  152|  1.41M|}
_ZN5Botan13typecast_copyIRNSt3__14spanIhLm8EEEmEEvOT_RKT0_:
  199|      4|inline constexpr void typecast_copy(ToR&& out, const FromT& in) {
  200|      4|   typecast_copy(out, std::span<const FromT, 1>(&in, 1));
  201|      4|}
_ZN5Botan13typecast_copyIRNSt3__14spanIhLm8EEENS2_IKmLm1EEEEEvOT_OT0_:
  176|      4|inline constexpr void typecast_copy(ToR&& out, FromR&& in) {
  177|      4|   ranges::assert_equal_byte_lengths(out, in);
  178|      4|   std::memcpy(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  179|      4|}
_ZN5Botan13typecast_copyImRNSt3__14spanIKhLm8EEEEET_OT0_:
  209|   525k|inline constexpr ToT typecast_copy(FromR&& src) noexcept {
  210|   525k|   ToT dst;
  211|   525k|   typecast_copy(dst, src);
  212|   525k|   return dst;
  213|   525k|}
_ZN5Botan13typecast_copyImRNSt3__14spanIKhLm8EEEEEvRT_OT0_:
  188|   525k|inline constexpr void typecast_copy(ToT& out, FromR&& in) noexcept {
  189|   525k|   typecast_copy(std::span<ToT, 1>(&out, 1), in);
  190|   525k|}
_ZN5Botan13typecast_copyINSt3__14spanImLm1EEERNS2_IKhLm8EEEEEvOT_OT0_:
  176|   525k|inline constexpr void typecast_copy(ToR&& out, FromR&& in) {
  177|   525k|   ranges::assert_equal_byte_lengths(out, in);
  178|   525k|   std::memcpy(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  179|   525k|}
_ZN5Botan8copy_memIhEEvPT_PKS1_m:
  146|   100k|inline constexpr void copy_mem(T* out, const T* in, size_t n) {
  147|   100k|   BOTAN_ASSERT_IMPLICATION(n > 0, in != nullptr && out != nullptr, "If n > 0 then args are not null");
  ------------------
  |  |   78|   100k|   do {                                                                                          \
  |  |   79|   197k|      if((expr1) && !(expr2))                                                                    \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 98.5k, False: 1.42k]
  |  |  |  Branch (79:23): [True: 98.5k, False: 0]
  |  |  |  Branch (79:23): [True: 98.5k, False: 0]
  |  |  ------------------
  |  |   80|   100k|         Botan::assertion_failure(#expr1 " implies " #expr2, msg, __func__, __FILE__, __LINE__); \
  |  |   81|   100k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (81:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  148|       |
  149|   100k|   if(in != nullptr && out != nullptr && n > 0) {
  ------------------
  |  Branch (149:7): [True: 100k, False: 0]
  |  Branch (149:24): [True: 100k, False: 0]
  |  Branch (149:42): [True: 98.5k, False: 1.42k]
  ------------------
  150|  98.5k|      std::memmove(out, in, sizeof(T) * n);
  151|  98.5k|   }
  152|   100k|}
_ZN5Botan9clear_memIhEEvPT_m:
  120|     25|inline constexpr void clear_mem(T* ptr, size_t n) {
  121|     25|   clear_bytes(ptr, sizeof(T) * n);
  122|     25|}
_ZN5Botan13typecast_copyIRNSt3__14spanIhLm4EEEjEEvOT_RKT0_:
  199|     32|inline constexpr void typecast_copy(ToR&& out, const FromT& in) {
  200|     32|   typecast_copy(out, std::span<const FromT, 1>(&in, 1));
  201|     32|}
_ZN5Botan13typecast_copyIRNSt3__14spanIhLm4EEENS2_IKjLm1EEEEEvOT_OT0_:
  176|     32|inline constexpr void typecast_copy(ToR&& out, FromR&& in) {
  177|     32|   ranges::assert_equal_byte_lengths(out, in);
  178|     32|   std::memcpy(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  179|     32|}
_ZN5Botan13typecast_copyIjRNSt3__14spanIKhLm4EEEEET_OT0_:
  209|    160|inline constexpr ToT typecast_copy(FromR&& src) noexcept {
  210|    160|   ToT dst;
  211|    160|   typecast_copy(dst, src);
  212|    160|   return dst;
  213|    160|}
_ZN5Botan13typecast_copyIjRNSt3__14spanIKhLm4EEEEEvRT_OT0_:
  188|    160|inline constexpr void typecast_copy(ToT& out, FromR&& in) noexcept {
  189|    160|   typecast_copy(std::span<ToT, 1>(&out, 1), in);
  190|    160|}
_ZN5Botan13typecast_copyINSt3__14spanIjLm1EEERNS2_IKhLm4EEEEEvOT_OT0_:
  176|    160|inline constexpr void typecast_copy(ToR&& out, FromR&& in) {
  177|    160|   ranges::assert_equal_byte_lengths(out, in);
  178|    160|   std::memcpy(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  179|    160|}
_ZN5Botan9clear_memIjEEvPT_m:
  120|      1|inline constexpr void clear_mem(T* ptr, size_t n) {
  121|      1|   clear_bytes(ptr, sizeof(T) * n);
  122|      1|}
_ZN5Botan13typecast_copyIjEEvPT_PKhm:
  228|      2|{
  229|       |   // asserts that *in and *out point to the correct amount of memory
  230|      2|   typecast_copy(std::span<T>(out, N), std::span<const uint8_t>(in, N * sizeof(T)));
  231|      2|}
_ZN5Botan13typecast_copyINSt3__14spanIjLm18446744073709551615EEENS2_IKhLm18446744073709551615EEEEEvOT_OT0_:
  176|      2|inline constexpr void typecast_copy(ToR&& out, FromR&& in) {
  177|      2|   ranges::assert_equal_byte_lengths(out, in);
  178|      2|   std::memcpy(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  179|      2|}

_ZNK5Botan15Modular_Reducer11get_modulusEv:
   20|      1|      const BigInt& get_modulus() const { return m_modulus; }
_ZNK5Botan15Modular_Reducer8multiplyERKNS_6BigIntES3_:
   30|    837|      BigInt multiply(const BigInt& x, const BigInt& y) const { return reduce(x * y); }
_ZNK5Botan15Modular_Reducer6squareERKNS_6BigIntE:
   43|    837|      BigInt square(const BigInt& x) const { return reduce(Botan::square(x)); }

_ZN5Botan21RandomNumberGeneratorD2Ev:
   32|      1|      virtual ~RandomNumberGenerator() = default;
_ZN5Botan21RandomNumberGenerator9randomizeENSt3__14spanIhLm18446744073709551615EEE:
   52|  91.8k|      void randomize(std::span<uint8_t> output) { this->fill_bytes_with_input(output, {}); }
_ZN5Botan21RandomNumberGenerator11add_entropyENSt3__14spanIKhLm18446744073709551615EEE:
   75|      1|      void add_entropy(std::span<const uint8_t> input) { this->fill_bytes_with_input({}, input); }
_ZN5Botan21RandomNumberGenerator10random_vecENSt3__14spanIhLm18446744073709551615EEE:
  179|  91.8k|      void random_vec(std::span<uint8_t> v) { this->randomize(v); }
_ZN5Botan21RandomNumberGeneratorC2Ev:
   34|      1|      RandomNumberGenerator() = default;
_ZN5Botan21RandomNumberGenerator10random_vecINSt3__16vectorIhNS_16secure_allocatorIhEEEEEET_m:
  205|  91.8k|      T random_vec(size_t bytes) {
  206|  91.8k|         T result;
  207|  91.8k|         random_vec(result, bytes);
  208|  91.8k|         return result;
  209|  91.8k|      }
_ZN5Botan21RandomNumberGenerator10random_vecINSt3__16vectorIhNS_16secure_allocatorIhEEEEEEvRT_m:
  190|  91.8k|      void random_vec(T& v, size_t bytes) {
  191|  91.8k|         v.resize(bytes);
  192|  91.8k|         random_vec(v);
  193|  91.8k|      }

_ZN5Botan16secure_allocatorImE8allocateEm:
   45|  2.84M|      T* allocate(std::size_t n) { return static_cast<T*>(allocate_memory(n, sizeof(T))); }
_ZN5Botan16secure_allocatorIhE8allocateEm:
   45|  91.8k|      T* allocate(std::size_t n) { return static_cast<T*>(allocate_memory(n, sizeof(T))); }
_ZN5Botan16secure_allocatorIhE10deallocateEPhm:
   47|  91.8k|      void deallocate(T* p, std::size_t n) { deallocate_memory(p, n, sizeof(T)); }
_ZN5Botan16secure_allocatorImE10deallocateEPmm:
   47|  2.84M|      void deallocate(T* p, std::size_t n) { deallocate_memory(p, n, sizeof(T)); }
_ZN5BotanneIhhEEbRKNS_16secure_allocatorIT_EERKNS1_IT0_EE:
   56|     10|inline bool operator!=(const secure_allocator<T>&, const secure_allocator<U>&) {
   57|     10|   return false;
   58|     10|}
_ZN5Botan16secure_allocatorIjE10deallocateEPjm:
   47|      3|      void deallocate(T* p, std::size_t n) { deallocate_memory(p, n, sizeof(T)); }
_ZN5Botan16secure_allocatorIjE8allocateEm:
   45|      3|      T* allocate(std::size_t n) { return static_cast<T*>(allocate_memory(n, sizeof(T))); }

_ZN5Botan12Stateful_RNGC2Ev:
   58|      1|      Stateful_RNG() : m_reseed_interval(0) {}

_ZN5Botan12StreamCipher15write_keystreamENSt3__14spanIhLm18446744073709551615EEE:
   87|  91.8k|      void write_keystream(std::span<uint8_t> out) { generate_keystream(out.data(), out.size()); }
_ZN5Botan12StreamCipher6set_ivEPKhm:
  157|      2|      void set_iv(const uint8_t iv[], size_t iv_len) { set_iv_bytes(iv, iv_len); }
_ZN5Botan12StreamCipher15keystream_bytesINSt3__16vectorIhNS_16secure_allocatorIhEEEEEET_m:
   95|      1|      T keystream_bytes(size_t bytes) {
   96|      1|         T out(bytes);
   97|      1|         write_keystream(out);
   98|      1|         return out;
   99|      1|      }

_ZN5Botan24Key_Length_SpecificationC2Emmm:
   36|      4|            m_min_keylen(min_k), m_max_keylen(max_k ? max_k : min_k), m_keylen_mod(k_mod) {}
_ZNK5Botan24Key_Length_Specification15valid_keylengthEm:
   42|      4|      bool valid_keylength(size_t length) const {
   43|      4|         return ((length >= m_min_keylen) && (length <= m_max_keylen) && (length % m_keylen_mod == 0));
  ------------------
  |  Branch (43:18): [True: 4, False: 0]
  |  Branch (43:46): [True: 4, False: 0]
  |  Branch (43:74): [True: 4, False: 0]
  ------------------
   44|      4|      }
_ZNK5Botan18SymmetricAlgorithm15valid_keylengthEm:
  107|      4|      bool valid_keylength(size_t length) const { return key_spec().valid_keylength(length); }
_ZNK5Botan18SymmetricAlgorithm23assert_key_material_setEv:
  139|  91.8k|      void assert_key_material_set() const { assert_key_material_set(has_keying_material()); }
_ZNK5Botan18SymmetricAlgorithm23assert_key_material_setEb:
  141|  91.8k|      void assert_key_material_set(bool predicate) const {
  142|  91.8k|         if(!predicate) {
  ------------------
  |  Branch (142:13): [True: 0, False: 91.8k]
  ------------------
  143|      0|            throw_key_not_set_error();
  144|      0|         }
  145|  91.8k|      }
_ZN5Botan18SymmetricAlgorithmD2Ev:
   79|      2|      virtual ~SymmetricAlgorithm() = default;

ecc_p384.cpp:_ZN12_GLOBAL__N_114check_ecc_mathERKN5Botan8EC_GroupEPKhm:
   48|  1.36k|inline void check_ecc_math(const Botan::EC_Group& group, const uint8_t in[], size_t len) {
   49|       |   // These depend only on the group, which is also static
   50|  1.36k|   static const Botan::EC_Point base_point = group.get_base_point();
   51|       |
   52|       |   // This is shared across runs to reduce overhead
   53|  1.36k|   static std::vector<Botan::BigInt> ws(Botan::EC_Point::WORKSPACE_SIZE);
   54|       |
   55|  1.36k|   const size_t hlen = len / 2;
   56|  1.36k|   const Botan::BigInt a = Botan::BigInt::decode(in, hlen);
   57|  1.36k|   const Botan::BigInt b = Botan::BigInt::decode(in + hlen, len - hlen);
   58|  1.36k|   const Botan::BigInt c = a + b;
   59|       |
   60|  1.36k|   const Botan::EC_Point P1 = base_point * a;
   61|  1.36k|   const Botan::EC_Point Q1 = base_point * b;
   62|  1.36k|   const Botan::EC_Point R1 = base_point * c;
   63|       |
   64|  1.36k|   const Botan::EC_Point S1 = P1 + Q1;
   65|  1.36k|   const Botan::EC_Point T1 = Q1 + P1;
   66|       |
   67|  1.36k|   FUZZER_ASSERT_EQUAL(S1, R1);
  ------------------
  |  |   60|  1.36k|   do {                                                                                  \
  |  |   61|  1.36k|      if(x != y) {                                                                       \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 1.36k]
  |  |  ------------------
  |  |   62|      0|         FUZZER_WRITE_AND_CRASH(#x << " = " << x << " != " << #y << " = " << y << "\n"); \
  |  |  ------------------
  |  |  |  |   54|      0|   do {                                                                          \
  |  |  |  |   55|      0|      std::cerr << expr << " @ Line " << __LINE__ << " in " << __FILE__ << "\n"; \
  |  |  |  |   56|      0|      abort();                                                                   \
  |  |  |  |   57|      0|   } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (57:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   63|      0|      }                                                                                  \
  |  |   64|  1.36k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (64:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   68|  1.36k|   FUZZER_ASSERT_EQUAL(T1, R1);
  ------------------
  |  |   60|  1.36k|   do {                                                                                  \
  |  |   61|  1.36k|      if(x != y) {                                                                       \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 1.36k]
  |  |  ------------------
  |  |   62|      0|         FUZZER_WRITE_AND_CRASH(#x << " = " << x << " != " << #y << " = " << y << "\n"); \
  |  |  ------------------
  |  |  |  |   54|      0|   do {                                                                          \
  |  |  |  |   55|      0|      std::cerr << expr << " @ Line " << __LINE__ << " in " << __FILE__ << "\n"; \
  |  |  |  |   56|      0|      abort();                                                                   \
  |  |  |  |   57|      0|   } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (57:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   63|      0|      }                                                                                  \
  |  |   64|  1.36k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (64:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   69|       |
   70|  1.36k|   const Botan::EC_Point P2 = group.blinded_base_point_multiply(a, fuzzer_rng(), ws);
   71|  1.36k|   const Botan::EC_Point Q2 = group.blinded_base_point_multiply(b, fuzzer_rng(), ws);
   72|  1.36k|   const Botan::EC_Point R2 = group.blinded_base_point_multiply(c, fuzzer_rng(), ws);
   73|  1.36k|   const Botan::EC_Point S2 = P2 + Q2;
   74|  1.36k|   const Botan::EC_Point T2 = Q2 + P2;
   75|       |
   76|  1.36k|   FUZZER_ASSERT_EQUAL(S2, R2);
  ------------------
  |  |   60|  1.36k|   do {                                                                                  \
  |  |   61|  1.36k|      if(x != y) {                                                                       \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 1.36k]
  |  |  ------------------
  |  |   62|      0|         FUZZER_WRITE_AND_CRASH(#x << " = " << x << " != " << #y << " = " << y << "\n"); \
  |  |  ------------------
  |  |  |  |   54|      0|   do {                                                                          \
  |  |  |  |   55|      0|      std::cerr << expr << " @ Line " << __LINE__ << " in " << __FILE__ << "\n"; \
  |  |  |  |   56|      0|      abort();                                                                   \
  |  |  |  |   57|      0|   } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (57:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   63|      0|      }                                                                                  \
  |  |   64|  1.36k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (64:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   77|  1.36k|   FUZZER_ASSERT_EQUAL(T2, R2);
  ------------------
  |  |   60|  1.36k|   do {                                                                                  \
  |  |   61|  1.36k|      if(x != y) {                                                                       \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 1.36k]
  |  |  ------------------
  |  |   62|      0|         FUZZER_WRITE_AND_CRASH(#x << " = " << x << " != " << #y << " = " << y << "\n"); \
  |  |  ------------------
  |  |  |  |   54|      0|   do {                                                                          \
  |  |  |  |   55|      0|      std::cerr << expr << " @ Line " << __LINE__ << " in " << __FILE__ << "\n"; \
  |  |  |  |   56|      0|      abort();                                                                   \
  |  |  |  |   57|      0|   } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (57:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   63|      0|      }                                                                                  \
  |  |   64|  1.36k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (64:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   78|       |
   79|  1.36k|   const Botan::EC_Point P3 = group.blinded_var_point_multiply(base_point, a, fuzzer_rng(), ws);
   80|  1.36k|   const Botan::EC_Point Q3 = group.blinded_var_point_multiply(base_point, b, fuzzer_rng(), ws);
   81|  1.36k|   const Botan::EC_Point R3 = group.blinded_var_point_multiply(base_point, c, fuzzer_rng(), ws);
   82|  1.36k|   const Botan::EC_Point S3 = P3 + Q3;
   83|  1.36k|   const Botan::EC_Point T3 = Q3 + P3;
   84|       |
   85|  1.36k|   FUZZER_ASSERT_EQUAL(S3, R3);
  ------------------
  |  |   60|  1.36k|   do {                                                                                  \
  |  |   61|  1.36k|      if(x != y) {                                                                       \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 1.36k]
  |  |  ------------------
  |  |   62|      0|         FUZZER_WRITE_AND_CRASH(#x << " = " << x << " != " << #y << " = " << y << "\n"); \
  |  |  ------------------
  |  |  |  |   54|      0|   do {                                                                          \
  |  |  |  |   55|      0|      std::cerr << expr << " @ Line " << __LINE__ << " in " << __FILE__ << "\n"; \
  |  |  |  |   56|      0|      abort();                                                                   \
  |  |  |  |   57|      0|   } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (57:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   63|      0|      }                                                                                  \
  |  |   64|  1.36k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (64:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   86|  1.36k|   FUZZER_ASSERT_EQUAL(T3, R3);
  ------------------
  |  |   60|  1.36k|   do {                                                                                  \
  |  |   61|  1.36k|      if(x != y) {                                                                       \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 1.36k]
  |  |  ------------------
  |  |   62|      0|         FUZZER_WRITE_AND_CRASH(#x << " = " << x << " != " << #y << " = " << y << "\n"); \
  |  |  ------------------
  |  |  |  |   54|      0|   do {                                                                          \
  |  |  |  |   55|      0|      std::cerr << expr << " @ Line " << __LINE__ << " in " << __FILE__ << "\n"; \
  |  |  |  |   56|      0|      abort();                                                                   \
  |  |  |  |   57|      0|   } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (57:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   63|      0|      }                                                                                  \
  |  |   64|  1.36k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (64:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   87|       |
   88|  1.36k|   FUZZER_ASSERT_EQUAL(S1, S2);
  ------------------
  |  |   60|  1.36k|   do {                                                                                  \
  |  |   61|  1.36k|      if(x != y) {                                                                       \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 1.36k]
  |  |  ------------------
  |  |   62|      0|         FUZZER_WRITE_AND_CRASH(#x << " = " << x << " != " << #y << " = " << y << "\n"); \
  |  |  ------------------
  |  |  |  |   54|      0|   do {                                                                          \
  |  |  |  |   55|      0|      std::cerr << expr << " @ Line " << __LINE__ << " in " << __FILE__ << "\n"; \
  |  |  |  |   56|      0|      abort();                                                                   \
  |  |  |  |   57|      0|   } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (57:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   63|      0|      }                                                                                  \
  |  |   64|  1.36k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (64:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   89|  1.36k|   FUZZER_ASSERT_EQUAL(S1, S3);
  ------------------
  |  |   60|  1.36k|   do {                                                                                  \
  |  |   61|  1.36k|      if(x != y) {                                                                       \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 1.36k]
  |  |  ------------------
  |  |   62|      0|         FUZZER_WRITE_AND_CRASH(#x << " = " << x << " != " << #y << " = " << y << "\n"); \
  |  |  ------------------
  |  |  |  |   54|      0|   do {                                                                          \
  |  |  |  |   55|      0|      std::cerr << expr << " @ Line " << __LINE__ << " in " << __FILE__ << "\n"; \
  |  |  |  |   56|      0|      abort();                                                                   \
  |  |  |  |   57|      0|   } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (57:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   63|      0|      }                                                                                  \
  |  |   64|  1.36k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (64:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   90|       |
   91|  1.36k|   try {
   92|  1.36k|      const auto yp = decompress_point(true, a, group.get_p(), group.get_a(), group.get_b());
   93|  1.36k|      const auto pt_p = group.blinded_var_point_multiply(group.point(a, yp), b, fuzzer_rng(), ws);
   94|       |
   95|  1.36k|      const auto yn = -yp;
   96|  1.36k|      const auto pt_n = group.blinded_var_point_multiply(group.point(a, yn), b, fuzzer_rng(), ws);
   97|       |
   98|  1.36k|      FUZZER_ASSERT_EQUAL(pt_p, -pt_n);
  ------------------
  |  |   60|  1.36k|   do {                                                                                  \
  |  |   61|  1.36k|      if(x != y) {                                                                       \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 1.36k]
  |  |  ------------------
  |  |   62|      0|         FUZZER_WRITE_AND_CRASH(#x << " = " << x << " != " << #y << " = " << y << "\n"); \
  |  |  ------------------
  |  |  |  |   54|      0|   do {                                                                          \
  |  |  |  |   55|      0|      std::cerr << expr << " @ Line " << __LINE__ << " in " << __FILE__ << "\n"; \
  |  |  |  |   56|      0|      abort();                                                                   \
  |  |  |  |   57|      0|   } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (57:12): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   63|      0|      }                                                                                  \
  |  |   64|  1.36k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (64:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   99|  1.36k|   } catch(...) {}
  100|  1.36k|}
ecc_p384.cpp:_ZN12_GLOBAL__N_116decompress_pointEbRKN5Botan6BigIntES3_S3_S3_:
   27|  1.36k|                                      const Botan::BigInt& curve_b) {
   28|  1.36k|   Botan::BigInt xpow3 = x * x * x;
   29|       |
   30|  1.36k|   Botan::BigInt g = curve_a * x;
   31|  1.36k|   g += xpow3;
   32|  1.36k|   g += curve_b;
   33|  1.36k|   g = g % curve_p;
   34|       |
   35|  1.36k|   Botan::BigInt z = sqrt_modulo_prime(g, curve_p);
   36|       |
   37|  1.36k|   if(z < 0) {
  ------------------
  |  Branch (37:7): [True: 525, False: 837]
  ------------------
   38|    525|      throw Botan::Exception("Could not perform square root");
   39|    525|   }
   40|       |
   41|    837|   if(z.get_bit(0) != yMod2) {
  ------------------
  |  Branch (41:7): [True: 357, False: 480]
  ------------------
   42|    357|      z = curve_p - z;
   43|    357|   }
   44|       |
   45|    837|   return z;
   46|  1.36k|}

_Z4fuzzPKhm:
   10|  1.38k|void fuzz(const uint8_t in[], size_t len) {
   11|  1.38k|   if(len > 2 * 384 / 8) {
  ------------------
  |  Branch (11:7): [True: 25, False: 1.36k]
  ------------------
   12|     25|      return;
   13|     25|   }
   14|  1.36k|   static Botan::EC_Group p384("secp384r1");
   15|  1.36k|   return check_ecc_math(p384, in, len);
   16|  1.38k|}

LLVMFuzzerInitialize:
   24|      2|extern "C" int LLVMFuzzerInitialize(int*, char***) {
   25|       |   /*
   26|       |   * This disables the mlock pool, as overwrites within the pool are
   27|       |   * opaque to ASan or other instrumentation.
   28|       |   */
   29|      2|   ::setenv("BOTAN_MLOCK_POOL_SIZE", "0", 1);
   30|      2|   return 0;
   31|      2|}
LLVMFuzzerTestOneInput:
   34|  1.39k|extern "C" int LLVMFuzzerTestOneInput(const uint8_t in[], size_t len) {
   35|  1.39k|   if(len <= max_fuzzer_input_size) {
  ------------------
  |  Branch (35:7): [True: 1.38k, False: 9]
  ------------------
   36|  1.38k|      fuzz(in, len);
   37|  1.38k|   }
   38|  1.39k|   return 0;
   39|  1.39k|}
_Z10fuzzer_rngv:
   49|  9.00k|inline Botan::RandomNumberGenerator& fuzzer_rng() {
   50|  9.00k|   return *fuzzer_rng_as_shared();
   51|  9.00k|}
_Z20fuzzer_rng_as_sharedv:
   43|  9.00k|inline std::shared_ptr<Botan::RandomNumberGenerator> fuzzer_rng_as_shared() {
   44|  9.00k|   static std::shared_ptr<Botan::ChaCha_RNG> rng =
   45|  9.00k|      std::make_shared<Botan::ChaCha_RNG>(Botan::secure_vector<uint8_t>(32));
   46|  9.00k|   return rng;
   47|  9.00k|}

_ZN5Botan3OID11from_stringENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
   74|      1|OID OID::from_string(std::string_view str) {
   75|      1|   if(str.empty()) {
  ------------------
  |  Branch (75:7): [True: 0, False: 1]
  ------------------
   76|      0|      throw Invalid_Argument("OID::from_string argument must be non-empty");
   77|      0|   }
   78|       |
   79|      1|   OID o = OID_Map::global_registry().str2oid(str);
   80|      1|   if(o.has_value()) {
  ------------------
  |  Branch (80:7): [True: 1, False: 0]
  ------------------
   81|      1|      return o;
   82|      1|   }
   83|       |
   84|      0|   std::vector<uint32_t> raw = parse_oid_str(str);
   85|       |
   86|      0|   if(!raw.empty()) {
  ------------------
  |  Branch (86:7): [True: 0, False: 0]
  ------------------
   87|      0|      return OID(std::move(raw));
   88|      0|   }
   89|       |
   90|      0|   throw Lookup_Error(fmt("No OID associated with name '{}'", str));
   91|      0|}

_ZN5Botan7OID_MapC2Ev:
   11|      1|OID_Map::OID_Map() {
   12|      1|   m_str2oid = OID_Map::load_str2oid_map();
   13|      1|   m_oid2str = OID_Map::load_oid2str_map();
   14|      1|}
_ZN5Botan7OID_Map15global_registryEv:
   16|      1|OID_Map& OID_Map::global_registry() {
   17|      1|   static OID_Map g_map;
   18|      1|   return g_map;
   19|      1|}
_ZN5Botan7OID_Map7str2oidENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
   69|      1|OID OID_Map::str2oid(std::string_view str) {
   70|      1|   lock_guard_type<mutex_type> lock(m_mutex);
   71|      1|   auto i = m_str2oid.find(std::string(str));
   72|      1|   if(i != m_str2oid.end()) {
  ------------------
  |  Branch (72:7): [True: 1, False: 0]
  ------------------
   73|      1|      return i->second;
   74|      1|   }
   75|       |
   76|      0|   return OID();
   77|      1|}

_ZN5Botan7OID_Map16load_oid2str_mapEv:
   17|      1|std::unordered_map<std::string, std::string> OID_Map::load_oid2str_map() {
   18|      1|   return std::unordered_map<std::string, std::string>{
   19|       |
   20|      1|      {"0.3.4401.5.3.1.9.26", "Camellia-192/GCM"},
   21|      1|      {"0.3.4401.5.3.1.9.46", "Camellia-256/GCM"},
   22|      1|      {"0.3.4401.5.3.1.9.6", "Camellia-128/GCM"},
   23|      1|      {"0.4.0.127.0.15.1.1.13.0", "XMSS"},
   24|      1|      {"1.0.14888.3.0.5", "ECKCDSA"},
   25|      1|      {"1.2.156.10197.1.104.100", "SM4/OCB"},
   26|      1|      {"1.2.156.10197.1.104.2", "SM4/CBC"},
   27|      1|      {"1.2.156.10197.1.104.8", "SM4/GCM"},
   28|      1|      {"1.2.156.10197.1.301", "sm2p256v1"},
   29|      1|      {"1.2.156.10197.1.301.1", "SM2"},
   30|      1|      {"1.2.156.10197.1.301.2", "SM2_Kex"},
   31|      1|      {"1.2.156.10197.1.301.3", "SM2_Enc"},
   32|      1|      {"1.2.156.10197.1.401", "SM3"},
   33|      1|      {"1.2.156.10197.1.501", "SM2_Sig/SM3"},
   34|      1|      {"1.2.156.10197.1.504", "RSA/EMSA3(SM3)"},
   35|      1|      {"1.2.250.1.223.101.256.1", "frp256v1"},
   36|      1|      {"1.2.392.200011.61.1.1.1.2", "Camellia-128/CBC"},
   37|      1|      {"1.2.392.200011.61.1.1.1.3", "Camellia-192/CBC"},
   38|      1|      {"1.2.392.200011.61.1.1.1.4", "Camellia-256/CBC"},
   39|      1|      {"1.2.410.200004.1.100.4.3", "ECKCDSA/SHA-1"},
   40|      1|      {"1.2.410.200004.1.100.4.4", "ECKCDSA/SHA-224"},
   41|      1|      {"1.2.410.200004.1.100.4.5", "ECKCDSA/SHA-256"},
   42|      1|      {"1.2.410.200004.1.4", "SEED/CBC"},
   43|      1|      {"1.2.643.100.1", "GOST.OGRN"},
   44|      1|      {"1.2.643.100.111", "GOST.SubjectSigningTool"},
   45|      1|      {"1.2.643.100.112", "GOST.IssuerSigningTool"},
   46|      1|      {"1.2.643.2.2.19", "GOST-34.10"},
   47|      1|      {"1.2.643.2.2.3", "GOST-34.10/GOST-R-34.11-94"},
   48|      1|      {"1.2.643.2.2.35.1", "gost_256A"},
   49|      1|      {"1.2.643.2.2.36.0", "gost_256A"},
   50|      1|      {"1.2.643.3.131.1.1", "GOST.INN"},
   51|      1|      {"1.2.643.7.1.1.1.1", "GOST-34.10-2012-256"},
   52|      1|      {"1.2.643.7.1.1.1.2", "GOST-34.10-2012-512"},
   53|      1|      {"1.2.643.7.1.1.2.2", "Streebog-256"},
   54|      1|      {"1.2.643.7.1.1.2.3", "Streebog-512"},
   55|      1|      {"1.2.643.7.1.1.3.2", "GOST-34.10-2012-256/Streebog-256"},
   56|      1|      {"1.2.643.7.1.1.3.3", "GOST-34.10-2012-512/Streebog-512"},
   57|      1|      {"1.2.643.7.1.2.1.1.1", "gost_256A"},
   58|      1|      {"1.2.643.7.1.2.1.1.2", "gost_256B"},
   59|      1|      {"1.2.643.7.1.2.1.2.1", "gost_512A"},
   60|      1|      {"1.2.643.7.1.2.1.2.2", "gost_512B"},
   61|      1|      {"1.2.840.10040.4.1", "DSA"},
   62|      1|      {"1.2.840.10040.4.3", "DSA/SHA-1"},
   63|      1|      {"1.2.840.10045.2.1", "ECDSA"},
   64|      1|      {"1.2.840.10045.3.1.1", "secp192r1"},
   65|      1|      {"1.2.840.10045.3.1.2", "x962_p192v2"},
   66|      1|      {"1.2.840.10045.3.1.3", "x962_p192v3"},
   67|      1|      {"1.2.840.10045.3.1.4", "x962_p239v1"},
   68|      1|      {"1.2.840.10045.3.1.5", "x962_p239v2"},
   69|      1|      {"1.2.840.10045.3.1.6", "x962_p239v3"},
   70|      1|      {"1.2.840.10045.3.1.7", "secp256r1"},
   71|      1|      {"1.2.840.10045.4.1", "ECDSA/SHA-1"},
   72|      1|      {"1.2.840.10045.4.3.1", "ECDSA/SHA-224"},
   73|      1|      {"1.2.840.10045.4.3.2", "ECDSA/SHA-256"},
   74|      1|      {"1.2.840.10045.4.3.3", "ECDSA/SHA-384"},
   75|      1|      {"1.2.840.10045.4.3.4", "ECDSA/SHA-512"},
   76|      1|      {"1.2.840.10046.2.1", "DH"},
   77|      1|      {"1.2.840.113533.7.66.10", "CAST-128/CBC"},
   78|      1|      {"1.2.840.113533.7.66.15", "KeyWrap.CAST-128"},
   79|      1|      {"1.2.840.113549.1.1.1", "RSA"},
   80|      1|      {"1.2.840.113549.1.1.10", "RSA/EMSA4"},
   81|      1|      {"1.2.840.113549.1.1.11", "RSA/EMSA3(SHA-256)"},
   82|      1|      {"1.2.840.113549.1.1.12", "RSA/EMSA3(SHA-384)"},
   83|      1|      {"1.2.840.113549.1.1.13", "RSA/EMSA3(SHA-512)"},
   84|      1|      {"1.2.840.113549.1.1.14", "RSA/EMSA3(SHA-224)"},
   85|      1|      {"1.2.840.113549.1.1.16", "RSA/EMSA3(SHA-512-256)"},
   86|      1|      {"1.2.840.113549.1.1.4", "RSA/EMSA3(MD5)"},
   87|      1|      {"1.2.840.113549.1.1.5", "RSA/EMSA3(SHA-1)"},
   88|      1|      {"1.2.840.113549.1.1.7", "RSA/OAEP"},
   89|      1|      {"1.2.840.113549.1.1.8", "MGF1"},
   90|      1|      {"1.2.840.113549.1.5.12", "PKCS5.PBKDF2"},
   91|      1|      {"1.2.840.113549.1.5.13", "PBE-PKCS5v20"},
   92|      1|      {"1.2.840.113549.1.9.1", "PKCS9.EmailAddress"},
   93|      1|      {"1.2.840.113549.1.9.14", "PKCS9.ExtensionRequest"},
   94|      1|      {"1.2.840.113549.1.9.16.3.18", "ChaCha20Poly1305"},
   95|      1|      {"1.2.840.113549.1.9.16.3.6", "KeyWrap.TripleDES"},
   96|      1|      {"1.2.840.113549.1.9.16.3.8", "Compression.Zlib"},
   97|      1|      {"1.2.840.113549.1.9.2", "PKCS9.UnstructuredName"},
   98|      1|      {"1.2.840.113549.1.9.3", "PKCS9.ContentType"},
   99|      1|      {"1.2.840.113549.1.9.4", "PKCS9.MessageDigest"},
  100|      1|      {"1.2.840.113549.1.9.7", "PKCS9.ChallengePassword"},
  101|      1|      {"1.2.840.113549.2.10", "HMAC(SHA-384)"},
  102|      1|      {"1.2.840.113549.2.11", "HMAC(SHA-512)"},
  103|      1|      {"1.2.840.113549.2.13", "HMAC(SHA-512-256)"},
  104|      1|      {"1.2.840.113549.2.5", "MD5"},
  105|      1|      {"1.2.840.113549.2.7", "HMAC(SHA-1)"},
  106|      1|      {"1.2.840.113549.2.8", "HMAC(SHA-224)"},
  107|      1|      {"1.2.840.113549.2.9", "HMAC(SHA-256)"},
  108|      1|      {"1.2.840.113549.3.7", "TripleDES/CBC"},
  109|      1|      {"1.3.101.110", "Curve25519"},
  110|      1|      {"1.3.101.112", "Ed25519"},
  111|      1|      {"1.3.132.0.10", "secp256k1"},
  112|      1|      {"1.3.132.0.30", "secp160r2"},
  113|      1|      {"1.3.132.0.31", "secp192k1"},
  114|      1|      {"1.3.132.0.32", "secp224k1"},
  115|      1|      {"1.3.132.0.33", "secp224r1"},
  116|      1|      {"1.3.132.0.34", "secp384r1"},
  117|      1|      {"1.3.132.0.35", "secp521r1"},
  118|      1|      {"1.3.132.0.8", "secp160r1"},
  119|      1|      {"1.3.132.0.9", "secp160k1"},
  120|      1|      {"1.3.132.1.12", "ECDH"},
  121|      1|      {"1.3.14.3.2.26", "SHA-1"},
  122|      1|      {"1.3.14.3.2.7", "DES/CBC"},
  123|      1|      {"1.3.36.3.2.1", "RIPEMD-160"},
  124|      1|      {"1.3.36.3.3.1.2", "RSA/EMSA3(RIPEMD-160)"},
  125|      1|      {"1.3.36.3.3.2.5.2.1", "ECGDSA"},
  126|      1|      {"1.3.36.3.3.2.5.4.1", "ECGDSA/RIPEMD-160"},
  127|      1|      {"1.3.36.3.3.2.5.4.2", "ECGDSA/SHA-1"},
  128|      1|      {"1.3.36.3.3.2.5.4.3", "ECGDSA/SHA-224"},
  129|      1|      {"1.3.36.3.3.2.5.4.4", "ECGDSA/SHA-256"},
  130|      1|      {"1.3.36.3.3.2.5.4.5", "ECGDSA/SHA-384"},
  131|      1|      {"1.3.36.3.3.2.5.4.6", "ECGDSA/SHA-512"},
  132|      1|      {"1.3.36.3.3.2.8.1.1.1", "brainpool160r1"},
  133|      1|      {"1.3.36.3.3.2.8.1.1.11", "brainpool384r1"},
  134|      1|      {"1.3.36.3.3.2.8.1.1.13", "brainpool512r1"},
  135|      1|      {"1.3.36.3.3.2.8.1.1.3", "brainpool192r1"},
  136|      1|      {"1.3.36.3.3.2.8.1.1.5", "brainpool224r1"},
  137|      1|      {"1.3.36.3.3.2.8.1.1.7", "brainpool256r1"},
  138|      1|      {"1.3.36.3.3.2.8.1.1.9", "brainpool320r1"},
  139|      1|      {"1.3.6.1.4.1.11591.15.1", "OpenPGP.Ed25519"},
  140|      1|      {"1.3.6.1.4.1.11591.4.11", "Scrypt"},
  141|      1|      {"1.3.6.1.4.1.25258.1.10.1", "Dilithium-4x4-AES-r3"},
  142|      1|      {"1.3.6.1.4.1.25258.1.10.2", "Dilithium-6x5-AES-r3"},
  143|      1|      {"1.3.6.1.4.1.25258.1.10.3", "Dilithium-8x7-AES-r3"},
  144|      1|      {"1.3.6.1.4.1.25258.1.11.1", "Kyber-512-90s-r3"},
  145|      1|      {"1.3.6.1.4.1.25258.1.11.2", "Kyber-768-90s-r3"},
  146|      1|      {"1.3.6.1.4.1.25258.1.11.3", "Kyber-1024-90s-r3"},
  147|      1|      {"1.3.6.1.4.1.25258.1.12.1.1", "SphincsPlus-shake-128s-r3.1"},
  148|      1|      {"1.3.6.1.4.1.25258.1.12.1.2", "SphincsPlus-shake-128f-r3.1"},
  149|      1|      {"1.3.6.1.4.1.25258.1.12.1.3", "SphincsPlus-shake-192s-r3.1"},
  150|      1|      {"1.3.6.1.4.1.25258.1.12.1.4", "SphincsPlus-shake-192f-r3.1"},
  151|      1|      {"1.3.6.1.4.1.25258.1.12.1.5", "SphincsPlus-shake-256s-r3.1"},
  152|      1|      {"1.3.6.1.4.1.25258.1.12.1.6", "SphincsPlus-shake-256f-r3.1"},
  153|      1|      {"1.3.6.1.4.1.25258.1.12.2.1", "SphincsPlus-sha2-128s-r3.1"},
  154|      1|      {"1.3.6.1.4.1.25258.1.12.2.2", "SphincsPlus-sha2-128f-r3.1"},
  155|      1|      {"1.3.6.1.4.1.25258.1.12.2.3", "SphincsPlus-sha2-192s-r3.1"},
  156|      1|      {"1.3.6.1.4.1.25258.1.12.2.4", "SphincsPlus-sha2-192f-r3.1"},
  157|      1|      {"1.3.6.1.4.1.25258.1.12.2.5", "SphincsPlus-sha2-256s-r3.1"},
  158|      1|      {"1.3.6.1.4.1.25258.1.12.2.6", "SphincsPlus-sha2-256f-r3.1"},
  159|      1|      {"1.3.6.1.4.1.25258.1.12.3.1", "SphincsPlus-haraka-128s-r3.1"},
  160|      1|      {"1.3.6.1.4.1.25258.1.12.3.2", "SphincsPlus-haraka-128f-r3.1"},
  161|      1|      {"1.3.6.1.4.1.25258.1.12.3.3", "SphincsPlus-haraka-192s-r3.1"},
  162|      1|      {"1.3.6.1.4.1.25258.1.12.3.4", "SphincsPlus-haraka-192f-r3.1"},
  163|      1|      {"1.3.6.1.4.1.25258.1.12.3.5", "SphincsPlus-haraka-256s-r3.1"},
  164|      1|      {"1.3.6.1.4.1.25258.1.12.3.6", "SphincsPlus-haraka-256f-r3.1"},
  165|      1|      {"1.3.6.1.4.1.25258.1.14.1", "FrodoKEM-640-SHAKE"},
  166|      1|      {"1.3.6.1.4.1.25258.1.14.2", "FrodoKEM-976-SHAKE"},
  167|      1|      {"1.3.6.1.4.1.25258.1.14.3", "FrodoKEM-1344-SHAKE"},
  168|      1|      {"1.3.6.1.4.1.25258.1.15.1", "FrodoKEM-640-AES"},
  169|      1|      {"1.3.6.1.4.1.25258.1.15.2", "FrodoKEM-976-AES"},
  170|      1|      {"1.3.6.1.4.1.25258.1.15.3", "FrodoKEM-1344-AES"},
  171|      1|      {"1.3.6.1.4.1.25258.1.16.1", "eFrodoKEM-640-SHAKE"},
  172|      1|      {"1.3.6.1.4.1.25258.1.16.2", "eFrodoKEM-976-SHAKE"},
  173|      1|      {"1.3.6.1.4.1.25258.1.16.3", "eFrodoKEM-1344-SHAKE"},
  174|      1|      {"1.3.6.1.4.1.25258.1.17.1", "eFrodoKEM-640-AES"},
  175|      1|      {"1.3.6.1.4.1.25258.1.17.2", "eFrodoKEM-976-AES"},
  176|      1|      {"1.3.6.1.4.1.25258.1.17.3", "eFrodoKEM-1344-AES"},
  177|      1|      {"1.3.6.1.4.1.25258.1.3", "McEliece"},
  178|      1|      {"1.3.6.1.4.1.25258.1.5", "XMSS-draft6"},
  179|      1|      {"1.3.6.1.4.1.25258.1.6.1", "GOST-34.10-2012-256/SHA-256"},
  180|      1|      {"1.3.6.1.4.1.25258.1.7.1", "Kyber-512-r3"},
  181|      1|      {"1.3.6.1.4.1.25258.1.7.2", "Kyber-768-r3"},
  182|      1|      {"1.3.6.1.4.1.25258.1.7.3", "Kyber-1024-r3"},
  183|      1|      {"1.3.6.1.4.1.25258.1.8", "XMSS-draft12"},
  184|      1|      {"1.3.6.1.4.1.25258.1.9.1", "Dilithium-4x4-r3"},
  185|      1|      {"1.3.6.1.4.1.25258.1.9.2", "Dilithium-6x5-r3"},
  186|      1|      {"1.3.6.1.4.1.25258.1.9.3", "Dilithium-8x7-r3"},
  187|      1|      {"1.3.6.1.4.1.25258.3.1", "Serpent/CBC"},
  188|      1|      {"1.3.6.1.4.1.25258.3.101", "Serpent/GCM"},
  189|      1|      {"1.3.6.1.4.1.25258.3.102", "Twofish/GCM"},
  190|      1|      {"1.3.6.1.4.1.25258.3.2", "Threefish-512/CBC"},
  191|      1|      {"1.3.6.1.4.1.25258.3.2.1", "AES-128/OCB"},
  192|      1|      {"1.3.6.1.4.1.25258.3.2.2", "AES-192/OCB"},
  193|      1|      {"1.3.6.1.4.1.25258.3.2.3", "AES-256/OCB"},
  194|      1|      {"1.3.6.1.4.1.25258.3.2.4", "Serpent/OCB"},
  195|      1|      {"1.3.6.1.4.1.25258.3.2.5", "Twofish/OCB"},
  196|      1|      {"1.3.6.1.4.1.25258.3.2.6", "Camellia-128/OCB"},
  197|      1|      {"1.3.6.1.4.1.25258.3.2.7", "Camellia-192/OCB"},
  198|      1|      {"1.3.6.1.4.1.25258.3.2.8", "Camellia-256/OCB"},
  199|      1|      {"1.3.6.1.4.1.25258.3.3", "Twofish/CBC"},
  200|      1|      {"1.3.6.1.4.1.25258.3.4.1", "AES-128/SIV"},
  201|      1|      {"1.3.6.1.4.1.25258.3.4.2", "AES-192/SIV"},
  202|      1|      {"1.3.6.1.4.1.25258.3.4.3", "AES-256/SIV"},
  203|      1|      {"1.3.6.1.4.1.25258.3.4.4", "Serpent/SIV"},
  204|      1|      {"1.3.6.1.4.1.25258.3.4.5", "Twofish/SIV"},
  205|      1|      {"1.3.6.1.4.1.25258.3.4.6", "Camellia-128/SIV"},
  206|      1|      {"1.3.6.1.4.1.25258.3.4.7", "Camellia-192/SIV"},
  207|      1|      {"1.3.6.1.4.1.25258.3.4.8", "Camellia-256/SIV"},
  208|      1|      {"1.3.6.1.4.1.25258.3.4.9", "SM4/SIV"},
  209|      1|      {"1.3.6.1.4.1.3029.1.2.1", "ElGamal"},
  210|      1|      {"1.3.6.1.4.1.3029.1.5.1", "OpenPGP.Curve25519"},
  211|      1|      {"1.3.6.1.4.1.311.20.2.2", "Microsoft SmartcardLogon"},
  212|      1|      {"1.3.6.1.4.1.311.20.2.3", "Microsoft UPN"},
  213|      1|      {"1.3.6.1.4.1.8301.3.1.2.9.0.38", "secp521r1"},
  214|      1|      {"1.3.6.1.5.5.7.1.1", "PKIX.AuthorityInformationAccess"},
  215|      1|      {"1.3.6.1.5.5.7.3.1", "PKIX.ServerAuth"},
  216|      1|      {"1.3.6.1.5.5.7.3.2", "PKIX.ClientAuth"},
  217|      1|      {"1.3.6.1.5.5.7.3.3", "PKIX.CodeSigning"},
  218|      1|      {"1.3.6.1.5.5.7.3.4", "PKIX.EmailProtection"},
  219|      1|      {"1.3.6.1.5.5.7.3.5", "PKIX.IPsecEndSystem"},
  220|      1|      {"1.3.6.1.5.5.7.3.6", "PKIX.IPsecTunnel"},
  221|      1|      {"1.3.6.1.5.5.7.3.7", "PKIX.IPsecUser"},
  222|      1|      {"1.3.6.1.5.5.7.3.8", "PKIX.TimeStamping"},
  223|      1|      {"1.3.6.1.5.5.7.3.9", "PKIX.OCSPSigning"},
  224|      1|      {"1.3.6.1.5.5.7.48.1", "PKIX.OCSP"},
  225|      1|      {"1.3.6.1.5.5.7.48.1.1", "PKIX.OCSP.BasicResponse"},
  226|      1|      {"1.3.6.1.5.5.7.48.1.5", "PKIX.OCSP.NoCheck"},
  227|      1|      {"1.3.6.1.5.5.7.48.2", "PKIX.CertificateAuthorityIssuers"},
  228|      1|      {"1.3.6.1.5.5.7.8.5", "PKIX.XMPPAddr"},
  229|      1|      {"2.16.840.1.101.3.4.1.2", "AES-128/CBC"},
  230|      1|      {"2.16.840.1.101.3.4.1.22", "AES-192/CBC"},
  231|      1|      {"2.16.840.1.101.3.4.1.25", "KeyWrap.AES-192"},
  232|      1|      {"2.16.840.1.101.3.4.1.26", "AES-192/GCM"},
  233|      1|      {"2.16.840.1.101.3.4.1.27", "AES-192/CCM"},
  234|      1|      {"2.16.840.1.101.3.4.1.42", "AES-256/CBC"},
  235|      1|      {"2.16.840.1.101.3.4.1.45", "KeyWrap.AES-256"},
  236|      1|      {"2.16.840.1.101.3.4.1.46", "AES-256/GCM"},
  237|      1|      {"2.16.840.1.101.3.4.1.47", "AES-256/CCM"},
  238|      1|      {"2.16.840.1.101.3.4.1.5", "KeyWrap.AES-128"},
  239|      1|      {"2.16.840.1.101.3.4.1.6", "AES-128/GCM"},
  240|      1|      {"2.16.840.1.101.3.4.1.7", "AES-128/CCM"},
  241|      1|      {"2.16.840.1.101.3.4.2.1", "SHA-256"},
  242|      1|      {"2.16.840.1.101.3.4.2.10", "SHA-3(512)"},
  243|      1|      {"2.16.840.1.101.3.4.2.11", "SHAKE-128"},
  244|      1|      {"2.16.840.1.101.3.4.2.12", "SHAKE-256"},
  245|      1|      {"2.16.840.1.101.3.4.2.2", "SHA-384"},
  246|      1|      {"2.16.840.1.101.3.4.2.3", "SHA-512"},
  247|      1|      {"2.16.840.1.101.3.4.2.4", "SHA-224"},
  248|      1|      {"2.16.840.1.101.3.4.2.6", "SHA-512-256"},
  249|      1|      {"2.16.840.1.101.3.4.2.7", "SHA-3(224)"},
  250|      1|      {"2.16.840.1.101.3.4.2.8", "SHA-3(256)"},
  251|      1|      {"2.16.840.1.101.3.4.2.9", "SHA-3(384)"},
  252|      1|      {"2.16.840.1.101.3.4.3.1", "DSA/SHA-224"},
  253|      1|      {"2.16.840.1.101.3.4.3.10", "ECDSA/SHA-3(256)"},
  254|      1|      {"2.16.840.1.101.3.4.3.11", "ECDSA/SHA-3(384)"},
  255|      1|      {"2.16.840.1.101.3.4.3.12", "ECDSA/SHA-3(512)"},
  256|      1|      {"2.16.840.1.101.3.4.3.13", "RSA/EMSA3(SHA-3(224))"},
  257|      1|      {"2.16.840.1.101.3.4.3.14", "RSA/EMSA3(SHA-3(256))"},
  258|      1|      {"2.16.840.1.101.3.4.3.15", "RSA/EMSA3(SHA-3(384))"},
  259|      1|      {"2.16.840.1.101.3.4.3.16", "RSA/EMSA3(SHA-3(512))"},
  260|      1|      {"2.16.840.1.101.3.4.3.2", "DSA/SHA-256"},
  261|      1|      {"2.16.840.1.101.3.4.3.3", "DSA/SHA-384"},
  262|      1|      {"2.16.840.1.101.3.4.3.4", "DSA/SHA-512"},
  263|      1|      {"2.16.840.1.101.3.4.3.5", "DSA/SHA-3(224)"},
  264|      1|      {"2.16.840.1.101.3.4.3.6", "DSA/SHA-3(256)"},
  265|      1|      {"2.16.840.1.101.3.4.3.7", "DSA/SHA-3(384)"},
  266|      1|      {"2.16.840.1.101.3.4.3.8", "DSA/SHA-3(512)"},
  267|      1|      {"2.16.840.1.101.3.4.3.9", "ECDSA/SHA-3(224)"},
  268|      1|      {"2.16.840.1.113730.1.13", "Certificate Comment"},
  269|      1|      {"2.5.29.14", "X509v3.SubjectKeyIdentifier"},
  270|      1|      {"2.5.29.15", "X509v3.KeyUsage"},
  271|      1|      {"2.5.29.16", "X509v3.PrivateKeyUsagePeriod"},
  272|      1|      {"2.5.29.17", "X509v3.SubjectAlternativeName"},
  273|      1|      {"2.5.29.18", "X509v3.IssuerAlternativeName"},
  274|      1|      {"2.5.29.19", "X509v3.BasicConstraints"},
  275|      1|      {"2.5.29.20", "X509v3.CRLNumber"},
  276|      1|      {"2.5.29.21", "X509v3.ReasonCode"},
  277|      1|      {"2.5.29.23", "X509v3.HoldInstructionCode"},
  278|      1|      {"2.5.29.24", "X509v3.InvalidityDate"},
  279|      1|      {"2.5.29.28", "X509v3.CRLIssuingDistributionPoint"},
  280|      1|      {"2.5.29.30", "X509v3.NameConstraints"},
  281|      1|      {"2.5.29.31", "X509v3.CRLDistributionPoints"},
  282|      1|      {"2.5.29.32", "X509v3.CertificatePolicies"},
  283|      1|      {"2.5.29.32.0", "X509v3.AnyPolicy"},
  284|      1|      {"2.5.29.35", "X509v3.AuthorityKeyIdentifier"},
  285|      1|      {"2.5.29.36", "X509v3.PolicyConstraints"},
  286|      1|      {"2.5.29.37", "X509v3.ExtendedKeyUsage"},
  287|      1|      {"2.5.4.10", "X520.Organization"},
  288|      1|      {"2.5.4.11", "X520.OrganizationalUnit"},
  289|      1|      {"2.5.4.12", "X520.Title"},
  290|      1|      {"2.5.4.3", "X520.CommonName"},
  291|      1|      {"2.5.4.4", "X520.Surname"},
  292|      1|      {"2.5.4.42", "X520.GivenName"},
  293|      1|      {"2.5.4.43", "X520.Initials"},
  294|      1|      {"2.5.4.44", "X520.GenerationalQualifier"},
  295|      1|      {"2.5.4.46", "X520.DNQualifier"},
  296|      1|      {"2.5.4.5", "X520.SerialNumber"},
  297|      1|      {"2.5.4.6", "X520.Country"},
  298|      1|      {"2.5.4.65", "X520.Pseudonym"},
  299|      1|      {"2.5.4.7", "X520.Locality"},
  300|      1|      {"2.5.4.8", "X520.State"},
  301|      1|      {"2.5.4.9", "X520.StreetAddress"},
  302|      1|      {"2.5.8.1.1", "RSA"}};
  303|      1|}
_ZN5Botan7OID_Map16load_str2oid_mapEv:
  305|      1|std::unordered_map<std::string, OID> OID_Map::load_str2oid_map() {
  306|      1|   return std::unordered_map<std::string, OID>{
  307|       |
  308|      1|      {"AES-128/CBC", OID({2, 16, 840, 1, 101, 3, 4, 1, 2})},
  309|      1|      {"AES-128/CCM", OID({2, 16, 840, 1, 101, 3, 4, 1, 7})},
  310|      1|      {"AES-128/GCM", OID({2, 16, 840, 1, 101, 3, 4, 1, 6})},
  311|      1|      {"AES-128/OCB", OID({1, 3, 6, 1, 4, 1, 25258, 3, 2, 1})},
  312|      1|      {"AES-128/SIV", OID({1, 3, 6, 1, 4, 1, 25258, 3, 4, 1})},
  313|      1|      {"AES-192/CBC", OID({2, 16, 840, 1, 101, 3, 4, 1, 22})},
  314|      1|      {"AES-192/CCM", OID({2, 16, 840, 1, 101, 3, 4, 1, 27})},
  315|      1|      {"AES-192/GCM", OID({2, 16, 840, 1, 101, 3, 4, 1, 26})},
  316|      1|      {"AES-192/OCB", OID({1, 3, 6, 1, 4, 1, 25258, 3, 2, 2})},
  317|      1|      {"AES-192/SIV", OID({1, 3, 6, 1, 4, 1, 25258, 3, 4, 2})},
  318|      1|      {"AES-256/CBC", OID({2, 16, 840, 1, 101, 3, 4, 1, 42})},
  319|      1|      {"AES-256/CCM", OID({2, 16, 840, 1, 101, 3, 4, 1, 47})},
  320|      1|      {"AES-256/GCM", OID({2, 16, 840, 1, 101, 3, 4, 1, 46})},
  321|      1|      {"AES-256/OCB", OID({1, 3, 6, 1, 4, 1, 25258, 3, 2, 3})},
  322|      1|      {"AES-256/SIV", OID({1, 3, 6, 1, 4, 1, 25258, 3, 4, 3})},
  323|      1|      {"CAST-128/CBC", OID({1, 2, 840, 113533, 7, 66, 10})},
  324|      1|      {"Camellia-128/CBC", OID({1, 2, 392, 200011, 61, 1, 1, 1, 2})},
  325|      1|      {"Camellia-128/GCM", OID({0, 3, 4401, 5, 3, 1, 9, 6})},
  326|      1|      {"Camellia-128/OCB", OID({1, 3, 6, 1, 4, 1, 25258, 3, 2, 6})},
  327|      1|      {"Camellia-128/SIV", OID({1, 3, 6, 1, 4, 1, 25258, 3, 4, 6})},
  328|      1|      {"Camellia-192/CBC", OID({1, 2, 392, 200011, 61, 1, 1, 1, 3})},
  329|      1|      {"Camellia-192/GCM", OID({0, 3, 4401, 5, 3, 1, 9, 26})},
  330|      1|      {"Camellia-192/OCB", OID({1, 3, 6, 1, 4, 1, 25258, 3, 2, 7})},
  331|      1|      {"Camellia-192/SIV", OID({1, 3, 6, 1, 4, 1, 25258, 3, 4, 7})},
  332|      1|      {"Camellia-256/CBC", OID({1, 2, 392, 200011, 61, 1, 1, 1, 4})},
  333|      1|      {"Camellia-256/GCM", OID({0, 3, 4401, 5, 3, 1, 9, 46})},
  334|      1|      {"Camellia-256/OCB", OID({1, 3, 6, 1, 4, 1, 25258, 3, 2, 8})},
  335|      1|      {"Camellia-256/SIV", OID({1, 3, 6, 1, 4, 1, 25258, 3, 4, 8})},
  336|      1|      {"Certificate Comment", OID({2, 16, 840, 1, 113730, 1, 13})},
  337|      1|      {"ChaCha20Poly1305", OID({1, 2, 840, 113549, 1, 9, 16, 3, 18})},
  338|      1|      {"Compression.Zlib", OID({1, 2, 840, 113549, 1, 9, 16, 3, 8})},
  339|      1|      {"Curve25519", OID({1, 3, 101, 110})},
  340|      1|      {"DES/CBC", OID({1, 3, 14, 3, 2, 7})},
  341|      1|      {"DH", OID({1, 2, 840, 10046, 2, 1})},
  342|      1|      {"DSA", OID({1, 2, 840, 10040, 4, 1})},
  343|      1|      {"DSA/SHA-1", OID({1, 2, 840, 10040, 4, 3})},
  344|      1|      {"DSA/SHA-224", OID({2, 16, 840, 1, 101, 3, 4, 3, 1})},
  345|      1|      {"DSA/SHA-256", OID({2, 16, 840, 1, 101, 3, 4, 3, 2})},
  346|      1|      {"DSA/SHA-3(224)", OID({2, 16, 840, 1, 101, 3, 4, 3, 5})},
  347|      1|      {"DSA/SHA-3(256)", OID({2, 16, 840, 1, 101, 3, 4, 3, 6})},
  348|      1|      {"DSA/SHA-3(384)", OID({2, 16, 840, 1, 101, 3, 4, 3, 7})},
  349|      1|      {"DSA/SHA-3(512)", OID({2, 16, 840, 1, 101, 3, 4, 3, 8})},
  350|      1|      {"DSA/SHA-384", OID({2, 16, 840, 1, 101, 3, 4, 3, 3})},
  351|      1|      {"DSA/SHA-512", OID({2, 16, 840, 1, 101, 3, 4, 3, 4})},
  352|      1|      {"Dilithium-4x4-AES-r3", OID({1, 3, 6, 1, 4, 1, 25258, 1, 10, 1})},
  353|      1|      {"Dilithium-4x4-r3", OID({1, 3, 6, 1, 4, 1, 25258, 1, 9, 1})},
  354|      1|      {"Dilithium-6x5-AES-r3", OID({1, 3, 6, 1, 4, 1, 25258, 1, 10, 2})},
  355|      1|      {"Dilithium-6x5-r3", OID({1, 3, 6, 1, 4, 1, 25258, 1, 9, 2})},
  356|      1|      {"Dilithium-8x7-AES-r3", OID({1, 3, 6, 1, 4, 1, 25258, 1, 10, 3})},
  357|      1|      {"Dilithium-8x7-r3", OID({1, 3, 6, 1, 4, 1, 25258, 1, 9, 3})},
  358|      1|      {"ECDH", OID({1, 3, 132, 1, 12})},
  359|      1|      {"ECDSA", OID({1, 2, 840, 10045, 2, 1})},
  360|      1|      {"ECDSA/SHA-1", OID({1, 2, 840, 10045, 4, 1})},
  361|      1|      {"ECDSA/SHA-224", OID({1, 2, 840, 10045, 4, 3, 1})},
  362|      1|      {"ECDSA/SHA-256", OID({1, 2, 840, 10045, 4, 3, 2})},
  363|      1|      {"ECDSA/SHA-3(224)", OID({2, 16, 840, 1, 101, 3, 4, 3, 9})},
  364|      1|      {"ECDSA/SHA-3(256)", OID({2, 16, 840, 1, 101, 3, 4, 3, 10})},
  365|      1|      {"ECDSA/SHA-3(384)", OID({2, 16, 840, 1, 101, 3, 4, 3, 11})},
  366|      1|      {"ECDSA/SHA-3(512)", OID({2, 16, 840, 1, 101, 3, 4, 3, 12})},
  367|      1|      {"ECDSA/SHA-384", OID({1, 2, 840, 10045, 4, 3, 3})},
  368|      1|      {"ECDSA/SHA-512", OID({1, 2, 840, 10045, 4, 3, 4})},
  369|      1|      {"ECGDSA", OID({1, 3, 36, 3, 3, 2, 5, 2, 1})},
  370|      1|      {"ECGDSA/RIPEMD-160", OID({1, 3, 36, 3, 3, 2, 5, 4, 1})},
  371|      1|      {"ECGDSA/SHA-1", OID({1, 3, 36, 3, 3, 2, 5, 4, 2})},
  372|      1|      {"ECGDSA/SHA-224", OID({1, 3, 36, 3, 3, 2, 5, 4, 3})},
  373|      1|      {"ECGDSA/SHA-256", OID({1, 3, 36, 3, 3, 2, 5, 4, 4})},
  374|      1|      {"ECGDSA/SHA-384", OID({1, 3, 36, 3, 3, 2, 5, 4, 5})},
  375|      1|      {"ECGDSA/SHA-512", OID({1, 3, 36, 3, 3, 2, 5, 4, 6})},
  376|      1|      {"ECKCDSA", OID({1, 0, 14888, 3, 0, 5})},
  377|      1|      {"ECKCDSA/SHA-1", OID({1, 2, 410, 200004, 1, 100, 4, 3})},
  378|      1|      {"ECKCDSA/SHA-224", OID({1, 2, 410, 200004, 1, 100, 4, 4})},
  379|      1|      {"ECKCDSA/SHA-256", OID({1, 2, 410, 200004, 1, 100, 4, 5})},
  380|      1|      {"Ed25519", OID({1, 3, 101, 112})},
  381|      1|      {"ElGamal", OID({1, 3, 6, 1, 4, 1, 3029, 1, 2, 1})},
  382|      1|      {"FrodoKEM-1344-AES", OID({1, 3, 6, 1, 4, 1, 25258, 1, 15, 3})},
  383|      1|      {"FrodoKEM-1344-SHAKE", OID({1, 3, 6, 1, 4, 1, 25258, 1, 14, 3})},
  384|      1|      {"FrodoKEM-640-AES", OID({1, 3, 6, 1, 4, 1, 25258, 1, 15, 1})},
  385|      1|      {"FrodoKEM-640-SHAKE", OID({1, 3, 6, 1, 4, 1, 25258, 1, 14, 1})},
  386|      1|      {"FrodoKEM-976-AES", OID({1, 3, 6, 1, 4, 1, 25258, 1, 15, 2})},
  387|      1|      {"FrodoKEM-976-SHAKE", OID({1, 3, 6, 1, 4, 1, 25258, 1, 14, 2})},
  388|      1|      {"GOST-34.10", OID({1, 2, 643, 2, 2, 19})},
  389|      1|      {"GOST-34.10-2012-256", OID({1, 2, 643, 7, 1, 1, 1, 1})},
  390|      1|      {"GOST-34.10-2012-256/SHA-256", OID({1, 3, 6, 1, 4, 1, 25258, 1, 6, 1})},
  391|      1|      {"GOST-34.10-2012-256/Streebog-256", OID({1, 2, 643, 7, 1, 1, 3, 2})},
  392|      1|      {"GOST-34.10-2012-512", OID({1, 2, 643, 7, 1, 1, 1, 2})},
  393|      1|      {"GOST-34.10-2012-512/Streebog-512", OID({1, 2, 643, 7, 1, 1, 3, 3})},
  394|      1|      {"GOST-34.10/GOST-R-34.11-94", OID({1, 2, 643, 2, 2, 3})},
  395|      1|      {"GOST.INN", OID({1, 2, 643, 3, 131, 1, 1})},
  396|      1|      {"GOST.IssuerSigningTool", OID({1, 2, 643, 100, 112})},
  397|      1|      {"GOST.OGRN", OID({1, 2, 643, 100, 1})},
  398|      1|      {"GOST.SubjectSigningTool", OID({1, 2, 643, 100, 111})},
  399|      1|      {"HMAC(SHA-1)", OID({1, 2, 840, 113549, 2, 7})},
  400|      1|      {"HMAC(SHA-224)", OID({1, 2, 840, 113549, 2, 8})},
  401|      1|      {"HMAC(SHA-256)", OID({1, 2, 840, 113549, 2, 9})},
  402|      1|      {"HMAC(SHA-384)", OID({1, 2, 840, 113549, 2, 10})},
  403|      1|      {"HMAC(SHA-512)", OID({1, 2, 840, 113549, 2, 11})},
  404|      1|      {"HMAC(SHA-512-256)", OID({1, 2, 840, 113549, 2, 13})},
  405|      1|      {"KeyWrap.AES-128", OID({2, 16, 840, 1, 101, 3, 4, 1, 5})},
  406|      1|      {"KeyWrap.AES-192", OID({2, 16, 840, 1, 101, 3, 4, 1, 25})},
  407|      1|      {"KeyWrap.AES-256", OID({2, 16, 840, 1, 101, 3, 4, 1, 45})},
  408|      1|      {"KeyWrap.CAST-128", OID({1, 2, 840, 113533, 7, 66, 15})},
  409|      1|      {"KeyWrap.TripleDES", OID({1, 2, 840, 113549, 1, 9, 16, 3, 6})},
  410|      1|      {"Kyber-1024-90s-r3", OID({1, 3, 6, 1, 4, 1, 25258, 1, 11, 3})},
  411|      1|      {"Kyber-1024-r3", OID({1, 3, 6, 1, 4, 1, 25258, 1, 7, 3})},
  412|      1|      {"Kyber-512-90s-r3", OID({1, 3, 6, 1, 4, 1, 25258, 1, 11, 1})},
  413|      1|      {"Kyber-512-r3", OID({1, 3, 6, 1, 4, 1, 25258, 1, 7, 1})},
  414|      1|      {"Kyber-768-90s-r3", OID({1, 3, 6, 1, 4, 1, 25258, 1, 11, 2})},
  415|      1|      {"Kyber-768-r3", OID({1, 3, 6, 1, 4, 1, 25258, 1, 7, 2})},
  416|      1|      {"MD5", OID({1, 2, 840, 113549, 2, 5})},
  417|      1|      {"MGF1", OID({1, 2, 840, 113549, 1, 1, 8})},
  418|      1|      {"McEliece", OID({1, 3, 6, 1, 4, 1, 25258, 1, 3})},
  419|      1|      {"Microsoft SmartcardLogon", OID({1, 3, 6, 1, 4, 1, 311, 20, 2, 2})},
  420|      1|      {"Microsoft UPN", OID({1, 3, 6, 1, 4, 1, 311, 20, 2, 3})},
  421|      1|      {"OpenPGP.Curve25519", OID({1, 3, 6, 1, 4, 1, 3029, 1, 5, 1})},
  422|      1|      {"OpenPGP.Ed25519", OID({1, 3, 6, 1, 4, 1, 11591, 15, 1})},
  423|      1|      {"PBE-PKCS5v20", OID({1, 2, 840, 113549, 1, 5, 13})},
  424|      1|      {"PBES2", OID({1, 2, 840, 113549, 1, 5, 13})},
  425|      1|      {"PKCS5.PBKDF2", OID({1, 2, 840, 113549, 1, 5, 12})},
  426|      1|      {"PKCS9.ChallengePassword", OID({1, 2, 840, 113549, 1, 9, 7})},
  427|      1|      {"PKCS9.ContentType", OID({1, 2, 840, 113549, 1, 9, 3})},
  428|      1|      {"PKCS9.EmailAddress", OID({1, 2, 840, 113549, 1, 9, 1})},
  429|      1|      {"PKCS9.ExtensionRequest", OID({1, 2, 840, 113549, 1, 9, 14})},
  430|      1|      {"PKCS9.MessageDigest", OID({1, 2, 840, 113549, 1, 9, 4})},
  431|      1|      {"PKCS9.UnstructuredName", OID({1, 2, 840, 113549, 1, 9, 2})},
  432|      1|      {"PKIX.AuthorityInformationAccess", OID({1, 3, 6, 1, 5, 5, 7, 1, 1})},
  433|      1|      {"PKIX.CertificateAuthorityIssuers", OID({1, 3, 6, 1, 5, 5, 7, 48, 2})},
  434|      1|      {"PKIX.ClientAuth", OID({1, 3, 6, 1, 5, 5, 7, 3, 2})},
  435|      1|      {"PKIX.CodeSigning", OID({1, 3, 6, 1, 5, 5, 7, 3, 3})},
  436|      1|      {"PKIX.EmailProtection", OID({1, 3, 6, 1, 5, 5, 7, 3, 4})},
  437|      1|      {"PKIX.IPsecEndSystem", OID({1, 3, 6, 1, 5, 5, 7, 3, 5})},
  438|      1|      {"PKIX.IPsecTunnel", OID({1, 3, 6, 1, 5, 5, 7, 3, 6})},
  439|      1|      {"PKIX.IPsecUser", OID({1, 3, 6, 1, 5, 5, 7, 3, 7})},
  440|      1|      {"PKIX.OCSP", OID({1, 3, 6, 1, 5, 5, 7, 48, 1})},
  441|      1|      {"PKIX.OCSP.BasicResponse", OID({1, 3, 6, 1, 5, 5, 7, 48, 1, 1})},
  442|      1|      {"PKIX.OCSP.NoCheck", OID({1, 3, 6, 1, 5, 5, 7, 48, 1, 5})},
  443|      1|      {"PKIX.OCSPSigning", OID({1, 3, 6, 1, 5, 5, 7, 3, 9})},
  444|      1|      {"PKIX.ServerAuth", OID({1, 3, 6, 1, 5, 5, 7, 3, 1})},
  445|      1|      {"PKIX.TimeStamping", OID({1, 3, 6, 1, 5, 5, 7, 3, 8})},
  446|      1|      {"PKIX.XMPPAddr", OID({1, 3, 6, 1, 5, 5, 7, 8, 5})},
  447|      1|      {"RIPEMD-160", OID({1, 3, 36, 3, 2, 1})},
  448|      1|      {"RSA", OID({1, 2, 840, 113549, 1, 1, 1})},
  449|      1|      {"RSA/EMSA3(MD5)", OID({1, 2, 840, 113549, 1, 1, 4})},
  450|      1|      {"RSA/EMSA3(RIPEMD-160)", OID({1, 3, 36, 3, 3, 1, 2})},
  451|      1|      {"RSA/EMSA3(SHA-1)", OID({1, 2, 840, 113549, 1, 1, 5})},
  452|      1|      {"RSA/EMSA3(SHA-224)", OID({1, 2, 840, 113549, 1, 1, 14})},
  453|      1|      {"RSA/EMSA3(SHA-256)", OID({1, 2, 840, 113549, 1, 1, 11})},
  454|      1|      {"RSA/EMSA3(SHA-3(224))", OID({2, 16, 840, 1, 101, 3, 4, 3, 13})},
  455|      1|      {"RSA/EMSA3(SHA-3(256))", OID({2, 16, 840, 1, 101, 3, 4, 3, 14})},
  456|      1|      {"RSA/EMSA3(SHA-3(384))", OID({2, 16, 840, 1, 101, 3, 4, 3, 15})},
  457|      1|      {"RSA/EMSA3(SHA-3(512))", OID({2, 16, 840, 1, 101, 3, 4, 3, 16})},
  458|      1|      {"RSA/EMSA3(SHA-384)", OID({1, 2, 840, 113549, 1, 1, 12})},
  459|      1|      {"RSA/EMSA3(SHA-512)", OID({1, 2, 840, 113549, 1, 1, 13})},
  460|      1|      {"RSA/EMSA3(SHA-512-256)", OID({1, 2, 840, 113549, 1, 1, 16})},
  461|      1|      {"RSA/EMSA3(SM3)", OID({1, 2, 156, 10197, 1, 504})},
  462|      1|      {"RSA/EMSA4", OID({1, 2, 840, 113549, 1, 1, 10})},
  463|      1|      {"RSA/OAEP", OID({1, 2, 840, 113549, 1, 1, 7})},
  464|      1|      {"SEED/CBC", OID({1, 2, 410, 200004, 1, 4})},
  465|      1|      {"SHA-1", OID({1, 3, 14, 3, 2, 26})},
  466|      1|      {"SHA-224", OID({2, 16, 840, 1, 101, 3, 4, 2, 4})},
  467|      1|      {"SHA-256", OID({2, 16, 840, 1, 101, 3, 4, 2, 1})},
  468|      1|      {"SHA-3(224)", OID({2, 16, 840, 1, 101, 3, 4, 2, 7})},
  469|      1|      {"SHA-3(256)", OID({2, 16, 840, 1, 101, 3, 4, 2, 8})},
  470|      1|      {"SHA-3(384)", OID({2, 16, 840, 1, 101, 3, 4, 2, 9})},
  471|      1|      {"SHA-3(512)", OID({2, 16, 840, 1, 101, 3, 4, 2, 10})},
  472|      1|      {"SHA-384", OID({2, 16, 840, 1, 101, 3, 4, 2, 2})},
  473|      1|      {"SHA-512", OID({2, 16, 840, 1, 101, 3, 4, 2, 3})},
  474|      1|      {"SHA-512-256", OID({2, 16, 840, 1, 101, 3, 4, 2, 6})},
  475|      1|      {"SHAKE-128", OID({2, 16, 840, 1, 101, 3, 4, 2, 11})},
  476|      1|      {"SHAKE-256", OID({2, 16, 840, 1, 101, 3, 4, 2, 12})},
  477|      1|      {"SM2", OID({1, 2, 156, 10197, 1, 301, 1})},
  478|      1|      {"SM2_Enc", OID({1, 2, 156, 10197, 1, 301, 3})},
  479|      1|      {"SM2_Kex", OID({1, 2, 156, 10197, 1, 301, 2})},
  480|      1|      {"SM2_Sig", OID({1, 2, 156, 10197, 1, 301, 1})},
  481|      1|      {"SM2_Sig/SM3", OID({1, 2, 156, 10197, 1, 501})},
  482|      1|      {"SM3", OID({1, 2, 156, 10197, 1, 401})},
  483|      1|      {"SM4/CBC", OID({1, 2, 156, 10197, 1, 104, 2})},
  484|      1|      {"SM4/GCM", OID({1, 2, 156, 10197, 1, 104, 8})},
  485|      1|      {"SM4/OCB", OID({1, 2, 156, 10197, 1, 104, 100})},
  486|      1|      {"SM4/SIV", OID({1, 3, 6, 1, 4, 1, 25258, 3, 4, 9})},
  487|      1|      {"Scrypt", OID({1, 3, 6, 1, 4, 1, 11591, 4, 11})},
  488|      1|      {"Serpent/CBC", OID({1, 3, 6, 1, 4, 1, 25258, 3, 1})},
  489|      1|      {"Serpent/GCM", OID({1, 3, 6, 1, 4, 1, 25258, 3, 101})},
  490|      1|      {"Serpent/OCB", OID({1, 3, 6, 1, 4, 1, 25258, 3, 2, 4})},
  491|      1|      {"Serpent/SIV", OID({1, 3, 6, 1, 4, 1, 25258, 3, 4, 4})},
  492|      1|      {"SphincsPlus-haraka-128f-r3.1", OID({1, 3, 6, 1, 4, 1, 25258, 1, 12, 3, 2})},
  493|      1|      {"SphincsPlus-haraka-128s-r3.1", OID({1, 3, 6, 1, 4, 1, 25258, 1, 12, 3, 1})},
  494|      1|      {"SphincsPlus-haraka-192f-r3.1", OID({1, 3, 6, 1, 4, 1, 25258, 1, 12, 3, 4})},
  495|      1|      {"SphincsPlus-haraka-192s-r3.1", OID({1, 3, 6, 1, 4, 1, 25258, 1, 12, 3, 3})},
  496|      1|      {"SphincsPlus-haraka-256f-r3.1", OID({1, 3, 6, 1, 4, 1, 25258, 1, 12, 3, 6})},
  497|      1|      {"SphincsPlus-haraka-256s-r3.1", OID({1, 3, 6, 1, 4, 1, 25258, 1, 12, 3, 5})},
  498|      1|      {"SphincsPlus-sha2-128f-r3.1", OID({1, 3, 6, 1, 4, 1, 25258, 1, 12, 2, 2})},
  499|      1|      {"SphincsPlus-sha2-128s-r3.1", OID({1, 3, 6, 1, 4, 1, 25258, 1, 12, 2, 1})},
  500|      1|      {"SphincsPlus-sha2-192f-r3.1", OID({1, 3, 6, 1, 4, 1, 25258, 1, 12, 2, 4})},
  501|      1|      {"SphincsPlus-sha2-192s-r3.1", OID({1, 3, 6, 1, 4, 1, 25258, 1, 12, 2, 3})},
  502|      1|      {"SphincsPlus-sha2-256f-r3.1", OID({1, 3, 6, 1, 4, 1, 25258, 1, 12, 2, 6})},
  503|      1|      {"SphincsPlus-sha2-256s-r3.1", OID({1, 3, 6, 1, 4, 1, 25258, 1, 12, 2, 5})},
  504|      1|      {"SphincsPlus-shake-128f-r3.1", OID({1, 3, 6, 1, 4, 1, 25258, 1, 12, 1, 2})},
  505|      1|      {"SphincsPlus-shake-128s-r3.1", OID({1, 3, 6, 1, 4, 1, 25258, 1, 12, 1, 1})},
  506|      1|      {"SphincsPlus-shake-192f-r3.1", OID({1, 3, 6, 1, 4, 1, 25258, 1, 12, 1, 4})},
  507|      1|      {"SphincsPlus-shake-192s-r3.1", OID({1, 3, 6, 1, 4, 1, 25258, 1, 12, 1, 3})},
  508|      1|      {"SphincsPlus-shake-256f-r3.1", OID({1, 3, 6, 1, 4, 1, 25258, 1, 12, 1, 6})},
  509|      1|      {"SphincsPlus-shake-256s-r3.1", OID({1, 3, 6, 1, 4, 1, 25258, 1, 12, 1, 5})},
  510|      1|      {"Streebog-256", OID({1, 2, 643, 7, 1, 1, 2, 2})},
  511|      1|      {"Streebog-512", OID({1, 2, 643, 7, 1, 1, 2, 3})},
  512|      1|      {"Threefish-512/CBC", OID({1, 3, 6, 1, 4, 1, 25258, 3, 2})},
  513|      1|      {"TripleDES/CBC", OID({1, 2, 840, 113549, 3, 7})},
  514|      1|      {"Twofish/CBC", OID({1, 3, 6, 1, 4, 1, 25258, 3, 3})},
  515|      1|      {"Twofish/GCM", OID({1, 3, 6, 1, 4, 1, 25258, 3, 102})},
  516|      1|      {"Twofish/OCB", OID({1, 3, 6, 1, 4, 1, 25258, 3, 2, 5})},
  517|      1|      {"Twofish/SIV", OID({1, 3, 6, 1, 4, 1, 25258, 3, 4, 5})},
  518|      1|      {"X509v3.AnyPolicy", OID({2, 5, 29, 32, 0})},
  519|      1|      {"X509v3.AuthorityKeyIdentifier", OID({2, 5, 29, 35})},
  520|      1|      {"X509v3.BasicConstraints", OID({2, 5, 29, 19})},
  521|      1|      {"X509v3.CRLDistributionPoints", OID({2, 5, 29, 31})},
  522|      1|      {"X509v3.CRLIssuingDistributionPoint", OID({2, 5, 29, 28})},
  523|      1|      {"X509v3.CRLNumber", OID({2, 5, 29, 20})},
  524|      1|      {"X509v3.CertificatePolicies", OID({2, 5, 29, 32})},
  525|      1|      {"X509v3.ExtendedKeyUsage", OID({2, 5, 29, 37})},
  526|      1|      {"X509v3.HoldInstructionCode", OID({2, 5, 29, 23})},
  527|      1|      {"X509v3.InvalidityDate", OID({2, 5, 29, 24})},
  528|      1|      {"X509v3.IssuerAlternativeName", OID({2, 5, 29, 18})},
  529|      1|      {"X509v3.KeyUsage", OID({2, 5, 29, 15})},
  530|      1|      {"X509v3.NameConstraints", OID({2, 5, 29, 30})},
  531|      1|      {"X509v3.PolicyConstraints", OID({2, 5, 29, 36})},
  532|      1|      {"X509v3.PrivateKeyUsagePeriod", OID({2, 5, 29, 16})},
  533|      1|      {"X509v3.ReasonCode", OID({2, 5, 29, 21})},
  534|      1|      {"X509v3.SubjectAlternativeName", OID({2, 5, 29, 17})},
  535|      1|      {"X509v3.SubjectKeyIdentifier", OID({2, 5, 29, 14})},
  536|      1|      {"X520.CommonName", OID({2, 5, 4, 3})},
  537|      1|      {"X520.Country", OID({2, 5, 4, 6})},
  538|      1|      {"X520.DNQualifier", OID({2, 5, 4, 46})},
  539|      1|      {"X520.GenerationalQualifier", OID({2, 5, 4, 44})},
  540|      1|      {"X520.GivenName", OID({2, 5, 4, 42})},
  541|      1|      {"X520.Initials", OID({2, 5, 4, 43})},
  542|      1|      {"X520.Locality", OID({2, 5, 4, 7})},
  543|      1|      {"X520.Organization", OID({2, 5, 4, 10})},
  544|      1|      {"X520.OrganizationalUnit", OID({2, 5, 4, 11})},
  545|      1|      {"X520.Pseudonym", OID({2, 5, 4, 65})},
  546|      1|      {"X520.SerialNumber", OID({2, 5, 4, 5})},
  547|      1|      {"X520.State", OID({2, 5, 4, 8})},
  548|      1|      {"X520.StreetAddress", OID({2, 5, 4, 9})},
  549|      1|      {"X520.Surname", OID({2, 5, 4, 4})},
  550|      1|      {"X520.Title", OID({2, 5, 4, 12})},
  551|      1|      {"XMSS", OID({0, 4, 0, 127, 0, 15, 1, 1, 13, 0})},
  552|      1|      {"XMSS-draft12", OID({1, 3, 6, 1, 4, 1, 25258, 1, 8})},
  553|      1|      {"XMSS-draft6", OID({1, 3, 6, 1, 4, 1, 25258, 1, 5})},
  554|      1|      {"brainpool160r1", OID({1, 3, 36, 3, 3, 2, 8, 1, 1, 1})},
  555|      1|      {"brainpool192r1", OID({1, 3, 36, 3, 3, 2, 8, 1, 1, 3})},
  556|      1|      {"brainpool224r1", OID({1, 3, 36, 3, 3, 2, 8, 1, 1, 5})},
  557|      1|      {"brainpool256r1", OID({1, 3, 36, 3, 3, 2, 8, 1, 1, 7})},
  558|      1|      {"brainpool320r1", OID({1, 3, 36, 3, 3, 2, 8, 1, 1, 9})},
  559|      1|      {"brainpool384r1", OID({1, 3, 36, 3, 3, 2, 8, 1, 1, 11})},
  560|      1|      {"brainpool512r1", OID({1, 3, 36, 3, 3, 2, 8, 1, 1, 13})},
  561|      1|      {"eFrodoKEM-1344-AES", OID({1, 3, 6, 1, 4, 1, 25258, 1, 17, 3})},
  562|      1|      {"eFrodoKEM-1344-SHAKE", OID({1, 3, 6, 1, 4, 1, 25258, 1, 16, 3})},
  563|      1|      {"eFrodoKEM-640-AES", OID({1, 3, 6, 1, 4, 1, 25258, 1, 17, 1})},
  564|      1|      {"eFrodoKEM-640-SHAKE", OID({1, 3, 6, 1, 4, 1, 25258, 1, 16, 1})},
  565|      1|      {"eFrodoKEM-976-AES", OID({1, 3, 6, 1, 4, 1, 25258, 1, 17, 2})},
  566|      1|      {"eFrodoKEM-976-SHAKE", OID({1, 3, 6, 1, 4, 1, 25258, 1, 16, 2})},
  567|      1|      {"frp256v1", OID({1, 2, 250, 1, 223, 101, 256, 1})},
  568|      1|      {"gost_256A", OID({1, 2, 643, 7, 1, 2, 1, 1, 1})},
  569|      1|      {"gost_256B", OID({1, 2, 643, 7, 1, 2, 1, 1, 2})},
  570|      1|      {"gost_512A", OID({1, 2, 643, 7, 1, 2, 1, 2, 1})},
  571|      1|      {"gost_512B", OID({1, 2, 643, 7, 1, 2, 1, 2, 2})},
  572|      1|      {"secp160k1", OID({1, 3, 132, 0, 9})},
  573|      1|      {"secp160r1", OID({1, 3, 132, 0, 8})},
  574|      1|      {"secp160r2", OID({1, 3, 132, 0, 30})},
  575|      1|      {"secp192k1", OID({1, 3, 132, 0, 31})},
  576|      1|      {"secp192r1", OID({1, 2, 840, 10045, 3, 1, 1})},
  577|      1|      {"secp224k1", OID({1, 3, 132, 0, 32})},
  578|      1|      {"secp224r1", OID({1, 3, 132, 0, 33})},
  579|      1|      {"secp256k1", OID({1, 3, 132, 0, 10})},
  580|      1|      {"secp256r1", OID({1, 2, 840, 10045, 3, 1, 7})},
  581|      1|      {"secp384r1", OID({1, 3, 132, 0, 34})},
  582|      1|      {"secp521r1", OID({1, 3, 132, 0, 35})},
  583|      1|      {"sm2p256v1", OID({1, 2, 156, 10197, 1, 301})},
  584|      1|      {"x962_p192v2", OID({1, 2, 840, 10045, 3, 1, 2})},
  585|      1|      {"x962_p192v3", OID({1, 2, 840, 10045, 3, 1, 3})},
  586|      1|      {"x962_p239v1", OID({1, 2, 840, 10045, 3, 1, 4})},
  587|      1|      {"x962_p239v2", OID({1, 2, 840, 10045, 3, 1, 5})},
  588|      1|      {"x962_p239v3", OID({1, 2, 840, 10045, 3, 1, 6})}};
  589|      1|}

_ZN5Botan18SymmetricAlgorithm7set_keyENSt3__14spanIKhLm18446744073709551615EEE:
   17|      4|void SymmetricAlgorithm::set_key(std::span<const uint8_t> key) {
   18|      4|   if(!valid_keylength(key.size())) {
  ------------------
  |  Branch (18:7): [True: 0, False: 4]
  ------------------
   19|      0|      throw Invalid_Key_Length(name(), key.size());
   20|      0|   }
   21|      4|   key_schedule(key);
   22|      4|}

_ZN5Botan10hex_decodeEPhPKcmRmb:
   81|     10|size_t hex_decode(uint8_t output[], const char input[], size_t input_length, size_t& input_consumed, bool ignore_ws) {
   82|     10|   uint8_t* out_ptr = output;
   83|     10|   bool top_nibble = true;
   84|       |
   85|     10|   clear_mem(output, input_length / 2);
   86|       |
   87|    850|   for(size_t i = 0; i != input_length; ++i) {
  ------------------
  |  Branch (87:22): [True: 840, False: 10]
  ------------------
   88|    840|      const uint8_t bin = hex_char_to_bin(input[i]);
   89|       |
   90|    840|      if(bin >= 0x10) {
  ------------------
  |  Branch (90:10): [True: 0, False: 840]
  ------------------
   91|      0|         if(bin == 0x80 && ignore_ws) {
  ------------------
  |  Branch (91:13): [True: 0, False: 0]
  |  Branch (91:28): [True: 0, False: 0]
  ------------------
   92|      0|            continue;
   93|      0|         }
   94|       |
   95|      0|         throw Invalid_Argument(fmt("hex_decode: invalid character '{}'", format_char_for_display(input[i])));
   96|      0|      }
   97|       |
   98|    840|      if(top_nibble) {
  ------------------
  |  Branch (98:10): [True: 420, False: 420]
  ------------------
   99|    420|         *out_ptr |= bin << 4;
  100|    420|      } else {
  101|    420|         *out_ptr |= bin;
  102|    420|      }
  103|       |
  104|    840|      top_nibble = !top_nibble;
  105|    840|      if(top_nibble) {
  ------------------
  |  Branch (105:10): [True: 420, False: 420]
  ------------------
  106|    420|         ++out_ptr;
  107|    420|      }
  108|    840|   }
  109|       |
  110|     10|   input_consumed = input_length;
  111|     10|   size_t written = (out_ptr - output);
  112|       |
  113|       |   /*
  114|       |   * We only got half of a uint8_t at the end; zap the half-written
  115|       |   * output and mark it as unread
  116|       |   */
  117|     10|   if(!top_nibble) {
  ------------------
  |  Branch (117:7): [True: 0, False: 10]
  ------------------
  118|      0|      *out_ptr = 0;
  119|      0|      input_consumed -= 1;
  120|      0|   }
  121|       |
  122|     10|   return written;
  123|     10|}
_ZN5Botan10hex_decodeEPhPKcmb:
  125|     10|size_t hex_decode(uint8_t output[], const char input[], size_t input_length, bool ignore_ws) {
  126|     10|   size_t consumed = 0;
  127|     10|   size_t written = hex_decode(output, input, input_length, consumed, ignore_ws);
  128|       |
  129|     10|   if(consumed != input_length) {
  ------------------
  |  Branch (129:7): [True: 0, False: 10]
  ------------------
  130|      0|      throw Invalid_Argument("hex_decode: input did not have full bytes");
  131|      0|   }
  132|       |
  133|     10|   return written;
  134|     10|}
_ZN5Botan17hex_decode_lockedEPKcmb:
  144|     10|secure_vector<uint8_t> hex_decode_locked(const char input[], size_t input_length, bool ignore_ws) {
  145|     10|   secure_vector<uint8_t> bin(1 + input_length / 2);
  146|       |
  147|     10|   size_t written = hex_decode(bin.data(), input, input_length, ignore_ws);
  148|       |
  149|     10|   bin.resize(written);
  150|     10|   return bin;
  151|     10|}
hex.cpp:_ZN5Botan12_GLOBAL__N_115hex_char_to_binEc:
   55|    840|uint8_t hex_char_to_bin(char input) {
   56|    840|   const uint8_t c = static_cast<uint8_t>(input);
   57|       |
   58|    840|   const auto is_alpha_upper = CT::Mask<uint8_t>::is_within_range(c, uint8_t('A'), uint8_t('F'));
   59|    840|   const auto is_alpha_lower = CT::Mask<uint8_t>::is_within_range(c, uint8_t('a'), uint8_t('f'));
   60|    840|   const auto is_decimal = CT::Mask<uint8_t>::is_within_range(c, uint8_t('0'), uint8_t('9'));
   61|       |
   62|    840|   const auto is_whitespace =
   63|    840|      CT::Mask<uint8_t>::is_any_of(c, {uint8_t(' '), uint8_t('\t'), uint8_t('\n'), uint8_t('\r')});
   64|       |
   65|    840|   const uint8_t c_upper = c - uint8_t('A') + 10;
   66|    840|   const uint8_t c_lower = c - uint8_t('a') + 10;
   67|    840|   const uint8_t c_decim = c - uint8_t('0');
   68|       |
   69|    840|   uint8_t ret = 0xFF;  // default value
   70|       |
   71|    840|   ret = is_alpha_upper.select(c_upper, ret);
   72|    840|   ret = is_alpha_lower.select(c_lower, ret);
   73|    840|   ret = is_decimal.select(c_decim, ret);
   74|    840|   ret = is_whitespace.select(0x80, ret);
   75|       |
   76|    840|   return ret;
   77|    840|}

_ZN5Botan12HashFunction6createENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEES5_:
  107|      1|std::unique_ptr<HashFunction> HashFunction::create(std::string_view algo_spec, std::string_view provider) {
  108|       |#if defined(BOTAN_HAS_COMMONCRYPTO)
  109|       |   if(provider.empty() || provider == "commoncrypto") {
  110|       |      if(auto hash = make_commoncrypto_hash(algo_spec))
  111|       |         return hash;
  112|       |
  113|       |      if(!provider.empty())
  114|       |         return nullptr;
  115|       |   }
  116|       |#endif
  117|       |
  118|      1|   if(provider.empty() == false && provider != "base") {
  ------------------
  |  Branch (118:7): [True: 0, False: 1]
  |  Branch (118:36): [True: 0, False: 0]
  ------------------
  119|      0|      return nullptr;  // unknown provider
  120|      0|   }
  121|       |
  122|      1|#if defined(BOTAN_HAS_SHA1)
  123|      1|   if(algo_spec == "SHA-1") {
  ------------------
  |  Branch (123:7): [True: 0, False: 1]
  ------------------
  124|      0|      return std::make_unique<SHA_1>();
  125|      0|   }
  126|      1|#endif
  127|       |
  128|      1|#if defined(BOTAN_HAS_SHA2_32)
  129|      1|   if(algo_spec == "SHA-224") {
  ------------------
  |  Branch (129:7): [True: 0, False: 1]
  ------------------
  130|      0|      return std::make_unique<SHA_224>();
  131|      0|   }
  132|       |
  133|      1|   if(algo_spec == "SHA-256") {
  ------------------
  |  Branch (133:7): [True: 1, False: 0]
  ------------------
  134|      1|      return std::make_unique<SHA_256>();
  135|      1|   }
  136|      0|#endif
  137|       |
  138|      0|#if defined(BOTAN_HAS_SHA2_64)
  139|      0|   if(algo_spec == "SHA-384") {
  ------------------
  |  Branch (139:7): [True: 0, False: 0]
  ------------------
  140|      0|      return std::make_unique<SHA_384>();
  141|      0|   }
  142|       |
  143|      0|   if(algo_spec == "SHA-512") {
  ------------------
  |  Branch (143:7): [True: 0, False: 0]
  ------------------
  144|      0|      return std::make_unique<SHA_512>();
  145|      0|   }
  146|       |
  147|      0|   if(algo_spec == "SHA-512-256") {
  ------------------
  |  Branch (147:7): [True: 0, False: 0]
  ------------------
  148|      0|      return std::make_unique<SHA_512_256>();
  149|      0|   }
  150|      0|#endif
  151|       |
  152|      0|#if defined(BOTAN_HAS_RIPEMD_160)
  153|      0|   if(algo_spec == "RIPEMD-160") {
  ------------------
  |  Branch (153:7): [True: 0, False: 0]
  ------------------
  154|      0|      return std::make_unique<RIPEMD_160>();
  155|      0|   }
  156|      0|#endif
  157|       |
  158|      0|#if defined(BOTAN_HAS_WHIRLPOOL)
  159|      0|   if(algo_spec == "Whirlpool") {
  ------------------
  |  Branch (159:7): [True: 0, False: 0]
  ------------------
  160|      0|      return std::make_unique<Whirlpool>();
  161|      0|   }
  162|      0|#endif
  163|       |
  164|      0|#if defined(BOTAN_HAS_MD5)
  165|      0|   if(algo_spec == "MD5") {
  ------------------
  |  Branch (165:7): [True: 0, False: 0]
  ------------------
  166|      0|      return std::make_unique<MD5>();
  167|      0|   }
  168|      0|#endif
  169|       |
  170|      0|#if defined(BOTAN_HAS_MD4)
  171|      0|   if(algo_spec == "MD4") {
  ------------------
  |  Branch (171:7): [True: 0, False: 0]
  ------------------
  172|      0|      return std::make_unique<MD4>();
  173|      0|   }
  174|      0|#endif
  175|       |
  176|      0|#if defined(BOTAN_HAS_GOST_34_11)
  177|      0|   if(algo_spec == "GOST-R-34.11-94" || algo_spec == "GOST-34.11") {
  ------------------
  |  Branch (177:7): [True: 0, False: 0]
  |  Branch (177:41): [True: 0, False: 0]
  ------------------
  178|      0|      return std::make_unique<GOST_34_11>();
  179|      0|   }
  180|      0|#endif
  181|       |
  182|      0|#if defined(BOTAN_HAS_ADLER32)
  183|      0|   if(algo_spec == "Adler32") {
  ------------------
  |  Branch (183:7): [True: 0, False: 0]
  ------------------
  184|      0|      return std::make_unique<Adler32>();
  185|      0|   }
  186|      0|#endif
  187|       |
  188|      0|#if defined(BOTAN_HAS_CRC24)
  189|      0|   if(algo_spec == "CRC24") {
  ------------------
  |  Branch (189:7): [True: 0, False: 0]
  ------------------
  190|      0|      return std::make_unique<CRC24>();
  191|      0|   }
  192|      0|#endif
  193|       |
  194|      0|#if defined(BOTAN_HAS_CRC32)
  195|      0|   if(algo_spec == "CRC32") {
  ------------------
  |  Branch (195:7): [True: 0, False: 0]
  ------------------
  196|      0|      return std::make_unique<CRC32>();
  197|      0|   }
  198|      0|#endif
  199|       |
  200|      0|#if defined(BOTAN_HAS_STREEBOG)
  201|      0|   if(algo_spec == "Streebog-256") {
  ------------------
  |  Branch (201:7): [True: 0, False: 0]
  ------------------
  202|      0|      return std::make_unique<Streebog>(256);
  203|      0|   }
  204|      0|   if(algo_spec == "Streebog-512") {
  ------------------
  |  Branch (204:7): [True: 0, False: 0]
  ------------------
  205|      0|      return std::make_unique<Streebog>(512);
  206|      0|   }
  207|      0|#endif
  208|       |
  209|      0|#if defined(BOTAN_HAS_SM3)
  210|      0|   if(algo_spec == "SM3") {
  ------------------
  |  Branch (210:7): [True: 0, False: 0]
  ------------------
  211|      0|      return std::make_unique<SM3>();
  212|      0|   }
  213|      0|#endif
  214|       |
  215|      0|   const SCAN_Name req(algo_spec);
  216|       |
  217|      0|#if defined(BOTAN_HAS_SKEIN_512)
  218|      0|   if(req.algo_name() == "Skein-512") {
  ------------------
  |  Branch (218:7): [True: 0, False: 0]
  ------------------
  219|      0|      return std::make_unique<Skein_512>(req.arg_as_integer(0, 512), req.arg(1, ""));
  220|      0|   }
  221|      0|#endif
  222|       |
  223|      0|#if defined(BOTAN_HAS_BLAKE2B)
  224|      0|   if(req.algo_name() == "Blake2b" || req.algo_name() == "BLAKE2b") {
  ------------------
  |  Branch (224:7): [True: 0, False: 0]
  |  Branch (224:39): [True: 0, False: 0]
  ------------------
  225|      0|      return std::make_unique<BLAKE2b>(req.arg_as_integer(0, 512));
  226|      0|   }
  227|      0|#endif
  228|       |
  229|      0|#if defined(BOTAN_HAS_BLAKE2S)
  230|      0|   if(req.algo_name() == "Blake2s" || req.algo_name() == "BLAKE2s") {
  ------------------
  |  Branch (230:7): [True: 0, False: 0]
  |  Branch (230:39): [True: 0, False: 0]
  ------------------
  231|      0|      return std::make_unique<BLAKE2s>(req.arg_as_integer(0, 256));
  232|      0|   }
  233|      0|#endif
  234|       |
  235|      0|#if defined(BOTAN_HAS_KECCAK)
  236|      0|   if(req.algo_name() == "Keccak-1600") {
  ------------------
  |  Branch (236:7): [True: 0, False: 0]
  ------------------
  237|      0|      return std::make_unique<Keccak_1600>(req.arg_as_integer(0, 512));
  238|      0|   }
  239|      0|#endif
  240|       |
  241|      0|#if defined(BOTAN_HAS_SHA3)
  242|      0|   if(req.algo_name() == "SHA-3") {
  ------------------
  |  Branch (242:7): [True: 0, False: 0]
  ------------------
  243|      0|      return std::make_unique<SHA_3>(req.arg_as_integer(0, 512));
  244|      0|   }
  245|      0|#endif
  246|       |
  247|      0|#if defined(BOTAN_HAS_SHAKE)
  248|      0|   if(req.algo_name() == "SHAKE-128" && req.arg_count() == 1) {
  ------------------
  |  Branch (248:7): [True: 0, False: 0]
  |  Branch (248:41): [True: 0, False: 0]
  ------------------
  249|      0|      return std::make_unique<SHAKE_128>(req.arg_as_integer(0));
  250|      0|   }
  251|      0|   if(req.algo_name() == "SHAKE-256" && req.arg_count() == 1) {
  ------------------
  |  Branch (251:7): [True: 0, False: 0]
  |  Branch (251:41): [True: 0, False: 0]
  ------------------
  252|      0|      return std::make_unique<SHAKE_256>(req.arg_as_integer(0));
  253|      0|   }
  254|      0|#endif
  255|       |
  256|      0|#if defined(BOTAN_HAS_PARALLEL_HASH)
  257|      0|   if(req.algo_name() == "Parallel") {
  ------------------
  |  Branch (257:7): [True: 0, False: 0]
  ------------------
  258|      0|      std::vector<std::unique_ptr<HashFunction>> hashes;
  259|       |
  260|      0|      for(size_t i = 0; i != req.arg_count(); ++i) {
  ------------------
  |  Branch (260:25): [True: 0, False: 0]
  ------------------
  261|      0|         auto h = HashFunction::create(req.arg(i));
  262|      0|         if(!h) {
  ------------------
  |  Branch (262:13): [True: 0, False: 0]
  ------------------
  263|      0|            return nullptr;
  264|      0|         }
  265|      0|         hashes.push_back(std::move(h));
  266|      0|      }
  267|       |
  268|      0|      return std::make_unique<Parallel>(hashes);
  269|      0|   }
  270|      0|#endif
  271|       |
  272|      0|#if defined(BOTAN_HAS_TRUNCATED_HASH)
  273|      0|   if(req.algo_name() == "Truncated" && req.arg_count() == 2) {
  ------------------
  |  Branch (273:7): [True: 0, False: 0]
  |  Branch (273:41): [True: 0, False: 0]
  ------------------
  274|      0|      auto hash = HashFunction::create(req.arg(0));
  275|      0|      if(!hash) {
  ------------------
  |  Branch (275:10): [True: 0, False: 0]
  ------------------
  276|      0|         return nullptr;
  277|      0|      }
  278|       |
  279|      0|      return std::make_unique<Truncated_Hash>(std::move(hash), req.arg_as_integer(1));
  280|      0|   }
  281|      0|#endif
  282|       |
  283|      0|#if defined(BOTAN_HAS_COMB4P)
  284|      0|   if(req.algo_name() == "Comb4P" && req.arg_count() == 2) {
  ------------------
  |  Branch (284:7): [True: 0, False: 0]
  |  Branch (284:38): [True: 0, False: 0]
  ------------------
  285|      0|      auto h1 = HashFunction::create(req.arg(0));
  286|      0|      auto h2 = HashFunction::create(req.arg(1));
  287|       |
  288|      0|      if(h1 && h2) {
  ------------------
  |  Branch (288:10): [True: 0, False: 0]
  |  Branch (288:16): [True: 0, False: 0]
  ------------------
  289|      0|         return std::make_unique<Comb4P>(std::move(h1), std::move(h2));
  290|      0|      }
  291|      0|   }
  292|      0|#endif
  293|       |
  294|      0|   return nullptr;
  295|      0|}

_ZN5Botan7SHA_25615compress_digestERNSt3__16vectorIjNS_16secure_allocatorIjEEEENS1_4spanIKhLm18446744073709551615EEEm:
   49|     10|void SHA_256::compress_digest(digest_type& digest, std::span<const uint8_t> input, size_t blocks) {
   50|     10|#if defined(BOTAN_HAS_SHA2_32_X86)
   51|     10|   if(CPUID::has_intel_sha()) {
  ------------------
  |  Branch (51:7): [True: 0, False: 10]
  ------------------
   52|      0|      return SHA_256::compress_digest_x86(digest, input, blocks);
   53|      0|   }
   54|     10|#endif
   55|       |
   56|     10|#if defined(BOTAN_HAS_SHA2_32_X86_BMI2)
   57|     10|   if(CPUID::has_bmi2()) {
  ------------------
  |  Branch (57:7): [True: 10, False: 0]
  ------------------
   58|     10|      return SHA_256::compress_digest_x86_bmi2(digest, input, blocks);
   59|     10|   }
   60|      0|#endif
   61|       |
   62|       |#if defined(BOTAN_HAS_SHA2_32_ARMV8)
   63|       |   if(CPUID::has_arm_sha2()) {
   64|       |      return SHA_256::compress_digest_armv8(digest, input, blocks);
   65|       |   }
   66|       |#endif
   67|       |
   68|      0|   uint32_t A = digest[0], B = digest[1], C = digest[2], D = digest[3], E = digest[4], F = digest[5], G = digest[6],
   69|      0|            H = digest[7];
   70|       |
   71|      0|   BufferSlicer in(input);
   72|       |
   73|      0|   for(size_t i = 0; i != blocks; ++i) {
  ------------------
  |  Branch (73:22): [True: 0, False: 0]
  ------------------
   74|      0|      const auto block = in.take(block_bytes);
   75|       |
   76|      0|      uint32_t W00 = load_be<uint32_t>(block.data(), 0);
   77|      0|      uint32_t W01 = load_be<uint32_t>(block.data(), 1);
   78|      0|      uint32_t W02 = load_be<uint32_t>(block.data(), 2);
   79|      0|      uint32_t W03 = load_be<uint32_t>(block.data(), 3);
   80|      0|      uint32_t W04 = load_be<uint32_t>(block.data(), 4);
   81|      0|      uint32_t W05 = load_be<uint32_t>(block.data(), 5);
   82|      0|      uint32_t W06 = load_be<uint32_t>(block.data(), 6);
   83|      0|      uint32_t W07 = load_be<uint32_t>(block.data(), 7);
   84|      0|      uint32_t W08 = load_be<uint32_t>(block.data(), 8);
   85|      0|      uint32_t W09 = load_be<uint32_t>(block.data(), 9);
   86|      0|      uint32_t W10 = load_be<uint32_t>(block.data(), 10);
   87|      0|      uint32_t W11 = load_be<uint32_t>(block.data(), 11);
   88|      0|      uint32_t W12 = load_be<uint32_t>(block.data(), 12);
   89|      0|      uint32_t W13 = load_be<uint32_t>(block.data(), 13);
   90|      0|      uint32_t W14 = load_be<uint32_t>(block.data(), 14);
   91|      0|      uint32_t W15 = load_be<uint32_t>(block.data(), 15);
   92|       |
   93|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W00, W14, W09, W01, 0x428A2F98);
   94|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W01, W15, W10, W02, 0x71374491);
   95|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W02, W00, W11, W03, 0xB5C0FBCF);
   96|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W03, W01, W12, W04, 0xE9B5DBA5);
   97|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W04, W02, W13, W05, 0x3956C25B);
   98|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W05, W03, W14, W06, 0x59F111F1);
   99|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W06, W04, W15, W07, 0x923F82A4);
  100|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W07, W05, W00, W08, 0xAB1C5ED5);
  101|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W08, W06, W01, W09, 0xD807AA98);
  102|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W09, W07, W02, W10, 0x12835B01);
  103|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W10, W08, W03, W11, 0x243185BE);
  104|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W11, W09, W04, W12, 0x550C7DC3);
  105|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W12, W10, W05, W13, 0x72BE5D74);
  106|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W13, W11, W06, W14, 0x80DEB1FE);
  107|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W14, W12, W07, W15, 0x9BDC06A7);
  108|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W15, W13, W08, W00, 0xC19BF174);
  109|       |
  110|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W00, W14, W09, W01, 0xE49B69C1);
  111|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W01, W15, W10, W02, 0xEFBE4786);
  112|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W02, W00, W11, W03, 0x0FC19DC6);
  113|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W03, W01, W12, W04, 0x240CA1CC);
  114|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W04, W02, W13, W05, 0x2DE92C6F);
  115|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W05, W03, W14, W06, 0x4A7484AA);
  116|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W06, W04, W15, W07, 0x5CB0A9DC);
  117|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W07, W05, W00, W08, 0x76F988DA);
  118|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W08, W06, W01, W09, 0x983E5152);
  119|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W09, W07, W02, W10, 0xA831C66D);
  120|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W10, W08, W03, W11, 0xB00327C8);
  121|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W11, W09, W04, W12, 0xBF597FC7);
  122|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W12, W10, W05, W13, 0xC6E00BF3);
  123|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W13, W11, W06, W14, 0xD5A79147);
  124|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W14, W12, W07, W15, 0x06CA6351);
  125|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W15, W13, W08, W00, 0x14292967);
  126|       |
  127|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W00, W14, W09, W01, 0x27B70A85);
  128|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W01, W15, W10, W02, 0x2E1B2138);
  129|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W02, W00, W11, W03, 0x4D2C6DFC);
  130|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W03, W01, W12, W04, 0x53380D13);
  131|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W04, W02, W13, W05, 0x650A7354);
  132|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W05, W03, W14, W06, 0x766A0ABB);
  133|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W06, W04, W15, W07, 0x81C2C92E);
  134|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W07, W05, W00, W08, 0x92722C85);
  135|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W08, W06, W01, W09, 0xA2BFE8A1);
  136|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W09, W07, W02, W10, 0xA81A664B);
  137|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W10, W08, W03, W11, 0xC24B8B70);
  138|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W11, W09, W04, W12, 0xC76C51A3);
  139|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W12, W10, W05, W13, 0xD192E819);
  140|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W13, W11, W06, W14, 0xD6990624);
  141|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W14, W12, W07, W15, 0xF40E3585);
  142|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W15, W13, W08, W00, 0x106AA070);
  143|       |
  144|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W00, W14, W09, W01, 0x19A4C116);
  145|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W01, W15, W10, W02, 0x1E376C08);
  146|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W02, W00, W11, W03, 0x2748774C);
  147|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W03, W01, W12, W04, 0x34B0BCB5);
  148|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W04, W02, W13, W05, 0x391C0CB3);
  149|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W05, W03, W14, W06, 0x4ED8AA4A);
  150|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W06, W04, W15, W07, 0x5B9CCA4F);
  151|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W07, W05, W00, W08, 0x682E6FF3);
  152|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W08, W06, W01, W09, 0x748F82EE);
  153|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W09, W07, W02, W10, 0x78A5636F);
  154|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W10, W08, W03, W11, 0x84C87814);
  155|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W11, W09, W04, W12, 0x8CC70208);
  156|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W12, W10, W05, W13, 0x90BEFFFA);
  157|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W13, W11, W06, W14, 0xA4506CEB);
  158|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W14, W12, W07, W15, 0xBEF9A3F7);
  159|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W15, W13, W08, W00, 0xC67178F2);
  160|       |
  161|      0|      A = (digest[0] += A);
  162|      0|      B = (digest[1] += B);
  163|      0|      C = (digest[2] += C);
  164|      0|      D = (digest[3] += D);
  165|      0|      E = (digest[4] += E);
  166|      0|      F = (digest[5] += F);
  167|      0|      G = (digest[6] += G);
  168|      0|      H = (digest[7] += H);
  169|      0|   }
  170|      0|}
_ZN5Botan7SHA_25610compress_nERNSt3__16vectorIjNS_16secure_allocatorIjEEEENS1_4spanIKhLm18446744073709551615EEEm:
  204|     10|void SHA_256::compress_n(digest_type& digest, std::span<const uint8_t> input, size_t blocks) {
  205|     10|   SHA_256::compress_digest(digest, input, blocks);
  206|     10|}
_ZN5Botan7SHA_2564initERNSt3__16vectorIjNS_16secure_allocatorIjEEEE:
  208|      7|void SHA_256::init(digest_type& digest) {
  209|      7|   digest.assign({0x6A09E667, 0xBB67AE85, 0x3C6EF372, 0xA54FF53A, 0x510E527F, 0x9B05688C, 0x1F83D9AB, 0x5BE0CD19});
  210|      7|}
_ZN5Botan7SHA_2568add_dataENSt3__14spanIKhLm18446744073709551615EEE:
  220|      9|void SHA_256::add_data(std::span<const uint8_t> input) {
  221|      9|   m_md.update(input);
  222|      9|}
_ZN5Botan7SHA_25612final_resultENSt3__14spanIhLm18446744073709551615EEE:
  224|      4|void SHA_256::final_result(std::span<uint8_t> output) {
  225|      4|   m_md.final(output);
  226|      4|}

_ZN5Botan7SHA_25624compress_digest_x86_bmi2ERNSt3__16vectorIjNS_16secure_allocatorIjEEEENS1_4spanIKhLm18446744073709551615EEEm:
   24|     10|void SHA_256::compress_digest_x86_bmi2(digest_type& digest, std::span<const uint8_t> input, size_t blocks) {
   25|     10|   uint32_t A = digest[0], B = digest[1], C = digest[2], D = digest[3], E = digest[4], F = digest[5], G = digest[6],
   26|     10|            H = digest[7];
   27|       |
   28|     10|   BufferSlicer in(input);
   29|       |
   30|     20|   for(size_t i = 0; i != blocks; ++i) {
  ------------------
  |  Branch (30:22): [True: 10, False: 10]
  ------------------
   31|     10|      const auto block = in.take(block_bytes);
   32|       |
   33|     10|      uint32_t W00 = load_be<uint32_t>(block.data(), 0);
   34|     10|      uint32_t W01 = load_be<uint32_t>(block.data(), 1);
   35|     10|      uint32_t W02 = load_be<uint32_t>(block.data(), 2);
   36|     10|      uint32_t W03 = load_be<uint32_t>(block.data(), 3);
   37|     10|      uint32_t W04 = load_be<uint32_t>(block.data(), 4);
   38|     10|      uint32_t W05 = load_be<uint32_t>(block.data(), 5);
   39|     10|      uint32_t W06 = load_be<uint32_t>(block.data(), 6);
   40|     10|      uint32_t W07 = load_be<uint32_t>(block.data(), 7);
   41|     10|      uint32_t W08 = load_be<uint32_t>(block.data(), 8);
   42|     10|      uint32_t W09 = load_be<uint32_t>(block.data(), 9);
   43|     10|      uint32_t W10 = load_be<uint32_t>(block.data(), 10);
   44|     10|      uint32_t W11 = load_be<uint32_t>(block.data(), 11);
   45|     10|      uint32_t W12 = load_be<uint32_t>(block.data(), 12);
   46|     10|      uint32_t W13 = load_be<uint32_t>(block.data(), 13);
   47|     10|      uint32_t W14 = load_be<uint32_t>(block.data(), 14);
   48|     10|      uint32_t W15 = load_be<uint32_t>(block.data(), 15);
   49|       |
   50|     10|      SHA2_32_F(A, B, C, D, E, F, G, H, W00, W14, W09, W01, 0x428A2F98);
   51|     10|      SHA2_32_F(H, A, B, C, D, E, F, G, W01, W15, W10, W02, 0x71374491);
   52|     10|      SHA2_32_F(G, H, A, B, C, D, E, F, W02, W00, W11, W03, 0xB5C0FBCF);
   53|     10|      SHA2_32_F(F, G, H, A, B, C, D, E, W03, W01, W12, W04, 0xE9B5DBA5);
   54|     10|      SHA2_32_F(E, F, G, H, A, B, C, D, W04, W02, W13, W05, 0x3956C25B);
   55|     10|      SHA2_32_F(D, E, F, G, H, A, B, C, W05, W03, W14, W06, 0x59F111F1);
   56|     10|      SHA2_32_F(C, D, E, F, G, H, A, B, W06, W04, W15, W07, 0x923F82A4);
   57|     10|      SHA2_32_F(B, C, D, E, F, G, H, A, W07, W05, W00, W08, 0xAB1C5ED5);
   58|     10|      SHA2_32_F(A, B, C, D, E, F, G, H, W08, W06, W01, W09, 0xD807AA98);
   59|     10|      SHA2_32_F(H, A, B, C, D, E, F, G, W09, W07, W02, W10, 0x12835B01);
   60|     10|      SHA2_32_F(G, H, A, B, C, D, E, F, W10, W08, W03, W11, 0x243185BE);
   61|     10|      SHA2_32_F(F, G, H, A, B, C, D, E, W11, W09, W04, W12, 0x550C7DC3);
   62|     10|      SHA2_32_F(E, F, G, H, A, B, C, D, W12, W10, W05, W13, 0x72BE5D74);
   63|     10|      SHA2_32_F(D, E, F, G, H, A, B, C, W13, W11, W06, W14, 0x80DEB1FE);
   64|     10|      SHA2_32_F(C, D, E, F, G, H, A, B, W14, W12, W07, W15, 0x9BDC06A7);
   65|     10|      SHA2_32_F(B, C, D, E, F, G, H, A, W15, W13, W08, W00, 0xC19BF174);
   66|       |
   67|     10|      SHA2_32_F(A, B, C, D, E, F, G, H, W00, W14, W09, W01, 0xE49B69C1);
   68|     10|      SHA2_32_F(H, A, B, C, D, E, F, G, W01, W15, W10, W02, 0xEFBE4786);
   69|     10|      SHA2_32_F(G, H, A, B, C, D, E, F, W02, W00, W11, W03, 0x0FC19DC6);
   70|     10|      SHA2_32_F(F, G, H, A, B, C, D, E, W03, W01, W12, W04, 0x240CA1CC);
   71|     10|      SHA2_32_F(E, F, G, H, A, B, C, D, W04, W02, W13, W05, 0x2DE92C6F);
   72|     10|      SHA2_32_F(D, E, F, G, H, A, B, C, W05, W03, W14, W06, 0x4A7484AA);
   73|     10|      SHA2_32_F(C, D, E, F, G, H, A, B, W06, W04, W15, W07, 0x5CB0A9DC);
   74|     10|      SHA2_32_F(B, C, D, E, F, G, H, A, W07, W05, W00, W08, 0x76F988DA);
   75|     10|      SHA2_32_F(A, B, C, D, E, F, G, H, W08, W06, W01, W09, 0x983E5152);
   76|     10|      SHA2_32_F(H, A, B, C, D, E, F, G, W09, W07, W02, W10, 0xA831C66D);
   77|     10|      SHA2_32_F(G, H, A, B, C, D, E, F, W10, W08, W03, W11, 0xB00327C8);
   78|     10|      SHA2_32_F(F, G, H, A, B, C, D, E, W11, W09, W04, W12, 0xBF597FC7);
   79|     10|      SHA2_32_F(E, F, G, H, A, B, C, D, W12, W10, W05, W13, 0xC6E00BF3);
   80|     10|      SHA2_32_F(D, E, F, G, H, A, B, C, W13, W11, W06, W14, 0xD5A79147);
   81|     10|      SHA2_32_F(C, D, E, F, G, H, A, B, W14, W12, W07, W15, 0x06CA6351);
   82|     10|      SHA2_32_F(B, C, D, E, F, G, H, A, W15, W13, W08, W00, 0x14292967);
   83|       |
   84|     10|      SHA2_32_F(A, B, C, D, E, F, G, H, W00, W14, W09, W01, 0x27B70A85);
   85|     10|      SHA2_32_F(H, A, B, C, D, E, F, G, W01, W15, W10, W02, 0x2E1B2138);
   86|     10|      SHA2_32_F(G, H, A, B, C, D, E, F, W02, W00, W11, W03, 0x4D2C6DFC);
   87|     10|      SHA2_32_F(F, G, H, A, B, C, D, E, W03, W01, W12, W04, 0x53380D13);
   88|     10|      SHA2_32_F(E, F, G, H, A, B, C, D, W04, W02, W13, W05, 0x650A7354);
   89|     10|      SHA2_32_F(D, E, F, G, H, A, B, C, W05, W03, W14, W06, 0x766A0ABB);
   90|     10|      SHA2_32_F(C, D, E, F, G, H, A, B, W06, W04, W15, W07, 0x81C2C92E);
   91|     10|      SHA2_32_F(B, C, D, E, F, G, H, A, W07, W05, W00, W08, 0x92722C85);
   92|     10|      SHA2_32_F(A, B, C, D, E, F, G, H, W08, W06, W01, W09, 0xA2BFE8A1);
   93|     10|      SHA2_32_F(H, A, B, C, D, E, F, G, W09, W07, W02, W10, 0xA81A664B);
   94|     10|      SHA2_32_F(G, H, A, B, C, D, E, F, W10, W08, W03, W11, 0xC24B8B70);
   95|     10|      SHA2_32_F(F, G, H, A, B, C, D, E, W11, W09, W04, W12, 0xC76C51A3);
   96|     10|      SHA2_32_F(E, F, G, H, A, B, C, D, W12, W10, W05, W13, 0xD192E819);
   97|     10|      SHA2_32_F(D, E, F, G, H, A, B, C, W13, W11, W06, W14, 0xD6990624);
   98|     10|      SHA2_32_F(C, D, E, F, G, H, A, B, W14, W12, W07, W15, 0xF40E3585);
   99|     10|      SHA2_32_F(B, C, D, E, F, G, H, A, W15, W13, W08, W00, 0x106AA070);
  100|       |
  101|     10|      SHA2_32_F(A, B, C, D, E, F, G, H, W00, W14, W09, W01, 0x19A4C116);
  102|     10|      SHA2_32_F(H, A, B, C, D, E, F, G, W01, W15, W10, W02, 0x1E376C08);
  103|     10|      SHA2_32_F(G, H, A, B, C, D, E, F, W02, W00, W11, W03, 0x2748774C);
  104|     10|      SHA2_32_F(F, G, H, A, B, C, D, E, W03, W01, W12, W04, 0x34B0BCB5);
  105|     10|      SHA2_32_F(E, F, G, H, A, B, C, D, W04, W02, W13, W05, 0x391C0CB3);
  106|     10|      SHA2_32_F(D, E, F, G, H, A, B, C, W05, W03, W14, W06, 0x4ED8AA4A);
  107|     10|      SHA2_32_F(C, D, E, F, G, H, A, B, W06, W04, W15, W07, 0x5B9CCA4F);
  108|     10|      SHA2_32_F(B, C, D, E, F, G, H, A, W07, W05, W00, W08, 0x682E6FF3);
  109|     10|      SHA2_32_F(A, B, C, D, E, F, G, H, W08, W06, W01, W09, 0x748F82EE);
  110|     10|      SHA2_32_F(H, A, B, C, D, E, F, G, W09, W07, W02, W10, 0x78A5636F);
  111|     10|      SHA2_32_F(G, H, A, B, C, D, E, F, W10, W08, W03, W11, 0x84C87814);
  112|     10|      SHA2_32_F(F, G, H, A, B, C, D, E, W11, W09, W04, W12, 0x8CC70208);
  113|     10|      SHA2_32_F(E, F, G, H, A, B, C, D, W12, W10, W05, W13, 0x90BEFFFA);
  114|     10|      SHA2_32_F(D, E, F, G, H, A, B, C, W13, W11, W06, W14, 0xA4506CEB);
  115|     10|      SHA2_32_F(C, D, E, F, G, H, A, B, W14, W12, W07, W15, 0xBEF9A3F7);
  116|     10|      SHA2_32_F(B, C, D, E, F, G, H, A, W15, W13, W08, W00, 0xC67178F2);
  117|       |
  118|     10|      A = (digest[0] += A);
  119|     10|      B = (digest[1] += B);
  120|     10|      C = (digest[2] += C);
  121|     10|      D = (digest[3] += D);
  122|     10|      E = (digest[4] += E);
  123|     10|      F = (digest[5] += F);
  124|     10|      G = (digest[6] += G);
  125|     10|      H = (digest[7] += H);
  126|     10|   }
  127|     10|}

_ZN5Botan4HMAC8add_dataENSt3__14spanIKhLm18446744073709551615EEE:
   19|      1|void HMAC::add_data(std::span<const uint8_t> input) {
   20|      1|   assert_key_material_set();
   21|      1|   m_hash->update(input);
   22|      1|}
_ZN5Botan4HMAC12final_resultENSt3__14spanIhLm18446744073709551615EEE:
   27|      2|void HMAC::final_result(std::span<uint8_t> mac) {
   28|      2|   assert_key_material_set();
   29|      2|   m_hash->final(mac);
   30|      2|   m_hash->update(m_okey);
   31|      2|   m_hash->update(mac.first(m_hash_output_length));
   32|      2|   m_hash->final(mac);
   33|      2|   m_hash->update(m_ikey);
   34|      2|}
_ZNK5Botan4HMAC8key_specEv:
   36|      2|Key_Length_Specification HMAC::key_spec() const {
   37|       |   // Support very long lengths for things like PBKDF2 and the TLS PRF
   38|      2|   return Key_Length_Specification(0, 4096);
   39|      2|}
_ZNK5Botan4HMAC13output_lengthEv:
   41|      4|size_t HMAC::output_length() const {
   42|      4|   return m_hash_output_length;
   43|      4|}
_ZNK5Botan4HMAC19has_keying_materialEv:
   45|      3|bool HMAC::has_keying_material() const {
   46|      3|   return !m_okey.empty();
   47|      3|}
_ZN5Botan4HMAC12key_scheduleENSt3__14spanIKhLm18446744073709551615EEE:
   52|      2|void HMAC::key_schedule(std::span<const uint8_t> key) {
   53|      2|   const uint8_t ipad = 0x36;
   54|      2|   const uint8_t opad = 0x5C;
   55|       |
   56|      2|   m_hash->clear();
   57|       |
   58|      2|   m_ikey.resize(m_hash_block_size);
   59|      2|   m_okey.resize(m_hash_block_size);
   60|       |
   61|      2|   clear_mem(m_ikey.data(), m_ikey.size());
   62|      2|   clear_mem(m_okey.data(), m_okey.size());
   63|       |
   64|       |   /*
   65|       |   * Sometimes the HMAC key length itself is sensitive, as with PBKDF2 where it
   66|       |   * reveals the length of the passphrase. Make some attempt to hide this to
   67|       |   * side channels. Clearly if the secret is longer than the block size then the
   68|       |   * branch to hash first reveals that. In addition, counting the number of
   69|       |   * compression functions executed reveals the size at the granularity of the
   70|       |   * hash function's block size.
   71|       |   *
   72|       |   * The greater concern is for smaller keys; being able to detect when a
   73|       |   * passphrase is say 4 bytes may assist choosing weaker targets. Even though
   74|       |   * the loop bounds are constant, we can only actually read key[0..length] so
   75|       |   * it doesn't seem possible to make this computation truly constant time.
   76|       |   *
   77|       |   * We don't mind leaking if the length is exactly zero since that's
   78|       |   * trivial to simply check.
   79|       |   */
   80|       |
   81|      2|   if(key.size() > m_hash_block_size) {
  ------------------
  |  Branch (81:7): [True: 0, False: 2]
  ------------------
   82|      0|      m_hash->update(key);
   83|      0|      m_hash->final(m_ikey.data());
   84|      2|   } else if(!key.empty()) {
  ------------------
  |  Branch (84:14): [True: 2, False: 0]
  ------------------
   85|    130|      for(size_t i = 0, i_mod_length = 0; i != m_hash_block_size; ++i) {
  ------------------
  |  Branch (85:43): [True: 128, False: 2]
  ------------------
   86|       |         /*
   87|       |         access key[i % length] but avoiding division due to variable
   88|       |         time computation on some processors.
   89|       |         */
   90|    128|         auto needs_reduction = CT::Mask<size_t>::is_lte(key.size(), i_mod_length);
   91|    128|         i_mod_length = needs_reduction.select(0, i_mod_length);
   92|    128|         const uint8_t kb = key[i_mod_length];
   93|       |
   94|    128|         auto in_range = CT::Mask<size_t>::is_lt(i, key.size());
   95|    128|         m_ikey[i] = static_cast<uint8_t>(in_range.if_set_return(kb));
   96|    128|         i_mod_length += 1;
   97|    128|      }
   98|      2|   }
   99|       |
  100|    130|   for(size_t i = 0; i != m_hash_block_size; ++i) {
  ------------------
  |  Branch (100:22): [True: 128, False: 2]
  ------------------
  101|    128|      m_ikey[i] ^= ipad;
  102|    128|      m_okey[i] = m_ikey[i] ^ ipad ^ opad;
  103|    128|   }
  104|       |
  105|      2|   m_hash->update(m_ikey);
  106|      2|}
_ZN5Botan4HMACC2ENSt3__110unique_ptrINS_12HashFunctionENS1_14default_deleteIS3_EEEE:
  137|      1|      m_hash_block_size(m_hash->hash_block_size()) {
  138|      1|   BOTAN_ARG_CHECK(m_hash_block_size >= m_hash_output_length, "HMAC is not compatible with this hash function");
  ------------------
  |  |   30|      1|   do {                                                          \
  |  |   31|      1|      if(!(expr))                                                \
  |  |  ------------------
  |  |  |  Branch (31:10): [True: 0, False: 1]
  |  |  ------------------
  |  |   32|      1|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   33|      1|   } while(0)
  |  |  ------------------
  |  |  |  Branch (33:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  139|      1|}

_ZN5Botan25MessageAuthenticationCode6createENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEES5_:
   52|      1|                                                                             std::string_view provider) {
   53|      1|   const SCAN_Name req(algo_spec);
   54|       |
   55|      1|#if defined(BOTAN_HAS_BLAKE2BMAC)
   56|      1|   if(req.algo_name() == "Blake2b" || req.algo_name() == "BLAKE2b") {
  ------------------
  |  Branch (56:7): [True: 0, False: 1]
  |  Branch (56:39): [True: 0, False: 1]
  ------------------
   57|      0|      return std::make_unique<BLAKE2bMAC>(req.arg_as_integer(0, 512));
   58|      0|   }
   59|      1|#endif
   60|       |
   61|      1|#if defined(BOTAN_HAS_GMAC)
   62|      1|   if(req.algo_name() == "GMAC" && req.arg_count() == 1) {
  ------------------
  |  Branch (62:7): [True: 0, False: 1]
  |  Branch (62:36): [True: 0, False: 0]
  ------------------
   63|      0|      if(provider.empty() || provider == "base") {
  ------------------
  |  Branch (63:10): [True: 0, False: 0]
  |  Branch (63:30): [True: 0, False: 0]
  ------------------
   64|      0|         if(auto bc = BlockCipher::create(req.arg(0))) {
  ------------------
  |  Branch (64:18): [True: 0, False: 0]
  ------------------
   65|      0|            return std::make_unique<GMAC>(std::move(bc));
   66|      0|         }
   67|      0|      }
   68|      0|   }
   69|      1|#endif
   70|       |
   71|      1|#if defined(BOTAN_HAS_HMAC)
   72|      1|   if(req.algo_name() == "HMAC" && req.arg_count() == 1) {
  ------------------
  |  Branch (72:7): [True: 1, False: 0]
  |  Branch (72:36): [True: 1, False: 0]
  ------------------
   73|      1|      if(provider.empty() || provider == "base") {
  ------------------
  |  Branch (73:10): [True: 1, False: 0]
  |  Branch (73:30): [True: 0, False: 0]
  ------------------
   74|      1|         if(auto hash = HashFunction::create(req.arg(0))) {
  ------------------
  |  Branch (74:18): [True: 1, False: 0]
  ------------------
   75|      1|            return std::make_unique<HMAC>(std::move(hash));
   76|      1|         }
   77|      1|      }
   78|      1|   }
   79|      0|#endif
   80|       |
   81|      0|#if defined(BOTAN_HAS_POLY1305)
   82|      0|   if(req.algo_name() == "Poly1305" && req.arg_count() == 0) {
  ------------------
  |  Branch (82:7): [True: 0, False: 0]
  |  Branch (82:40): [True: 0, False: 0]
  ------------------
   83|      0|      if(provider.empty() || provider == "base") {
  ------------------
  |  Branch (83:10): [True: 0, False: 0]
  |  Branch (83:30): [True: 0, False: 0]
  ------------------
   84|      0|         return std::make_unique<Poly1305>();
   85|      0|      }
   86|      0|   }
   87|      0|#endif
   88|       |
   89|      0|#if defined(BOTAN_HAS_SIPHASH)
   90|      0|   if(req.algo_name() == "SipHash") {
  ------------------
  |  Branch (90:7): [True: 0, False: 0]
  ------------------
   91|      0|      if(provider.empty() || provider == "base") {
  ------------------
  |  Branch (91:10): [True: 0, False: 0]
  |  Branch (91:30): [True: 0, False: 0]
  ------------------
   92|      0|         return std::make_unique<SipHash>(req.arg_as_integer(0, 2), req.arg_as_integer(1, 4));
   93|      0|      }
   94|      0|   }
   95|      0|#endif
   96|       |
   97|      0|#if defined(BOTAN_HAS_CMAC)
   98|      0|   if((req.algo_name() == "CMAC" || req.algo_name() == "OMAC") && req.arg_count() == 1) {
  ------------------
  |  Branch (98:8): [True: 0, False: 0]
  |  Branch (98:37): [True: 0, False: 0]
  |  Branch (98:67): [True: 0, False: 0]
  ------------------
   99|      0|      if(provider.empty() || provider == "base") {
  ------------------
  |  Branch (99:10): [True: 0, False: 0]
  |  Branch (99:30): [True: 0, False: 0]
  ------------------
  100|      0|         if(auto bc = BlockCipher::create(req.arg(0))) {
  ------------------
  |  Branch (100:18): [True: 0, False: 0]
  ------------------
  101|      0|            return std::make_unique<CMAC>(std::move(bc));
  102|      0|         }
  103|      0|      }
  104|      0|   }
  105|      0|#endif
  106|       |
  107|      0|#if defined(BOTAN_HAS_ANSI_X919_MAC)
  108|      0|   if(req.algo_name() == "X9.19-MAC") {
  ------------------
  |  Branch (108:7): [True: 0, False: 0]
  ------------------
  109|      0|      if(provider.empty() || provider == "base") {
  ------------------
  |  Branch (109:10): [True: 0, False: 0]
  |  Branch (109:30): [True: 0, False: 0]
  ------------------
  110|      0|         return std::make_unique<ANSI_X919_MAC>();
  111|      0|      }
  112|      0|   }
  113|      0|#endif
  114|       |
  115|      0|#if defined(BOTAN_HAS_KMAC)
  116|      0|   if(req.algo_name() == "KMAC-128") {
  ------------------
  |  Branch (116:7): [True: 0, False: 0]
  ------------------
  117|      0|      if(provider.empty() || provider == "base") {
  ------------------
  |  Branch (117:10): [True: 0, False: 0]
  |  Branch (117:30): [True: 0, False: 0]
  ------------------
  118|      0|         if(req.arg_count() != 1) {
  ------------------
  |  Branch (118:13): [True: 0, False: 0]
  ------------------
  119|      0|            throw Invalid_Argument(
  120|      0|               "invalid algorithm specification for KMAC-128: need exactly one argument for output bit length");
  121|      0|         }
  122|      0|         return std::make_unique<KMAC128>(req.arg_as_integer(0));
  123|      0|      }
  124|      0|   }
  125|       |
  126|      0|   if(req.algo_name() == "KMAC-256") {
  ------------------
  |  Branch (126:7): [True: 0, False: 0]
  ------------------
  127|      0|      if(provider.empty() || provider == "base") {
  ------------------
  |  Branch (127:10): [True: 0, False: 0]
  |  Branch (127:30): [True: 0, False: 0]
  ------------------
  128|      0|         if(req.arg_count() != 1) {
  ------------------
  |  Branch (128:13): [True: 0, False: 0]
  ------------------
  129|      0|            throw Invalid_Argument(
  130|      0|               "invalid algorithm specification for KMAC-256: need exactly one argument for output bit length");
  131|      0|         }
  132|      0|         return std::make_unique<KMAC256>(req.arg_as_integer(0));
  133|      0|      }
  134|      0|   }
  135|      0|#endif
  136|       |
  137|      0|   BOTAN_UNUSED(req);
  ------------------
  |  |  118|      0|#define BOTAN_UNUSED Botan::ignore_params
  ------------------
  138|      0|   BOTAN_UNUSED(provider);
  ------------------
  |  |  118|      0|#define BOTAN_UNUSED Botan::ignore_params
  ------------------
  139|       |
  140|      0|   return nullptr;
  141|      0|}
_ZN5Botan25MessageAuthenticationCode15create_or_throwENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEES5_:
  149|      1|                                                                                      std::string_view provider) {
  150|      1|   if(auto mac = MessageAuthenticationCode::create(algo, provider)) {
  ------------------
  |  Branch (150:12): [True: 1, False: 0]
  ------------------
  151|      1|      return mac;
  152|      1|   }
  153|      0|   throw Lookup_Error("MAC", algo, provider);
  154|      1|}

_ZN5Botan6BigInt6decodeEPKhmNS0_4BaseE:
  151|     10|BigInt BigInt::decode(const uint8_t buf[], size_t length, Base base) {
  152|     10|   BigInt r;
  153|     10|   if(base == Binary) {
  ------------------
  |  Branch (153:7): [True: 0, False: 10]
  ------------------
  154|      0|      r.binary_decode(buf, length);
  155|     10|   } else if(base == Hexadecimal) {
  ------------------
  |  Branch (155:14): [True: 10, False: 0]
  ------------------
  156|     10|      secure_vector<uint8_t> binary;
  157|       |
  158|     10|      if(length % 2) {
  ------------------
  |  Branch (158:10): [True: 0, False: 10]
  ------------------
  159|       |         // Handle lack of leading 0
  160|      0|         const char buf0_with_leading_0[2] = {'0', static_cast<char>(buf[0])};
  161|       |
  162|      0|         binary = hex_decode_locked(buf0_with_leading_0, 2);
  163|       |
  164|      0|         binary += hex_decode_locked(cast_uint8_ptr_to_char(&buf[1]), length - 1, false);
  165|     10|      } else {
  166|     10|         binary = hex_decode_locked(cast_uint8_ptr_to_char(buf), length, false);
  167|     10|      }
  168|       |
  169|     10|      r.binary_decode(binary.data(), binary.size());
  170|     10|   } else if(base == Decimal) {
  ------------------
  |  Branch (170:14): [True: 0, False: 0]
  ------------------
  171|       |      // This could be made faster using the same trick as to_dec_string
  172|      0|      for(size_t i = 0; i != length; ++i) {
  ------------------
  |  Branch (172:25): [True: 0, False: 0]
  ------------------
  173|      0|         const char c = buf[i];
  174|       |
  175|      0|         if(c < '0' || c > '9') {
  ------------------
  |  Branch (175:13): [True: 0, False: 0]
  |  Branch (175:24): [True: 0, False: 0]
  ------------------
  176|      0|            throw Invalid_Argument("BigInt::decode: invalid decimal char");
  177|      0|         }
  178|       |
  179|      0|         const uint8_t x = c - '0';
  180|      0|         BOTAN_ASSERT_NOMSG(x < 10);
  ------------------
  |  |   60|      0|   do {                                                                     \
  |  |   61|      0|      if(!(expr))                                                           \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 0]
  |  |  ------------------
  |  |   62|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   63|      0|   } while(0)
  |  |  ------------------
  |  |  |  Branch (63:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  181|       |
  182|      0|         r *= 10;
  183|      0|         r += x;
  184|      0|      }
  185|      0|   } else {
  186|      0|      throw Invalid_Argument("Unknown BigInt decoding method");
  187|      0|   }
  188|     10|   return r;
  189|     10|}

_ZN5Botan6BigInt3addEPKmmNS0_4SignE:
   16|   266k|BigInt& BigInt::add(const word y[], size_t y_words, Sign y_sign) {
   17|   266k|   const size_t x_sw = sig_words();
   18|       |
   19|   266k|   grow_to(std::max(x_sw, y_words) + 1);
   20|       |
   21|   266k|   if(sign() == y_sign) {
  ------------------
  |  Branch (21:7): [True: 140k, False: 126k]
  ------------------
   22|   140k|      bigint_add2(mutable_data(), size() - 1, y, y_words);
   23|   140k|   } else {
   24|   126k|      const int32_t relative_size = bigint_cmp(data(), x_sw, y, y_words);
   25|       |
   26|   126k|      if(relative_size >= 0) {
  ------------------
  |  Branch (26:10): [True: 126k, False: 66]
  ------------------
   27|       |         // *this >= y
   28|   126k|         bigint_sub2(mutable_data(), x_sw, y, y_words);
   29|   126k|      } else {
   30|       |         // *this < y
   31|     66|         bigint_sub2_rev(mutable_data(), y, y_words);
   32|     66|      }
   33|       |
   34|       |      //this->sign_fixup(relative_size, y_sign);
   35|   126k|      if(relative_size < 0) {
  ------------------
  |  Branch (35:10): [True: 66, False: 126k]
  ------------------
   36|     66|         set_sign(y_sign);
   37|   126k|      } else if(relative_size == 0) {
  ------------------
  |  Branch (37:17): [True: 0, False: 126k]
  ------------------
   38|      0|         set_sign(Positive);
   39|      0|      }
   40|   126k|   }
   41|       |
   42|   266k|   return (*this);
   43|   266k|}
_ZN5Botan6BigInt7mod_addERKS0_S2_RNSt3__16vectorImNS_16secure_allocatorImEEEE:
   45|  3.09M|BigInt& BigInt::mod_add(const BigInt& s, const BigInt& mod, secure_vector<word>& ws) {
   46|  3.09M|   if(this->is_negative() || s.is_negative() || mod.is_negative()) {
  ------------------
  |  Branch (46:7): [True: 0, False: 3.09M]
  |  Branch (46:30): [True: 0, False: 3.09M]
  |  Branch (46:49): [True: 0, False: 3.09M]
  ------------------
   47|      0|      throw Invalid_Argument("BigInt::mod_add expects all arguments are positive");
   48|      0|   }
   49|       |
   50|  3.09M|   BOTAN_DEBUG_ASSERT(*this < mod);
  ------------------
  |  |   99|  3.09M|      do {                          \
  |  |  100|  3.09M|      } while(0)
  |  |  ------------------
  |  |  |  Branch (100:15): [Folded - Ignored]
  |  |  ------------------
  ------------------
   51|  3.09M|   BOTAN_DEBUG_ASSERT(s < mod);
  ------------------
  |  |   99|  3.09M|      do {                          \
  |  |  100|  3.09M|      } while(0)
  |  |  ------------------
  |  |  |  Branch (100:15): [Folded - Ignored]
  |  |  ------------------
  ------------------
   52|       |
   53|       |   /*
   54|       |   t + s or t + s - p == t - (p - s)
   55|       |
   56|       |   So first compute ws = p - s
   57|       |
   58|       |   Then compute t + s and t - ws
   59|       |
   60|       |   If t - ws does not borrow, then that is the correct valued
   61|       |   */
   62|       |
   63|  3.09M|   const size_t mod_sw = mod.sig_words();
   64|  3.09M|   BOTAN_ARG_CHECK(mod_sw > 0, "BigInt::mod_add modulus must be positive");
  ------------------
  |  |   30|  3.09M|   do {                                                          \
  |  |   31|  3.09M|      if(!(expr))                                                \
  |  |  ------------------
  |  |  |  Branch (31:10): [True: 0, False: 3.09M]
  |  |  ------------------
  |  |   32|  3.09M|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   33|  3.09M|   } while(0)
  |  |  ------------------
  |  |  |  Branch (33:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   65|       |
   66|  3.09M|   this->grow_to(mod_sw);
   67|  3.09M|   s.grow_to(mod_sw);
   68|       |
   69|       |   // First mod_sw for p - s, 2*mod_sw for bigint_addsub workspace
   70|  3.09M|   if(ws.size() < 3 * mod_sw) {
  ------------------
  |  Branch (70:7): [True: 2.33M, False: 758k]
  ------------------
   71|  2.33M|      ws.resize(3 * mod_sw);
   72|  2.33M|   }
   73|       |
   74|  3.09M|   word borrow = bigint_sub3(&ws[0], mod.data(), mod_sw, s.data(), mod_sw);
   75|  3.09M|   BOTAN_DEBUG_ASSERT(borrow == 0);
  ------------------
  |  |   99|  3.09M|      do {                          \
  |  |  100|  3.09M|      } while(0)
  |  |  ------------------
  |  |  |  Branch (100:15): [Folded - Ignored]
  |  |  ------------------
  ------------------
   76|  3.09M|   BOTAN_UNUSED(borrow);
  ------------------
  |  |  118|  3.09M|#define BOTAN_UNUSED Botan::ignore_params
  ------------------
   77|       |
   78|       |   // Compute t - ws
   79|  3.09M|   borrow = bigint_sub3(&ws[mod_sw], this->data(), mod_sw, &ws[0], mod_sw);
   80|       |
   81|       |   // Compute t + s
   82|  3.09M|   bigint_add3_nc(&ws[mod_sw * 2], this->data(), mod_sw, s.data(), mod_sw);
   83|       |
   84|  3.09M|   CT::conditional_copy_mem(borrow, &ws[0], &ws[mod_sw * 2], &ws[mod_sw], mod_sw);
   85|  3.09M|   set_words(&ws[0], mod_sw);
   86|       |
   87|  3.09M|   return (*this);
   88|  3.09M|}
_ZN5Botan6BigInt7mod_subERKS0_S2_RNSt3__16vectorImNS_16secure_allocatorImEEEE:
   90|  26.8M|BigInt& BigInt::mod_sub(const BigInt& s, const BigInt& mod, secure_vector<word>& ws) {
   91|  26.8M|   if(this->is_negative() || s.is_negative() || mod.is_negative()) {
  ------------------
  |  Branch (91:7): [True: 0, False: 26.8M]
  |  Branch (91:30): [True: 0, False: 26.8M]
  |  Branch (91:49): [True: 0, False: 26.8M]
  ------------------
   92|      0|      throw Invalid_Argument("BigInt::mod_sub expects all arguments are positive");
   93|      0|   }
   94|       |
   95|       |   // We are assuming in this function that *this and s are no more than mod_sw words long
   96|  26.8M|   BOTAN_DEBUG_ASSERT(*this < mod);
  ------------------
  |  |   99|  26.8M|      do {                          \
  |  |  100|  26.8M|      } while(0)
  |  |  ------------------
  |  |  |  Branch (100:15): [Folded - Ignored]
  |  |  ------------------
  ------------------
   97|  26.8M|   BOTAN_DEBUG_ASSERT(s < mod);
  ------------------
  |  |   99|  26.8M|      do {                          \
  |  |  100|  26.8M|      } while(0)
  |  |  ------------------
  |  |  |  Branch (100:15): [Folded - Ignored]
  |  |  ------------------
  ------------------
   98|       |
   99|  26.8M|   const size_t mod_sw = mod.sig_words();
  100|       |
  101|  26.8M|   this->grow_to(mod_sw);
  102|  26.8M|   s.grow_to(mod_sw);
  103|       |
  104|  26.8M|   if(ws.size() < mod_sw) {
  ------------------
  |  Branch (104:7): [True: 0, False: 26.8M]
  ------------------
  105|      0|      ws.resize(mod_sw);
  106|      0|   }
  107|       |
  108|  26.8M|   if(mod_sw == 4) {
  ------------------
  |  Branch (108:7): [True: 0, False: 26.8M]
  ------------------
  109|      0|      bigint_mod_sub_n<4>(mutable_data(), s.data(), mod.data(), ws.data());
  110|  26.8M|   } else if(mod_sw == 6) {
  ------------------
  |  Branch (110:14): [True: 26.8M, False: 0]
  ------------------
  111|  26.8M|      bigint_mod_sub_n<6>(mutable_data(), s.data(), mod.data(), ws.data());
  112|  26.8M|   } else {
  113|      0|      bigint_mod_sub(mutable_data(), s.data(), mod.data(), mod_sw, ws.data());
  114|      0|   }
  115|       |
  116|  26.8M|   return (*this);
  117|  26.8M|}
_ZN5Botan6BigInt7mod_mulEhRKS0_RNSt3__16vectorImNS_16secure_allocatorImEEEE:
  119|  12.3M|BigInt& BigInt::mod_mul(uint8_t y, const BigInt& mod, secure_vector<word>& ws) {
  120|  12.3M|   BOTAN_ARG_CHECK(this->is_negative() == false, "*this must be positive");
  ------------------
  |  |   30|  12.3M|   do {                                                          \
  |  |   31|  12.3M|      if(!(expr))                                                \
  |  |  ------------------
  |  |  |  Branch (31:10): [True: 0, False: 12.3M]
  |  |  ------------------
  |  |   32|  12.3M|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   33|  12.3M|   } while(0)
  |  |  ------------------
  |  |  |  Branch (33:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  121|  12.3M|   BOTAN_ARG_CHECK(y < 16, "y too large");
  ------------------
  |  |   30|  12.3M|   do {                                                          \
  |  |   31|  12.3M|      if(!(expr))                                                \
  |  |  ------------------
  |  |  |  Branch (31:10): [True: 0, False: 12.3M]
  |  |  ------------------
  |  |   32|  12.3M|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   33|  12.3M|   } while(0)
  |  |  ------------------
  |  |  |  Branch (33:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  122|       |
  123|  12.3M|   BOTAN_DEBUG_ASSERT(*this < mod);
  ------------------
  |  |   99|  12.3M|      do {                          \
  |  |  100|  12.3M|      } while(0)
  |  |  ------------------
  |  |  |  Branch (100:15): [Folded - Ignored]
  |  |  ------------------
  ------------------
  124|       |
  125|  12.3M|   *this *= static_cast<word>(y);
  126|  12.3M|   this->reduce_below(mod, ws);
  127|  12.3M|   return (*this);
  128|  12.3M|}
_ZN5Botan6BigInt7rev_subEPKmmRNSt3__16vectorImNS_16secure_allocatorImEEEE:
  130|  6.59k|BigInt& BigInt::rev_sub(const word y[], size_t y_sw, secure_vector<word>& ws) {
  131|  6.59k|   if(this->sign() != BigInt::Positive) {
  ------------------
  |  Branch (131:7): [True: 0, False: 6.59k]
  ------------------
  132|      0|      throw Invalid_State("BigInt::sub_rev requires this is positive");
  133|      0|   }
  134|       |
  135|  6.59k|   const size_t x_sw = this->sig_words();
  136|       |
  137|  6.59k|   ws.resize(std::max(x_sw, y_sw));
  138|  6.59k|   clear_mem(ws.data(), ws.size());
  139|       |
  140|  6.59k|   const int32_t relative_size = bigint_sub_abs(ws.data(), data(), x_sw, y, y_sw);
  141|       |
  142|  6.59k|   this->cond_flip_sign(relative_size > 0);
  143|  6.59k|   this->swap_reg(ws);
  144|       |
  145|  6.59k|   return (*this);
  146|  6.59k|}
_ZN5Botan6BigInt3mulERKS0_RNSt3__16vectorImNS_16secure_allocatorImEEEE:
  156|  13.1k|BigInt& BigInt::mul(const BigInt& y, secure_vector<word>& ws) {
  157|  13.1k|   const size_t x_sw = sig_words();
  158|  13.1k|   const size_t y_sw = y.sig_words();
  159|  13.1k|   set_sign((sign() == y.sign()) ? Positive : Negative);
  ------------------
  |  Branch (159:13): [True: 13.1k, False: 0]
  ------------------
  160|       |
  161|  13.1k|   if(x_sw == 0 || y_sw == 0) {
  ------------------
  |  Branch (161:7): [True: 9.75k, False: 3.44k]
  |  Branch (161:20): [True: 0, False: 3.44k]
  ------------------
  162|  9.75k|      clear();
  163|  9.75k|      set_sign(Positive);
  164|  9.75k|   } else if(x_sw == 1 && y_sw) {
  ------------------
  |  Branch (164:14): [True: 1.75k, False: 1.68k]
  |  Branch (164:27): [True: 1.75k, False: 0]
  ------------------
  165|  1.75k|      grow_to(y_sw + 1);
  166|  1.75k|      bigint_linmul3(mutable_data(), y.data(), y_sw, word_at(0));
  167|  1.75k|   } else if(y_sw == 1 && x_sw) {
  ------------------
  |  Branch (167:14): [True: 0, False: 1.68k]
  |  Branch (167:27): [True: 0, False: 0]
  ------------------
  168|      0|      word carry = bigint_linmul2(mutable_data(), x_sw, y.word_at(0));
  169|      0|      set_word_at(x_sw, carry);
  170|  1.68k|   } else {
  171|  1.68k|      const size_t new_size = x_sw + y_sw + 1;
  172|  1.68k|      ws.resize(new_size);
  173|  1.68k|      secure_vector<word> z_reg(new_size);
  174|       |
  175|  1.68k|      bigint_mul(z_reg.data(), z_reg.size(), data(), size(), x_sw, y.data(), y.size(), y_sw, ws.data(), ws.size());
  176|       |
  177|  1.68k|      this->swap_reg(z_reg);
  178|  1.68k|   }
  179|       |
  180|  13.1k|   return (*this);
  181|  13.1k|}
_ZN5Botan6BigInt6squareERNSt3__16vectorImNS_16secure_allocatorImEEEE:
  183|    837|BigInt& BigInt::square(secure_vector<word>& ws) {
  184|    837|   const size_t sw = sig_words();
  185|       |
  186|    837|   secure_vector<word> z(2 * sw);
  187|    837|   ws.resize(z.size());
  188|       |
  189|    837|   bigint_sqr(z.data(), z.size(), data(), size(), sw, ws.data(), ws.size());
  190|       |
  191|    837|   swap_reg(z);
  192|    837|   set_sign(BigInt::Positive);
  193|       |
  194|    837|   return (*this);
  195|    837|}
_ZN5Botan6BigIntmLEm:
  197|  13.0M|BigInt& BigInt::operator*=(word y) {
  198|  13.0M|   if(y == 0) {
  ------------------
  |  Branch (198:7): [True: 0, False: 13.0M]
  ------------------
  199|      0|      clear();
  200|      0|      set_sign(Positive);
  201|      0|   }
  202|       |
  203|  13.0M|   const word carry = bigint_linmul2(mutable_data(), size(), y);
  204|  13.0M|   set_word_at(size(), carry);
  205|       |
  206|  13.0M|   return (*this);
  207|  13.0M|}
_ZN5Botan6BigIntrMERKS0_:
  224|   150k|BigInt& BigInt::operator%=(const BigInt& mod) {
  225|   150k|   return (*this = (*this) % mod);
  226|   150k|}
_ZN5Botan6BigIntlSEm:
  260|   251k|BigInt& BigInt::operator<<=(size_t shift) {
  261|   251k|   const size_t shift_words = shift / BOTAN_MP_WORD_BITS;
  ------------------
  |  |   50|   251k|#define BOTAN_MP_WORD_BITS 64
  ------------------
  262|   251k|   const size_t shift_bits = shift % BOTAN_MP_WORD_BITS;
  ------------------
  |  |   50|   251k|#define BOTAN_MP_WORD_BITS 64
  ------------------
  263|   251k|   const size_t size = sig_words();
  264|       |
  265|   251k|   const size_t bits_free = top_bits_free();
  266|       |
  267|   251k|   const size_t new_size = size + shift_words + (bits_free < shift_bits);
  268|       |
  269|   251k|   m_data.grow_to(new_size);
  270|       |
  271|   251k|   bigint_shl1(m_data.mutable_data(), new_size, size, shift_words, shift_bits);
  272|       |
  273|   251k|   return (*this);
  274|   251k|}
_ZN5Botan6BigIntrSEm:
  279|   416k|BigInt& BigInt::operator>>=(size_t shift) {
  280|   416k|   const size_t shift_words = shift / BOTAN_MP_WORD_BITS;
  ------------------
  |  |   50|   416k|#define BOTAN_MP_WORD_BITS 64
  ------------------
  281|   416k|   const size_t shift_bits = shift % BOTAN_MP_WORD_BITS;
  ------------------
  |  |   50|   416k|#define BOTAN_MP_WORD_BITS 64
  ------------------
  282|       |
  283|   416k|   bigint_shr1(m_data.mutable_data(), m_data.size(), shift_words, shift_bits);
  284|       |
  285|   416k|   if(is_negative() && is_zero()) {
  ------------------
  |  Branch (285:7): [True: 0, False: 416k]
  |  Branch (285:24): [True: 0, False: 0]
  ------------------
  286|      0|      set_sign(Positive);
  287|      0|   }
  288|       |
  289|   416k|   return (*this);
  290|   416k|}

_ZN5Botan6BigInt4add2ERKS0_PKmmNS0_4SignE:
   19|  96.8k|BigInt BigInt::add2(const BigInt& x, const word y[], size_t y_words, BigInt::Sign y_sign) {
   20|  96.8k|   const size_t x_sw = x.sig_words();
   21|       |
   22|  96.8k|   BigInt z = BigInt::with_capacity(std::max(x_sw, y_words) + 1);
   23|       |
   24|  96.8k|   if(x.sign() == y_sign) {
  ------------------
  |  Branch (24:7): [True: 16.1k, False: 80.7k]
  ------------------
   25|  16.1k|      bigint_add3(z.mutable_data(), x.data(), x_sw, y, y_words);
   26|  16.1k|      z.set_sign(x.sign());
   27|  80.7k|   } else {
   28|  80.7k|      const int32_t relative_size = bigint_sub_abs(z.mutable_data(), x.data(), x_sw, y, y_words);
   29|       |
   30|       |      //z.sign_fixup(relative_size, y_sign);
   31|  80.7k|      if(relative_size < 0) {
  ------------------
  |  Branch (31:10): [True: 0, False: 80.7k]
  ------------------
   32|      0|         z.set_sign(y_sign);
   33|  80.7k|      } else if(relative_size == 0) {
  ------------------
  |  Branch (33:17): [True: 0, False: 80.7k]
  ------------------
   34|      0|         z.set_sign(BigInt::Positive);
   35|  80.7k|      } else {
   36|  80.7k|         z.set_sign(x.sign());
   37|  80.7k|      }
   38|  80.7k|   }
   39|       |
   40|  96.8k|   return z;
   41|  96.8k|}
_ZN5BotanmlERKNS_6BigIntES2_:
   46|  18.8k|BigInt operator*(const BigInt& x, const BigInt& y) {
   47|  18.8k|   const size_t x_sw = x.sig_words();
   48|  18.8k|   const size_t y_sw = y.sig_words();
   49|       |
   50|  18.8k|   BigInt z = BigInt::with_capacity(x.size() + y.size());
   51|       |
   52|  18.8k|   if(x_sw == 1 && y_sw) {
  ------------------
  |  Branch (52:7): [True: 1.50k, False: 17.3k]
  |  Branch (52:20): [True: 1.50k, False: 0]
  ------------------
   53|  1.50k|      bigint_linmul3(z.mutable_data(), y.data(), y_sw, x.word_at(0));
   54|  17.3k|   } else if(y_sw == 1 && x_sw) {
  ------------------
  |  Branch (54:14): [True: 6.11k, False: 11.2k]
  |  Branch (54:27): [True: 6.11k, False: 0]
  ------------------
   55|  6.11k|      bigint_linmul3(z.mutable_data(), x.data(), x_sw, y.word_at(0));
   56|  11.2k|   } else if(x_sw && y_sw) {
  ------------------
  |  Branch (56:14): [True: 10.9k, False: 236]
  |  Branch (56:22): [True: 10.8k, False: 118]
  ------------------
   57|  10.8k|      secure_vector<word> workspace(z.size());
   58|       |
   59|  10.8k|      bigint_mul(z.mutable_data(),
   60|  10.8k|                 z.size(),
   61|  10.8k|                 x.data(),
   62|  10.8k|                 x.size(),
   63|  10.8k|                 x_sw,
   64|  10.8k|                 y.data(),
   65|  10.8k|                 y.size(),
   66|  10.8k|                 y_sw,
   67|  10.8k|                 workspace.data(),
   68|  10.8k|                 workspace.size());
   69|  10.8k|   }
   70|       |
   71|  18.8k|   z.cond_flip_sign(x_sw > 0 && y_sw > 0 && x.sign() != y.sign());
  ------------------
  |  Branch (71:21): [True: 18.6k, False: 236]
  |  Branch (71:33): [True: 18.4k, False: 118]
  |  Branch (71:45): [True: 0, False: 18.4k]
  ------------------
   72|       |
   73|  18.8k|   return z;
   74|  18.8k|}
_ZN5BotanmlERKNS_6BigIntEm:
   79|   253k|BigInt operator*(const BigInt& x, word y) {
   80|   253k|   const size_t x_sw = x.sig_words();
   81|       |
   82|   253k|   BigInt z = BigInt::with_capacity(x_sw + 1);
   83|       |
   84|   253k|   if(x_sw && y) {
  ------------------
  |  Branch (84:7): [True: 253k, False: 0]
  |  Branch (84:15): [True: 126k, False: 126k]
  ------------------
   85|   126k|      bigint_linmul3(z.mutable_data(), x.data(), x_sw, y);
   86|   126k|      z.set_sign(x.sign());
   87|   126k|   }
   88|       |
   89|   253k|   return z;
   90|   253k|}
_ZN5BotandvERKNS_6BigIntEm:
  108|   150k|BigInt operator/(const BigInt& x, word y) {
  109|   150k|   if(y == 0) {
  ------------------
  |  Branch (109:7): [True: 0, False: 150k]
  ------------------
  110|      0|      throw Invalid_Argument("BigInt::operator/ divide by zero");
  111|      0|   }
  112|       |
  113|   150k|   BigInt q;
  114|   150k|   word r;
  115|   150k|   ct_divide_word(x, y, q, r);
  116|   150k|   return q;
  117|   150k|}
_ZN5BotanrmERKNS_6BigIntES2_:
  122|   153k|BigInt operator%(const BigInt& n, const BigInt& mod) {
  123|   153k|   if(mod.is_zero()) {
  ------------------
  |  Branch (123:7): [True: 0, False: 153k]
  ------------------
  124|      0|      throw Invalid_Argument("BigInt::operator% divide by zero");
  125|      0|   }
  126|   153k|   if(mod.is_negative()) {
  ------------------
  |  Branch (126:7): [True: 0, False: 153k]
  ------------------
  127|      0|      throw Invalid_Argument("BigInt::operator% modulus must be > 0");
  128|      0|   }
  129|   153k|   if(n.is_positive() && mod.is_positive() && n < mod) {
  ------------------
  |  Branch (129:7): [True: 153k, False: 0]
  |  Branch (129:26): [True: 153k, False: 0]
  |  Branch (129:47): [True: 2.84k, False: 150k]
  ------------------
  130|  2.84k|      return n;
  131|  2.84k|   }
  132|       |
  133|   150k|   if(mod.sig_words() == 1) {
  ------------------
  |  Branch (133:7): [True: 24.7k, False: 125k]
  ------------------
  134|  24.7k|      return BigInt::from_word(n % mod.word_at(0));
  135|  24.7k|   }
  136|       |
  137|   125k|   BigInt q, r;
  138|   125k|   vartime_divide(n, mod, q, r);
  139|   125k|   return r;
  140|   150k|}
_ZN5BotanrmERKNS_6BigIntEm:
  145|   370k|word operator%(const BigInt& n, word mod) {
  146|   370k|   if(mod == 0) {
  ------------------
  |  Branch (146:7): [True: 0, False: 370k]
  ------------------
  147|      0|      throw Invalid_Argument("BigInt::operator% divide by zero");
  148|      0|   }
  149|       |
  150|   370k|   if(mod == 1) {
  ------------------
  |  Branch (150:7): [True: 0, False: 370k]
  ------------------
  151|      0|      return 0;
  152|      0|   }
  153|       |
  154|   370k|   word remainder = 0;
  155|       |
  156|   370k|   if(is_power_of_2(mod)) {
  ------------------
  |  Branch (156:7): [True: 345k, False: 24.7k]
  ------------------
  157|   345k|      remainder = (n.word_at(0) & (mod - 1));
  158|   345k|   } else {
  159|  24.7k|      const size_t sw = n.sig_words();
  160|  50.8k|      for(size_t i = sw; i > 0; --i) {
  ------------------
  |  Branch (160:26): [True: 26.1k, False: 24.7k]
  ------------------
  161|  26.1k|         remainder = bigint_modop_vartime(remainder, n.word_at(i - 1), mod);
  162|  26.1k|      }
  163|  24.7k|   }
  164|       |
  165|   370k|   if(remainder && n.sign() == BigInt::Negative) {
  ------------------
  |  Branch (165:7): [True: 370k, False: 0]
  |  Branch (165:20): [True: 0, False: 370k]
  ------------------
  166|      0|      return mod - remainder;
  167|      0|   }
  168|   370k|   return remainder;
  169|   370k|}
_ZN5BotanlsERKNS_6BigIntEm:
  174|   125k|BigInt operator<<(const BigInt& x, size_t shift) {
  175|   125k|   const size_t shift_words = shift / BOTAN_MP_WORD_BITS, shift_bits = shift % BOTAN_MP_WORD_BITS;
  ------------------
  |  |   50|   125k|#define BOTAN_MP_WORD_BITS 64
  ------------------
                 const size_t shift_words = shift / BOTAN_MP_WORD_BITS, shift_bits = shift % BOTAN_MP_WORD_BITS;
  ------------------
  |  |   50|   125k|#define BOTAN_MP_WORD_BITS 64
  ------------------
  176|       |
  177|   125k|   const size_t x_sw = x.sig_words();
  178|       |
  179|   125k|   BigInt y = BigInt::with_capacity(x_sw + shift_words + (shift_bits ? 1 : 0));
  ------------------
  |  Branch (179:59): [True: 0, False: 125k]
  ------------------
  180|   125k|   bigint_shl2(y.mutable_data(), x.data(), x_sw, shift_words, shift_bits);
  181|   125k|   y.set_sign(x.sign());
  182|   125k|   return y;
  183|   125k|}
_ZN5BotanrsERKNS_6BigIntEm:
  188|    837|BigInt operator>>(const BigInt& x, size_t shift) {
  189|    837|   const size_t shift_words = shift / BOTAN_MP_WORD_BITS;
  ------------------
  |  |   50|    837|#define BOTAN_MP_WORD_BITS 64
  ------------------
  190|    837|   const size_t shift_bits = shift % BOTAN_MP_WORD_BITS;
  ------------------
  |  |   50|    837|#define BOTAN_MP_WORD_BITS 64
  ------------------
  191|    837|   const size_t x_sw = x.sig_words();
  192|       |
  193|    837|   if(shift_words >= x_sw) {
  ------------------
  |  Branch (193:7): [True: 0, False: 837]
  ------------------
  194|      0|      return BigInt::zero();
  195|      0|   }
  196|       |
  197|    837|   BigInt y = BigInt::with_capacity(x_sw - shift_words);
  198|    837|   bigint_shr2(y.mutable_data(), x.data(), x_sw, shift_words, shift_bits);
  199|       |
  200|    837|   if(x.is_negative() && y.is_zero()) {
  ------------------
  |  Branch (200:7): [True: 0, False: 837]
  |  Branch (200:26): [True: 0, False: 0]
  ------------------
  201|      0|      y.set_sign(BigInt::Positive);
  202|    837|   } else {
  203|    837|      y.set_sign(x.sign());
  204|    837|   }
  205|       |
  206|    837|   return y;
  207|    837|}

_ZN5Botan6BigInt9randomizeERNS_21RandomNumberGeneratorEmb:
   18|  91.8k|void BigInt::randomize(RandomNumberGenerator& rng, size_t bitsize, bool set_high_bit) {
   19|  91.8k|   set_sign(Positive);
   20|       |
   21|  91.8k|   if(bitsize == 0) {
  ------------------
  |  Branch (21:7): [True: 0, False: 91.8k]
  ------------------
   22|      0|      clear();
   23|  91.8k|   } else {
   24|  91.8k|      secure_vector<uint8_t> array = rng.random_vec(round_up(bitsize, 8) / 8);
   25|       |
   26|       |      // Always cut unwanted bits
   27|  91.8k|      if(bitsize % 8) {
  ------------------
  |  Branch (27:10): [True: 73.8k, False: 18.0k]
  ------------------
   28|  73.8k|         array[0] &= 0xFF >> (8 - (bitsize % 8));
   29|  73.8k|      }
   30|       |
   31|       |      // Set the highest bit if wanted
   32|  91.8k|      if(set_high_bit) {
  ------------------
  |  Branch (32:10): [True: 4.08k, False: 87.7k]
  ------------------
   33|  4.08k|         array[0] |= 0x80 >> ((bitsize % 8) ? (8 - bitsize % 8) : 0);
  ------------------
  |  Branch (33:31): [True: 0, False: 4.08k]
  ------------------
   34|  4.08k|      }
   35|       |
   36|  91.8k|      binary_decode(array);
   37|  91.8k|   }
   38|  91.8k|}
_ZN5Botan6BigInt14random_integerERNS_21RandomNumberGeneratorERKS0_S4_:
   43|  18.0k|BigInt BigInt::random_integer(RandomNumberGenerator& rng, const BigInt& min, const BigInt& max) {
   44|  18.0k|   if(min.is_negative() || max.is_negative() || max <= min) {
  ------------------
  |  Branch (44:7): [True: 0, False: 18.0k]
  |  Branch (44:28): [True: 0, False: 18.0k]
  |  Branch (44:49): [True: 0, False: 18.0k]
  ------------------
   45|      0|      throw Invalid_Argument("BigInt::random_integer invalid range");
   46|      0|   }
   47|       |
   48|       |   /*
   49|       |   If min is > 1 then we generate a random number `r` in [0,max-min)
   50|       |   and return min + r.
   51|       |
   52|       |   This same logic could also be reasonbly chosen for min == 1, but
   53|       |   that breaks certain tests which expect stability of this function
   54|       |   when generating within [1,n)
   55|       |   */
   56|  18.0k|   if(min > 1) {
  ------------------
  |  Branch (56:7): [True: 9.00k, False: 9.00k]
  ------------------
   57|  9.00k|      const BigInt diff = max - min;
   58|       |      // This call is recursive, but will not recurse further
   59|  9.00k|      return min + BigInt::random_integer(rng, BigInt::zero(), diff);
   60|  9.00k|   }
   61|       |
   62|  9.00k|   BOTAN_DEBUG_ASSERT(min <= 1);
  ------------------
  |  |   99|  9.00k|      do {                          \
  |  |  100|  9.00k|      } while(0)
  |  |  ------------------
  |  |  |  Branch (100:15): [Folded - Ignored]
  |  |  ------------------
  ------------------
   63|       |
   64|  9.00k|   const size_t bits = max.bits();
   65|       |
   66|  9.00k|   BigInt r;
   67|       |
   68|  9.00k|   do {
   69|  9.00k|      r.randomize(rng, bits, false);
   70|  9.00k|   } while(r < min || r >= max);
  ------------------
  |  Branch (70:12): [True: 0, False: 9.00k]
  |  Branch (70:23): [True: 0, False: 9.00k]
  ------------------
   71|       |
   72|  9.00k|   return r;
   73|  18.0k|}

_ZN5Botan6BigIntC2Em:
   18|  45.0k|BigInt::BigInt(uint64_t n) {
   19|  45.0k|#if BOTAN_MP_WORD_BITS == 64
   20|  45.0k|   m_data.set_word_at(0, n);
   21|       |#else
   22|       |   m_data.set_word_at(1, static_cast<word>(n >> 32));
   23|       |   m_data.set_word_at(0, static_cast<word>(n));
   24|       |#endif
   25|  45.0k|}
_ZN5Botan6BigInt8from_u64Em:
   28|    525|BigInt BigInt::from_u64(uint64_t n) {
   29|    525|   BigInt bn;
   30|       |
   31|    525|#if BOTAN_MP_WORD_BITS == 64
   32|    525|   bn.set_word_at(0, n);
   33|       |#else
   34|       |   bn.set_word_at(1, static_cast<word>(n >> 32));
   35|       |   bn.set_word_at(0, static_cast<word>(n));
   36|       |#endif
   37|       |
   38|    525|   return bn;
   39|    525|}
_ZN5Botan6BigInt9from_wordEm:
   42|  24.7k|BigInt BigInt::from_word(word n) {
   43|  24.7k|   BigInt bn;
   44|  24.7k|   bn.set_word_at(0, n);
   45|  24.7k|   return bn;
   46|  24.7k|}
_ZN5Botan6BigInt8from_s32Ei:
   49|    525|BigInt BigInt::from_s32(int32_t n) {
   50|    525|   if(n >= 0) {
  ------------------
  |  Branch (50:7): [True: 0, False: 525]
  ------------------
   51|      0|      return BigInt::from_u64(static_cast<uint64_t>(n));
   52|    525|   } else {
   53|    525|      return -BigInt::from_u64(static_cast<uint64_t>(-n));
   54|    525|   }
   55|    525|}
_ZN5Botan6BigInt13with_capacityEm:
   58|   661k|BigInt BigInt::with_capacity(size_t size) {
   59|   661k|   BigInt bn;
   60|   661k|   bn.grow_to(size);
   61|   661k|   return bn;
   62|   661k|}
_ZN5Botan6BigIntC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
   67|     10|BigInt::BigInt(std::string_view str) {
   68|     10|   Base base = Decimal;
   69|     10|   size_t markers = 0;
   70|     10|   bool negative = false;
   71|       |
   72|     10|   if(str.length() > 0 && str[0] == '-') {
  ------------------
  |  Branch (72:7): [True: 10, False: 0]
  |  Branch (72:27): [True: 0, False: 10]
  ------------------
   73|      0|      markers += 1;
   74|      0|      negative = true;
   75|      0|   }
   76|       |
   77|     10|   if(str.length() > markers + 2 && str[markers] == '0' && str[markers + 1] == 'x') {
  ------------------
  |  Branch (77:7): [True: 10, False: 0]
  |  Branch (77:37): [True: 10, False: 0]
  |  Branch (77:60): [True: 10, False: 0]
  ------------------
   78|     10|      markers += 2;
   79|     10|      base = Hexadecimal;
   80|     10|   }
   81|       |
   82|     10|   *this = decode(cast_char_ptr_to_uint8(str.data()) + markers, str.length() - markers, base);
   83|       |
   84|     10|   if(negative) {
  ------------------
  |  Branch (84:7): [True: 0, False: 10]
  ------------------
   85|      0|      set_sign(Negative);
   86|     10|   } else {
   87|     10|      set_sign(Positive);
   88|     10|   }
   89|     10|}
_ZN5Botan6BigIntC2EPKhm:
   91|  2.72k|BigInt::BigInt(const uint8_t input[], size_t length) {
   92|  2.72k|   binary_decode(input, length);
   93|  2.72k|}
_ZN5Botan6BigIntC2ERNS_21RandomNumberGeneratorEmb:
  121|  9.00k|BigInt::BigInt(RandomNumberGenerator& rng, size_t bits, bool set_high_bit) {
  122|  9.00k|   randomize(rng, bits, set_high_bit);
  123|  9.00k|}
_ZNK5Botan6BigInt8cmp_wordEm:
  129|   227k|int32_t BigInt::cmp_word(word other) const {
  130|   227k|   if(is_negative()) {
  ------------------
  |  Branch (130:7): [True: 1.36k, False: 226k]
  ------------------
  131|  1.36k|      return -1;  // other is positive ...
  132|  1.36k|   }
  133|       |
  134|   226k|   const size_t sw = this->sig_words();
  135|   226k|   if(sw > 1) {
  ------------------
  |  Branch (135:7): [True: 180k, False: 45.4k]
  ------------------
  136|   180k|      return 1;  // must be larger since other is just one word ...
  137|   180k|   }
  138|       |
  139|  45.4k|   return bigint_cmp(this->data(), sw, &other, 1);
  140|   226k|}
_ZNK5Botan6BigInt3cmpERKS0_b:
  145|  29.5k|int32_t BigInt::cmp(const BigInt& other, bool check_signs) const {
  146|  29.5k|   if(check_signs) {
  ------------------
  |  Branch (146:7): [True: 29.5k, False: 0]
  ------------------
  147|  29.5k|      if(other.is_positive() && this->is_negative()) {
  ------------------
  |  Branch (147:10): [True: 29.5k, False: 0]
  |  Branch (147:33): [True: 0, False: 29.5k]
  ------------------
  148|      0|         return -1;
  149|      0|      }
  150|       |
  151|  29.5k|      if(other.is_negative() && this->is_positive()) {
  ------------------
  |  Branch (151:10): [True: 0, False: 29.5k]
  |  Branch (151:33): [True: 0, False: 0]
  ------------------
  152|      0|         return 1;
  153|      0|      }
  154|       |
  155|  29.5k|      if(other.is_negative() && this->is_negative()) {
  ------------------
  |  Branch (155:10): [True: 0, False: 29.5k]
  |  Branch (155:33): [True: 0, False: 0]
  ------------------
  156|      0|         return (-bigint_cmp(this->data(), this->size(), other.data(), other.size()));
  157|      0|      }
  158|  29.5k|   }
  159|       |
  160|  29.5k|   return bigint_cmp(this->data(), this->size(), other.data(), other.size());
  161|  29.5k|}
_ZNK5Botan6BigInt8is_equalERKS0_:
  163|  21.7k|bool BigInt::is_equal(const BigInt& other) const {
  164|  21.7k|   if(this->sign() != other.sign()) {
  ------------------
  |  Branch (164:7): [True: 0, False: 21.7k]
  ------------------
  165|      0|      return false;
  166|      0|   }
  167|       |
  168|  21.7k|   return bigint_ct_is_eq(this->data(), this->sig_words(), other.data(), other.sig_words()).as_bool();
  169|  21.7k|}
_ZNK5Botan6BigInt12is_less_thanERKS0_:
  171|   316k|bool BigInt::is_less_than(const BigInt& other) const {
  172|   316k|   if(this->is_negative() && other.is_positive()) {
  ------------------
  |  Branch (172:7): [True: 0, False: 316k]
  |  Branch (172:30): [True: 0, False: 0]
  ------------------
  173|      0|      return true;
  174|      0|   }
  175|       |
  176|   316k|   if(this->is_positive() && other.is_negative()) {
  ------------------
  |  Branch (176:7): [True: 316k, False: 0]
  |  Branch (176:30): [True: 0, False: 316k]
  ------------------
  177|      0|      return false;
  178|      0|   }
  179|       |
  180|   316k|   if(other.is_negative() && this->is_negative()) {
  ------------------
  |  Branch (180:7): [True: 0, False: 316k]
  |  Branch (180:30): [True: 0, False: 0]
  ------------------
  181|      0|      return bigint_ct_is_lt(other.data(), other.sig_words(), this->data(), this->sig_words()).as_bool();
  182|      0|   }
  183|       |
  184|   316k|   return bigint_ct_is_lt(this->data(), this->sig_words(), other.data(), other.sig_words()).as_bool();
  185|   316k|}
_ZNK5Botan6BigInt12encode_wordsEPmm:
  187|   238k|void BigInt::encode_words(word out[], size_t size) const {
  188|   238k|   const size_t words = sig_words();
  189|       |
  190|   238k|   if(words > size) {
  ------------------
  |  Branch (190:7): [True: 0, False: 238k]
  ------------------
  191|      0|      throw Encoding_Error("BigInt::encode_words value too large to encode");
  192|      0|   }
  193|       |
  194|   238k|   clear_mem(out, size);
  195|   238k|   copy_mem(out, data(), words);
  196|   238k|}
_ZNK5Botan6BigInt4Data14calc_sig_wordsEv:
  198|  11.2M|size_t BigInt::Data::calc_sig_words() const {
  199|  11.2M|   const size_t sz = m_reg.size();
  200|  11.2M|   size_t sig = sz;
  201|       |
  202|  11.2M|   word sub = 1;
  203|       |
  204|   180M|   for(size_t i = 0; i != sz; ++i) {
  ------------------
  |  Branch (204:22): [True: 168M, False: 11.2M]
  ------------------
  205|   168M|      const word w = m_reg[sz - i - 1];
  206|   168M|      sub &= ct_is_zero(w);
  207|   168M|      sig -= sub;
  208|   168M|   }
  209|       |
  210|       |   /*
  211|       |   * This depends on the data so is poisoned, but unpoison it here as
  212|       |   * later conditionals are made on the size.
  213|       |   */
  214|  11.2M|   CT::unpoison(sig);
  215|       |
  216|  11.2M|   return sig;
  217|  11.2M|}
_ZNK5Botan6BigInt13get_substringEmm:
  222|  1.57M|uint32_t BigInt::get_substring(size_t offset, size_t length) const {
  223|  1.57M|   if(length == 0 || length > 32) {
  ------------------
  |  Branch (223:7): [True: 0, False: 1.57M]
  |  Branch (223:22): [True: 0, False: 1.57M]
  ------------------
  224|      0|      throw Invalid_Argument("BigInt::get_substring invalid substring length");
  225|      0|   }
  226|       |
  227|  1.57M|   const uint32_t mask = 0xFFFFFFFF >> (32 - length);
  228|       |
  229|  1.57M|   const size_t word_offset = offset / BOTAN_MP_WORD_BITS;
  ------------------
  |  |   50|  1.57M|#define BOTAN_MP_WORD_BITS 64
  ------------------
  230|  1.57M|   const size_t wshift = (offset % BOTAN_MP_WORD_BITS);
  ------------------
  |  |   50|  1.57M|#define BOTAN_MP_WORD_BITS 64
  ------------------
  231|       |
  232|       |   /*
  233|       |   * The substring is contained within one or at most two words. The
  234|       |   * offset and length are not secret, so we can perform conditional
  235|       |   * operations on those values.
  236|       |   */
  237|  1.57M|   const word w0 = word_at(word_offset);
  238|       |
  239|  1.57M|   if(wshift == 0 || (offset + length) / BOTAN_MP_WORD_BITS == word_offset) {
  ------------------
  |  |   50|  1.51M|#define BOTAN_MP_WORD_BITS 64
  ------------------
  |  Branch (239:7): [True: 61.5k, False: 1.51M]
  |  Branch (239:22): [True: 1.42M, False: 85.7k]
  ------------------
  240|  1.48M|      return static_cast<uint32_t>(w0 >> wshift) & mask;
  241|  1.48M|   } else {
  242|  85.7k|      const word w1 = word_at(word_offset + 1);
  243|  85.7k|      return static_cast<uint32_t>((w0 >> wshift) | (w1 << (BOTAN_MP_WORD_BITS - wshift))) & mask;
  ------------------
  |  |   50|  85.7k|#define BOTAN_MP_WORD_BITS 64
  ------------------
  244|  85.7k|   }
  245|  1.57M|}
_ZNK5Botan6BigInt13top_bits_freeEv:
  281|   565k|size_t BigInt::top_bits_free() const {
  282|   565k|   const size_t words = sig_words();
  283|       |
  284|   565k|   const word top_word = word_at(words - 1);
  285|   565k|   const size_t bits_used = high_bit(top_word);
  286|   565k|   CT::unpoison(bits_used);
  287|   565k|   return BOTAN_MP_WORD_BITS - bits_used;
  ------------------
  |  |   50|   565k|#define BOTAN_MP_WORD_BITS 64
  ------------------
  288|   565k|}
_ZNK5Botan6BigInt4bitsEv:
  290|   188k|size_t BigInt::bits() const {
  291|   188k|   const size_t words = sig_words();
  292|       |
  293|   188k|   if(words == 0) {
  ------------------
  |  Branch (293:7): [True: 161, False: 188k]
  ------------------
  294|    161|      return 0;
  295|    161|   }
  296|       |
  297|   188k|   const size_t full_words = (words - 1) * BOTAN_MP_WORD_BITS;
  ------------------
  |  |   50|   188k|#define BOTAN_MP_WORD_BITS 64
  ------------------
  298|   188k|   const size_t top_bits = BOTAN_MP_WORD_BITS - top_bits_free();
  ------------------
  |  |   50|   188k|#define BOTAN_MP_WORD_BITS 64
  ------------------
  299|       |
  300|   188k|   return full_words + top_bits;
  301|   188k|}
_ZNK5Botan6BigIntngEv:
  306|  1.36k|BigInt BigInt::operator-() const {
  307|  1.36k|   BigInt x = (*this);
  308|  1.36k|   x.flip_sign();
  309|  1.36k|   return x;
  310|  1.36k|}
_ZN5Botan6BigInt12reduce_belowERKS0_RNSt3__16vectorImNS_16secure_allocatorImEEEE:
  312|  12.4M|size_t BigInt::reduce_below(const BigInt& p, secure_vector<word>& ws) {
  313|  12.4M|   if(p.is_negative() || this->is_negative()) {
  ------------------
  |  Branch (313:7): [True: 0, False: 12.4M]
  |  Branch (313:26): [True: 0, False: 12.4M]
  ------------------
  314|      0|      throw Invalid_Argument("BigInt::reduce_below both values must be positive");
  315|      0|   }
  316|       |
  317|  12.4M|   const size_t p_words = p.sig_words();
  318|       |
  319|  12.4M|   if(size() < p_words + 1) {
  ------------------
  |  Branch (319:7): [True: 0, False: 12.4M]
  ------------------
  320|      0|      grow_to(p_words + 1);
  321|      0|   }
  322|       |
  323|  12.4M|   if(ws.size() < p_words + 1) {
  ------------------
  |  Branch (323:7): [True: 125k, False: 12.3M]
  ------------------
  324|   125k|      ws.resize(p_words + 1);
  325|   125k|   }
  326|       |
  327|  12.4M|   clear_mem(ws.data(), ws.size());
  328|       |
  329|  12.4M|   size_t reductions = 0;
  330|       |
  331|  32.6M|   for(;;) {
  332|  32.6M|      word borrow = bigint_sub3(ws.data(), data(), p_words + 1, p.data(), p_words);
  333|  32.6M|      if(borrow) {
  ------------------
  |  Branch (333:10): [True: 12.4M, False: 20.1M]
  ------------------
  334|  12.4M|         break;
  335|  12.4M|      }
  336|       |
  337|  20.1M|      ++reductions;
  338|  20.1M|      swap_reg(ws);
  339|  20.1M|   }
  340|       |
  341|  12.4M|   return reductions;
  342|  12.4M|}
_ZN5Botan6BigInt15ct_reduce_belowERKS0_RNSt3__16vectorImNS_16secure_allocatorImEEEEm:
  344|  6.59k|void BigInt::ct_reduce_below(const BigInt& mod, secure_vector<word>& ws, size_t bound) {
  345|  6.59k|   if(mod.is_negative() || this->is_negative()) {
  ------------------
  |  Branch (345:7): [True: 0, False: 6.59k]
  |  Branch (345:28): [True: 0, False: 6.59k]
  ------------------
  346|      0|      throw Invalid_Argument("BigInt::ct_reduce_below both values must be positive");
  347|      0|   }
  348|       |
  349|  6.59k|   const size_t mod_words = mod.sig_words();
  350|       |
  351|  6.59k|   grow_to(mod_words);
  352|       |
  353|  6.59k|   const size_t sz = size();
  354|       |
  355|  6.59k|   ws.resize(sz);
  356|       |
  357|  6.59k|   clear_mem(ws.data(), sz);
  358|       |
  359|  19.7k|   for(size_t i = 0; i != bound; ++i) {
  ------------------
  |  Branch (359:22): [True: 13.1k, False: 6.59k]
  ------------------
  360|  13.1k|      word borrow = bigint_sub3(ws.data(), data(), sz, mod.data(), mod_words);
  361|       |
  362|  13.1k|      CT::Mask<word>::is_zero(borrow).select_n(mutable_data(), ws.data(), data(), sz);
  363|  13.1k|   }
  364|  6.59k|}
_ZN5Botan6BigInt13binary_decodeEPKhm:
  403|  94.5k|void BigInt::binary_decode(const uint8_t buf[], size_t length) {
  404|  94.5k|   clear();
  405|       |
  406|  94.5k|   const size_t full_words = length / sizeof(word);
  407|  94.5k|   const size_t extra_bytes = length % sizeof(word);
  408|       |
  409|  94.5k|   secure_vector<word> reg((round_up(full_words + (extra_bytes > 0 ? 1 : 0), 8)));
  ------------------
  |  Branch (409:52): [True: 2.15k, False: 92.4k]
  ------------------
  410|       |
  411|   620k|   for(size_t i = 0; i != full_words; ++i) {
  ------------------
  |  Branch (411:22): [True: 525k, False: 94.5k]
  ------------------
  412|   525k|      reg[i] = load_be<word>(buf + length - sizeof(word) * (i + 1), 0);
  413|   525k|   }
  414|       |
  415|  94.5k|   if(extra_bytes > 0) {
  ------------------
  |  Branch (415:7): [True: 2.15k, False: 92.4k]
  ------------------
  416|  8.65k|      for(size_t i = 0; i != extra_bytes; ++i) {
  ------------------
  |  Branch (416:25): [True: 6.49k, False: 2.15k]
  ------------------
  417|  6.49k|         reg[full_words] = (reg[full_words] << 8) | buf[i];
  418|  6.49k|      }
  419|  2.15k|   }
  420|       |
  421|  94.5k|   m_data.swap(reg);
  422|  94.5k|}
_ZN5Botan6BigInt12ct_cond_swapEbRS0_:
  467|   644k|void BigInt::ct_cond_swap(bool predicate, BigInt& other) {
  468|   644k|   const size_t max_words = std::max(size(), other.size());
  469|   644k|   grow_to(max_words);
  470|   644k|   other.grow_to(max_words);
  471|       |
  472|   644k|   bigint_cnd_swap(predicate, this->mutable_data(), other.mutable_data(), max_words);
  473|   644k|}
_ZN5Botan6BigInt14cond_flip_signEb:
  475|   158k|void BigInt::cond_flip_sign(bool predicate) {
  476|       |   // This code is assuming Negative == 0, Positive == 1
  477|       |
  478|   158k|   const auto mask = CT::Mask<uint8_t>::expand(predicate);
  479|       |
  480|   158k|   const uint8_t current_sign = static_cast<uint8_t>(sign());
  481|       |
  482|   158k|   const uint8_t new_sign = mask.select(current_sign ^ 1, current_sign);
  483|       |
  484|   158k|   set_sign(static_cast<Sign>(new_sign));
  485|   158k|}

_ZN5Botan9ct_divideERKNS_6BigIntES2_RS0_S3_:
   48|    838|void ct_divide(const BigInt& x, const BigInt& y, BigInt& q_out, BigInt& r_out) {
   49|    838|   if(y.is_zero()) {
  ------------------
  |  Branch (49:7): [True: 0, False: 838]
  ------------------
   50|      0|      throw Invalid_Argument("ct_divide: cannot divide by zero");
   51|      0|   }
   52|       |
   53|    838|   const size_t x_words = x.sig_words();
   54|    838|   const size_t y_words = y.sig_words();
   55|       |
   56|    838|   const size_t x_bits = x.bits();
   57|       |
   58|    838|   BigInt q = BigInt::with_capacity(x_words);
   59|    838|   BigInt r = BigInt::with_capacity(y_words);
   60|    838|   BigInt t = BigInt::with_capacity(y_words);  // a temporary
   61|       |
   62|   645k|   for(size_t i = 0; i != x_bits; ++i) {
  ------------------
  |  Branch (62:22): [True: 644k, False: 838]
  ------------------
   63|   644k|      const size_t b = x_bits - 1 - i;
   64|   644k|      const bool x_b = x.get_bit(b);
   65|       |
   66|   644k|      r *= 2;
   67|   644k|      r.conditionally_set_bit(0, x_b);
   68|       |
   69|   644k|      const bool r_gte_y = bigint_sub3(t.mutable_data(), r.data(), r.size(), y.data(), y_words) == 0;
   70|       |
   71|   644k|      q.conditionally_set_bit(b, r_gte_y);
   72|   644k|      r.ct_cond_swap(r_gte_y, t);
   73|   644k|   }
   74|       |
   75|    838|   sign_fixup(x, y, q, r);
   76|    838|   r_out = r;
   77|    838|   q_out = q;
   78|    838|}
_ZN5Botan14ct_divide_wordERKNS_6BigIntEmRS0_Rm:
   80|   150k|void ct_divide_word(const BigInt& x, word y, BigInt& q_out, word& r_out) {
   81|   150k|   if(y == 0) {
  ------------------
  |  Branch (81:7): [True: 0, False: 150k]
  ------------------
   82|      0|      throw Invalid_Argument("ct_divide_word: cannot divide by zero");
   83|      0|   }
   84|       |
   85|   150k|   const size_t x_words = x.sig_words();
   86|   150k|   const size_t x_bits = x.bits();
   87|       |
   88|   150k|   BigInt q = BigInt::with_capacity(x_words);
   89|   150k|   word r = 0;
   90|       |
   91|  29.1M|   for(size_t i = 0; i != x_bits; ++i) {
  ------------------
  |  Branch (91:22): [True: 29.0M, False: 150k]
  ------------------
   92|  29.0M|      const size_t b = x_bits - 1 - i;
   93|  29.0M|      const bool x_b = x.get_bit(b);
   94|       |
   95|  29.0M|      const auto r_carry = CT::Mask<word>::expand(r >> (BOTAN_MP_WORD_BITS - 1));
  ------------------
  |  |   50|  29.0M|#define BOTAN_MP_WORD_BITS 64
  ------------------
   96|       |
   97|  29.0M|      r *= 2;
   98|  29.0M|      r += x_b;
   99|       |
  100|  29.0M|      const auto r_gte_y = CT::Mask<word>::is_gte(r, y) | r_carry;
  101|  29.0M|      q.conditionally_set_bit(b, r_gte_y.as_bool());
  102|  29.0M|      r = r_gte_y.select(r - y, r);
  103|  29.0M|   }
  104|       |
  105|   150k|   if(x.is_negative()) {
  ------------------
  |  Branch (105:7): [True: 0, False: 150k]
  ------------------
  106|      0|      q.flip_sign();
  107|      0|      if(r != 0) {
  ------------------
  |  Branch (107:10): [True: 0, False: 0]
  ------------------
  108|      0|         --q;
  109|      0|         r = y - r;
  110|      0|      }
  111|      0|   }
  112|       |
  113|   150k|   r_out = r;
  114|   150k|   q_out = q;
  115|   150k|}
_ZN5Botan14vartime_divideERKNS_6BigIntES2_RS0_S3_:
  155|   125k|void vartime_divide(const BigInt& x, const BigInt& y_arg, BigInt& q_out, BigInt& r_out) {
  156|   125k|   if(y_arg.is_zero()) {
  ------------------
  |  Branch (156:7): [True: 0, False: 125k]
  ------------------
  157|      0|      throw Invalid_Argument("vartime_divide: cannot divide by zero");
  158|      0|   }
  159|       |
  160|   125k|   const size_t y_words = y_arg.sig_words();
  161|       |
  162|   125k|   BOTAN_ASSERT_NOMSG(y_words > 0);
  ------------------
  |  |   60|   125k|   do {                                                                     \
  |  |   61|   125k|      if(!(expr))                                                           \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 125k]
  |  |  ------------------
  |  |   62|   125k|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   63|   125k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (63:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  163|       |
  164|   125k|   BigInt y = y_arg;
  165|       |
  166|   125k|   BigInt r = x;
  167|   125k|   BigInt q = BigInt::zero();
  168|   125k|   secure_vector<word> ws;
  169|       |
  170|   125k|   r.set_sign(BigInt::Positive);
  171|   125k|   y.set_sign(BigInt::Positive);
  172|       |
  173|       |   // Calculate shifts needed to normalize y with high bit set
  174|   125k|   const size_t shifts = y.top_bits_free();
  175|       |
  176|   125k|   y <<= shifts;
  177|   125k|   r <<= shifts;
  178|       |
  179|       |   // we know y has not changed size, since we only shifted up to set high bit
  180|   125k|   const size_t t = y_words - 1;
  181|   125k|   const size_t n = std::max(y_words, r.sig_words()) - 1;  // r may have changed size however
  182|       |
  183|   125k|   BOTAN_ASSERT_NOMSG(n >= t);
  ------------------
  |  |   60|   125k|   do {                                                                     \
  |  |   61|   125k|      if(!(expr))                                                           \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 125k]
  |  |  ------------------
  |  |   62|   125k|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   63|   125k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (63:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  184|       |
  185|   125k|   q.grow_to(n - t + 1);
  186|       |
  187|   125k|   word* q_words = q.mutable_data();
  188|       |
  189|   125k|   BigInt shifted_y = y << (BOTAN_MP_WORD_BITS * (n - t));
  ------------------
  |  |   50|   125k|#define BOTAN_MP_WORD_BITS 64
  ------------------
  190|       |
  191|       |   // Set q_{n-t} to number of times r > shifted_y
  192|   125k|   q_words[n - t] = r.reduce_below(shifted_y, ws);
  193|       |
  194|   125k|   const word y_t0 = y.word_at(t);
  195|   125k|   const word y_t1 = y.word_at(t - 1);
  196|   125k|   BOTAN_DEBUG_ASSERT((y_t0 >> (BOTAN_MP_WORD_BITS - 1)) == 1);
  ------------------
  |  |   99|   125k|      do {                          \
  |  |  100|   125k|      } while(0)
  |  |  ------------------
  |  |  |  Branch (100:15): [Folded - Ignored]
  |  |  ------------------
  ------------------
  197|       |
  198|   252k|   for(size_t j = n; j != t; --j) {
  ------------------
  |  Branch (198:22): [True: 126k, False: 125k]
  ------------------
  199|   126k|      const word x_j0 = r.word_at(j);
  200|   126k|      const word x_j1 = r.word_at(j - 1);
  201|   126k|      const word x_j2 = r.word_at(j - 2);
  202|       |
  203|   126k|      word qjt = bigint_divop_vartime(x_j0, x_j1, y_t0);
  204|       |
  205|   126k|      qjt = CT::Mask<word>::is_equal(x_j0, y_t0).select(MP_WORD_MAX, qjt);
  206|       |
  207|       |      // Per HAC 14.23, this operation is required at most twice
  208|   126k|      qjt -= division_check(qjt, y_t0, y_t1, x_j0, x_j1, x_j2);
  209|   126k|      qjt -= division_check(qjt, y_t0, y_t1, x_j0, x_j1, x_j2);
  210|   126k|      BOTAN_DEBUG_ASSERT(division_check(qjt, y_t0, y_t1, x_j0, x_j1, x_j2) == false);
  ------------------
  |  |   99|   126k|      do {                          \
  |  |  100|   126k|      } while(0)
  |  |  ------------------
  |  |  |  Branch (100:15): [Folded - Ignored]
  |  |  ------------------
  ------------------
  211|       |
  212|   126k|      shifted_y >>= BOTAN_MP_WORD_BITS;
  ------------------
  |  |   50|   126k|#define BOTAN_MP_WORD_BITS 64
  ------------------
  213|       |      // Now shifted_y == y << (BOTAN_MP_WORD_BITS * (j-t-1))
  214|       |
  215|       |      // TODO this sequence could be better
  216|   126k|      r -= qjt * shifted_y;
  217|   126k|      qjt -= r.is_negative();
  218|   126k|      r += static_cast<word>(r.is_negative()) * shifted_y;
  219|       |
  220|   126k|      q_words[j - t - 1] = qjt;
  221|   126k|   }
  222|       |
  223|   125k|   r >>= shifts;
  224|       |
  225|   125k|   sign_fixup(x, y_arg, q, r);
  226|       |
  227|   125k|   r_out = r;
  228|   125k|   q_out = q;
  229|   125k|}
divide.cpp:_ZN5Botan12_GLOBAL__N_110sign_fixupERKNS_6BigIntES3_RS1_S4_:
   21|   126k|void sign_fixup(const BigInt& x, const BigInt& y, BigInt& q, BigInt& r) {
   22|   126k|   q.cond_flip_sign(x.sign() != y.sign());
   23|       |
   24|   126k|   if(x.is_negative() && r.is_nonzero()) {
  ------------------
  |  Branch (24:7): [True: 0, False: 126k]
  |  Branch (24:26): [True: 0, False: 0]
  ------------------
   25|      0|      q -= 1;
   26|      0|      r = y.abs() - r;
   27|      0|   }
   28|   126k|}
divide.cpp:_ZN5Botan12_GLOBAL__N_114division_checkEmmmmmm:
   30|   253k|inline bool division_check(word q, word y2, word y1, word x3, word x2, word x1) {
   31|       |   /*
   32|       |   Compute (y3,y2,y1) = (y2,y1) * q
   33|       |   and return true if (y3,y2,y1) > (x3,x2,x1)
   34|       |   */
   35|       |
   36|   253k|   word y3 = 0;
   37|   253k|   y1 = word_madd2(q, y1, &y3);
   38|   253k|   y2 = word_madd2(q, y2, &y3);
   39|       |
   40|   253k|   const word x[3] = {x1, x2, x3};
   41|   253k|   const word y[3] = {y1, y2, y3};
   42|       |
   43|   253k|   return bigint_ct_is_lt(x, 3, y, 3).as_bool();
   44|   253k|}

_ZN5Botan17bigint_comba_mul4EPmPKmS2_:
   54|    481|void bigint_comba_mul4(word z[8], const word x[4], const word y[4]) {
   55|    481|   word w2 = 0, w1 = 0, w0 = 0;
   56|       |
   57|    481|   word3_muladd(&w2, &w1, &w0, x[0], y[0]);
   58|    481|   z[0] = w0;
   59|    481|   w0 = 0;
   60|       |
   61|    481|   word3_muladd(&w0, &w2, &w1, x[0], y[1]);
   62|    481|   word3_muladd(&w0, &w2, &w1, x[1], y[0]);
   63|    481|   z[1] = w1;
   64|    481|   w1 = 0;
   65|       |
   66|    481|   word3_muladd(&w1, &w0, &w2, x[0], y[2]);
   67|    481|   word3_muladd(&w1, &w0, &w2, x[1], y[1]);
   68|    481|   word3_muladd(&w1, &w0, &w2, x[2], y[0]);
   69|    481|   z[2] = w2;
   70|    481|   w2 = 0;
   71|       |
   72|    481|   word3_muladd(&w2, &w1, &w0, x[0], y[3]);
   73|    481|   word3_muladd(&w2, &w1, &w0, x[1], y[2]);
   74|    481|   word3_muladd(&w2, &w1, &w0, x[2], y[1]);
   75|    481|   word3_muladd(&w2, &w1, &w0, x[3], y[0]);
   76|    481|   z[3] = w0;
   77|    481|   w0 = 0;
   78|       |
   79|    481|   word3_muladd(&w0, &w2, &w1, x[1], y[3]);
   80|    481|   word3_muladd(&w0, &w2, &w1, x[2], y[2]);
   81|    481|   word3_muladd(&w0, &w2, &w1, x[3], y[1]);
   82|    481|   z[4] = w1;
   83|    481|   w1 = 0;
   84|       |
   85|    481|   word3_muladd(&w1, &w0, &w2, x[2], y[3]);
   86|    481|   word3_muladd(&w1, &w0, &w2, x[3], y[2]);
   87|    481|   z[5] = w2;
   88|    481|   w2 = 0;
   89|       |
   90|    481|   word3_muladd(&w2, &w1, &w0, x[3], y[3]);
   91|    481|   z[6] = w0;
   92|    481|   z[7] = w1;
   93|    481|}
_ZN5Botan17bigint_comba_sqr6EPmPKm:
   98|  35.2M|void bigint_comba_sqr6(word z[12], const word x[6]) {
   99|  35.2M|   word w2 = 0, w1 = 0, w0 = 0;
  100|       |
  101|  35.2M|   word3_muladd(&w2, &w1, &w0, x[0], x[0]);
  102|  35.2M|   z[0] = w0;
  103|  35.2M|   w0 = 0;
  104|       |
  105|  35.2M|   word3_muladd_2(&w0, &w2, &w1, x[0], x[1]);
  106|  35.2M|   z[1] = w1;
  107|  35.2M|   w1 = 0;
  108|       |
  109|  35.2M|   word3_muladd_2(&w1, &w0, &w2, x[0], x[2]);
  110|  35.2M|   word3_muladd(&w1, &w0, &w2, x[1], x[1]);
  111|  35.2M|   z[2] = w2;
  112|  35.2M|   w2 = 0;
  113|       |
  114|  35.2M|   word3_muladd_2(&w2, &w1, &w0, x[0], x[3]);
  115|  35.2M|   word3_muladd_2(&w2, &w1, &w0, x[1], x[2]);
  116|  35.2M|   z[3] = w0;
  117|  35.2M|   w0 = 0;
  118|       |
  119|  35.2M|   word3_muladd_2(&w0, &w2, &w1, x[0], x[4]);
  120|  35.2M|   word3_muladd_2(&w0, &w2, &w1, x[1], x[3]);
  121|  35.2M|   word3_muladd(&w0, &w2, &w1, x[2], x[2]);
  122|  35.2M|   z[4] = w1;
  123|  35.2M|   w1 = 0;
  124|       |
  125|  35.2M|   word3_muladd_2(&w1, &w0, &w2, x[0], x[5]);
  126|  35.2M|   word3_muladd_2(&w1, &w0, &w2, x[1], x[4]);
  127|  35.2M|   word3_muladd_2(&w1, &w0, &w2, x[2], x[3]);
  128|  35.2M|   z[5] = w2;
  129|  35.2M|   w2 = 0;
  130|       |
  131|  35.2M|   word3_muladd_2(&w2, &w1, &w0, x[1], x[5]);
  132|  35.2M|   word3_muladd_2(&w2, &w1, &w0, x[2], x[4]);
  133|  35.2M|   word3_muladd(&w2, &w1, &w0, x[3], x[3]);
  134|  35.2M|   z[6] = w0;
  135|  35.2M|   w0 = 0;
  136|       |
  137|  35.2M|   word3_muladd_2(&w0, &w2, &w1, x[2], x[5]);
  138|  35.2M|   word3_muladd_2(&w0, &w2, &w1, x[3], x[4]);
  139|  35.2M|   z[7] = w1;
  140|  35.2M|   w1 = 0;
  141|       |
  142|  35.2M|   word3_muladd_2(&w1, &w0, &w2, x[3], x[5]);
  143|  35.2M|   word3_muladd(&w1, &w0, &w2, x[4], x[4]);
  144|  35.2M|   z[8] = w2;
  145|  35.2M|   w2 = 0;
  146|       |
  147|  35.2M|   word3_muladd_2(&w2, &w1, &w0, x[4], x[5]);
  148|  35.2M|   z[9] = w0;
  149|  35.2M|   w0 = 0;
  150|       |
  151|  35.2M|   word3_muladd(&w0, &w2, &w1, x[5], x[5]);
  152|  35.2M|   z[10] = w1;
  153|  35.2M|   z[11] = w2;
  154|  35.2M|}
_ZN5Botan17bigint_comba_mul6EPmPKmS2_:
  159|  30.2M|void bigint_comba_mul6(word z[12], const word x[6], const word y[6]) {
  160|  30.2M|   word w2 = 0, w1 = 0, w0 = 0;
  161|       |
  162|  30.2M|   word3_muladd(&w2, &w1, &w0, x[0], y[0]);
  163|  30.2M|   z[0] = w0;
  164|  30.2M|   w0 = 0;
  165|       |
  166|  30.2M|   word3_muladd(&w0, &w2, &w1, x[0], y[1]);
  167|  30.2M|   word3_muladd(&w0, &w2, &w1, x[1], y[0]);
  168|  30.2M|   z[1] = w1;
  169|  30.2M|   w1 = 0;
  170|       |
  171|  30.2M|   word3_muladd(&w1, &w0, &w2, x[0], y[2]);
  172|  30.2M|   word3_muladd(&w1, &w0, &w2, x[1], y[1]);
  173|  30.2M|   word3_muladd(&w1, &w0, &w2, x[2], y[0]);
  174|  30.2M|   z[2] = w2;
  175|  30.2M|   w2 = 0;
  176|       |
  177|  30.2M|   word3_muladd(&w2, &w1, &w0, x[0], y[3]);
  178|  30.2M|   word3_muladd(&w2, &w1, &w0, x[1], y[2]);
  179|  30.2M|   word3_muladd(&w2, &w1, &w0, x[2], y[1]);
  180|  30.2M|   word3_muladd(&w2, &w1, &w0, x[3], y[0]);
  181|  30.2M|   z[3] = w0;
  182|  30.2M|   w0 = 0;
  183|       |
  184|  30.2M|   word3_muladd(&w0, &w2, &w1, x[0], y[4]);
  185|  30.2M|   word3_muladd(&w0, &w2, &w1, x[1], y[3]);
  186|  30.2M|   word3_muladd(&w0, &w2, &w1, x[2], y[2]);
  187|  30.2M|   word3_muladd(&w0, &w2, &w1, x[3], y[1]);
  188|  30.2M|   word3_muladd(&w0, &w2, &w1, x[4], y[0]);
  189|  30.2M|   z[4] = w1;
  190|  30.2M|   w1 = 0;
  191|       |
  192|  30.2M|   word3_muladd(&w1, &w0, &w2, x[0], y[5]);
  193|  30.2M|   word3_muladd(&w1, &w0, &w2, x[1], y[4]);
  194|  30.2M|   word3_muladd(&w1, &w0, &w2, x[2], y[3]);
  195|  30.2M|   word3_muladd(&w1, &w0, &w2, x[3], y[2]);
  196|  30.2M|   word3_muladd(&w1, &w0, &w2, x[4], y[1]);
  197|  30.2M|   word3_muladd(&w1, &w0, &w2, x[5], y[0]);
  198|  30.2M|   z[5] = w2;
  199|  30.2M|   w2 = 0;
  200|       |
  201|  30.2M|   word3_muladd(&w2, &w1, &w0, x[1], y[5]);
  202|  30.2M|   word3_muladd(&w2, &w1, &w0, x[2], y[4]);
  203|  30.2M|   word3_muladd(&w2, &w1, &w0, x[3], y[3]);
  204|  30.2M|   word3_muladd(&w2, &w1, &w0, x[4], y[2]);
  205|  30.2M|   word3_muladd(&w2, &w1, &w0, x[5], y[1]);
  206|  30.2M|   z[6] = w0;
  207|  30.2M|   w0 = 0;
  208|       |
  209|  30.2M|   word3_muladd(&w0, &w2, &w1, x[2], y[5]);
  210|  30.2M|   word3_muladd(&w0, &w2, &w1, x[3], y[4]);
  211|  30.2M|   word3_muladd(&w0, &w2, &w1, x[4], y[3]);
  212|  30.2M|   word3_muladd(&w0, &w2, &w1, x[5], y[2]);
  213|  30.2M|   z[7] = w1;
  214|  30.2M|   w1 = 0;
  215|       |
  216|  30.2M|   word3_muladd(&w1, &w0, &w2, x[3], y[5]);
  217|  30.2M|   word3_muladd(&w1, &w0, &w2, x[4], y[4]);
  218|  30.2M|   word3_muladd(&w1, &w0, &w2, x[5], y[3]);
  219|  30.2M|   z[8] = w2;
  220|  30.2M|   w2 = 0;
  221|       |
  222|  30.2M|   word3_muladd(&w2, &w1, &w0, x[4], y[5]);
  223|  30.2M|   word3_muladd(&w2, &w1, &w0, x[5], y[4]);
  224|  30.2M|   z[9] = w0;
  225|  30.2M|   w0 = 0;
  226|       |
  227|  30.2M|   word3_muladd(&w0, &w2, &w1, x[5], y[5]);
  228|  30.2M|   z[10] = w1;
  229|  30.2M|   z[11] = w2;
  230|  30.2M|}
_ZN5Botan17bigint_comba_mul8EPmPKmS2_:
  323|     36|void bigint_comba_mul8(word z[16], const word x[8], const word y[8]) {
  324|     36|   word w2 = 0, w1 = 0, w0 = 0;
  325|       |
  326|     36|   word3_muladd(&w2, &w1, &w0, x[0], y[0]);
  327|     36|   z[0] = w0;
  328|     36|   w0 = 0;
  329|       |
  330|     36|   word3_muladd(&w0, &w2, &w1, x[0], y[1]);
  331|     36|   word3_muladd(&w0, &w2, &w1, x[1], y[0]);
  332|     36|   z[1] = w1;
  333|     36|   w1 = 0;
  334|       |
  335|     36|   word3_muladd(&w1, &w0, &w2, x[0], y[2]);
  336|     36|   word3_muladd(&w1, &w0, &w2, x[1], y[1]);
  337|     36|   word3_muladd(&w1, &w0, &w2, x[2], y[0]);
  338|     36|   z[2] = w2;
  339|     36|   w2 = 0;
  340|       |
  341|     36|   word3_muladd(&w2, &w1, &w0, x[0], y[3]);
  342|     36|   word3_muladd(&w2, &w1, &w0, x[1], y[2]);
  343|     36|   word3_muladd(&w2, &w1, &w0, x[2], y[1]);
  344|     36|   word3_muladd(&w2, &w1, &w0, x[3], y[0]);
  345|     36|   z[3] = w0;
  346|     36|   w0 = 0;
  347|       |
  348|     36|   word3_muladd(&w0, &w2, &w1, x[0], y[4]);
  349|     36|   word3_muladd(&w0, &w2, &w1, x[1], y[3]);
  350|     36|   word3_muladd(&w0, &w2, &w1, x[2], y[2]);
  351|     36|   word3_muladd(&w0, &w2, &w1, x[3], y[1]);
  352|     36|   word3_muladd(&w0, &w2, &w1, x[4], y[0]);
  353|     36|   z[4] = w1;
  354|     36|   w1 = 0;
  355|       |
  356|     36|   word3_muladd(&w1, &w0, &w2, x[0], y[5]);
  357|     36|   word3_muladd(&w1, &w0, &w2, x[1], y[4]);
  358|     36|   word3_muladd(&w1, &w0, &w2, x[2], y[3]);
  359|     36|   word3_muladd(&w1, &w0, &w2, x[3], y[2]);
  360|     36|   word3_muladd(&w1, &w0, &w2, x[4], y[1]);
  361|     36|   word3_muladd(&w1, &w0, &w2, x[5], y[0]);
  362|     36|   z[5] = w2;
  363|     36|   w2 = 0;
  364|       |
  365|     36|   word3_muladd(&w2, &w1, &w0, x[0], y[6]);
  366|     36|   word3_muladd(&w2, &w1, &w0, x[1], y[5]);
  367|     36|   word3_muladd(&w2, &w1, &w0, x[2], y[4]);
  368|     36|   word3_muladd(&w2, &w1, &w0, x[3], y[3]);
  369|     36|   word3_muladd(&w2, &w1, &w0, x[4], y[2]);
  370|     36|   word3_muladd(&w2, &w1, &w0, x[5], y[1]);
  371|     36|   word3_muladd(&w2, &w1, &w0, x[6], y[0]);
  372|     36|   z[6] = w0;
  373|     36|   w0 = 0;
  374|       |
  375|     36|   word3_muladd(&w0, &w2, &w1, x[0], y[7]);
  376|     36|   word3_muladd(&w0, &w2, &w1, x[1], y[6]);
  377|     36|   word3_muladd(&w0, &w2, &w1, x[2], y[5]);
  378|     36|   word3_muladd(&w0, &w2, &w1, x[3], y[4]);
  379|     36|   word3_muladd(&w0, &w2, &w1, x[4], y[3]);
  380|     36|   word3_muladd(&w0, &w2, &w1, x[5], y[2]);
  381|     36|   word3_muladd(&w0, &w2, &w1, x[6], y[1]);
  382|     36|   word3_muladd(&w0, &w2, &w1, x[7], y[0]);
  383|     36|   z[7] = w1;
  384|     36|   w1 = 0;
  385|       |
  386|     36|   word3_muladd(&w1, &w0, &w2, x[1], y[7]);
  387|     36|   word3_muladd(&w1, &w0, &w2, x[2], y[6]);
  388|     36|   word3_muladd(&w1, &w0, &w2, x[3], y[5]);
  389|     36|   word3_muladd(&w1, &w0, &w2, x[4], y[4]);
  390|     36|   word3_muladd(&w1, &w0, &w2, x[5], y[3]);
  391|     36|   word3_muladd(&w1, &w0, &w2, x[6], y[2]);
  392|     36|   word3_muladd(&w1, &w0, &w2, x[7], y[1]);
  393|     36|   z[8] = w2;
  394|     36|   w2 = 0;
  395|       |
  396|     36|   word3_muladd(&w2, &w1, &w0, x[2], y[7]);
  397|     36|   word3_muladd(&w2, &w1, &w0, x[3], y[6]);
  398|     36|   word3_muladd(&w2, &w1, &w0, x[4], y[5]);
  399|     36|   word3_muladd(&w2, &w1, &w0, x[5], y[4]);
  400|     36|   word3_muladd(&w2, &w1, &w0, x[6], y[3]);
  401|     36|   word3_muladd(&w2, &w1, &w0, x[7], y[2]);
  402|     36|   z[9] = w0;
  403|     36|   w0 = 0;
  404|       |
  405|     36|   word3_muladd(&w0, &w2, &w1, x[3], y[7]);
  406|     36|   word3_muladd(&w0, &w2, &w1, x[4], y[6]);
  407|     36|   word3_muladd(&w0, &w2, &w1, x[5], y[5]);
  408|     36|   word3_muladd(&w0, &w2, &w1, x[6], y[4]);
  409|     36|   word3_muladd(&w0, &w2, &w1, x[7], y[3]);
  410|     36|   z[10] = w1;
  411|     36|   w1 = 0;
  412|       |
  413|     36|   word3_muladd(&w1, &w0, &w2, x[4], y[7]);
  414|     36|   word3_muladd(&w1, &w0, &w2, x[5], y[6]);
  415|     36|   word3_muladd(&w1, &w0, &w2, x[6], y[5]);
  416|     36|   word3_muladd(&w1, &w0, &w2, x[7], y[4]);
  417|     36|   z[11] = w2;
  418|     36|   w2 = 0;
  419|       |
  420|     36|   word3_muladd(&w2, &w1, &w0, x[5], y[7]);
  421|     36|   word3_muladd(&w2, &w1, &w0, x[6], y[6]);
  422|     36|   word3_muladd(&w2, &w1, &w0, x[7], y[5]);
  423|     36|   z[12] = w0;
  424|     36|   w0 = 0;
  425|       |
  426|     36|   word3_muladd(&w0, &w2, &w1, x[6], y[7]);
  427|     36|   word3_muladd(&w0, &w2, &w1, x[7], y[6]);
  428|     36|   z[13] = w1;
  429|     36|   w1 = 0;
  430|       |
  431|     36|   word3_muladd(&w1, &w0, &w2, x[7], y[7]);
  432|     36|   z[14] = w2;
  433|     36|   z[15] = w0;
  434|     36|}

_ZN5Botan12basecase_mulEPmmPKmmS2_m:
   20|  1.73k|void basecase_mul(word z[], size_t z_size, const word x[], size_t x_size, const word y[], size_t y_size) {
   21|  1.73k|   if(z_size < x_size + y_size) {
  ------------------
  |  Branch (21:7): [True: 0, False: 1.73k]
  ------------------
   22|      0|      throw Invalid_Argument("basecase_mul z_size too small");
   23|      0|   }
   24|       |
   25|  1.73k|   const size_t x_size_8 = x_size - (x_size % 8);
   26|       |
   27|  1.73k|   clear_mem(z, z_size);
   28|       |
   29|  13.7k|   for(size_t i = 0; i != y_size; ++i) {
  ------------------
  |  Branch (29:22): [True: 12.0k, False: 1.73k]
  ------------------
   30|  12.0k|      const word y_i = y[i];
   31|       |
   32|  12.0k|      word carry = 0;
   33|       |
   34|  12.3k|      for(size_t j = 0; j != x_size_8; j += 8) {
  ------------------
  |  Branch (34:25): [True: 265, False: 12.0k]
  ------------------
   35|    265|         carry = word8_madd3(z + i + j, x + j, y_i, carry);
   36|    265|      }
   37|       |
   38|  36.3k|      for(size_t j = x_size_8; j != x_size; ++j) {
  ------------------
  |  Branch (38:32): [True: 24.3k, False: 12.0k]
  ------------------
   39|  24.3k|         z[i + j] = word_madd3(x[j], y_i, z[i + j], &carry);
   40|  24.3k|      }
   41|       |
   42|  12.0k|      z[x_size + i] = carry;
   43|  12.0k|   }
   44|  1.73k|}
_ZN5Botan12basecase_sqrEPmmPKmm:
   46|    837|void basecase_sqr(word z[], size_t z_size, const word x[], size_t x_size) {
   47|    837|   if(z_size < 2 * x_size) {
  ------------------
  |  Branch (47:7): [True: 0, False: 837]
  ------------------
   48|      0|      throw Invalid_Argument("basecase_sqr z_size too small");
   49|      0|   }
   50|       |
   51|    837|   const size_t x_size_8 = x_size - (x_size % 8);
   52|       |
   53|    837|   clear_mem(z, z_size);
   54|       |
   55|  3.34k|   for(size_t i = 0; i != x_size; ++i) {
  ------------------
  |  Branch (55:22): [True: 2.51k, False: 837]
  ------------------
   56|  2.51k|      const word x_i = x[i];
   57|       |
   58|  2.51k|      word carry = 0;
   59|       |
   60|  2.51k|      for(size_t j = 0; j != x_size_8; j += 8) {
  ------------------
  |  Branch (60:25): [True: 0, False: 2.51k]
  ------------------
   61|      0|         carry = word8_madd3(z + i + j, x + j, x_i, carry);
   62|      0|      }
   63|       |
   64|  10.0k|      for(size_t j = x_size_8; j != x_size; ++j) {
  ------------------
  |  Branch (64:32): [True: 7.53k, False: 2.51k]
  ------------------
   65|  7.53k|         z[i + j] = word_madd3(x[j], x_i, z[i + j], &carry);
   66|  7.53k|      }
   67|       |
   68|  2.51k|      z[x_size + i] = carry;
   69|  2.51k|   }
   70|    837|}
_ZN5Botan10bigint_mulEPmmPKmmmS2_mmS0_m:
  291|  30.2M|                size_t ws_size) {
  292|  30.2M|   clear_mem(z, z_size);
  293|       |
  294|  30.2M|   if(x_sw == 1) {
  ------------------
  |  Branch (294:7): [True: 0, False: 30.2M]
  ------------------
  295|      0|      bigint_linmul3(z, y, y_sw, x[0]);
  296|  30.2M|   } else if(y_sw == 1) {
  ------------------
  |  Branch (296:14): [True: 0, False: 30.2M]
  ------------------
  297|      0|      bigint_linmul3(z, x, x_sw, y[0]);
  298|  30.2M|   } else if(sized_for_comba_mul<4>(x_sw, x_size, y_sw, y_size, z_size)) {
  ------------------
  |  Branch (298:14): [True: 481, False: 30.2M]
  ------------------
  299|    481|      bigint_comba_mul4(z, x, y);
  300|  30.2M|   } else if(sized_for_comba_mul<6>(x_sw, x_size, y_sw, y_size, z_size)) {
  ------------------
  |  Branch (300:14): [True: 30.2M, False: 1.76k]
  ------------------
  301|  30.2M|      bigint_comba_mul6(z, x, y);
  302|  30.2M|   } else if(sized_for_comba_mul<8>(x_sw, x_size, y_sw, y_size, z_size)) {
  ------------------
  |  Branch (302:14): [True: 36, False: 1.73k]
  ------------------
  303|     36|      bigint_comba_mul8(z, x, y);
  304|  1.73k|   } else if(sized_for_comba_mul<9>(x_sw, x_size, y_sw, y_size, z_size)) {
  ------------------
  |  Branch (304:14): [True: 0, False: 1.73k]
  ------------------
  305|      0|      bigint_comba_mul9(z, x, y);
  306|  1.73k|   } else if(sized_for_comba_mul<16>(x_sw, x_size, y_sw, y_size, z_size)) {
  ------------------
  |  Branch (306:14): [True: 0, False: 1.73k]
  ------------------
  307|      0|      bigint_comba_mul16(z, x, y);
  308|  1.73k|   } else if(sized_for_comba_mul<24>(x_sw, x_size, y_sw, y_size, z_size)) {
  ------------------
  |  Branch (308:14): [True: 0, False: 1.73k]
  ------------------
  309|      0|      bigint_comba_mul24(z, x, y);
  310|  1.73k|   } else if(x_sw < KARATSUBA_MULTIPLY_THRESHOLD || y_sw < KARATSUBA_MULTIPLY_THRESHOLD || !workspace) {
  ------------------
  |  Branch (310:14): [True: 1.73k, False: 0]
  |  Branch (310:53): [True: 0, False: 0]
  |  Branch (310:92): [True: 0, False: 0]
  ------------------
  311|  1.73k|      basecase_mul(z, z_size, x, x_sw, y, y_sw);
  312|  1.73k|   } else {
  313|      0|      const size_t N = karatsuba_size(z_size, x_size, x_sw, y_size, y_sw);
  314|       |
  315|      0|      if(N && z_size >= 2 * N && ws_size >= 2 * N) {
  ------------------
  |  Branch (315:10): [True: 0, False: 0]
  |  Branch (315:15): [True: 0, False: 0]
  |  Branch (315:34): [True: 0, False: 0]
  ------------------
  316|      0|         karatsuba_mul(z, x, y, N, workspace);
  317|      0|      } else {
  318|      0|         basecase_mul(z, z_size, x, x_sw, y, y_sw);
  319|      0|      }
  320|      0|   }
  321|  30.2M|}
_ZN5Botan10bigint_sqrEPmmPKmmmS0_m:
  326|  35.2M|void bigint_sqr(word z[], size_t z_size, const word x[], size_t x_size, size_t x_sw, word workspace[], size_t ws_size) {
  327|  35.2M|   clear_mem(z, z_size);
  328|       |
  329|  35.2M|   BOTAN_ASSERT(z_size / 2 >= x_sw, "Output size is sufficient");
  ------------------
  |  |   51|  35.2M|   do {                                                                                 \
  |  |   52|  35.2M|      if(!(expr))                                                                       \
  |  |  ------------------
  |  |  |  Branch (52:10): [True: 0, False: 35.2M]
  |  |  ------------------
  |  |   53|  35.2M|         Botan::assertion_failure(#expr, assertion_made, __func__, __FILE__, __LINE__); \
  |  |   54|  35.2M|   } while(0)
  |  |  ------------------
  |  |  |  Branch (54:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  330|       |
  331|  35.2M|   if(x_sw == 1) {
  ------------------
  |  Branch (331:7): [True: 0, False: 35.2M]
  ------------------
  332|      0|      bigint_linmul3(z, x, x_sw, x[0]);
  333|  35.2M|   } else if(sized_for_comba_sqr<4>(x_sw, x_size, z_size)) {
  ------------------
  |  Branch (333:14): [True: 0, False: 35.2M]
  ------------------
  334|      0|      bigint_comba_sqr4(z, x);
  335|  35.2M|   } else if(sized_for_comba_sqr<6>(x_sw, x_size, z_size)) {
  ------------------
  |  Branch (335:14): [True: 35.2M, False: 837]
  ------------------
  336|  35.2M|      bigint_comba_sqr6(z, x);
  337|  35.2M|   } else if(sized_for_comba_sqr<8>(x_sw, x_size, z_size)) {
  ------------------
  |  Branch (337:14): [True: 0, False: 837]
  ------------------
  338|      0|      bigint_comba_sqr8(z, x);
  339|    837|   } else if(sized_for_comba_sqr<9>(x_sw, x_size, z_size)) {
  ------------------
  |  Branch (339:14): [True: 0, False: 837]
  ------------------
  340|      0|      bigint_comba_sqr9(z, x);
  341|    837|   } else if(sized_for_comba_sqr<16>(x_sw, x_size, z_size)) {
  ------------------
  |  Branch (341:14): [True: 0, False: 837]
  ------------------
  342|      0|      bigint_comba_sqr16(z, x);
  343|    837|   } else if(sized_for_comba_sqr<24>(x_sw, x_size, z_size)) {
  ------------------
  |  Branch (343:14): [True: 0, False: 837]
  ------------------
  344|      0|      bigint_comba_sqr24(z, x);
  345|    837|   } else if(x_size < KARATSUBA_SQUARE_THRESHOLD || !workspace) {
  ------------------
  |  Branch (345:14): [True: 837, False: 0]
  |  Branch (345:53): [True: 0, False: 0]
  ------------------
  346|    837|      basecase_sqr(z, z_size, x, x_sw);
  347|    837|   } else {
  348|      0|      const size_t N = karatsuba_size(z_size, x_size, x_sw);
  349|       |
  350|      0|      if(N && z_size >= 2 * N && ws_size >= 2 * N) {
  ------------------
  |  Branch (350:10): [True: 0, False: 0]
  |  Branch (350:15): [True: 0, False: 0]
  |  Branch (350:34): [True: 0, False: 0]
  ------------------
  351|      0|         karatsuba_sqr(z, x, N, workspace);
  352|      0|      } else {
  353|      0|         basecase_sqr(z, z_size, x, x_sw);
  354|      0|      }
  355|      0|   }
  356|  35.2M|}
mp_karat.cpp:_ZN5Botan12_GLOBAL__N_119sized_for_comba_mulILm4EEEbmmmmm:
  271|  30.2M|inline bool sized_for_comba_mul(size_t x_sw, size_t x_size, size_t y_sw, size_t y_size, size_t z_size) {
  272|  30.2M|   return (x_sw <= SZ && x_size >= SZ && y_sw <= SZ && y_size >= SZ && z_size >= 2 * SZ);
  ------------------
  |  Branch (272:12): [True: 3.00k, False: 30.2M]
  |  Branch (272:26): [True: 3.00k, False: 0]
  |  Branch (272:42): [True: 481, False: 2.52k]
  |  Branch (272:56): [True: 481, False: 0]
  |  Branch (272:72): [True: 481, False: 0]
  ------------------
  273|  30.2M|}
mp_karat.cpp:_ZN5Botan12_GLOBAL__N_119sized_for_comba_mulILm6EEEbmmmmm:
  271|  30.2M|inline bool sized_for_comba_mul(size_t x_sw, size_t x_size, size_t y_sw, size_t y_size, size_t z_size) {
  272|  30.2M|   return (x_sw <= SZ && x_size >= SZ && y_sw <= SZ && y_size >= SZ && z_size >= 2 * SZ);
  ------------------
  |  Branch (272:12): [True: 30.2M, False: 84]
  |  Branch (272:26): [True: 30.2M, False: 0]
  |  Branch (272:42): [True: 30.2M, False: 1.68k]
  |  Branch (272:56): [True: 30.2M, False: 0]
  |  Branch (272:72): [True: 30.2M, False: 0]
  ------------------
  273|  30.2M|}
mp_karat.cpp:_ZN5Botan12_GLOBAL__N_119sized_for_comba_mulILm8EEEbmmmmm:
  271|  1.76k|inline bool sized_for_comba_mul(size_t x_sw, size_t x_size, size_t y_sw, size_t y_size, size_t z_size) {
  272|  1.76k|   return (x_sw <= SZ && x_size >= SZ && y_sw <= SZ && y_size >= SZ && z_size >= 2 * SZ);
  ------------------
  |  Branch (272:12): [True: 1.72k, False: 48]
  |  Branch (272:26): [True: 1.72k, False: 0]
  |  Branch (272:42): [True: 1.72k, False: 0]
  |  Branch (272:56): [True: 1.72k, False: 0]
  |  Branch (272:72): [True: 36, False: 1.68k]
  ------------------
  273|  1.76k|}
mp_karat.cpp:_ZN5Botan12_GLOBAL__N_119sized_for_comba_mulILm9EEEbmmmmm:
  271|  1.73k|inline bool sized_for_comba_mul(size_t x_sw, size_t x_size, size_t y_sw, size_t y_size, size_t z_size) {
  272|  1.73k|   return (x_sw <= SZ && x_size >= SZ && y_sw <= SZ && y_size >= SZ && z_size >= 2 * SZ);
  ------------------
  |  Branch (272:12): [True: 1.69k, False: 42]
  |  Branch (272:26): [True: 843, False: 847]
  |  Branch (272:42): [True: 843, False: 0]
  |  Branch (272:56): [True: 837, False: 6]
  |  Branch (272:72): [True: 0, False: 837]
  ------------------
  273|  1.73k|}
mp_karat.cpp:_ZN5Botan12_GLOBAL__N_119sized_for_comba_mulILm16EEEbmmmmm:
  271|  1.73k|inline bool sized_for_comba_mul(size_t x_sw, size_t x_size, size_t y_sw, size_t y_size, size_t z_size) {
  272|  1.73k|   return (x_sw <= SZ && x_size >= SZ && y_sw <= SZ && y_size >= SZ && z_size >= 2 * SZ);
  ------------------
  |  Branch (272:12): [True: 1.73k, False: 0]
  |  Branch (272:26): [True: 885, False: 847]
  |  Branch (272:42): [True: 885, False: 0]
  |  Branch (272:56): [True: 837, False: 48]
  |  Branch (272:72): [True: 0, False: 837]
  ------------------
  273|  1.73k|}
mp_karat.cpp:_ZN5Botan12_GLOBAL__N_119sized_for_comba_mulILm24EEEbmmmmm:
  271|  1.73k|inline bool sized_for_comba_mul(size_t x_sw, size_t x_size, size_t y_sw, size_t y_size, size_t z_size) {
  272|  1.73k|   return (x_sw <= SZ && x_size >= SZ && y_sw <= SZ && y_size >= SZ && z_size >= 2 * SZ);
  ------------------
  |  Branch (272:12): [True: 1.73k, False: 0]
  |  Branch (272:26): [True: 885, False: 847]
  |  Branch (272:42): [True: 885, False: 0]
  |  Branch (272:56): [True: 0, False: 885]
  |  Branch (272:72): [True: 0, False: 0]
  ------------------
  273|  1.73k|}
mp_karat.cpp:_ZN5Botan12_GLOBAL__N_119sized_for_comba_sqrILm4EEEbmmm:
  276|  35.2M|inline bool sized_for_comba_sqr(size_t x_sw, size_t x_size, size_t z_size) {
  277|  35.2M|   return (x_sw <= SZ && x_size >= SZ && z_size >= 2 * SZ);
  ------------------
  |  Branch (277:12): [True: 837, False: 35.2M]
  |  Branch (277:26): [True: 837, False: 0]
  |  Branch (277:42): [True: 0, False: 837]
  ------------------
  278|  35.2M|}
mp_karat.cpp:_ZN5Botan12_GLOBAL__N_119sized_for_comba_sqrILm6EEEbmmm:
  276|  35.2M|inline bool sized_for_comba_sqr(size_t x_sw, size_t x_size, size_t z_size) {
  277|  35.2M|   return (x_sw <= SZ && x_size >= SZ && z_size >= 2 * SZ);
  ------------------
  |  Branch (277:12): [True: 35.2M, False: 0]
  |  Branch (277:26): [True: 35.2M, False: 0]
  |  Branch (277:42): [True: 35.2M, False: 837]
  ------------------
  278|  35.2M|}
mp_karat.cpp:_ZN5Botan12_GLOBAL__N_119sized_for_comba_sqrILm8EEEbmmm:
  276|    837|inline bool sized_for_comba_sqr(size_t x_sw, size_t x_size, size_t z_size) {
  277|    837|   return (x_sw <= SZ && x_size >= SZ && z_size >= 2 * SZ);
  ------------------
  |  Branch (277:12): [True: 837, False: 0]
  |  Branch (277:26): [True: 837, False: 0]
  |  Branch (277:42): [True: 0, False: 837]
  ------------------
  278|    837|}
mp_karat.cpp:_ZN5Botan12_GLOBAL__N_119sized_for_comba_sqrILm9EEEbmmm:
  276|    837|inline bool sized_for_comba_sqr(size_t x_sw, size_t x_size, size_t z_size) {
  277|    837|   return (x_sw <= SZ && x_size >= SZ && z_size >= 2 * SZ);
  ------------------
  |  Branch (277:12): [True: 837, False: 0]
  |  Branch (277:26): [True: 837, False: 0]
  |  Branch (277:42): [True: 0, False: 837]
  ------------------
  278|    837|}
mp_karat.cpp:_ZN5Botan12_GLOBAL__N_119sized_for_comba_sqrILm16EEEbmmm:
  276|    837|inline bool sized_for_comba_sqr(size_t x_sw, size_t x_size, size_t z_size) {
  277|    837|   return (x_sw <= SZ && x_size >= SZ && z_size >= 2 * SZ);
  ------------------
  |  Branch (277:12): [True: 837, False: 0]
  |  Branch (277:26): [True: 0, False: 837]
  |  Branch (277:42): [True: 0, False: 0]
  ------------------
  278|    837|}
mp_karat.cpp:_ZN5Botan12_GLOBAL__N_119sized_for_comba_sqrILm24EEEbmmm:
  276|    837|inline bool sized_for_comba_sqr(size_t x_sw, size_t x_size, size_t z_size) {
  277|    837|   return (x_sw <= SZ && x_size >= SZ && z_size >= 2 * SZ);
  ------------------
  |  Branch (277:12): [True: 837, False: 0]
  |  Branch (277:26): [True: 0, False: 837]
  |  Branch (277:42): [True: 0, False: 0]
  ------------------
  278|    837|}

_ZN5Botan19bigint_monty_redc_6EPmPKmmS0_:
   75|   392k|void bigint_monty_redc_6(word z[12], const word p[6], word p_dash, word ws[]) {
   76|   392k|   word w2 = 0, w1 = 0, w0 = 0;
   77|   392k|   w0 = z[0];
   78|   392k|   ws[0] = w0 * p_dash;
   79|   392k|   word3_muladd(&w2, &w1, &w0, ws[0], p[0]);
   80|   392k|   w0 = w1;
   81|   392k|   w1 = w2;
   82|   392k|   w2 = 0;
   83|   392k|   word3_muladd(&w2, &w1, &w0, ws[0], p[1]);
   84|   392k|   word3_add(&w2, &w1, &w0, z[1]);
   85|   392k|   ws[1] = w0 * p_dash;
   86|   392k|   word3_muladd(&w2, &w1, &w0, ws[1], p[0]);
   87|   392k|   w0 = w1;
   88|   392k|   w1 = w2;
   89|   392k|   w2 = 0;
   90|   392k|   word3_muladd(&w2, &w1, &w0, ws[0], p[2]);
   91|   392k|   word3_muladd(&w2, &w1, &w0, ws[1], p[1]);
   92|   392k|   word3_add(&w2, &w1, &w0, z[2]);
   93|   392k|   ws[2] = w0 * p_dash;
   94|   392k|   word3_muladd(&w2, &w1, &w0, ws[2], p[0]);
   95|   392k|   w0 = w1;
   96|   392k|   w1 = w2;
   97|   392k|   w2 = 0;
   98|   392k|   word3_muladd(&w2, &w1, &w0, ws[0], p[3]);
   99|   392k|   word3_muladd(&w2, &w1, &w0, ws[1], p[2]);
  100|   392k|   word3_muladd(&w2, &w1, &w0, ws[2], p[1]);
  101|   392k|   word3_add(&w2, &w1, &w0, z[3]);
  102|   392k|   ws[3] = w0 * p_dash;
  103|   392k|   word3_muladd(&w2, &w1, &w0, ws[3], p[0]);
  104|   392k|   w0 = w1;
  105|   392k|   w1 = w2;
  106|   392k|   w2 = 0;
  107|   392k|   word3_muladd(&w2, &w1, &w0, ws[0], p[4]);
  108|   392k|   word3_muladd(&w2, &w1, &w0, ws[1], p[3]);
  109|   392k|   word3_muladd(&w2, &w1, &w0, ws[2], p[2]);
  110|   392k|   word3_muladd(&w2, &w1, &w0, ws[3], p[1]);
  111|   392k|   word3_add(&w2, &w1, &w0, z[4]);
  112|   392k|   ws[4] = w0 * p_dash;
  113|   392k|   word3_muladd(&w2, &w1, &w0, ws[4], p[0]);
  114|   392k|   w0 = w1;
  115|   392k|   w1 = w2;
  116|   392k|   w2 = 0;
  117|   392k|   word3_muladd(&w2, &w1, &w0, ws[0], p[5]);
  118|   392k|   word3_muladd(&w2, &w1, &w0, ws[1], p[4]);
  119|   392k|   word3_muladd(&w2, &w1, &w0, ws[2], p[3]);
  120|   392k|   word3_muladd(&w2, &w1, &w0, ws[3], p[2]);
  121|   392k|   word3_muladd(&w2, &w1, &w0, ws[4], p[1]);
  122|   392k|   word3_add(&w2, &w1, &w0, z[5]);
  123|   392k|   ws[5] = w0 * p_dash;
  124|   392k|   word3_muladd(&w2, &w1, &w0, ws[5], p[0]);
  125|   392k|   w0 = w1;
  126|   392k|   w1 = w2;
  127|   392k|   w2 = 0;
  128|   392k|   word3_muladd(&w2, &w1, &w0, ws[1], p[5]);
  129|   392k|   word3_muladd(&w2, &w1, &w0, ws[2], p[4]);
  130|   392k|   word3_muladd(&w2, &w1, &w0, ws[3], p[3]);
  131|   392k|   word3_muladd(&w2, &w1, &w0, ws[4], p[2]);
  132|   392k|   word3_muladd(&w2, &w1, &w0, ws[5], p[1]);
  133|   392k|   word3_add(&w2, &w1, &w0, z[6]);
  134|   392k|   ws[0] = w0;
  135|   392k|   w0 = w1;
  136|   392k|   w1 = w2;
  137|   392k|   w2 = 0;
  138|   392k|   word3_muladd(&w2, &w1, &w0, ws[2], p[5]);
  139|   392k|   word3_muladd(&w2, &w1, &w0, ws[3], p[4]);
  140|   392k|   word3_muladd(&w2, &w1, &w0, ws[4], p[3]);
  141|   392k|   word3_muladd(&w2, &w1, &w0, ws[5], p[2]);
  142|   392k|   word3_add(&w2, &w1, &w0, z[7]);
  143|   392k|   ws[1] = w0;
  144|   392k|   w0 = w1;
  145|   392k|   w1 = w2;
  146|   392k|   w2 = 0;
  147|   392k|   word3_muladd(&w2, &w1, &w0, ws[3], p[5]);
  148|   392k|   word3_muladd(&w2, &w1, &w0, ws[4], p[4]);
  149|   392k|   word3_muladd(&w2, &w1, &w0, ws[5], p[3]);
  150|   392k|   word3_add(&w2, &w1, &w0, z[8]);
  151|   392k|   ws[2] = w0;
  152|   392k|   w0 = w1;
  153|   392k|   w1 = w2;
  154|   392k|   w2 = 0;
  155|   392k|   word3_muladd(&w2, &w1, &w0, ws[4], p[5]);
  156|   392k|   word3_muladd(&w2, &w1, &w0, ws[5], p[4]);
  157|   392k|   word3_add(&w2, &w1, &w0, z[9]);
  158|   392k|   ws[3] = w0;
  159|   392k|   w0 = w1;
  160|   392k|   w1 = w2;
  161|   392k|   w2 = 0;
  162|   392k|   word3_muladd(&w2, &w1, &w0, ws[5], p[5]);
  163|   392k|   word3_add(&w2, &w1, &w0, z[10]);
  164|   392k|   ws[4] = w0;
  165|   392k|   w0 = w1;
  166|   392k|   w1 = w2;
  167|   392k|   w2 = 0;
  168|   392k|   word3_add(&w2, &w1, &w0, z[11]);
  169|   392k|   ws[5] = w0;
  170|   392k|   ws[6] = w1;
  171|   392k|   word borrow = bigint_sub3(z, ws, 6 + 1, p, 6);
  172|   392k|   CT::conditional_assign_mem(borrow, z, ws, 6);
  173|   392k|   clear_mem(z + 6, 6);
  174|   392k|}

_ZN5Botan13monty_inverseEm:
   16|    837|word monty_inverse(word a) {
   17|    837|   if(a % 2 == 0) {
  ------------------
  |  Branch (17:7): [True: 0, False: 837]
  ------------------
   18|      0|      throw Invalid_Argument("monty_inverse only valid for odd integers");
   19|      0|   }
   20|       |
   21|       |   /*
   22|       |   * From "A New Algorithm for Inversion mod p^k" by Çetin Kaya Koç
   23|       |   * https://eprint.iacr.org/2017/411.pdf sections 5 and 7.
   24|       |   */
   25|       |
   26|    837|   word b = 1;
   27|    837|   word r = 0;
   28|       |
   29|  54.4k|   for(size_t i = 0; i != BOTAN_MP_WORD_BITS; ++i) {
  ------------------
  |  |   50|  54.4k|#define BOTAN_MP_WORD_BITS 64
  ------------------
  |  Branch (29:22): [True: 53.5k, False: 837]
  ------------------
   30|  53.5k|      const word bi = b % 2;
   31|  53.5k|      r >>= 1;
   32|  53.5k|      r += bi << (BOTAN_MP_WORD_BITS - 1);
  ------------------
  |  |   50|  53.5k|#define BOTAN_MP_WORD_BITS 64
  ------------------
   33|       |
   34|  53.5k|      b -= a * bi;
   35|  53.5k|      b >>= 1;
   36|  53.5k|   }
   37|       |
   38|       |   // Now invert in addition space
   39|    837|   r = (MP_WORD_MAX - r) + 1;
   40|       |
   41|    837|   return r;
   42|    837|}
_ZN5Botan17Montgomery_ParamsC2ERKNS_6BigIntERKNS_15Modular_ReducerE:
   44|    837|Montgomery_Params::Montgomery_Params(const BigInt& p, const Modular_Reducer& mod_p) {
   45|    837|   if(p.is_even() || p < 3) {
  ------------------
  |  Branch (45:7): [True: 0, False: 837]
  |  Branch (45:22): [True: 0, False: 837]
  ------------------
   46|      0|      throw Invalid_Argument("Montgomery_Params invalid modulus");
   47|      0|   }
   48|       |
   49|    837|   m_p = p;
   50|    837|   m_p_words = m_p.sig_words();
   51|    837|   m_p_dash = monty_inverse(m_p.word_at(0));
   52|       |
   53|    837|   const BigInt r = BigInt::power_of_2(m_p_words * BOTAN_MP_WORD_BITS);
  ------------------
  |  |   50|    837|#define BOTAN_MP_WORD_BITS 64
  ------------------
   54|       |
   55|    837|   m_r1 = mod_p.reduce(r);
   56|    837|   m_r2 = mod_p.square(m_r1);
   57|    837|   m_r3 = mod_p.multiply(m_r1, m_r2);
   58|    837|}
_ZNK5Botan17Montgomery_Params4redcERKNS_6BigIntERNSt3__16vectorImNS_16secure_allocatorImEEEE:
   84|    837|BigInt Montgomery_Params::redc(const BigInt& x, secure_vector<word>& ws) const {
   85|    837|   const size_t output_size = m_p_words + 1;
   86|       |
   87|    837|   if(ws.size() < output_size) {
  ------------------
  |  Branch (87:7): [True: 837, False: 0]
  ------------------
   88|    837|      ws.resize(output_size);
   89|    837|   }
   90|       |
   91|    837|   BigInt z = x;
   92|    837|   z.grow_to(2 * m_p_words);
   93|       |
   94|    837|   bigint_monty_redc(z.mutable_data(), m_p.data(), m_p_words, m_p_dash, ws.data(), ws.size());
   95|       |
   96|    837|   return z;
   97|    837|}
_ZNK5Botan17Montgomery_Params3mulERKNS_6BigIntES3_RNSt3__16vectorImNS_16secure_allocatorImEEEE:
   99|  12.5k|BigInt Montgomery_Params::mul(const BigInt& x, const BigInt& y, secure_vector<word>& ws) const {
  100|  12.5k|   const size_t output_size = 2 * m_p_words + 2;
  101|       |
  102|  12.5k|   if(ws.size() < output_size) {
  ------------------
  |  Branch (102:7): [True: 12.5k, False: 0]
  ------------------
  103|  12.5k|      ws.resize(output_size);
  104|  12.5k|   }
  105|       |
  106|  12.5k|   BOTAN_DEBUG_ASSERT(x.sig_words() <= m_p_words);
  ------------------
  |  |   99|  12.5k|      do {                          \
  |  |  100|  12.5k|      } while(0)
  |  |  ------------------
  |  |  |  Branch (100:15): [Folded - Ignored]
  |  |  ------------------
  ------------------
  107|  12.5k|   BOTAN_DEBUG_ASSERT(y.sig_words() <= m_p_words);
  ------------------
  |  |   99|  12.5k|      do {                          \
  |  |  100|  12.5k|      } while(0)
  |  |  ------------------
  |  |  |  Branch (100:15): [Folded - Ignored]
  |  |  ------------------
  ------------------
  108|       |
  109|  12.5k|   BigInt z = BigInt::with_capacity(output_size);
  110|  12.5k|   bigint_mul(z.mutable_data(),
  111|  12.5k|              z.size(),
  112|  12.5k|              x.data(),
  113|  12.5k|              x.size(),
  114|  12.5k|              std::min(m_p_words, x.size()),
  115|  12.5k|              y.data(),
  116|  12.5k|              y.size(),
  117|  12.5k|              std::min(m_p_words, y.size()),
  118|  12.5k|              ws.data(),
  119|  12.5k|              ws.size());
  120|       |
  121|  12.5k|   bigint_monty_redc(z.mutable_data(), m_p.data(), m_p_words, m_p_dash, ws.data(), ws.size());
  122|       |
  123|  12.5k|   return z;
  124|  12.5k|}
_ZNK5Botan17Montgomery_Params6mul_byERNS_6BigIntERKS1_RNSt3__16vectorImNS_16secure_allocatorImEEEE:
  182|  61.1k|void Montgomery_Params::mul_by(BigInt& x, const BigInt& y, secure_vector<word>& ws) const {
  183|  61.1k|   const size_t output_size = 2 * m_p_words;
  184|       |
  185|  61.1k|   if(ws.size() < 2 * output_size) {
  ------------------
  |  Branch (185:7): [True: 0, False: 61.1k]
  ------------------
  186|      0|      ws.resize(2 * output_size);
  187|      0|   }
  188|       |
  189|  61.1k|   word* z_data = &ws[0];
  190|  61.1k|   word* ws_data = &ws[output_size];
  191|       |
  192|  61.1k|   BOTAN_DEBUG_ASSERT(x.sig_words() <= m_p_words);
  ------------------
  |  |   99|  61.1k|      do {                          \
  |  |  100|  61.1k|      } while(0)
  |  |  ------------------
  |  |  |  Branch (100:15): [Folded - Ignored]
  |  |  ------------------
  ------------------
  193|       |
  194|  61.1k|   bigint_mul(z_data,
  195|  61.1k|              output_size,
  196|  61.1k|              x.data(),
  197|  61.1k|              x.size(),
  198|  61.1k|              std::min(m_p_words, x.size()),
  199|  61.1k|              y.data(),
  200|  61.1k|              y.size(),
  201|  61.1k|              std::min(m_p_words, y.size()),
  202|  61.1k|              ws_data,
  203|  61.1k|              output_size);
  204|       |
  205|  61.1k|   bigint_monty_redc(z_data, m_p.data(), m_p_words, m_p_dash, ws_data, output_size);
  206|       |
  207|  61.1k|   if(x.size() < output_size) {
  ------------------
  |  Branch (207:7): [True: 0, False: 61.1k]
  ------------------
  208|      0|      x.grow_to(output_size);
  209|      0|   }
  210|  61.1k|   copy_mem(x.mutable_data(), z_data, output_size);
  211|  61.1k|}
_ZNK5Botan17Montgomery_Params11square_thisERNS_6BigIntERNSt3__16vectorImNS_16secure_allocatorImEEEE:
  231|   318k|void Montgomery_Params::square_this(BigInt& x, secure_vector<word>& ws) const {
  232|   318k|   const size_t output_size = 2 * m_p_words;
  233|       |
  234|   318k|   if(ws.size() < 2 * output_size) {
  ------------------
  |  Branch (234:7): [True: 837, False: 317k]
  ------------------
  235|    837|      ws.resize(2 * output_size);
  236|    837|   }
  237|       |
  238|   318k|   word* z_data = &ws[0];
  239|   318k|   word* ws_data = &ws[output_size];
  240|       |
  241|   318k|   BOTAN_DEBUG_ASSERT(x.sig_words() <= m_p_words);
  ------------------
  |  |   99|   318k|      do {                          \
  |  |  100|   318k|      } while(0)
  |  |  ------------------
  |  |  |  Branch (100:15): [Folded - Ignored]
  |  |  ------------------
  ------------------
  242|       |
  243|   318k|   bigint_sqr(z_data, output_size, x.data(), x.size(), std::min(m_p_words, x.size()), ws_data, output_size);
  244|       |
  245|   318k|   bigint_monty_redc(z_data, m_p.data(), m_p_words, m_p_dash, ws_data, output_size);
  246|       |
  247|   318k|   if(x.size() < output_size) {
  ------------------
  |  Branch (247:7): [True: 0, False: 318k]
  ------------------
  248|      0|      x.grow_to(output_size);
  249|      0|   }
  250|   318k|   copy_mem(x.mutable_data(), z_data, output_size);
  251|   318k|}
_ZN5Botan14Montgomery_IntC2ERKNSt3__110shared_ptrIKNS_17Montgomery_ParamsEEERKNS_6BigIntEb:
  256|  13.3k|      m_params(params) {
  257|  13.3k|   if(redc_needed == false) {
  ------------------
  |  Branch (257:7): [True: 12.5k, False: 837]
  ------------------
  258|  12.5k|      m_v = v;
  259|  12.5k|   } else {
  260|    837|      BOTAN_ASSERT_NOMSG(m_v < m_params->p());
  ------------------
  |  |   60|    837|   do {                                                                     \
  |  |   61|    837|      if(!(expr))                                                           \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 837]
  |  |  ------------------
  |  |   62|    837|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   63|    837|   } while(0)
  |  |  ------------------
  |  |  |  Branch (63:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  261|    837|      secure_vector<word> ws;
  262|    837|      m_v = m_params->mul(v, m_params->R2(), ws);
  263|    837|   }
  264|  13.3k|}
_ZN5Botan14Montgomery_Int8fix_sizeEv:
  292|  13.3k|void Montgomery_Int::fix_size() {
  293|  13.3k|   const size_t p_words = m_params->p_words();
  294|       |
  295|  13.3k|   if(m_v.sig_words() > p_words) {
  ------------------
  |  Branch (295:7): [True: 0, False: 13.3k]
  ------------------
  296|      0|      throw Internal_Error("Montgomery_Int::fix_size v too large");
  297|      0|   }
  298|       |
  299|  13.3k|   m_v.grow_to(p_words);
  300|  13.3k|}
_ZNK5Botan14Montgomery_Int5valueEv:
  324|    837|BigInt Montgomery_Int::value() const {
  325|    837|   secure_vector<word> ws;
  326|    837|   return m_params->redc(m_v, ws);
  327|    837|}
_ZNK5Botan14Montgomery_IntmlERKS0_:
  363|  11.7k|Montgomery_Int Montgomery_Int::operator*(const Montgomery_Int& other) const {
  364|  11.7k|   secure_vector<word> ws;
  365|  11.7k|   return Montgomery_Int(m_params, m_params->mul(m_v, other.m_v, ws), false);
  366|  11.7k|}
_ZN5Botan14Montgomery_Int6mul_byERKS0_RNSt3__16vectorImNS_16secure_allocatorImEEEE:
  372|  61.1k|Montgomery_Int& Montgomery_Int::mul_by(const Montgomery_Int& other, secure_vector<word>& ws) {
  373|  61.1k|   m_params->mul_by(m_v, other.m_v, ws);
  374|  61.1k|   return (*this);
  375|  61.1k|}
_ZN5Botan14Montgomery_Int19square_this_n_timesERNSt3__16vectorImNS_16secure_allocatorImEEEEm:
  392|  79.5k|Montgomery_Int& Montgomery_Int::square_this_n_times(secure_vector<word>& ws, size_t n) {
  393|   397k|   for(size_t i = 0; i != n; ++i) {
  ------------------
  |  Branch (393:22): [True: 318k, False: 79.5k]
  ------------------
  394|   318k|      m_params->square_this(m_v, ws);
  395|   318k|   }
  396|  79.5k|   return (*this);
  397|  79.5k|}

_ZN5Botan30Montgomery_Exponentation_StateC2ERKNSt3__110shared_ptrIKNS_17Montgomery_ParamsEEERKNS_6BigIntEmb:
   40|    837|      m_params(params), m_window_bits(window_bits == 0 ? 4 : window_bits) {
   41|    837|   BOTAN_ARG_CHECK(g < m_params->p(), "Montgomery base too big");
  ------------------
  |  |   30|    837|   do {                                                          \
  |  |   31|    837|      if(!(expr))                                                \
  |  |  ------------------
  |  |  |  Branch (31:10): [True: 0, False: 837]
  |  |  ------------------
  |  |   32|    837|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   33|    837|   } while(0)
  |  |  ------------------
  |  |  |  Branch (33:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   42|       |
   43|    837|   if(m_window_bits < 1 || m_window_bits > 12) {  // really even 8 is too large ...
  ------------------
  |  Branch (43:7): [True: 0, False: 837]
  |  Branch (43:28): [True: 0, False: 837]
  ------------------
   44|      0|      throw Invalid_Argument("Invalid window bits for Montgomery exponentiation");
   45|      0|   }
   46|       |
   47|    837|   const size_t window_size = (static_cast<size_t>(1) << m_window_bits);
   48|       |
   49|    837|   m_g.reserve(window_size);
   50|       |
   51|    837|   m_g.push_back(Montgomery_Int(m_params, m_params->R1(), false));
   52|       |
   53|    837|   m_g.push_back(Montgomery_Int(m_params, g));
   54|       |
   55|  12.5k|   for(size_t i = 2; i != window_size; ++i) {
  ------------------
  |  Branch (55:22): [True: 11.7k, False: 837]
  ------------------
   56|  11.7k|      m_g.push_back(m_g[1] * m_g[i - 1]);
   57|  11.7k|   }
   58|       |
   59|       |   // Resize each element to exactly p words
   60|  14.2k|   for(size_t i = 0; i != window_size; ++i) {
  ------------------
  |  Branch (60:22): [True: 13.3k, False: 837]
  ------------------
   61|  13.3k|      m_g[i].fix_size();
   62|  13.3k|      if(const_time) {
  ------------------
  |  Branch (62:10): [True: 0, False: 13.3k]
  ------------------
   63|      0|         m_g[i].const_time_poison();
   64|      0|      }
   65|  13.3k|   }
   66|    837|}
_ZNK5Botan30Montgomery_Exponentation_State22exponentiation_vartimeERKNS_6BigIntE:
  121|    837|BigInt Montgomery_Exponentation_State::exponentiation_vartime(const BigInt& scalar) const {
  122|    837|   const size_t exp_nibbles = (scalar.bits() + m_window_bits - 1) / m_window_bits;
  123|       |
  124|    837|   secure_vector<word> ws;
  125|       |
  126|    837|   if(exp_nibbles == 0) {
  ------------------
  |  Branch (126:7): [True: 0, False: 837]
  ------------------
  127|      0|      return BigInt::one();
  128|      0|   }
  129|       |
  130|    837|   Montgomery_Int x = m_g[scalar.get_substring(m_window_bits * (exp_nibbles - 1), m_window_bits)];
  131|       |
  132|  80.3k|   for(size_t i = exp_nibbles - 1; i > 0; --i) {
  ------------------
  |  Branch (132:36): [True: 79.5k, False: 837]
  ------------------
  133|  79.5k|      x.square_this_n_times(ws, m_window_bits);
  134|       |
  135|  79.5k|      const uint32_t nibble = scalar.get_substring(m_window_bits * (i - 1), m_window_bits);
  136|  79.5k|      if(nibble > 0) {
  ------------------
  |  Branch (136:10): [True: 61.1k, False: 18.4k]
  ------------------
  137|  61.1k|         x.mul_by(m_g[nibble], ws);
  138|  61.1k|      }
  139|  79.5k|   }
  140|       |
  141|    837|   x.const_time_unpoison();
  142|    837|   return x.value();
  143|    837|}
_ZN5Botan16monty_precomputeERKNSt3__110shared_ptrIKNS_17Montgomery_ParamsEEERKNS_6BigIntEmb:
  146|    837|   const std::shared_ptr<const Montgomery_Params>& params, const BigInt& g, size_t window_bits, bool const_time) {
  147|    837|   return std::make_shared<const Montgomery_Exponentation_State>(params, g, window_bits, const_time);
  148|    837|}
_ZN5Botan21monty_execute_vartimeERKNS_30Montgomery_Exponentation_StateERKNS_6BigIntE:
  154|    837|BigInt monty_execute_vartime(const Montgomery_Exponentation_State& precomputed_state, const BigInt& k) {
  155|    837|   return precomputed_state.exponentiation_vartime(k);
  156|    837|}

_ZN5Botan10prime_p192Ev:
  122|      1|const BigInt& prime_p192() {
  123|      1|   static const BigInt p192("0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFF");
  124|      1|   return p192;
  125|      1|}
_ZN5Botan10prime_p224Ev:
  217|      1|const BigInt& prime_p224() {
  218|      1|   static const BigInt p224("0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF000000000000000000000001");
  219|      1|   return p224;
  220|      1|}
_ZN5Botan10prime_p256Ev:
  319|      1|const BigInt& prime_p256() {
  320|      1|   static const BigInt p256("0xFFFFFFFF00000001000000000000000000000000FFFFFFFFFFFFFFFFFFFFFFFF");
  321|      1|   return p256;
  322|      1|}
_ZN5Botan10prime_p384Ev:
  447|  4.74M|const BigInt& prime_p384() {
  448|  4.74M|   static const BigInt p384(
  449|  4.74M|      "0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFF0000000000000000FFFFFFFF");
  450|  4.74M|   return p384;
  451|  4.74M|}
_ZN5Botan9redc_p384ERNS_6BigIntERNSt3__16vectorImNS_16secure_allocatorImEEEE:
  453|  65.1M|void redc_p384(BigInt& x, secure_vector<word>& ws) {
  454|  65.1M|   BOTAN_DEBUG_ASSERT(x.is_positive());
  ------------------
  |  |   99|  65.1M|      do {                          \
  |  |  100|  65.1M|      } while(0)
  |  |  ------------------
  |  |  |  Branch (100:15): [Folded - Ignored]
  |  |  ------------------
  ------------------
  455|       |
  456|  65.1M|   BOTAN_UNUSED(ws);
  ------------------
  |  |  118|  65.1M|#define BOTAN_UNUSED Botan::ignore_params
  ------------------
  457|       |
  458|  65.1M|   static const size_t p384_limbs = (BOTAN_MP_WORD_BITS == 32) ? 12 : 6;
  ------------------
  |  |   50|  65.1M|#define BOTAN_MP_WORD_BITS 64
  ------------------
  |  Branch (458:37): [Folded - Ignored]
  ------------------
  459|       |
  460|  65.1M|   x.grow_to(2 * p384_limbs);
  461|  65.1M|   word* xw = x.mutable_data();
  462|       |
  463|  65.1M|   const int64_t X00 = get_uint32(xw, 0);
  464|  65.1M|   const int64_t X01 = get_uint32(xw, 1);
  465|  65.1M|   const int64_t X02 = get_uint32(xw, 2);
  466|  65.1M|   const int64_t X03 = get_uint32(xw, 3);
  467|  65.1M|   const int64_t X04 = get_uint32(xw, 4);
  468|  65.1M|   const int64_t X05 = get_uint32(xw, 5);
  469|  65.1M|   const int64_t X06 = get_uint32(xw, 6);
  470|  65.1M|   const int64_t X07 = get_uint32(xw, 7);
  471|  65.1M|   const int64_t X08 = get_uint32(xw, 8);
  472|  65.1M|   const int64_t X09 = get_uint32(xw, 9);
  473|  65.1M|   const int64_t X10 = get_uint32(xw, 10);
  474|  65.1M|   const int64_t X11 = get_uint32(xw, 11);
  475|  65.1M|   const int64_t X12 = get_uint32(xw, 12);
  476|  65.1M|   const int64_t X13 = get_uint32(xw, 13);
  477|  65.1M|   const int64_t X14 = get_uint32(xw, 14);
  478|  65.1M|   const int64_t X15 = get_uint32(xw, 15);
  479|  65.1M|   const int64_t X16 = get_uint32(xw, 16);
  480|  65.1M|   const int64_t X17 = get_uint32(xw, 17);
  481|  65.1M|   const int64_t X18 = get_uint32(xw, 18);
  482|  65.1M|   const int64_t X19 = get_uint32(xw, 19);
  483|  65.1M|   const int64_t X20 = get_uint32(xw, 20);
  484|  65.1M|   const int64_t X21 = get_uint32(xw, 21);
  485|  65.1M|   const int64_t X22 = get_uint32(xw, 22);
  486|  65.1M|   const int64_t X23 = get_uint32(xw, 23);
  487|       |
  488|       |   // One copy of P-384 is added to prevent underflow
  489|  65.1M|   const int64_t S0 = 0xFFFFFFFF + X00 + X12 + X20 + X21 - X23;
  490|  65.1M|   const int64_t S1 = 0x00000000 + X01 + X13 + X22 + X23 - X12 - X20;
  491|  65.1M|   const int64_t S2 = 0x00000000 + X02 + X14 + X23 - X13 - X21;
  492|  65.1M|   const int64_t S3 = 0xFFFFFFFF + X03 + X12 + X15 + X20 + X21 - X14 - X22 - X23;
  493|  65.1M|   const int64_t S4 = 0xFFFFFFFE + X04 + X12 + X13 + X16 + X20 + X21 * 2 + X22 - X15 - X23 * 2;
  494|  65.1M|   const int64_t S5 = 0xFFFFFFFF + X05 + X13 + X14 + X17 + X21 + X22 * 2 + X23 - X16;
  495|  65.1M|   const int64_t S6 = 0xFFFFFFFF + X06 + X14 + X15 + X18 + X22 + X23 * 2 - X17;
  496|  65.1M|   const int64_t S7 = 0xFFFFFFFF + X07 + X15 + X16 + X19 + X23 - X18;
  497|  65.1M|   const int64_t S8 = 0xFFFFFFFF + X08 + X16 + X17 + X20 - X19;
  498|  65.1M|   const int64_t S9 = 0xFFFFFFFF + X09 + X17 + X18 + X21 - X20;
  499|  65.1M|   const int64_t SA = 0xFFFFFFFF + X10 + X18 + X19 + X22 - X21;
  500|  65.1M|   const int64_t SB = 0xFFFFFFFF + X11 + X19 + X20 + X23 - X22;
  501|       |
  502|  65.1M|   int64_t S = 0;
  503|       |
  504|  65.1M|   uint32_t R0 = 0, R1 = 0;
  505|       |
  506|  65.1M|   S += S0;
  507|  65.1M|   R0 = static_cast<uint32_t>(S);
  508|  65.1M|   S >>= 32;
  509|       |
  510|  65.1M|   S += S1;
  511|  65.1M|   R1 = static_cast<uint32_t>(S);
  512|  65.1M|   S >>= 32;
  513|       |
  514|  65.1M|   set_words(xw, 0, R0, R1);
  515|       |
  516|  65.1M|   S += S2;
  517|  65.1M|   R0 = static_cast<uint32_t>(S);
  518|  65.1M|   S >>= 32;
  519|       |
  520|  65.1M|   S += S3;
  521|  65.1M|   R1 = static_cast<uint32_t>(S);
  522|  65.1M|   S >>= 32;
  523|       |
  524|  65.1M|   set_words(xw, 2, R0, R1);
  525|       |
  526|  65.1M|   S += S4;
  527|  65.1M|   R0 = static_cast<uint32_t>(S);
  528|  65.1M|   S >>= 32;
  529|       |
  530|  65.1M|   S += S5;
  531|  65.1M|   R1 = static_cast<uint32_t>(S);
  532|  65.1M|   S >>= 32;
  533|       |
  534|  65.1M|   set_words(xw, 4, R0, R1);
  535|       |
  536|  65.1M|   S += S6;
  537|  65.1M|   R0 = static_cast<uint32_t>(S);
  538|  65.1M|   S >>= 32;
  539|       |
  540|  65.1M|   S += S7;
  541|  65.1M|   R1 = static_cast<uint32_t>(S);
  542|  65.1M|   S >>= 32;
  543|       |
  544|  65.1M|   set_words(xw, 6, R0, R1);
  545|       |
  546|  65.1M|   S += S8;
  547|  65.1M|   R0 = static_cast<uint32_t>(S);
  548|  65.1M|   S >>= 32;
  549|       |
  550|  65.1M|   S += S9;
  551|  65.1M|   R1 = static_cast<uint32_t>(S);
  552|  65.1M|   S >>= 32;
  553|       |
  554|  65.1M|   set_words(xw, 8, R0, R1);
  555|       |
  556|  65.1M|   S += SA;
  557|  65.1M|   R0 = static_cast<uint32_t>(S);
  558|  65.1M|   S >>= 32;
  559|       |
  560|  65.1M|   S += SB;
  561|  65.1M|   R1 = static_cast<uint32_t>(S);
  562|  65.1M|   S >>= 32;
  563|       |
  564|  65.1M|   set_words(xw, 10, R0, R1);
  565|       |
  566|       |   /*
  567|       |   This is a table of (i*P-384) % 2**384 for i in 1...4
  568|       |   */
  569|  65.1M|   static const word p384_mults[5][p384_limbs] = {
  570|  65.1M|#if(BOTAN_MP_WORD_BITS == 64)
  571|  65.1M|      {0x00000000FFFFFFFF,
  572|  65.1M|       0xFFFFFFFF00000000,
  573|  65.1M|       0xFFFFFFFFFFFFFFFE,
  574|  65.1M|       0xFFFFFFFFFFFFFFFF,
  575|  65.1M|       0xFFFFFFFFFFFFFFFF,
  576|  65.1M|       0xFFFFFFFFFFFFFFFF},
  577|  65.1M|      {0x00000001FFFFFFFE,
  578|  65.1M|       0xFFFFFFFE00000000,
  579|  65.1M|       0xFFFFFFFFFFFFFFFD,
  580|  65.1M|       0xFFFFFFFFFFFFFFFF,
  581|  65.1M|       0xFFFFFFFFFFFFFFFF,
  582|  65.1M|       0xFFFFFFFFFFFFFFFF},
  583|  65.1M|      {0x00000002FFFFFFFD,
  584|  65.1M|       0xFFFFFFFD00000000,
  585|  65.1M|       0xFFFFFFFFFFFFFFFC,
  586|  65.1M|       0xFFFFFFFFFFFFFFFF,
  587|  65.1M|       0xFFFFFFFFFFFFFFFF,
  588|  65.1M|       0xFFFFFFFFFFFFFFFF},
  589|  65.1M|      {0x00000003FFFFFFFC,
  590|  65.1M|       0xFFFFFFFC00000000,
  591|  65.1M|       0xFFFFFFFFFFFFFFFB,
  592|  65.1M|       0xFFFFFFFFFFFFFFFF,
  593|  65.1M|       0xFFFFFFFFFFFFFFFF,
  594|  65.1M|       0xFFFFFFFFFFFFFFFF},
  595|  65.1M|      {0x00000004FFFFFFFB,
  596|  65.1M|       0xFFFFFFFB00000000,
  597|  65.1M|       0xFFFFFFFFFFFFFFFA,
  598|  65.1M|       0xFFFFFFFFFFFFFFFF,
  599|  65.1M|       0xFFFFFFFFFFFFFFFF,
  600|  65.1M|       0xFFFFFFFFFFFFFFFF},
  601|       |
  602|       |#else
  603|       |      {0xFFFFFFFF,
  604|       |       0x00000000,
  605|       |       0x00000000,
  606|       |       0xFFFFFFFF,
  607|       |       0xFFFFFFFE,
  608|       |       0xFFFFFFFF,
  609|       |       0xFFFFFFFF,
  610|       |       0xFFFFFFFF,
  611|       |       0xFFFFFFFF,
  612|       |       0xFFFFFFFF,
  613|       |       0xFFFFFFFF,
  614|       |       0xFFFFFFFF},
  615|       |      {0xFFFFFFFE,
  616|       |       0x00000001,
  617|       |       0x00000000,
  618|       |       0xFFFFFFFE,
  619|       |       0xFFFFFFFD,
  620|       |       0xFFFFFFFF,
  621|       |       0xFFFFFFFF,
  622|       |       0xFFFFFFFF,
  623|       |       0xFFFFFFFF,
  624|       |       0xFFFFFFFF,
  625|       |       0xFFFFFFFF,
  626|       |       0xFFFFFFFF},
  627|       |      {0xFFFFFFFD,
  628|       |       0x00000002,
  629|       |       0x00000000,
  630|       |       0xFFFFFFFD,
  631|       |       0xFFFFFFFC,
  632|       |       0xFFFFFFFF,
  633|       |       0xFFFFFFFF,
  634|       |       0xFFFFFFFF,
  635|       |       0xFFFFFFFF,
  636|       |       0xFFFFFFFF,
  637|       |       0xFFFFFFFF,
  638|       |       0xFFFFFFFF},
  639|       |      {0xFFFFFFFC,
  640|       |       0x00000003,
  641|       |       0x00000000,
  642|       |       0xFFFFFFFC,
  643|       |       0xFFFFFFFB,
  644|       |       0xFFFFFFFF,
  645|       |       0xFFFFFFFF,
  646|       |       0xFFFFFFFF,
  647|       |       0xFFFFFFFF,
  648|       |       0xFFFFFFFF,
  649|       |       0xFFFFFFFF,
  650|       |       0xFFFFFFFF},
  651|       |      {0xFFFFFFFB,
  652|       |       0x00000004,
  653|       |       0x00000000,
  654|       |       0xFFFFFFFB,
  655|       |       0xFFFFFFFA,
  656|       |       0xFFFFFFFF,
  657|       |       0xFFFFFFFF,
  658|       |       0xFFFFFFFF,
  659|       |       0xFFFFFFFF,
  660|       |       0xFFFFFFFF,
  661|       |       0xFFFFFFFF,
  662|       |       0xFFFFFFFF},
  663|       |#endif
  664|  65.1M|   };
  665|       |
  666|  65.1M|   CT::unpoison(S);
  667|  65.1M|   BOTAN_ASSERT(S >= 0 && S <= 4, "Expected overflow");
  ------------------
  |  |   51|  65.1M|   do {                                                                                 \
  |  |   52|   130M|      if(!(expr))                                                                       \
  |  |  ------------------
  |  |  |  Branch (52:12): [True: 65.1M, False: 0]
  |  |  |  Branch (52:12): [True: 65.1M, False: 0]
  |  |  ------------------
  |  |   53|  65.1M|         Botan::assertion_failure(#expr, assertion_made, __func__, __FILE__, __LINE__); \
  |  |   54|  65.1M|   } while(0)
  |  |  ------------------
  |  |  |  Branch (54:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  668|       |
  669|  65.1M|   BOTAN_ASSERT_NOMSG(x.size() >= p384_limbs + 1);
  ------------------
  |  |   60|  65.1M|   do {                                                                     \
  |  |   61|  65.1M|      if(!(expr))                                                           \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 65.1M]
  |  |  ------------------
  |  |   62|  65.1M|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   63|  65.1M|   } while(0)
  |  |  ------------------
  |  |  |  Branch (63:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  670|  65.1M|   x.mask_bits(384);
  671|  65.1M|   word borrow = bigint_sub2(x.mutable_data(), p384_limbs + 1, p384_mults[S], p384_limbs);
  672|  65.1M|   BOTAN_DEBUG_ASSERT(borrow == 0 || borrow == 1);
  ------------------
  |  |   99|  65.1M|      do {                          \
  |  |  100|  65.1M|      } while(0)
  |  |  ------------------
  |  |  |  Branch (100:15): [Folded - Ignored]
  |  |  ------------------
  ------------------
  673|  65.1M|   bigint_cnd_add(borrow, x.mutable_data(), p384_limbs + 1, p384_mults[0], p384_limbs);
  674|  65.1M|}
nistp_redc.cpp:_ZN5Botan12_GLOBAL__N_110get_uint32EPKmm:
  103|  1.56G|inline uint32_t get_uint32(const word xw[], size_t i) {
  104|       |#if(BOTAN_MP_WORD_BITS == 32)
  105|       |   return xw[i];
  106|       |#else
  107|  1.56G|   return static_cast<uint32_t>(xw[i / 2] >> ((i % 2) * 32));
  108|  1.56G|#endif
  109|  1.56G|}
nistp_redc.cpp:_ZN5Botan12_GLOBAL__N_19set_wordsEPmmjj:
  111|   390M|inline void set_words(word x[], size_t i, uint32_t R0, uint32_t R1) {
  112|       |#if(BOTAN_MP_WORD_BITS == 32)
  113|       |   x[i] = R0;
  114|       |   x[i + 1] = R1;
  115|       |#else
  116|   390M|   x[i / 2] = (static_cast<uint64_t>(R1) << 32) | R0;
  117|   390M|#endif
  118|   390M|}

_ZN5Botan17sqrt_modulo_primeERKNS_6BigIntES2_:
   26|  1.36k|BigInt sqrt_modulo_prime(const BigInt& a, const BigInt& p) {
   27|  1.36k|   BOTAN_ARG_CHECK(p > 1, "invalid prime");
  ------------------
  |  |   30|  1.36k|   do {                                                          \
  |  |   31|  1.36k|      if(!(expr))                                                \
  |  |  ------------------
  |  |  |  Branch (31:10): [True: 0, False: 1.36k]
  |  |  ------------------
  |  |   32|  1.36k|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   33|  1.36k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (33:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   28|  1.36k|   BOTAN_ARG_CHECK(a < p, "value to solve for must be less than p");
  ------------------
  |  |   30|  1.36k|   do {                                                          \
  |  |   31|  1.36k|      if(!(expr))                                                \
  |  |  ------------------
  |  |  |  Branch (31:10): [True: 0, False: 1.36k]
  |  |  ------------------
  |  |   32|  1.36k|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   33|  1.36k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (33:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   29|  1.36k|   BOTAN_ARG_CHECK(a >= 0, "value to solve for must not be negative");
  ------------------
  |  |   30|  1.36k|   do {                                                          \
  |  |   31|  1.36k|      if(!(expr))                                                \
  |  |  ------------------
  |  |  |  Branch (31:10): [True: 0, False: 1.36k]
  |  |  ------------------
  |  |   32|  1.36k|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   33|  1.36k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (33:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   30|       |
   31|       |   // some very easy cases
   32|  1.36k|   if(p == 2 || a <= 1) {
  ------------------
  |  Branch (32:7): [True: 0, False: 1.36k]
  |  Branch (32:17): [True: 0, False: 1.36k]
  ------------------
   33|      0|      return a;
   34|      0|   }
   35|       |
   36|  1.36k|   BOTAN_ARG_CHECK(p.is_odd(), "invalid prime");
  ------------------
  |  |   30|  1.36k|   do {                                                          \
  |  |   31|  1.36k|      if(!(expr))                                                \
  |  |  ------------------
  |  |  |  Branch (31:10): [True: 0, False: 1.36k]
  |  |  ------------------
  |  |   32|  1.36k|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   33|  1.36k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (33:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   37|       |
   38|  1.36k|   if(jacobi(a, p) != 1) {  // not a quadratic residue
  ------------------
  |  Branch (38:7): [True: 525, False: 837]
  ------------------
   39|    525|      return BigInt::from_s32(-1);
   40|    525|   }
   41|       |
   42|    837|   Modular_Reducer mod_p(p);
   43|    837|   auto monty_p = std::make_shared<Montgomery_Params>(p, mod_p);
   44|       |
   45|       |   // If p == 3 (mod 4) there is a simple solution
   46|    837|   if(p % 4 == 3) {
  ------------------
  |  Branch (46:7): [True: 837, False: 0]
  ------------------
   47|    837|      return monty_exp_vartime(monty_p, a, ((p + 1) >> 2));
   48|    837|   }
   49|       |
   50|       |   // Otherwise we have to use Shanks-Tonelli
   51|      0|   size_t s = low_zero_bits(p - 1);
   52|      0|   BigInt q = p >> s;
   53|       |
   54|      0|   q -= 1;
   55|      0|   q >>= 1;
   56|       |
   57|      0|   BigInt r = monty_exp_vartime(monty_p, a, q);
   58|      0|   BigInt n = mod_p.multiply(a, mod_p.square(r));
   59|      0|   r = mod_p.multiply(r, a);
   60|       |
   61|      0|   if(n == 1) {
  ------------------
  |  Branch (61:7): [True: 0, False: 0]
  ------------------
   62|      0|      return r;
   63|      0|   }
   64|       |
   65|       |   // find random quadratic nonresidue z
   66|      0|   word z = 2;
   67|      0|   for(;;) {
   68|      0|      if(jacobi(BigInt::from_word(z), p) == -1) {  // found one
  ------------------
  |  Branch (68:10): [True: 0, False: 0]
  ------------------
   69|      0|         break;
   70|      0|      }
   71|       |
   72|      0|      z += 1;  // try next z
   73|       |
   74|       |      /*
   75|       |      * The expected number of tests to find a non-residue modulo a
   76|       |      * prime is 2. If we have not found one after 256 then almost
   77|       |      * certainly we have been given a non-prime p.
   78|       |      */
   79|      0|      if(z >= 256) {
  ------------------
  |  Branch (79:10): [True: 0, False: 0]
  ------------------
   80|      0|         return BigInt::from_s32(-1);
   81|      0|      }
   82|      0|   }
   83|       |
   84|      0|   BigInt c = monty_exp_vartime(monty_p, BigInt::from_word(z), (q << 1) + 1);
   85|       |
   86|      0|   while(n > 1) {
  ------------------
  |  Branch (86:10): [True: 0, False: 0]
  ------------------
   87|      0|      q = n;
   88|       |
   89|      0|      size_t i = 0;
   90|      0|      while(q != 1) {
  ------------------
  |  Branch (90:13): [True: 0, False: 0]
  ------------------
   91|      0|         q = mod_p.square(q);
   92|      0|         ++i;
   93|       |
   94|      0|         if(i >= s) {
  ------------------
  |  Branch (94:13): [True: 0, False: 0]
  ------------------
   95|      0|            return BigInt::from_s32(-1);
   96|      0|         }
   97|      0|      }
   98|       |
   99|      0|      BOTAN_ASSERT_NOMSG(s >= (i + 1));  // No underflow!
  ------------------
  |  |   60|      0|   do {                                                                     \
  |  |   61|      0|      if(!(expr))                                                           \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 0]
  |  |  ------------------
  |  |   62|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   63|      0|   } while(0)
  |  |  ------------------
  |  |  |  Branch (63:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  100|      0|      c = monty_exp_vartime(monty_p, c, BigInt::power_of_2(s - i - 1));
  101|      0|      r = mod_p.multiply(r, c);
  102|      0|      c = mod_p.square(c);
  103|      0|      n = mod_p.multiply(n, c);
  104|       |
  105|       |      // s decreases as the algorithm proceeds
  106|      0|      BOTAN_ASSERT_NOMSG(s >= i);
  ------------------
  |  |   60|      0|   do {                                                                     \
  |  |   61|      0|      if(!(expr))                                                           \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 0]
  |  |  ------------------
  |  |   62|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   63|      0|   } while(0)
  |  |  ------------------
  |  |  |  Branch (63:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  107|      0|      s = i;
  108|      0|   }
  109|       |
  110|      0|   return r;
  111|      0|}
_ZN5Botan6jacobiERKNS_6BigIntES2_:
  116|  1.36k|int32_t jacobi(const BigInt& a, const BigInt& n) {
  117|  1.36k|   if(n.is_even() || n < 2) {
  ------------------
  |  Branch (117:7): [True: 0, False: 1.36k]
  |  Branch (117:22): [True: 0, False: 1.36k]
  ------------------
  118|      0|      throw Invalid_Argument("jacobi: second argument must be odd and > 1");
  119|      0|   }
  120|       |
  121|  1.36k|   BigInt x = a % n;
  122|  1.36k|   BigInt y = n;
  123|  1.36k|   int32_t J = 1;
  124|       |
  125|   152k|   while(y > 1) {
  ------------------
  |  Branch (125:10): [True: 150k, False: 1.36k]
  ------------------
  126|   150k|      x %= y;
  127|   150k|      if(x > y / 2) {
  ------------------
  |  Branch (127:10): [True: 71.3k, False: 79.2k]
  ------------------
  128|  71.3k|         x = y - x;
  129|  71.3k|         if(y % 4 == 3) {
  ------------------
  |  Branch (129:13): [True: 35.9k, False: 35.4k]
  ------------------
  130|  35.9k|            J = -J;
  131|  35.9k|         }
  132|  71.3k|      }
  133|   150k|      if(x.is_zero()) {
  ------------------
  |  Branch (133:10): [True: 0, False: 150k]
  ------------------
  134|      0|         return 0;
  135|      0|      }
  136|       |
  137|   150k|      size_t shifts = low_zero_bits(x);
  138|   150k|      x >>= shifts;
  139|   150k|      if(shifts % 2) {
  ------------------
  |  Branch (139:10): [True: 49.4k, False: 101k]
  ------------------
  140|  49.4k|         word y_mod_8 = y % 8;
  141|  49.4k|         if(y_mod_8 == 3 || y_mod_8 == 5) {
  ------------------
  |  Branch (141:13): [True: 11.1k, False: 38.3k]
  |  Branch (141:29): [True: 12.5k, False: 25.8k]
  ------------------
  142|  23.6k|            J = -J;
  143|  23.6k|         }
  144|  49.4k|      }
  145|       |
  146|   150k|      if(x % 4 == 3 && y % 4 == 3) {
  ------------------
  |  Branch (146:10): [True: 73.4k, False: 77.1k]
  |  Branch (146:24): [True: 36.4k, False: 37.0k]
  ------------------
  147|  36.4k|         J = -J;
  148|  36.4k|      }
  149|   150k|      std::swap(x, y);
  150|   150k|   }
  151|  1.36k|   return J;
  152|  1.36k|}
_ZN5Botan6squareERKNS_6BigIntE:
  157|    837|BigInt square(const BigInt& x) {
  158|    837|   BigInt z = x;
  159|    837|   secure_vector<word> ws;
  160|    837|   z.square(ws);
  161|    837|   return z;
  162|    837|}
_ZN5Botan13low_zero_bitsERKNS_6BigIntE:
  167|   150k|size_t low_zero_bits(const BigInt& n) {
  168|   150k|   size_t low_zero = 0;
  169|       |
  170|   150k|   auto seen_nonempty_word = CT::Mask<word>::cleared();
  171|       |
  172|  1.35M|   for(size_t i = 0; i != n.size(); ++i) {
  ------------------
  |  Branch (172:22): [True: 1.20M, False: 150k]
  ------------------
  173|  1.20M|      const word x = n.word_at(i);
  174|       |
  175|       |      // ctz(0) will return sizeof(word)
  176|  1.20M|      const size_t tz_x = ctz(x);
  177|       |
  178|       |      // if x > 0 we want to count tz_x in total but not any
  179|       |      // further words, so set the mask after the addition
  180|  1.20M|      low_zero += seen_nonempty_word.if_not_set_return(tz_x);
  181|       |
  182|  1.20M|      seen_nonempty_word |= CT::Mask<word>::expand(x);
  183|  1.20M|   }
  184|       |
  185|       |   // if we saw no words with x > 0 then n == 0 and the value we have
  186|       |   // computed is meaningless. Instead return BigInt::zero() in that case.
  187|   150k|   return static_cast<size_t>(seen_nonempty_word.if_set_return(low_zero));
  188|   150k|}

_ZN5Botan15Modular_ReducerC2ERKNS_6BigIntE:
   19|    838|Modular_Reducer::Modular_Reducer(const BigInt& mod) {
   20|    838|   if(mod < 0) {
  ------------------
  |  Branch (20:7): [True: 0, False: 838]
  ------------------
   21|      0|      throw Invalid_Argument("Modular_Reducer: modulus must be positive");
   22|      0|   }
   23|       |
   24|       |   // Left uninitialized if mod == 0
   25|    838|   m_mod_words = 0;
   26|       |
   27|    838|   if(mod > 0) {
  ------------------
  |  Branch (27:7): [True: 838, False: 0]
  ------------------
   28|    838|      m_modulus = mod;
   29|    838|      m_mod_words = m_modulus.sig_words();
   30|       |
   31|       |      // Compute mu = floor(2^{2k} / m)
   32|    838|      m_mu.set_bit(2 * BOTAN_MP_WORD_BITS * m_mod_words);
  ------------------
  |  |   50|    838|#define BOTAN_MP_WORD_BITS 64
  ------------------
   33|    838|      m_mu = ct_divide(m_mu, m_modulus);
   34|    838|   }
   35|    838|}
_ZNK5Botan15Modular_Reducer6reduceERKNS_6BigIntE:
   37|  6.59k|BigInt Modular_Reducer::reduce(const BigInt& x) const {
   38|  6.59k|   BigInt r;
   39|  6.59k|   secure_vector<word> ws;
   40|  6.59k|   reduce(r, x, ws);
   41|  6.59k|   return r;
   42|  6.59k|}
_ZNK5Botan15Modular_Reducer6reduceERNS_6BigIntERKS1_RNSt3__16vectorImNS_16secure_allocatorImEEEE:
   69|  6.59k|void Modular_Reducer::reduce(BigInt& t1, const BigInt& x, secure_vector<word>& ws) const {
   70|  6.59k|   if(&t1 == &x) {
  ------------------
  |  Branch (70:7): [True: 0, False: 6.59k]
  ------------------
   71|      0|      throw Invalid_State("Modular_Reducer arguments cannot alias");
   72|      0|   }
   73|  6.59k|   if(m_mod_words == 0) {
  ------------------
  |  Branch (73:7): [True: 0, False: 6.59k]
  ------------------
   74|      0|      throw Invalid_State("Modular_Reducer: Never initalized");
   75|      0|   }
   76|       |
   77|  6.59k|   const size_t x_sw = x.sig_words();
   78|       |
   79|  6.59k|   if(x_sw > 2 * m_mod_words) {
  ------------------
  |  Branch (79:7): [True: 0, False: 6.59k]
  ------------------
   80|       |      // too big, fall back to slow boat division
   81|      0|      t1 = ct_modulo(x, m_modulus);
   82|      0|      return;
   83|      0|   }
   84|       |
   85|  6.59k|   t1 = x;
   86|  6.59k|   t1.set_sign(BigInt::Positive);
   87|  6.59k|   t1 >>= (BOTAN_MP_WORD_BITS * (m_mod_words - 1));
  ------------------
  |  |   50|  6.59k|#define BOTAN_MP_WORD_BITS 64
  ------------------
   88|       |
   89|  6.59k|   t1.mul(m_mu, ws);
   90|  6.59k|   t1 >>= (BOTAN_MP_WORD_BITS * (m_mod_words + 1));
  ------------------
  |  |   50|  6.59k|#define BOTAN_MP_WORD_BITS 64
  ------------------
   91|       |
   92|       |   // TODO add masked mul to avoid computing high bits
   93|  6.59k|   t1.mul(m_modulus, ws);
   94|  6.59k|   t1.mask_bits(BOTAN_MP_WORD_BITS * (m_mod_words + 1));
  ------------------
  |  |   50|  6.59k|#define BOTAN_MP_WORD_BITS 64
  ------------------
   95|       |
   96|  6.59k|   t1.rev_sub(x.data(), std::min(x_sw, m_mod_words + 1), ws);
   97|       |
   98|       |   /*
   99|       |   * If t1 < 0 then we must add b^(k+1) where b = 2^w. To avoid a
  100|       |   * side channel perform the addition unconditionally, with ws set
  101|       |   * to either b^(k+1) or else 0.
  102|       |   */
  103|  6.59k|   const word t1_neg = t1.is_negative();
  104|       |
  105|  6.59k|   if(ws.size() < m_mod_words + 2) {
  ------------------
  |  Branch (105:7): [True: 950, False: 5.64k]
  ------------------
  106|    950|      ws.resize(m_mod_words + 2);
  107|    950|   }
  108|  6.59k|   clear_mem(ws.data(), ws.size());
  109|  6.59k|   ws[m_mod_words + 1] = t1_neg;
  110|       |
  111|  6.59k|   t1.add(ws.data(), m_mod_words + 2, BigInt::Positive);
  112|       |
  113|       |   // Per HAC this step requires at most 2 subtractions
  114|  6.59k|   t1.ct_reduce_below(m_modulus, ws, 2);
  115|       |
  116|  6.59k|   cnd_rev_sub(t1.is_nonzero() && x.is_negative(), t1, m_modulus.data(), m_modulus.size(), ws);
  ------------------
  |  Branch (116:16): [True: 6.43k, False: 161]
  |  Branch (116:35): [True: 0, False: 6.43k]
  ------------------
  117|  6.59k|}
reducer.cpp:_ZN5Botan12_GLOBAL__N_111cnd_rev_subEbRNS_6BigIntEPKmmRNSt3__16vectorImNS_16secure_allocatorImEEEE:
   49|  6.59k|void cnd_rev_sub(bool cnd, BigInt& x, const word y[], size_t y_sw, secure_vector<word>& ws) {
   50|  6.59k|   if(x.sign() != BigInt::Positive) {
  ------------------
  |  Branch (50:7): [True: 0, False: 6.59k]
  ------------------
   51|      0|      throw Invalid_State("BigInt::sub_rev requires this is positive");
   52|      0|   }
   53|       |
   54|  6.59k|   const size_t x_sw = x.sig_words();
   55|       |
   56|  6.59k|   const size_t max_words = std::max(x_sw, y_sw);
   57|  6.59k|   ws.resize(std::max(x_sw, y_sw));
   58|  6.59k|   clear_mem(ws.data(), ws.size());
   59|  6.59k|   x.grow_to(max_words);
   60|       |
   61|  6.59k|   const int32_t relative_size = bigint_sub_abs(ws.data(), x.data(), x_sw, y, y_sw);
   62|       |
   63|  6.59k|   x.cond_flip_sign((relative_size > 0) && cnd);
  ------------------
  |  Branch (63:21): [True: 0, False: 6.59k]
  |  Branch (63:44): [True: 0, False: 0]
  ------------------
   64|  6.59k|   bigint_cnd_swap(cnd, x.mutable_data(), ws.data(), max_words);
   65|  6.59k|}

_ZN5Botan8CurveGFp11choose_reprERKNS_6BigIntES3_S3_:
  564|      1|std::shared_ptr<CurveGFp_Repr> CurveGFp::choose_repr(const BigInt& p, const BigInt& a, const BigInt& b) {
  565|      1|   if(p == prime_p192()) {
  ------------------
  |  Branch (565:7): [True: 0, False: 1]
  ------------------
  566|      0|      return std::make_shared<CurveGFp_P192>(a, b);
  567|      0|   }
  568|      1|   if(p == prime_p224()) {
  ------------------
  |  Branch (568:7): [True: 0, False: 1]
  ------------------
  569|      0|      return std::make_shared<CurveGFp_P224>(a, b);
  570|      0|   }
  571|      1|   if(p == prime_p256()) {
  ------------------
  |  Branch (571:7): [True: 0, False: 1]
  ------------------
  572|      0|      return std::make_shared<CurveGFp_P256>(a, b);
  573|      0|   }
  574|      1|   if(p == prime_p384()) {
  ------------------
  |  Branch (574:7): [True: 1, False: 0]
  ------------------
  575|      1|      return std::make_shared<CurveGFp_P384>(a, b);
  576|      1|   }
  577|      0|   if(p == prime_p521()) {
  ------------------
  |  Branch (577:7): [True: 0, False: 0]
  ------------------
  578|      0|      return std::make_shared<CurveGFp_P521>(a, b);
  579|      0|   }
  580|       |
  581|      0|   return std::make_shared<CurveGFp_Montgomery>(p, a, b);
  582|      0|}
curve_gfp.cpp:_ZN5Botan12_GLOBAL__N_113CurveGFp_NISTC2EmRKNS_6BigIntES4_:
  157|      1|            m_1(1), m_a(a), m_b(b), m_p_words((p_bits + BOTAN_MP_WORD_BITS - 1) / BOTAN_MP_WORD_BITS) {
  158|       |         // All Solinas prime curves are assumed a == -3
  159|      1|      }
curve_gfp.cpp:_ZNK5Botan12_GLOBAL__N_113CurveGFp_NIST5get_aEv:
  165|  1.36k|      const BigInt& get_a() const override { return m_a; }
curve_gfp.cpp:_ZNK5Botan12_GLOBAL__N_113CurveGFp_NIST5get_bEv:
  167|  1.36k|      const BigInt& get_b() const override { return m_b; }
curve_gfp.cpp:_ZNK5Botan12_GLOBAL__N_113CurveGFp_NIST11get_p_wordsEv:
  171|   287k|      size_t get_p_words() const override { return m_p_words; }
curve_gfp.cpp:_ZNK5Botan12_GLOBAL__N_113CurveGFp_NIST11get_ws_sizeEv:
  173|  69.8M|      size_t get_ws_size() const override { return 2 * m_p_words; }
curve_gfp.cpp:_ZNK5Botan12_GLOBAL__N_113CurveGFp_NIST6is_oneERKNS_6BigIntE:
  179|  43.4k|      bool is_one(const BigInt& x) const override { return x == 1; }
curve_gfp.cpp:_ZNK5Botan12_GLOBAL__N_113CurveGFp_NIST9a_is_zeroEv:
  161|  3.09M|      bool a_is_zero() const override { return false; }
curve_gfp.cpp:_ZNK5Botan12_GLOBAL__N_113CurveGFp_NIST12a_is_minus_3Ev:
  163|  3.09M|      bool a_is_minus_3() const override { return true; }
curve_gfp.cpp:_ZNK5Botan12_GLOBAL__N_113CurveGFp_NIST9get_1_repEv:
  169|  24.1k|      const BigInt& get_1_rep() const override { return m_1; }
curve_gfp.cpp:_ZNK5Botan12_GLOBAL__N_113CurveGFp_NIST12to_curve_repERNS_6BigIntERNSt3__16vectorImNS_16secure_allocatorImEEEE:
  181|  1.67k|      void to_curve_rep(BigInt& x, secure_vector<word>& ws) const override { redc_mod_p(x, ws); }
curve_gfp.cpp:_ZNK5Botan12_GLOBAL__N_113CurveGFp_NIST14from_curve_repERNS_6BigIntERNSt3__16vectorImNS_16secure_allocatorImEEEE:
  183|  43.4k|      void from_curve_rep(BigInt& x, secure_vector<word>& ws) const override { redc_mod_p(x, ws); }
curve_gfp.cpp:_ZNK5Botan12_GLOBAL__N_113CurveGFp_NIST15curve_mul_wordsERNS_6BigIntEPKmmRKS2_RNSt3__16vectorImNS_16secure_allocatorImEEEE:
  217|  30.1M|   BigInt& z, const word x_w[], size_t x_size, const BigInt& y, secure_vector<word>& ws) const {
  218|  30.1M|   BOTAN_DEBUG_ASSERT(y.sig_words() <= m_p_words);
  ------------------
  |  |   99|  30.1M|      do {                          \
  |  |  100|  30.1M|      } while(0)
  |  |  ------------------
  |  |  |  Branch (100:15): [Folded - Ignored]
  |  |  ------------------
  ------------------
  219|       |
  220|  30.1M|   if(ws.size() < get_ws_size()) {
  ------------------
  |  Branch (220:7): [True: 0, False: 30.1M]
  ------------------
  221|      0|      ws.resize(get_ws_size());
  222|      0|   }
  223|       |
  224|  30.1M|   const size_t output_size = 2 * m_p_words;
  225|  30.1M|   if(z.size() < output_size) {
  ------------------
  |  Branch (225:7): [True: 117k, False: 30.0M]
  ------------------
  226|   117k|      z.grow_to(output_size);
  227|   117k|   }
  228|       |
  229|  30.1M|   bigint_mul(z.mutable_data(),
  230|  30.1M|              z.size(),
  231|  30.1M|              x_w,
  232|  30.1M|              x_size,
  233|  30.1M|              std::min(m_p_words, x_size),
  234|  30.1M|              y.data(),
  235|  30.1M|              y.size(),
  236|  30.1M|              std::min(m_p_words, y.size()),
  237|  30.1M|              ws.data(),
  238|  30.1M|              ws.size());
  239|       |
  240|  30.1M|   this->redc_mod_p(z, ws);
  241|  30.1M|}
curve_gfp.cpp:_ZNK5Botan12_GLOBAL__N_113CurveGFp_NIST15curve_sqr_wordsERNS_6BigIntEPKmmRNSt3__16vectorImNS_16secure_allocatorImEEEE:
  243|  34.9M|void CurveGFp_NIST::curve_sqr_words(BigInt& z, const word x[], size_t x_size, secure_vector<word>& ws) const {
  244|  34.9M|   if(ws.size() < get_ws_size()) {
  ------------------
  |  Branch (244:7): [True: 48.3k, False: 34.8M]
  ------------------
  245|  48.3k|      ws.resize(get_ws_size());
  246|  48.3k|   }
  247|       |
  248|  34.9M|   const size_t output_size = 2 * m_p_words;
  249|  34.9M|   if(z.size() < output_size) {
  ------------------
  |  Branch (249:7): [True: 3.19M, False: 31.7M]
  ------------------
  250|  3.19M|      z.grow_to(output_size);
  251|  3.19M|   }
  252|       |
  253|  34.9M|   bigint_sqr(z.mutable_data(), output_size, x, x_size, std::min(m_p_words, x_size), ws.data(), ws.size());
  254|       |
  255|  34.9M|   this->redc_mod_p(z, ws);
  256|  34.9M|}
curve_gfp.cpp:_ZNK5Botan12_GLOBAL__N_113CurveGFp_NIST13curve_sqr_tmpERNS_6BigIntES3_RNSt3__16vectorImNS_16secure_allocatorImEEEE:
  197|  16.6M|      void curve_sqr_tmp(BigInt& x, BigInt& tmp, secure_vector<word>& ws) const {
  198|  16.6M|         curve_sqr(tmp, x, ws);
  199|  16.6M|         x.swap(tmp);
  200|  16.6M|      }
curve_gfp.cpp:_ZNK5Botan12_GLOBAL__N_113CurveGFp_NIST13curve_mul_tmpERNS_6BigIntERKS2_S3_RNSt3__16vectorImNS_16secure_allocatorImEEEE:
  192|   607k|      void curve_mul_tmp(BigInt& x, const BigInt& y, BigInt& tmp, secure_vector<word>& ws) const {
  193|   607k|         curve_mul(tmp, x, y, ws);
  194|   607k|         x.swap(tmp);
  195|   607k|      }
curve_gfp.cpp:_ZN5Botan12_GLOBAL__N_113CurveGFp_P384C2ERKNS_6BigIntES4_:
  376|      1|      CurveGFp_P384(const BigInt& a, const BigInt& b) : CurveGFp_NIST(384, a, b) {}
curve_gfp.cpp:_ZNK5Botan12_GLOBAL__N_113CurveGFp_P3845get_pEv:
  378|  4.74M|      const BigInt& get_p() const override { return prime_p384(); }
curve_gfp.cpp:_ZNK5Botan12_GLOBAL__N_113CurveGFp_P38414invert_elementERKNS_6BigIntERNSt3__16vectorImNS_16secure_allocatorImEEEE:
  386|  43.4k|BigInt CurveGFp_P384::invert_element(const BigInt& x, secure_vector<word>& ws) const {
  387|       |   // From https://briansmith.org/ecc-inversion-addition-chains-01
  388|       |
  389|  43.4k|   BigInt r, x2, x3, x15, x30, tmp, rl;
  390|       |
  391|  43.4k|   r = x;
  392|  43.4k|   curve_sqr_tmp(r, tmp, ws);
  393|  43.4k|   curve_mul_tmp(r, x, tmp, ws);
  394|  43.4k|   x2 = r;
  395|       |
  396|  43.4k|   curve_sqr_tmp(r, tmp, ws);
  397|  43.4k|   curve_mul_tmp(r, x, tmp, ws);
  398|       |
  399|  43.4k|   x3 = r;
  400|       |
  401|   173k|   for(size_t i = 0; i != 3; ++i) {
  ------------------
  |  Branch (401:22): [True: 130k, False: 43.4k]
  ------------------
  402|   130k|      curve_sqr_tmp(r, tmp, ws);
  403|   130k|   }
  404|  43.4k|   curve_mul_tmp(r, x3, tmp, ws);
  405|       |
  406|  43.4k|   rl = r;
  407|   303k|   for(size_t i = 0; i != 6; ++i) {
  ------------------
  |  Branch (407:22): [True: 260k, False: 43.4k]
  ------------------
  408|   260k|      curve_sqr_tmp(r, tmp, ws);
  409|   260k|   }
  410|  43.4k|   curve_mul_tmp(r, rl, tmp, ws);
  411|       |
  412|   173k|   for(size_t i = 0; i != 3; ++i) {
  ------------------
  |  Branch (412:22): [True: 130k, False: 43.4k]
  ------------------
  413|   130k|      curve_sqr_tmp(r, tmp, ws);
  414|   130k|   }
  415|  43.4k|   curve_mul_tmp(r, x3, tmp, ws);
  416|       |
  417|  43.4k|   x15 = r;
  418|   694k|   for(size_t i = 0; i != 15; ++i) {
  ------------------
  |  Branch (418:22): [True: 651k, False: 43.4k]
  ------------------
  419|   651k|      curve_sqr_tmp(r, tmp, ws);
  420|   651k|   }
  421|  43.4k|   curve_mul_tmp(r, x15, tmp, ws);
  422|       |
  423|  43.4k|   x30 = r;
  424|  1.34M|   for(size_t i = 0; i != 30; ++i) {
  ------------------
  |  Branch (424:22): [True: 1.30M, False: 43.4k]
  ------------------
  425|  1.30M|      curve_sqr_tmp(r, tmp, ws);
  426|  1.30M|   }
  427|  43.4k|   curve_mul_tmp(r, x30, tmp, ws);
  428|       |
  429|  43.4k|   rl = r;
  430|  2.64M|   for(size_t i = 0; i != 60; ++i) {
  ------------------
  |  Branch (430:22): [True: 2.60M, False: 43.4k]
  ------------------
  431|  2.60M|      curve_sqr_tmp(r, tmp, ws);
  432|  2.60M|   }
  433|  43.4k|   curve_mul_tmp(r, rl, tmp, ws);
  434|       |
  435|  43.4k|   rl = r;
  436|  5.25M|   for(size_t i = 0; i != 120; ++i) {
  ------------------
  |  Branch (436:22): [True: 5.21M, False: 43.4k]
  ------------------
  437|  5.21M|      curve_sqr_tmp(r, tmp, ws);
  438|  5.21M|   }
  439|  43.4k|   curve_mul_tmp(r, rl, tmp, ws);
  440|       |
  441|   694k|   for(size_t i = 0; i != 15; ++i) {
  ------------------
  |  Branch (441:22): [True: 651k, False: 43.4k]
  ------------------
  442|   651k|      curve_sqr_tmp(r, tmp, ws);
  443|   651k|   }
  444|  43.4k|   curve_mul_tmp(r, x15, tmp, ws);
  445|       |
  446|  1.38M|   for(size_t i = 0; i != 31; ++i) {
  ------------------
  |  Branch (446:22): [True: 1.34M, False: 43.4k]
  ------------------
  447|  1.34M|      curve_sqr_tmp(r, tmp, ws);
  448|  1.34M|   }
  449|  43.4k|   curve_mul_tmp(r, x30, tmp, ws);
  450|       |
  451|   130k|   for(size_t i = 0; i != 2; ++i) {
  ------------------
  |  Branch (451:22): [True: 86.8k, False: 43.4k]
  ------------------
  452|  86.8k|      curve_sqr_tmp(r, tmp, ws);
  453|  86.8k|   }
  454|  43.4k|   curve_mul_tmp(r, x2, tmp, ws);
  455|       |
  456|  4.12M|   for(size_t i = 0; i != 94; ++i) {
  ------------------
  |  Branch (456:22): [True: 4.08M, False: 43.4k]
  ------------------
  457|  4.08M|      curve_sqr_tmp(r, tmp, ws);
  458|  4.08M|   }
  459|  43.4k|   curve_mul_tmp(r, x30, tmp, ws);
  460|       |
  461|   130k|   for(size_t i = 0; i != 2; ++i) {
  ------------------
  |  Branch (461:22): [True: 86.8k, False: 43.4k]
  ------------------
  462|  86.8k|      curve_sqr_tmp(r, tmp, ws);
  463|  86.8k|   }
  464|       |
  465|  43.4k|   curve_mul_tmp(r, x, tmp, ws);
  466|       |
  467|  43.4k|   return r;
  468|  43.4k|}
curve_gfp.cpp:_ZNK5Botan12_GLOBAL__N_113CurveGFp_P38410redc_mod_pERNS_6BigIntERNSt3__16vectorImNS_16secure_allocatorImEEEE:
  381|  65.1M|      void redc_mod_p(BigInt& x, secure_vector<word>& ws) const override { redc_p384(x, ws); }

_ZN5Botan8EC_Group13ec_group_dataEv:
  289|      1|EC_Group_Data_Map& EC_Group::ec_group_data() {
  290|       |   /*
  291|       |   * This exists purely to ensure the allocator is constructed before g_ec_data,
  292|       |   * which ensures that its destructor runs after ~g_ec_data is complete.
  293|       |   */
  294|       |
  295|      1|   static Allocator_Initializer g_init_allocator;
  296|      1|   static EC_Group_Data_Map g_ec_data;
  297|      1|   return g_ec_data;
  298|      1|}
_ZN5Botan8EC_Group18load_EC_group_infoEPKcS2_S2_S2_S2_S2_RKNS_3OIDE:
  312|      1|                                                            const OID& oid) {
  313|      1|   const BigInt p(p_str);
  314|      1|   const BigInt a(a_str);
  315|      1|   const BigInt b(b_str);
  316|      1|   const BigInt g_x(g_x_str);
  317|      1|   const BigInt g_y(g_y_str);
  318|      1|   const BigInt order(order_str);
  319|      1|   const BigInt cofactor(1);  // implicit
  320|       |
  321|      1|   return std::make_shared<EC_Group_Data>(p, a, b, g_x, g_y, order, cofactor, oid, EC_Group_Source::Builtin);
  322|      1|}
_ZN5Botan8EC_GroupD2Ev:
  400|      1|EC_Group::~EC_Group() = default;
_ZN5Botan8EC_GroupC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
  409|      1|EC_Group::EC_Group(std::string_view str) {
  410|      1|   if(str.empty()) {
  ------------------
  |  Branch (410:7): [True: 0, False: 1]
  ------------------
  411|      0|      return;  // no initialization / uninitialized
  412|      0|   }
  413|       |
  414|      1|   try {
  415|      1|      const OID oid = OID::from_string(str);
  416|      1|      if(oid.has_value()) {
  ------------------
  |  Branch (416:10): [True: 1, False: 0]
  ------------------
  417|      1|         m_data = ec_group_data().lookup(oid);
  418|      1|      }
  419|      1|   } catch(...) {}
  420|       |
  421|      1|   if(m_data == nullptr) {
  ------------------
  |  Branch (421:7): [True: 0, False: 1]
  ------------------
  422|      0|      if(str.size() > 30 && str.substr(0, 29) == "-----BEGIN EC PARAMETERS-----") {
  ------------------
  |  Branch (422:10): [True: 0, False: 0]
  |  Branch (422:29): [True: 0, False: 0]
  ------------------
  423|       |         // OK try it as PEM ...
  424|      0|         secure_vector<uint8_t> ber = PEM_Code::decode_check_label(str, "EC PARAMETERS");
  425|       |
  426|      0|         auto data = BER_decode_EC_group(ber.data(), ber.size(), EC_Group_Source::ExternalSource);
  427|      0|         this->m_data = data.first;
  428|      0|         this->m_explicit_encoding = data.second;
  429|      0|      }
  430|      0|   }
  431|       |
  432|      1|   if(m_data == nullptr) {
  ------------------
  |  Branch (432:7): [True: 0, False: 1]
  ------------------
  433|      0|      throw Invalid_Argument(fmt("Unknown ECC group '{}'", str));
  434|      0|   }
  435|      1|}
_ZNK5Botan8EC_Group4dataEv:
  461|  19.6k|const EC_Group_Data& EC_Group::data() const {
  462|  19.6k|   if(m_data == nullptr) {
  ------------------
  |  Branch (462:7): [True: 0, False: 19.6k]
  ------------------
  463|      0|      throw Invalid_State("EC_Group uninitialized");
  464|      0|   }
  465|  19.6k|   return *m_data;
  466|  19.6k|}
_ZNK5Botan8EC_Group5get_pEv:
  492|  1.36k|const BigInt& EC_Group::get_p() const {
  493|  1.36k|   return data().p();
  494|  1.36k|}
_ZNK5Botan8EC_Group5get_aEv:
  496|  1.36k|const BigInt& EC_Group::get_a() const {
  497|  1.36k|   return data().a();
  498|  1.36k|}
_ZNK5Botan8EC_Group5get_bEv:
  500|  1.36k|const BigInt& EC_Group::get_b() const {
  501|  1.36k|   return data().b();
  502|  1.36k|}
_ZNK5Botan8EC_Group14get_base_pointEv:
  504|      1|const EC_Point& EC_Group::get_base_point() const {
  505|      1|   return data().base_point();
  506|      1|}
_ZNK5Botan8EC_Group9get_orderEv:
  508|  4.92k|const BigInt& EC_Group::get_order() const {
  509|  4.92k|   return data().order();
  510|  4.92k|}
_ZNK5Botan8EC_Group12get_cofactorEv:
  520|  4.92k|const BigInt& EC_Group::get_cofactor() const {
  521|  4.92k|   return data().cofactor();
  522|  4.92k|}
_ZNK5Botan8EC_Group5pointERKNS_6BigIntES3_:
  565|  1.67k|EC_Point EC_Group::point(const BigInt& x, const BigInt& y) const {
  566|       |   // TODO: randomize the representation?
  567|  1.67k|   return EC_Point(data().curve(), x, y);
  568|  1.67k|}
_ZNK5Botan8EC_Group27blinded_base_point_multiplyERKNS_6BigIntERNS_21RandomNumberGeneratorERNSt3__16vectorIS1_NS6_9allocatorIS1_EEEE:
  577|  4.08k|                                               std::vector<BigInt>& ws) const {
  578|  4.08k|   return data().blinded_base_point_multiply(k, rng, ws);
  579|  4.08k|}
_ZNK5Botan8EC_Group26blinded_var_point_multiplyERKNS_8EC_PointERKNS_6BigIntERNS_21RandomNumberGeneratorERNSt3__16vectorIS4_NS9_9allocatorIS4_EEEE:
  599|  4.92k|                                              std::vector<BigInt>& ws) const {
  600|  4.92k|   EC_Point_Var_Point_Precompute mul(point, rng, ws);
  601|       |   // We pass order*cofactor here to "correctly" handle the case where the
  602|       |   // point is on the curve but not in the prime order subgroup. This only
  603|       |   // matters for groups with cofactor > 1
  604|       |   // See https://github.com/randombit/botan/issues/3800
  605|  4.92k|   return mul.mul(k, rng, get_order() * get_cofactor(), ws);
  606|  4.92k|}
_ZN5Botan17EC_Group_Data_MapC2Ev:
  147|      1|      EC_Group_Data_Map() = default;
_ZN5Botan17EC_Group_Data_Map6lookupERKNS_3OIDE:
  156|      1|      std::shared_ptr<EC_Group_Data> lookup(const OID& oid) {
  157|      1|         lock_guard_type<mutex_type> lock(m_mutex);
  158|       |
  159|      1|         for(auto i : m_registered_curves) {
  ------------------
  |  Branch (159:21): [True: 0, False: 1]
  ------------------
  160|      0|            if(i->oid() == oid) {
  ------------------
  |  Branch (160:16): [True: 0, False: 0]
  ------------------
  161|      0|               return i;
  162|      0|            }
  163|      0|         }
  164|       |
  165|       |         // Not found, check hardcoded data
  166|      1|         std::shared_ptr<EC_Group_Data> data = EC_Group::EC_group_info(oid);
  167|       |
  168|      1|         if(data) {
  ------------------
  |  Branch (168:13): [True: 1, False: 0]
  ------------------
  169|      1|            for(auto curve : m_registered_curves) {
  ------------------
  |  Branch (169:28): [True: 0, False: 1]
  ------------------
  170|      0|               if(curve->oid().empty() == true && curve->params_match(*data)) {
  ------------------
  |  Branch (170:19): [True: 0, False: 0]
  |  Branch (170:51): [True: 0, False: 0]
  ------------------
  171|      0|                  curve->set_oid(oid);
  172|      0|                  return curve;
  173|      0|               }
  174|      0|            }
  175|       |
  176|      1|            m_registered_curves.push_back(data);
  177|      1|            return data;
  178|      1|         }
  179|       |
  180|       |         // Nope, unknown curve
  181|      0|         return std::shared_ptr<EC_Group_Data>();
  182|      1|      }
_ZN5Botan13EC_Group_DataC2ERKNS_6BigIntES3_S3_S3_S3_S3_S3_RKNS_3OIDENS_15EC_Group_SourceE:
   54|      1|            m_source(source) {}
_ZNK5Botan13EC_Group_Data1pEv:
   79|  1.36k|      const BigInt& p() const { return m_curve.get_p(); }
_ZNK5Botan13EC_Group_Data1aEv:
   81|  1.36k|      const BigInt& a() const { return m_curve.get_a(); }
_ZNK5Botan13EC_Group_Data1bEv:
   83|  1.36k|      const BigInt& b() const { return m_curve.get_b(); }
_ZNK5Botan13EC_Group_Data10base_pointEv:
  103|      1|      const EC_Point& base_point() const { return m_base_point; }
_ZNK5Botan13EC_Group_Data5orderEv:
   85|  4.92k|      const BigInt& order() const { return m_order; }
_ZNK5Botan13EC_Group_Data8cofactorEv:
   87|  4.92k|      const BigInt& cofactor() const { return m_cofactor; }
_ZNK5Botan13EC_Group_Data5curveEv:
  101|  1.67k|      const CurveGFp& curve() const { return m_curve; }
_ZNK5Botan13EC_Group_Data27blinded_base_point_multiplyERKNS_6BigIntERNS_21RandomNumberGeneratorERNSt3__16vectorIS1_NS6_9allocatorIS1_EEEE:
  121|  4.08k|      EC_Point blinded_base_point_multiply(const BigInt& k, RandomNumberGenerator& rng, std::vector<BigInt>& ws) const {
  122|  4.08k|         return m_base_mult.mul(k, rng, m_order, ws);
  123|  4.08k|      }

_ZN5Botan8EC_Group13EC_group_infoERKNS_3OIDE:
   15|      1|std::shared_ptr<EC_Group_Data> EC_Group::EC_group_info(const OID& oid) {
   16|       |   // secp256r1
   17|      1|   if(oid == OID{1, 2, 840, 10045, 3, 1, 7}) {
  ------------------
  |  Branch (17:7): [True: 0, False: 1]
  ------------------
   18|      0|      return load_EC_group_info(
   19|      0|         "0xFFFFFFFF00000001000000000000000000000000FFFFFFFFFFFFFFFFFFFFFFFF",
   20|      0|         "0xFFFFFFFF00000001000000000000000000000000FFFFFFFFFFFFFFFFFFFFFFFC",
   21|      0|         "0x5AC635D8AA3A93E7B3EBBD55769886BC651D06B0CC53B0F63BCE3C3E27D2604B",
   22|      0|         "0x6B17D1F2E12C4247F8BCE6E563A440F277037D812DEB33A0F4A13945D898C296",
   23|      0|         "0x4FE342E2FE1A7F9B8EE7EB4A7C0F9E162BCE33576B315ECECBB6406837BF51F5",
   24|      0|         "0xFFFFFFFF00000000FFFFFFFFFFFFFFFFBCE6FAADA7179E84F3B9CAC2FC632551",
   25|      0|         oid);
   26|      0|   }
   27|       |
   28|       |   // secp384r1
   29|      1|   if(oid == OID{1, 3, 132, 0, 34}) {
  ------------------
  |  Branch (29:7): [True: 1, False: 0]
  ------------------
   30|      1|      return load_EC_group_info(
   31|      1|         "0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFF0000000000000000FFFFFFFF",
   32|      1|         "0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFF0000000000000000FFFFFFFC",
   33|      1|         "0xB3312FA7E23EE7E4988E056BE3F82D19181D9C6EFE8141120314088F5013875AC656398D8A2ED19D2A85C8EDD3EC2AEF",
   34|      1|         "0xAA87CA22BE8B05378EB1C71EF320AD746E1D3B628BA79B9859F741E082542A385502F25DBF55296C3A545E3872760AB7",
   35|      1|         "0x3617DE4A96262C6F5D9E98BF9292DC29F8F41DBD289A147CE9DA3113B5F0B8C00A60B1CE1D7E819D7A431D7C90EA0E5F",
   36|      1|         "0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFC7634D81F4372DDF581A0DB248B0A77AECEC196ACCC52973",
   37|      1|         oid);
   38|      1|   }
   39|       |
   40|       |   // secp521r1
   41|      0|   if(oid == OID{1, 3, 132, 0, 35}) {
  ------------------
  |  Branch (41:7): [True: 0, False: 0]
  ------------------
   42|      0|      return load_EC_group_info(
   43|      0|         "0x1FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF",
   44|      0|         "0x1FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFC",
   45|      0|         "0x51953EB9618E1C9A1F929A21A0B68540EEA2DA725B99B315F3B8B489918EF109E156193951EC7E937B1652C0BD3BB1BF073573DF883D2C34F1EF451FD46B503F00",
   46|      0|         "0xC6858E06B70404E9CD9E3ECB662395B4429C648139053FB521F828AF606B4D3DBAA14B5E77EFE75928FE1DC127A2FFA8DE3348B3C1856A429BF97E7E31C2E5BD66",
   47|      0|         "0x11839296A789A3BC0045C8A5FB42C7D1BD998F54449579B446817AFBD17273E662C97EE72995EF42640C550B9013FAD0761353C7086A272C24088BE94769FD16650",
   48|      0|         "0x1FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFA51868783BF2F966B7FCC0148F709A5D03BB5C9B8899C47AEBB6FB71E91386409",
   49|      0|         oid);
   50|      0|   }
   51|       |
   52|       |   // brainpool160r1
   53|      0|   if(oid == OID{1, 3, 36, 3, 3, 2, 8, 1, 1, 1}) {
  ------------------
  |  Branch (53:7): [True: 0, False: 0]
  ------------------
   54|      0|      return load_EC_group_info(
   55|      0|         "0xE95E4A5F737059DC60DFC7AD95B3D8139515620F",
   56|      0|         "0x340E7BE2A280EB74E2BE61BADA745D97E8F7C300",
   57|      0|         "0x1E589A8595423412134FAA2DBDEC95C8D8675E58",
   58|      0|         "0xBED5AF16EA3F6A4F62938C4631EB5AF7BDBCDBC3",
   59|      0|         "0x1667CB477A1A8EC338F94741669C976316DA6321",
   60|      0|         "0xE95E4A5F737059DC60DF5991D45029409E60FC09",
   61|      0|         oid);
   62|      0|   }
   63|       |
   64|       |   // brainpool192r1
   65|      0|   if(oid == OID{1, 3, 36, 3, 3, 2, 8, 1, 1, 3}) {
  ------------------
  |  Branch (65:7): [True: 0, False: 0]
  ------------------
   66|      0|      return load_EC_group_info(
   67|      0|         "0xC302F41D932A36CDA7A3463093D18DB78FCE476DE1A86297",
   68|      0|         "0x6A91174076B1E0E19C39C031FE8685C1CAE040E5C69A28EF",
   69|      0|         "0x469A28EF7C28CCA3DC721D044F4496BCCA7EF4146FBF25C9",
   70|      0|         "0xC0A0647EAAB6A48753B033C56CB0F0900A2F5C4853375FD6",
   71|      0|         "0x14B690866ABD5BB88B5F4828C1490002E6773FA2FA299B8F",
   72|      0|         "0xC302F41D932A36CDA7A3462F9E9E916B5BE8F1029AC4ACC1",
   73|      0|         oid);
   74|      0|   }
   75|       |
   76|       |   // brainpool224r1
   77|      0|   if(oid == OID{1, 3, 36, 3, 3, 2, 8, 1, 1, 5}) {
  ------------------
  |  Branch (77:7): [True: 0, False: 0]
  ------------------
   78|      0|      return load_EC_group_info(
   79|      0|         "0xD7C134AA264366862A18302575D1D787B09F075797DA89F57EC8C0FF",
   80|      0|         "0x68A5E62CA9CE6C1C299803A6C1530B514E182AD8B0042A59CAD29F43",
   81|      0|         "0x2580F63CCFE44138870713B1A92369E33E2135D266DBB372386C400B",
   82|      0|         "0xD9029AD2C7E5CF4340823B2A87DC68C9E4CE3174C1E6EFDEE12C07D",
   83|      0|         "0x58AA56F772C0726F24C6B89E4ECDAC24354B9E99CAA3F6D3761402CD",
   84|      0|         "0xD7C134AA264366862A18302575D0FB98D116BC4B6DDEBCA3A5A7939F",
   85|      0|         oid);
   86|      0|   }
   87|       |
   88|       |   // brainpool256r1
   89|      0|   if(oid == OID{1, 3, 36, 3, 3, 2, 8, 1, 1, 7}) {
  ------------------
  |  Branch (89:7): [True: 0, False: 0]
  ------------------
   90|      0|      return load_EC_group_info(
   91|      0|         "0xA9FB57DBA1EEA9BC3E660A909D838D726E3BF623D52620282013481D1F6E5377",
   92|      0|         "0x7D5A0975FC2C3057EEF67530417AFFE7FB8055C126DC5C6CE94A4B44F330B5D9",
   93|      0|         "0x26DC5C6CE94A4B44F330B5D9BBD77CBF958416295CF7E1CE6BCCDC18FF8C07B6",
   94|      0|         "0x8BD2AEB9CB7E57CB2C4B482FFC81B7AFB9DE27E1E3BD23C23A4453BD9ACE3262",
   95|      0|         "0x547EF835C3DAC4FD97F8461A14611DC9C27745132DED8E545C1D54C72F046997",
   96|      0|         "0xA9FB57DBA1EEA9BC3E660A909D838D718C397AA3B561A6F7901E0E82974856A7",
   97|      0|         oid);
   98|      0|   }
   99|       |
  100|       |   // brainpool320r1
  101|      0|   if(oid == OID{1, 3, 36, 3, 3, 2, 8, 1, 1, 9}) {
  ------------------
  |  Branch (101:7): [True: 0, False: 0]
  ------------------
  102|      0|      return load_EC_group_info(
  103|      0|         "0xD35E472036BC4FB7E13C785ED201E065F98FCFA6F6F40DEF4F92B9EC7893EC28FCD412B1F1B32E27",
  104|      0|         "0x3EE30B568FBAB0F883CCEBD46D3F3BB8A2A73513F5EB79DA66190EB085FFA9F492F375A97D860EB4",
  105|      0|         "0x520883949DFDBC42D3AD198640688A6FE13F41349554B49ACC31DCCD884539816F5EB4AC8FB1F1A6",
  106|      0|         "0x43BD7E9AFB53D8B85289BCC48EE5BFE6F20137D10A087EB6E7871E2A10A599C710AF8D0D39E20611",
  107|      0|         "0x14FDD05545EC1CC8AB4093247F77275E0743FFED117182EAA9C77877AAAC6AC7D35245D1692E8EE1",
  108|      0|         "0xD35E472036BC4FB7E13C785ED201E065F98FCFA5B68F12A32D482EC7EE8658E98691555B44C59311",
  109|      0|         oid);
  110|      0|   }
  111|       |
  112|       |   // brainpool384r1
  113|      0|   if(oid == OID{1, 3, 36, 3, 3, 2, 8, 1, 1, 11}) {
  ------------------
  |  Branch (113:7): [True: 0, False: 0]
  ------------------
  114|      0|      return load_EC_group_info(
  115|      0|         "0x8CB91E82A3386D280F5D6F7E50E641DF152F7109ED5456B412B1DA197FB71123ACD3A729901D1A71874700133107EC53",
  116|      0|         "0x7BC382C63D8C150C3C72080ACE05AFA0C2BEA28E4FB22787139165EFBA91F90F8AA5814A503AD4EB04A8C7DD22CE2826",
  117|      0|         "0x4A8C7DD22CE28268B39B55416F0447C2FB77DE107DCD2A62E880EA53EEB62D57CB4390295DBC9943AB78696FA504C11",
  118|      0|         "0x1D1C64F068CF45FFA2A63A81B7C13F6B8847A3E77EF14FE3DB7FCAFE0CBD10E8E826E03436D646AAEF87B2E247D4AF1E",
  119|      0|         "0x8ABE1D7520F9C2A45CB1EB8E95CFD55262B70B29FEEC5864E19C054FF99129280E4646217791811142820341263C5315",
  120|      0|         "0x8CB91E82A3386D280F5D6F7E50E641DF152F7109ED5456B31F166E6CAC0425A7CF3AB6AF6B7FC3103B883202E9046565",
  121|      0|         oid);
  122|      0|   }
  123|       |
  124|       |   // brainpool512r1
  125|      0|   if(oid == OID{1, 3, 36, 3, 3, 2, 8, 1, 1, 13}) {
  ------------------
  |  Branch (125:7): [True: 0, False: 0]
  ------------------
  126|      0|      return load_EC_group_info(
  127|      0|         "0xAADD9DB8DBE9C48B3FD4E6AE33C9FC07CB308DB3B3C9D20ED6639CCA703308717D4D9B009BC66842AECDA12AE6A380E62881FF2F2D82C68528AA6056583A48F3",
  128|      0|         "0x7830A3318B603B89E2327145AC234CC594CBDD8D3DF91610A83441CAEA9863BC2DED5D5AA8253AA10A2EF1C98B9AC8B57F1117A72BF2C7B9E7C1AC4D77FC94CA",
  129|      0|         "0x3DF91610A83441CAEA9863BC2DED5D5AA8253AA10A2EF1C98B9AC8B57F1117A72BF2C7B9E7C1AC4D77FC94CADC083E67984050B75EBAE5DD2809BD638016F723",
  130|      0|         "0x81AEE4BDD82ED9645A21322E9C4C6A9385ED9F70B5D916C1B43B62EEF4D0098EFF3B1F78E2D0D48D50D1687B93B97D5F7C6D5047406A5E688B352209BCB9F822",
  131|      0|         "0x7DDE385D566332ECC0EABFA9CF7822FDF209F70024A57B1AA000C55B881F8111B2DCDE494A5F485E5BCA4BD88A2763AED1CA2B2FA8F0540678CD1E0F3AD80892",
  132|      0|         "0xAADD9DB8DBE9C48B3FD4E6AE33C9FC07CB308DB3B3C9D20ED6639CCA70330870553E5C414CA92619418661197FAC10471DB1D381085DDADDB58796829CA90069",
  133|      0|         oid);
  134|      0|   }
  135|       |
  136|       |   // frp256v1
  137|      0|   if(oid == OID{1, 2, 250, 1, 223, 101, 256, 1}) {
  ------------------
  |  Branch (137:7): [True: 0, False: 0]
  ------------------
  138|      0|      return load_EC_group_info(
  139|      0|         "0xF1FD178C0B3AD58F10126DE8CE42435B3961ADBCABC8CA6DE8FCF353D86E9C03",
  140|      0|         "0xF1FD178C0B3AD58F10126DE8CE42435B3961ADBCABC8CA6DE8FCF353D86E9C00",
  141|      0|         "0xEE353FCA5428A9300D4ABA754A44C00FDFEC0C9AE4B1A1803075ED967B7BB73F",
  142|      0|         "0xB6B3D4C356C139EB31183D4749D423958C27D2DCAF98B70164C97A2DD98F5CFF",
  143|      0|         "0x6142E0F7C8B204911F9271F0F3ECEF8C2701C307E8E4C9E183115A1554062CFB",
  144|      0|         "0xF1FD178C0B3AD58F10126DE8CE42435B53DC67E140D2BF941FFDD459C6D655E1",
  145|      0|         oid);
  146|      0|   }
  147|       |
  148|       |   // gost_256A
  149|      0|   if(oid == OID{1, 2, 643, 7, 1, 2, 1, 1, 1} || oid == OID{1, 2, 643, 2, 2, 35, 1} || oid == OID{1, 2, 643, 2, 2, 36, 0}) {
  ------------------
  |  Branch (149:7): [True: 0, False: 0]
  |  Branch (149:7): [True: 0, False: 0]
  |  Branch (149:50): [True: 0, False: 0]
  |  Branch (149:88): [True: 0, False: 0]
  ------------------
  150|      0|      return load_EC_group_info(
  151|      0|         "0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFD97",
  152|      0|         "0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFD94",
  153|      0|         "0xA6",
  154|      0|         "1",
  155|      0|         "0x8D91E471E0989CDA27DF505A453F2B7635294F2DDF23E3B122ACC99C9E9F1E14",
  156|      0|         "0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF6C611070995AD10045841B09B761B893",
  157|      0|         OID{1, 2, 643, 7, 1, 2, 1, 1, 1});
  158|      0|   }
  159|       |
  160|       |   // gost_512A
  161|      0|   if(oid == OID{1, 2, 643, 7, 1, 2, 1, 2, 1}) {
  ------------------
  |  Branch (161:7): [True: 0, False: 0]
  ------------------
  162|      0|      return load_EC_group_info(
  163|      0|         "0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFDC7",
  164|      0|         "0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFDC4",
  165|      0|         "0xE8C2505DEDFC86DDC1BD0B2B6667F1DA34B82574761CB0E879BD081CFD0B6265EE3CB090F30D27614CB4574010DA90DD862EF9D4EBEE4761503190785A71C760",
  166|      0|         "3",
  167|      0|         "0x7503CFE87A836AE3A61B8816E25450E6CE5E1C93ACF1ABC1778064FDCBEFA921DF1626BE4FD036E93D75E6A50E3A41E98028FE5FC235F5B889A589CB5215F2A4",
  168|      0|         "0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF27E69532F48D89116FF22B8D4E0560609B4B38ABFAD2B85DCACDB1411F10B275",
  169|      0|         oid);
  170|      0|   }
  171|       |
  172|       |   // secp160k1
  173|      0|   if(oid == OID{1, 3, 132, 0, 9}) {
  ------------------
  |  Branch (173:7): [True: 0, False: 0]
  ------------------
  174|      0|      return load_EC_group_info(
  175|      0|         "0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFAC73",
  176|      0|         "0",
  177|      0|         "7",
  178|      0|         "0x3B4C382CE37AA192A4019E763036F4F5DD4D7EBB",
  179|      0|         "0x938CF935318FDCED6BC28286531733C3F03C4FEE",
  180|      0|         "0x100000000000000000001B8FA16DFAB9ACA16B6B3",
  181|      0|         oid);
  182|      0|   }
  183|       |
  184|       |   // secp160r1
  185|      0|   if(oid == OID{1, 3, 132, 0, 8}) {
  ------------------
  |  Branch (185:7): [True: 0, False: 0]
  ------------------
  186|      0|      return load_EC_group_info(
  187|      0|         "0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF7FFFFFFF",
  188|      0|         "0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF7FFFFFFC",
  189|      0|         "0x1C97BEFC54BD7A8B65ACF89F81D4D4ADC565FA45",
  190|      0|         "0x4A96B5688EF573284664698968C38BB913CBFC82",
  191|      0|         "0x23A628553168947D59DCC912042351377AC5FB32",
  192|      0|         "0x100000000000000000001F4C8F927AED3CA752257",
  193|      0|         oid);
  194|      0|   }
  195|       |
  196|       |   // secp160r2
  197|      0|   if(oid == OID{1, 3, 132, 0, 30}) {
  ------------------
  |  Branch (197:7): [True: 0, False: 0]
  ------------------
  198|      0|      return load_EC_group_info(
  199|      0|         "0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFAC73",
  200|      0|         "0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFAC70",
  201|      0|         "0xB4E134D3FB59EB8BAB57274904664D5AF50388BA",
  202|      0|         "0x52DCB034293A117E1F4FF11B30F7199D3144CE6D",
  203|      0|         "0xFEAFFEF2E331F296E071FA0DF9982CFEA7D43F2E",
  204|      0|         "0x100000000000000000000351EE786A818F3A1A16B",
  205|      0|         oid);
  206|      0|   }
  207|       |
  208|       |   // secp192k1
  209|      0|   if(oid == OID{1, 3, 132, 0, 31}) {
  ------------------
  |  Branch (209:7): [True: 0, False: 0]
  ------------------
  210|      0|      return load_EC_group_info(
  211|      0|         "0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFEE37",
  212|      0|         "0",
  213|      0|         "3",
  214|      0|         "0xDB4FF10EC057E9AE26B07D0280B7F4341DA5D1B1EAE06C7D",
  215|      0|         "0x9B2F2F6D9C5628A7844163D015BE86344082AA88D95E2F9D",
  216|      0|         "0xFFFFFFFFFFFFFFFFFFFFFFFE26F2FC170F69466A74DEFD8D",
  217|      0|         oid);
  218|      0|   }
  219|       |
  220|       |   // secp192r1
  221|      0|   if(oid == OID{1, 2, 840, 10045, 3, 1, 1}) {
  ------------------
  |  Branch (221:7): [True: 0, False: 0]
  ------------------
  222|      0|      return load_EC_group_info(
  223|      0|         "0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFF",
  224|      0|         "0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFC",
  225|      0|         "0x64210519E59C80E70FA7E9AB72243049FEB8DEECC146B9B1",
  226|      0|         "0x188DA80EB03090F67CBF20EB43A18800F4FF0AFD82FF1012",
  227|      0|         "0x7192B95FFC8DA78631011ED6B24CDD573F977A11E794811",
  228|      0|         "0xFFFFFFFFFFFFFFFFFFFFFFFF99DEF836146BC9B1B4D22831",
  229|      0|         oid);
  230|      0|   }
  231|       |
  232|       |   // secp224k1
  233|      0|   if(oid == OID{1, 3, 132, 0, 32}) {
  ------------------
  |  Branch (233:7): [True: 0, False: 0]
  ------------------
  234|      0|      return load_EC_group_info(
  235|      0|         "0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFE56D",
  236|      0|         "0",
  237|      0|         "5",
  238|      0|         "0xA1455B334DF099DF30FC28A169A467E9E47075A90F7E650EB6B7A45C",
  239|      0|         "0x7E089FED7FBA344282CAFBD6F7E319F7C0B0BD59E2CA4BDB556D61A5",
  240|      0|         "0x10000000000000000000000000001DCE8D2EC6184CAF0A971769FB1F7",
  241|      0|         oid);
  242|      0|   }
  243|       |
  244|       |   // secp224r1
  245|      0|   if(oid == OID{1, 3, 132, 0, 33}) {
  ------------------
  |  Branch (245:7): [True: 0, False: 0]
  ------------------
  246|      0|      return load_EC_group_info(
  247|      0|         "0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF000000000000000000000001",
  248|      0|         "0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFFFFFFFFFE",
  249|      0|         "0xB4050A850C04B3ABF54132565044B0B7D7BFD8BA270B39432355FFB4",
  250|      0|         "0xB70E0CBD6BB4BF7F321390B94A03C1D356C21122343280D6115C1D21",
  251|      0|         "0xBD376388B5F723FB4C22DFE6CD4375A05A07476444D5819985007E34",
  252|      0|         "0xFFFFFFFFFFFFFFFFFFFFFFFFFFFF16A2E0B8F03E13DD29455C5C2A3D",
  253|      0|         oid);
  254|      0|   }
  255|       |
  256|       |   // secp256k1
  257|      0|   if(oid == OID{1, 3, 132, 0, 10}) {
  ------------------
  |  Branch (257:7): [True: 0, False: 0]
  ------------------
  258|      0|      return load_EC_group_info(
  259|      0|         "0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFC2F",
  260|      0|         "0",
  261|      0|         "7",
  262|      0|         "0x79BE667EF9DCBBAC55A06295CE870B07029BFCDB2DCE28D959F2815B16F81798",
  263|      0|         "0x483ADA7726A3C4655DA4FBFC0E1108A8FD17B448A68554199C47D08FFB10D4B8",
  264|      0|         "0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEBAAEDCE6AF48A03BBFD25E8CD0364141",
  265|      0|         oid);
  266|      0|   }
  267|       |
  268|       |   // sm2p256v1
  269|      0|   if(oid == OID{1, 2, 156, 10197, 1, 301}) {
  ------------------
  |  Branch (269:7): [True: 0, False: 0]
  ------------------
  270|      0|      return load_EC_group_info(
  271|      0|         "0xFFFFFFFEFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00000000FFFFFFFFFFFFFFFF",
  272|      0|         "0xFFFFFFFEFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00000000FFFFFFFFFFFFFFFC",
  273|      0|         "0x28E9FA9E9D9F5E344D5A9E4BCF6509A7F39789F515AB8F92DDBCBD414D940E93",
  274|      0|         "0x32C4AE2C1F1981195F9904466A39C9948FE30BBFF2660BE1715A4589334C74C7",
  275|      0|         "0xBC3736A2F4F6779C59BDCEE36B692153D0A9877CC62A474002DF32E52139F0A0",
  276|      0|         "0xFFFFFFFEFFFFFFFFFFFFFFFFFFFFFFFF7203DF6B21C6052B53BBF40939D54123",
  277|      0|         oid);
  278|      0|   }
  279|       |
  280|       |   // x962_p192v2
  281|      0|   if(oid == OID{1, 2, 840, 10045, 3, 1, 2}) {
  ------------------
  |  Branch (281:7): [True: 0, False: 0]
  ------------------
  282|      0|      return load_EC_group_info(
  283|      0|         "0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFF",
  284|      0|         "0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFC",
  285|      0|         "0xCC22D6DFB95C6B25E49C0D6364A4E5980C393AA21668D953",
  286|      0|         "0xEEA2BAE7E1497842F2DE7769CFE9C989C072AD696F48034A",
  287|      0|         "0x6574D11D69B6EC7A672BB82A083DF2F2B0847DE970B2DE15",
  288|      0|         "0xFFFFFFFFFFFFFFFFFFFFFFFE5FB1A724DC80418648D8DD31",
  289|      0|         oid);
  290|      0|   }
  291|       |
  292|       |   // x962_p192v3
  293|      0|   if(oid == OID{1, 2, 840, 10045, 3, 1, 3}) {
  ------------------
  |  Branch (293:7): [True: 0, False: 0]
  ------------------
  294|      0|      return load_EC_group_info(
  295|      0|         "0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFF",
  296|      0|         "0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFEFFFFFFFFFFFFFFFC",
  297|      0|         "0x22123DC2395A05CAA7423DAECCC94760A7D462256BD56916",
  298|      0|         "0x7D29778100C65A1DA1783716588DCE2B8B4AEE8E228F1896",
  299|      0|         "0x38A90F22637337334B49DCB66A6DC8F9978ACA7648A943B0",
  300|      0|         "0xFFFFFFFFFFFFFFFFFFFFFFFF7A62D031C83F4294F640EC13",
  301|      0|         oid);
  302|      0|   }
  303|       |
  304|       |   // x962_p239v1
  305|      0|   if(oid == OID{1, 2, 840, 10045, 3, 1, 4}) {
  ------------------
  |  Branch (305:7): [True: 0, False: 0]
  ------------------
  306|      0|      return load_EC_group_info(
  307|      0|         "0x7FFFFFFFFFFFFFFFFFFFFFFF7FFFFFFFFFFF8000000000007FFFFFFFFFFF",
  308|      0|         "0x7FFFFFFFFFFFFFFFFFFFFFFF7FFFFFFFFFFF8000000000007FFFFFFFFFFC",
  309|      0|         "0x6B016C3BDCF18941D0D654921475CA71A9DB2FB27D1D37796185C2942C0A",
  310|      0|         "0xFFA963CDCA8816CCC33B8642BEDF905C3D358573D3F27FBBD3B3CB9AAAF",
  311|      0|         "0x7DEBE8E4E90A5DAE6E4054CA530BA04654B36818CE226B39FCCB7B02F1AE",
  312|      0|         "0x7FFFFFFFFFFFFFFFFFFFFFFF7FFFFF9E5E9A9F5D9071FBD1522688909D0B",
  313|      0|         oid);
  314|      0|   }
  315|       |
  316|       |   // x962_p239v2
  317|      0|   if(oid == OID{1, 2, 840, 10045, 3, 1, 5}) {
  ------------------
  |  Branch (317:7): [True: 0, False: 0]
  ------------------
  318|      0|      return load_EC_group_info(
  319|      0|         "0x7FFFFFFFFFFFFFFFFFFFFFFF7FFFFFFFFFFF8000000000007FFFFFFFFFFF",
  320|      0|         "0x7FFFFFFFFFFFFFFFFFFFFFFF7FFFFFFFFFFF8000000000007FFFFFFFFFFC",
  321|      0|         "0x617FAB6832576CBBFED50D99F0249C3FEE58B94BA0038C7AE84C8C832F2C",
  322|      0|         "0x38AF09D98727705120C921BB5E9E26296A3CDCF2F35757A0EAFD87B830E7",
  323|      0|         "0x5B0125E4DBEA0EC7206DA0FC01D9B081329FB555DE6EF460237DFF8BE4BA",
  324|      0|         "0x7FFFFFFFFFFFFFFFFFFFFFFF800000CFA7E8594377D414C03821BC582063",
  325|      0|         oid);
  326|      0|   }
  327|       |
  328|       |   // x962_p239v3
  329|      0|   if(oid == OID{1, 2, 840, 10045, 3, 1, 6}) {
  ------------------
  |  Branch (329:7): [True: 0, False: 0]
  ------------------
  330|      0|      return load_EC_group_info(
  331|      0|         "0x7FFFFFFFFFFFFFFFFFFFFFFF7FFFFFFFFFFF8000000000007FFFFFFFFFFF",
  332|      0|         "0x7FFFFFFFFFFFFFFFFFFFFFFF7FFFFFFFFFFF8000000000007FFFFFFFFFFC",
  333|      0|         "0x255705FA2A306654B1F4CB03D6A750A30C250102D4988717D9BA15AB6D3E",
  334|      0|         "0x6768AE8E18BB92CFCF005C949AA2C6D94853D0E660BBF854B1C9505FE95A",
  335|      0|         "0x1607E6898F390C06BC1D552BAD226F3B6FCFE48B6E818499AF18E3ED6CF3",
  336|      0|         "0x7FFFFFFFFFFFFFFFFFFFFFFF7FFFFF975DEB41B3A6057C3C432146526551",
  337|      0|         oid);
  338|      0|   }
  339|       |
  340|      0|   return std::shared_ptr<EC_Group_Data>();
  341|      0|}

_ZN5Botan8EC_PointC2ERKNS_8CurveGFpE:
   18|  18.0k|EC_Point::EC_Point(const CurveGFp& curve) : m_curve(curve), m_coord_x(0), m_coord_y(curve.get_1_rep()), m_coord_z(0) {
   19|       |   // Assumes Montgomery rep of zero is zero
   20|  18.0k|}
_ZN5Botan8EC_PointC2ERKNS_8CurveGFpERKNS_6BigIntES6_:
   23|  1.67k|      m_curve(curve), m_coord_x(x), m_coord_y(y), m_coord_z(m_curve.get_1_rep()) {
   24|  1.67k|   if(x < 0 || x >= curve.get_p()) {
  ------------------
  |  Branch (24:7): [True: 0, False: 1.67k]
  |  Branch (24:16): [True: 2, False: 1.67k]
  ------------------
   25|      2|      throw Invalid_Argument("Invalid EC_Point affine x");
   26|      2|   }
   27|  1.67k|   if(y < 0 || y >= curve.get_p()) {
  ------------------
  |  Branch (27:7): [True: 835, False: 836]
  |  Branch (27:16): [True: 0, False: 836]
  ------------------
   28|    835|      throw Invalid_Argument("Invalid EC_Point affine y");
   29|    835|   }
   30|       |
   31|    836|   secure_vector<word> monty_ws(m_curve.get_ws_size());
   32|    836|   m_curve.to_rep(m_coord_x, monty_ws);
   33|    836|   m_curve.to_rep(m_coord_y, monty_ws);
   34|    836|}
_ZN5Botan8EC_Point14randomize_reprERNS_21RandomNumberGeneratorERNSt3__16vectorImNS_16secure_allocatorImEEEE:
   41|  9.00k|void EC_Point::randomize_repr(RandomNumberGenerator& rng, secure_vector<word>& ws) {
   42|  9.00k|   const BigInt mask = BigInt::random_integer(rng, 2, m_curve.get_p());
   43|       |
   44|       |   /*
   45|       |   * No reason to convert this to Montgomery representation first,
   46|       |   * just pretend the random mask was chosen as Redc(mask) and the
   47|       |   * random mask we generated above is in the Montgomery
   48|       |   * representation.
   49|       |   * //m_curve.to_rep(mask, ws);
   50|       |   */
   51|  9.00k|   const BigInt mask2 = m_curve.sqr_to_tmp(mask, ws);
   52|  9.00k|   const BigInt mask3 = m_curve.mul_to_tmp(mask2, mask, ws);
   53|       |
   54|  9.00k|   m_coord_x = m_curve.mul_to_tmp(m_coord_x, mask2, ws);
   55|  9.00k|   m_coord_y = m_curve.mul_to_tmp(m_coord_y, mask3, ws);
   56|  9.00k|   m_coord_z = m_curve.mul_to_tmp(m_coord_z, mask, ws);
   57|  9.00k|}
_ZN5Botan8EC_Point10add_affineEPKmmS2_mRNSt3__16vectorINS_6BigIntENS3_9allocatorIS5_EEEE:
   74|   784k|   const word x_words[], size_t x_size, const word y_words[], size_t y_size, std::vector<BigInt>& ws_bn) {
   75|   784k|   if((CT::all_zeros(x_words, x_size) & CT::all_zeros(y_words, y_size)).as_bool()) {
  ------------------
  |  Branch (75:7): [True: 96.8k, False: 687k]
  ------------------
   76|  96.8k|      return;
   77|  96.8k|   }
   78|       |
   79|   687k|   if(is_zero()) {
  ------------------
  |  Branch (79:7): [True: 4.09k, False: 683k]
  ------------------
   80|  4.09k|      m_coord_x.set_words(x_words, x_size);
   81|  4.09k|      m_coord_y.set_words(y_words, y_size);
   82|  4.09k|      m_coord_z = m_curve.get_1_rep();
   83|  4.09k|      return;
   84|  4.09k|   }
   85|       |
   86|   683k|   resize_ws(ws_bn, m_curve.get_ws_size());
   87|       |
   88|   683k|   secure_vector<word>& ws = ws_bn[0].get_word_vector();
   89|   683k|   secure_vector<word>& sub_ws = ws_bn[1].get_word_vector();
   90|       |
   91|   683k|   BigInt& T0 = ws_bn[2];
   92|   683k|   BigInt& T1 = ws_bn[3];
   93|   683k|   BigInt& T2 = ws_bn[4];
   94|   683k|   BigInt& T3 = ws_bn[5];
   95|   683k|   BigInt& T4 = ws_bn[6];
   96|       |
   97|       |   /*
   98|       |   https://hyperelliptic.org/EFD/g1p/auto-shortw-jacobian-3.html#addition-add-1998-cmo-2
   99|       |   simplified with Z2 = 1
  100|       |   */
  101|       |
  102|   683k|   const BigInt& p = m_curve.get_p();
  103|       |
  104|   683k|   m_curve.sqr(T3, m_coord_z, ws);            // z1^2
  105|   683k|   m_curve.mul(T4, x_words, x_size, T3, ws);  // x2*z1^2
  106|       |
  107|   683k|   m_curve.mul(T2, m_coord_z, T3, ws);        // z1^3
  108|   683k|   m_curve.mul(T0, y_words, y_size, T2, ws);  // y2*z1^3
  109|       |
  110|   683k|   T4.mod_sub(m_coord_x, p, sub_ws);  // x2*z1^2 - x1*z2^2
  111|       |
  112|   683k|   T0.mod_sub(m_coord_y, p, sub_ws);
  113|       |
  114|   683k|   if(T4.is_zero()) {
  ------------------
  |  Branch (114:7): [True: 182, False: 683k]
  ------------------
  115|    182|      if(T0.is_zero()) {
  ------------------
  |  Branch (115:10): [True: 10, False: 172]
  ------------------
  116|     10|         mult2(ws_bn);
  117|     10|         return;
  118|     10|      }
  119|       |
  120|       |      // setting to zero:
  121|    172|      m_coord_x.clear();
  122|    172|      m_coord_y = m_curve.get_1_rep();
  123|    172|      m_coord_z.clear();
  124|    172|      return;
  125|    182|   }
  126|       |
  127|   683k|   m_curve.sqr(T2, T4, ws);
  128|       |
  129|   683k|   m_curve.mul(T3, m_coord_x, T2, ws);
  130|       |
  131|   683k|   m_curve.mul(T1, T2, T4, ws);
  132|       |
  133|   683k|   m_curve.sqr(m_coord_x, T0, ws);
  134|   683k|   m_coord_x.mod_sub(T1, p, sub_ws);
  135|       |
  136|   683k|   m_coord_x.mod_sub(T3, p, sub_ws);
  137|   683k|   m_coord_x.mod_sub(T3, p, sub_ws);
  138|       |
  139|   683k|   T3.mod_sub(m_coord_x, p, sub_ws);
  140|       |
  141|   683k|   m_curve.mul(T2, T0, T3, ws);
  142|   683k|   m_curve.mul(T0, m_coord_y, T1, ws);
  143|   683k|   T2.mod_sub(T0, p, sub_ws);
  144|   683k|   m_coord_y.swap(T2);
  145|       |
  146|   683k|   m_curve.mul(T0, m_coord_z, T4, ws);
  147|   683k|   m_coord_z.swap(T0);
  148|   683k|}
_ZN5Botan8EC_Point3addEPKmmS2_mS2_mRNSt3__16vectorINS_6BigIntENS3_9allocatorIS5_EEEE:
  156|   995k|                   std::vector<BigInt>& ws_bn) {
  157|   995k|   if((CT::all_zeros(x_words, x_size) & CT::all_zeros(z_words, z_size)).as_bool()) {
  ------------------
  |  Branch (157:7): [True: 44.4k, False: 950k]
  ------------------
  158|  44.4k|      return;
  159|  44.4k|   }
  160|       |
  161|   950k|   if(is_zero()) {
  ------------------
  |  Branch (161:7): [True: 9.30k, False: 941k]
  ------------------
  162|  9.30k|      m_coord_x.set_words(x_words, x_size);
  163|  9.30k|      m_coord_y.set_words(y_words, y_size);
  164|  9.30k|      m_coord_z.set_words(z_words, z_size);
  165|  9.30k|      return;
  166|  9.30k|   }
  167|       |
  168|   941k|   resize_ws(ws_bn, m_curve.get_ws_size());
  169|       |
  170|   941k|   secure_vector<word>& ws = ws_bn[0].get_word_vector();
  171|   941k|   secure_vector<word>& sub_ws = ws_bn[1].get_word_vector();
  172|       |
  173|   941k|   BigInt& T0 = ws_bn[2];
  174|   941k|   BigInt& T1 = ws_bn[3];
  175|   941k|   BigInt& T2 = ws_bn[4];
  176|   941k|   BigInt& T3 = ws_bn[5];
  177|   941k|   BigInt& T4 = ws_bn[6];
  178|   941k|   BigInt& T5 = ws_bn[7];
  179|       |
  180|       |   /*
  181|       |   https://hyperelliptic.org/EFD/g1p/auto-shortw-jacobian-3.html#addition-add-1998-cmo-2
  182|       |   */
  183|       |
  184|   941k|   const BigInt& p = m_curve.get_p();
  185|       |
  186|   941k|   m_curve.sqr(T0, z_words, z_size, ws);      // z2^2
  187|   941k|   m_curve.mul(T1, m_coord_x, T0, ws);        // x1*z2^2
  188|   941k|   m_curve.mul(T3, z_words, z_size, T0, ws);  // z2^3
  189|   941k|   m_curve.mul(T2, m_coord_y, T3, ws);        // y1*z2^3
  190|       |
  191|   941k|   m_curve.sqr(T3, m_coord_z, ws);            // z1^2
  192|   941k|   m_curve.mul(T4, x_words, x_size, T3, ws);  // x2*z1^2
  193|       |
  194|   941k|   m_curve.mul(T5, m_coord_z, T3, ws);        // z1^3
  195|   941k|   m_curve.mul(T0, y_words, y_size, T5, ws);  // y2*z1^3
  196|       |
  197|   941k|   T4.mod_sub(T1, p, sub_ws);  // x2*z1^2 - x1*z2^2
  198|       |
  199|   941k|   T0.mod_sub(T2, p, sub_ws);
  200|       |
  201|   941k|   if(T4.is_zero()) {
  ------------------
  |  Branch (201:7): [True: 395, False: 941k]
  ------------------
  202|    395|      if(T0.is_zero()) {
  ------------------
  |  Branch (202:10): [True: 207, False: 188]
  ------------------
  203|    207|         mult2(ws_bn);
  204|    207|         return;
  205|    207|      }
  206|       |
  207|       |      // setting to zero:
  208|    188|      m_coord_x.clear();
  209|    188|      m_coord_y = m_curve.get_1_rep();
  210|    188|      m_coord_z.clear();
  211|    188|      return;
  212|    395|   }
  213|       |
  214|   941k|   m_curve.sqr(T5, T4, ws);
  215|       |
  216|   941k|   m_curve.mul(T3, T1, T5, ws);
  217|       |
  218|   941k|   m_curve.mul(T1, T5, T4, ws);
  219|       |
  220|   941k|   m_curve.sqr(m_coord_x, T0, ws);
  221|   941k|   m_coord_x.mod_sub(T1, p, sub_ws);
  222|   941k|   m_coord_x.mod_sub(T3, p, sub_ws);
  223|   941k|   m_coord_x.mod_sub(T3, p, sub_ws);
  224|       |
  225|   941k|   T3.mod_sub(m_coord_x, p, sub_ws);
  226|       |
  227|   941k|   m_curve.mul(m_coord_y, T0, T3, ws);
  228|   941k|   m_curve.mul(T3, T2, T1, ws);
  229|       |
  230|   941k|   m_coord_y.mod_sub(T3, p, sub_ws);
  231|       |
  232|   941k|   m_curve.mul(T3, z_words, z_size, m_coord_z, ws);
  233|   941k|   m_curve.mul(m_coord_z, T3, T4, ws);
  234|   941k|}
_ZN5Botan8EC_Point6mult2iEmRNSt3__16vectorINS_6BigIntENS1_9allocatorIS3_EEEE:
  236|   703k|void EC_Point::mult2i(size_t iterations, std::vector<BigInt>& ws_bn) {
  237|   703k|   if(iterations == 0) {
  ------------------
  |  Branch (237:7): [True: 0, False: 703k]
  ------------------
  238|      0|      return;
  239|      0|   }
  240|       |
  241|   703k|   if(m_coord_y.is_zero()) {
  ------------------
  |  Branch (241:7): [True: 0, False: 703k]
  ------------------
  242|      0|      *this = EC_Point(m_curve);  // setting myself to zero
  243|      0|      return;
  244|      0|   }
  245|       |
  246|       |   /*
  247|       |   TODO we can save 2 squarings per iteration by computing
  248|       |   a*Z^4 using values cached from previous iteration
  249|       |   */
  250|  3.51M|   for(size_t i = 0; i != iterations; ++i) {
  ------------------
  |  Branch (250:22): [True: 2.81M, False: 703k]
  ------------------
  251|  2.81M|      mult2(ws_bn);
  252|  2.81M|   }
  253|   703k|}
_ZN5Botan8EC_Point5mult2ERNSt3__16vectorINS_6BigIntENS1_9allocatorIS3_EEEE:
  256|  3.09M|void EC_Point::mult2(std::vector<BigInt>& ws_bn) {
  257|  3.09M|   if(is_zero()) {
  ------------------
  |  Branch (257:7): [True: 84, False: 3.09M]
  ------------------
  258|     84|      return;
  259|     84|   }
  260|       |
  261|  3.09M|   if(m_coord_y.is_zero()) {
  ------------------
  |  Branch (261:7): [True: 0, False: 3.09M]
  ------------------
  262|      0|      *this = EC_Point(m_curve);  // setting myself to zero
  263|      0|      return;
  264|      0|   }
  265|       |
  266|  3.09M|   resize_ws(ws_bn, m_curve.get_ws_size());
  267|       |
  268|  3.09M|   secure_vector<word>& ws = ws_bn[0].get_word_vector();
  269|  3.09M|   secure_vector<word>& sub_ws = ws_bn[1].get_word_vector();
  270|       |
  271|  3.09M|   BigInt& T0 = ws_bn[2];
  272|  3.09M|   BigInt& T1 = ws_bn[3];
  273|  3.09M|   BigInt& T2 = ws_bn[4];
  274|  3.09M|   BigInt& T3 = ws_bn[5];
  275|  3.09M|   BigInt& T4 = ws_bn[6];
  276|       |
  277|       |   /*
  278|       |   https://hyperelliptic.org/EFD/g1p/auto-shortw-jacobian-3.html#doubling-dbl-1986-cc
  279|       |   */
  280|  3.09M|   const BigInt& p = m_curve.get_p();
  281|       |
  282|  3.09M|   m_curve.sqr(T0, m_coord_y, ws);
  283|       |
  284|  3.09M|   m_curve.mul(T1, m_coord_x, T0, ws);
  285|  3.09M|   T1.mod_mul(4, p, sub_ws);
  286|       |
  287|  3.09M|   if(m_curve.a_is_zero()) {
  ------------------
  |  Branch (287:7): [True: 0, False: 3.09M]
  ------------------
  288|       |      // if a == 0 then 3*x^2 + a*z^4 is just 3*x^2
  289|      0|      m_curve.sqr(T4, m_coord_x, ws);  // x^2
  290|      0|      T4.mod_mul(3, p, sub_ws);        // 3*x^2
  291|  3.09M|   } else if(m_curve.a_is_minus_3()) {
  ------------------
  |  Branch (291:14): [True: 3.09M, False: 0]
  ------------------
  292|       |      /*
  293|       |      if a == -3 then
  294|       |        3*x^2 + a*z^4 == 3*x^2 - 3*z^4 == 3*(x^2-z^4) == 3*(x-z^2)*(x+z^2)
  295|       |      */
  296|  3.09M|      m_curve.sqr(T3, m_coord_z, ws);  // z^2
  297|       |
  298|       |      // (x-z^2)
  299|  3.09M|      T2 = m_coord_x;
  300|  3.09M|      T2.mod_sub(T3, p, sub_ws);
  301|       |
  302|       |      // (x+z^2)
  303|  3.09M|      T3.mod_add(m_coord_x, p, sub_ws);
  304|       |
  305|  3.09M|      m_curve.mul(T4, T2, T3, ws);  // (x-z^2)*(x+z^2)
  306|       |
  307|  3.09M|      T4.mod_mul(3, p, sub_ws);  // 3*(x-z^2)*(x+z^2)
  308|  3.09M|   } else {
  309|      0|      m_curve.sqr(T3, m_coord_z, ws);                // z^2
  310|      0|      m_curve.sqr(T4, T3, ws);                       // z^4
  311|      0|      m_curve.mul(T3, m_curve.get_a_rep(), T4, ws);  // a*z^4
  312|       |
  313|      0|      m_curve.sqr(T4, m_coord_x, ws);  // x^2
  314|      0|      T4.mod_mul(3, p, sub_ws);
  315|      0|      T4.mod_add(T3, p, sub_ws);  // 3*x^2 + a*z^4
  316|      0|   }
  317|       |
  318|  3.09M|   m_curve.sqr(T2, T4, ws);
  319|  3.09M|   T2.mod_sub(T1, p, sub_ws);
  320|  3.09M|   T2.mod_sub(T1, p, sub_ws);
  321|       |
  322|  3.09M|   m_curve.sqr(T3, T0, ws);
  323|  3.09M|   T3.mod_mul(8, p, sub_ws);
  324|       |
  325|  3.09M|   T1.mod_sub(T2, p, sub_ws);
  326|       |
  327|  3.09M|   m_curve.mul(T0, T4, T1, ws);
  328|  3.09M|   T0.mod_sub(T3, p, sub_ws);
  329|       |
  330|  3.09M|   m_coord_x.swap(T2);
  331|       |
  332|  3.09M|   m_curve.mul(T2, m_coord_y, m_coord_z, ws);
  333|  3.09M|   T2.mod_mul(2, p, sub_ws);
  334|       |
  335|  3.09M|   m_coord_y.swap(T0);
  336|  3.09M|   m_coord_z.swap(T2);
  337|  3.09M|}
_ZN5Botan8EC_PointpLERKS0_:
  340|  8.17k|EC_Point& EC_Point::operator+=(const EC_Point& rhs) {
  341|  8.17k|   std::vector<BigInt> ws(EC_Point::WORKSPACE_SIZE);
  342|  8.17k|   add(rhs, ws);
  343|  8.17k|   return *this;
  344|  8.17k|}
_ZN5BotanmlERKNS_6BigIntERKNS_8EC_PointE:
  363|  4.08k|EC_Point operator*(const BigInt& scalar, const EC_Point& point) {
  364|  4.08k|   BOTAN_DEBUG_ASSERT(point.on_the_curve());
  ------------------
  |  |   99|  4.08k|      do {                          \
  |  |  100|  4.08k|      } while(0)
  |  |  ------------------
  |  |  |  Branch (100:15): [Folded - Ignored]
  |  |  ------------------
  ------------------
  365|       |
  366|  4.08k|   const size_t scalar_bits = scalar.bits();
  367|       |
  368|  4.08k|   std::vector<BigInt> ws(EC_Point::WORKSPACE_SIZE);
  369|       |
  370|  4.08k|   EC_Point R[2] = {point.zero(), point};
  371|       |
  372|   247k|   for(size_t i = scalar_bits; i > 0; i--) {
  ------------------
  |  Branch (372:32): [True: 243k, False: 4.08k]
  ------------------
  373|   243k|      const size_t b = scalar.get_bit(i - 1);
  374|   243k|      R[b ^ 1].add(R[b], ws);
  375|   243k|      R[b].mult2(ws);
  376|   243k|   }
  377|       |
  378|  4.08k|   if(scalar.is_negative()) {
  ------------------
  |  Branch (378:7): [True: 0, False: 4.08k]
  ------------------
  379|      0|      R[0].negate();
  380|      0|   }
  381|       |
  382|  4.08k|   BOTAN_DEBUG_ASSERT(R[0].on_the_curve());
  ------------------
  |  |   99|  4.08k|      do {                          \
  |  |  100|  4.08k|      } while(0)
  |  |  ------------------
  |  |  |  Branch (100:15): [Folded - Ignored]
  |  |  ------------------
  ------------------
  383|       |
  384|  4.08k|   return R[0];
  385|  4.08k|}
_ZN5Botan8EC_Point16force_all_affineERNSt3__16vectorIS0_NS1_9allocatorIS0_EEEERNS2_ImNS_16secure_allocatorImEEEE:
  388|      1|void EC_Point::force_all_affine(std::vector<EC_Point>& points, secure_vector<word>& ws) {
  389|      1|   if(points.size() <= 1) {
  ------------------
  |  Branch (389:7): [True: 0, False: 1]
  ------------------
  390|      0|      for(auto& point : points) {
  ------------------
  |  Branch (390:23): [True: 0, False: 0]
  ------------------
  391|      0|         point.force_affine();
  392|      0|      }
  393|      0|      return;
  394|      0|   }
  395|       |
  396|  1.35k|   for(auto& point : points) {
  ------------------
  |  Branch (396:20): [True: 1.35k, False: 1]
  ------------------
  397|  1.35k|      if(point.is_zero()) {
  ------------------
  |  Branch (397:10): [True: 0, False: 1.35k]
  ------------------
  398|      0|         throw Invalid_State("Cannot convert zero ECC point to affine");
  399|      0|      }
  400|  1.35k|   }
  401|       |
  402|       |   /*
  403|       |   For >= 2 points use Montgomery's trick
  404|       |
  405|       |   See Algorithm 2.26 in "Guide to Elliptic Curve Cryptography"
  406|       |   (Hankerson, Menezes, Vanstone)
  407|       |
  408|       |   TODO is it really necessary to save all k points in c?
  409|       |   */
  410|       |
  411|      1|   const CurveGFp& curve = points[0].m_curve;
  412|      1|   const BigInt& rep_1 = curve.get_1_rep();
  413|       |
  414|      1|   if(ws.size() < curve.get_ws_size()) {
  ------------------
  |  Branch (414:7): [True: 0, False: 1]
  ------------------
  415|      0|      ws.resize(curve.get_ws_size());
  416|      0|   }
  417|       |
  418|      1|   std::vector<BigInt> c(points.size());
  419|      1|   c[0] = points[0].m_coord_z;
  420|       |
  421|  1.35k|   for(size_t i = 1; i != points.size(); ++i) {
  ------------------
  |  Branch (421:22): [True: 1.35k, False: 1]
  ------------------
  422|  1.35k|      curve.mul(c[i], c[i - 1], points[i].m_coord_z, ws);
  423|  1.35k|   }
  424|       |
  425|      1|   BigInt s_inv = curve.invert_element(c[c.size() - 1], ws);
  426|       |
  427|      1|   BigInt z_inv, z2_inv, z3_inv;
  428|       |
  429|  1.35k|   for(size_t i = points.size() - 1; i != 0; i--) {
  ------------------
  |  Branch (429:38): [True: 1.35k, False: 1]
  ------------------
  430|  1.35k|      EC_Point& point = points[i];
  431|       |
  432|  1.35k|      curve.mul(z_inv, s_inv, c[i - 1], ws);
  433|       |
  434|  1.35k|      s_inv = curve.mul_to_tmp(s_inv, point.m_coord_z, ws);
  435|       |
  436|  1.35k|      curve.sqr(z2_inv, z_inv, ws);
  437|  1.35k|      curve.mul(z3_inv, z2_inv, z_inv, ws);
  438|  1.35k|      point.m_coord_x = curve.mul_to_tmp(point.m_coord_x, z2_inv, ws);
  439|  1.35k|      point.m_coord_y = curve.mul_to_tmp(point.m_coord_y, z3_inv, ws);
  440|  1.35k|      point.m_coord_z = rep_1;
  441|  1.35k|   }
  442|       |
  443|      1|   curve.sqr(z2_inv, s_inv, ws);
  444|      1|   curve.mul(z3_inv, z2_inv, s_inv, ws);
  445|      1|   points[0].m_coord_x = curve.mul_to_tmp(points[0].m_coord_x, z2_inv, ws);
  446|      1|   points[0].m_coord_y = curve.mul_to_tmp(points[0].m_coord_y, z3_inv, ws);
  447|      1|   points[0].m_coord_z = rep_1;
  448|      1|}
_ZNK5Botan8EC_Point9is_affineEv:
  465|  43.4k|bool EC_Point::is_affine() const {
  466|  43.4k|   return m_curve.is_one(m_coord_z);
  467|  43.4k|}
_ZNK5Botan8EC_Point12get_affine_xEv:
  469|  21.7k|BigInt EC_Point::get_affine_x() const {
  470|  21.7k|   if(is_zero()) {
  ------------------
  |  Branch (470:7): [True: 0, False: 21.7k]
  ------------------
  471|      0|      throw Invalid_State("Cannot convert zero point to affine");
  472|      0|   }
  473|       |
  474|  21.7k|   secure_vector<word> monty_ws;
  475|       |
  476|  21.7k|   if(is_affine()) {
  ------------------
  |  Branch (476:7): [True: 36, False: 21.7k]
  ------------------
  477|     36|      return m_curve.from_rep_to_tmp(m_coord_x, monty_ws);
  478|     36|   }
  479|       |
  480|  21.7k|   BigInt z2 = m_curve.sqr_to_tmp(m_coord_z, monty_ws);
  481|  21.7k|   z2 = m_curve.invert_element(z2, monty_ws);
  482|       |
  483|  21.7k|   BigInt r;
  484|  21.7k|   m_curve.mul(r, m_coord_x, z2, monty_ws);
  485|  21.7k|   m_curve.from_rep(r, monty_ws);
  486|  21.7k|   return r;
  487|  21.7k|}
_ZNK5Botan8EC_Point12get_affine_yEv:
  489|  21.7k|BigInt EC_Point::get_affine_y() const {
  490|  21.7k|   if(is_zero()) {
  ------------------
  |  Branch (490:7): [True: 0, False: 21.7k]
  ------------------
  491|      0|      throw Invalid_State("Cannot convert zero point to affine");
  492|      0|   }
  493|       |
  494|  21.7k|   secure_vector<word> monty_ws;
  495|       |
  496|  21.7k|   if(is_affine()) {
  ------------------
  |  Branch (496:7): [True: 36, False: 21.7k]
  ------------------
  497|     36|      return m_curve.from_rep_to_tmp(m_coord_y, monty_ws);
  498|     36|   }
  499|       |
  500|  21.7k|   const BigInt z2 = m_curve.sqr_to_tmp(m_coord_z, monty_ws);
  501|  21.7k|   const BigInt z3 = m_curve.mul_to_tmp(m_coord_z, z2, monty_ws);
  502|  21.7k|   const BigInt z3_inv = m_curve.invert_element(z3, monty_ws);
  503|       |
  504|  21.7k|   BigInt r;
  505|  21.7k|   m_curve.mul(r, m_coord_y, z3_inv, monty_ws);
  506|  21.7k|   m_curve.from_rep(r, monty_ws);
  507|  21.7k|   return r;
  508|  21.7k|}
_ZN5Botan8EC_Point4swapERS0_:
  547|  74.9k|void EC_Point::swap(EC_Point& other) {
  548|  74.9k|   m_curve.swap(other.m_curve);
  549|  74.9k|   m_coord_x.swap(other.m_coord_x);
  550|  74.9k|   m_coord_y.swap(other.m_coord_y);
  551|  74.9k|   m_coord_z.swap(other.m_coord_z);
  552|  74.9k|}
_ZNK5Botan8EC_PointeqERKS0_:
  554|  10.8k|bool EC_Point::operator==(const EC_Point& other) const {
  555|  10.8k|   if(m_curve != other.m_curve) {
  ------------------
  |  Branch (555:7): [True: 0, False: 10.8k]
  ------------------
  556|      0|      return false;
  557|      0|   }
  558|       |
  559|       |   // If this is zero, only equal if other is also zero
  560|  10.8k|   if(is_zero()) {
  ------------------
  |  Branch (560:7): [True: 24, False: 10.8k]
  ------------------
  561|     24|      return other.is_zero();
  562|     24|   }
  563|       |
  564|  10.8k|   return (get_affine_x() == other.get_affine_x() && get_affine_y() == other.get_affine_y());
  ------------------
  |  Branch (564:12): [True: 10.8k, False: 0]
  |  Branch (564:54): [True: 10.8k, False: 0]
  ------------------
  565|  10.8k|}
ec_point.cpp:_ZN5Botan12_GLOBAL__N_19resize_wsERNSt3__16vectorINS_6BigIntENS1_9allocatorIS3_EEEEm:
   61|  4.71M|inline void resize_ws(std::vector<BigInt>& ws_bn, size_t cap_size) {
   62|  4.71M|   BOTAN_ASSERT(ws_bn.size() >= EC_Point::WORKSPACE_SIZE, "Expected size for EC_Point workspace");
  ------------------
  |  |   51|  4.71M|   do {                                                                                 \
  |  |   52|  4.71M|      if(!(expr))                                                                       \
  |  |  ------------------
  |  |  |  Branch (52:10): [True: 0, False: 4.71M]
  |  |  ------------------
  |  |   53|  4.71M|         Botan::assertion_failure(#expr, assertion_made, __func__, __FILE__, __LINE__); \
  |  |   54|  4.71M|   } while(0)
  |  |  ------------------
  |  |  |  Branch (54:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   63|       |
   64|  37.7M|   for(auto& ws : ws_bn) {
  ------------------
  |  Branch (64:17): [True: 37.7M, False: 4.71M]
  ------------------
   65|  37.7M|      if(ws.size() < cap_size) {
  ------------------
  |  Branch (65:10): [True: 101k, False: 37.6M]
  ------------------
   66|   101k|         ws.get_word_vector().resize(cap_size);
   67|   101k|      }
   68|  37.7M|   }
   69|  4.71M|}

_ZN5Botan30EC_Point_Base_Point_PrecomputeC2ERKNS_8EC_PointERKNS_15Modular_ReducerE:
   30|      1|      m_base_point(base), m_mod_order(mod_order), m_p_words(base.get_curve().get_p().sig_words()) {
   31|      1|   std::vector<BigInt> ws(EC_Point::WORKSPACE_SIZE);
   32|       |
   33|      1|   const size_t p_bits = base.get_curve().get_p().bits();
   34|       |
   35|       |   /*
   36|       |   * Some of the curves (eg secp160k1) have an order slightly larger than
   37|       |   * the size of the prime modulus. In all cases they are at most 1 bit
   38|       |   * longer. The +1 compensates for this.
   39|       |   */
   40|      1|   const size_t T_bits = round_up(p_bits + blinding_size(mod_order.get_modulus()) + 1, WINDOW_BITS) / WINDOW_BITS;
   41|       |
   42|      1|   std::vector<EC_Point> T(WINDOW_SIZE * T_bits);
   43|       |
   44|      1|   EC_Point g = base;
   45|      1|   EC_Point g2, g4;
   46|       |
   47|    194|   for(size_t i = 0; i != T_bits; i++) {
  ------------------
  |  Branch (47:22): [True: 193, False: 1]
  ------------------
   48|    193|      g2 = g;
   49|    193|      g2.mult2(ws);
   50|    193|      g4 = g2;
   51|    193|      g4.mult2(ws);
   52|       |
   53|    193|      T[7 * i + 0] = g;
   54|    193|      T[7 * i + 1] = std::move(g2);
   55|    193|      T[7 * i + 2] = T[7 * i + 1].plus(T[7 * i + 0], ws);  // g2+g
   56|    193|      T[7 * i + 3] = g4;
   57|    193|      T[7 * i + 4] = T[7 * i + 3].plus(T[7 * i + 0], ws);  // g4+g
   58|    193|      T[7 * i + 5] = T[7 * i + 3].plus(T[7 * i + 1], ws);  // g4+g2
   59|    193|      T[7 * i + 6] = T[7 * i + 3].plus(T[7 * i + 2], ws);  // g4+g2+g
   60|       |
   61|    193|      g.swap(g4);
   62|    193|      g.mult2(ws);
   63|    193|   }
   64|       |
   65|      1|   EC_Point::force_all_affine(T, ws[0].get_word_vector());
   66|       |
   67|      1|   m_W.resize(T.size() * 2 * m_p_words);
   68|       |
   69|      1|   word* p = &m_W[0];
   70|  1.35k|   for(size_t i = 0; i != T.size(); ++i) {
  ------------------
  |  Branch (70:22): [True: 1.35k, False: 1]
  ------------------
   71|  1.35k|      T[i].get_x().encode_words(p, m_p_words);
   72|  1.35k|      p += m_p_words;
   73|  1.35k|      T[i].get_y().encode_words(p, m_p_words);
   74|  1.35k|      p += m_p_words;
   75|  1.35k|   }
   76|      1|}
_ZNK5Botan30EC_Point_Base_Point_Precompute3mulERKNS_6BigIntERNS_21RandomNumberGeneratorES3_RNSt3__16vectorIS1_NS6_9allocatorIS1_EEEE:
   81|  4.08k|                                             std::vector<BigInt>& ws) const {
   82|  4.08k|   if(k.is_negative()) {
  ------------------
  |  Branch (82:7): [True: 0, False: 4.08k]
  ------------------
   83|      0|      throw Invalid_Argument("EC_Point_Base_Point_Precompute scalar must be positive");
   84|      0|   }
   85|       |
   86|       |   // Instead of reducing k mod group order should we alter the mask size??
   87|  4.08k|   BigInt scalar = m_mod_order.reduce(k);
   88|       |
   89|  4.08k|   if(rng.is_seeded()) {
  ------------------
  |  Branch (89:7): [True: 4.08k, False: 0]
  ------------------
   90|       |      // Choose a small mask m and use k' = k + m*order (Coron's 1st countermeasure)
   91|  4.08k|      const BigInt mask(rng, blinding_size(group_order));
   92|  4.08k|      scalar += group_order * mask;
   93|  4.08k|   } else {
   94|       |      /*
   95|       |      When we don't have an RNG we cannot do scalar blinding. Instead use the
   96|       |      same trick as OpenSSL and add one or two copies of the order to normalize
   97|       |      the length of the scalar at order.bits()+1. This at least ensures the loop
   98|       |      bound does not leak information about the high bits of the scalar.
   99|       |      */
  100|      0|      scalar += group_order;
  101|      0|      if(scalar.bits() == group_order.bits()) {
  ------------------
  |  Branch (101:10): [True: 0, False: 0]
  ------------------
  102|      0|         scalar += group_order;
  103|      0|      }
  104|      0|      BOTAN_DEBUG_ASSERT(scalar.bits() == group_order.bits() + 1);
  ------------------
  |  |   99|      0|      do {                          \
  |  |  100|      0|      } while(0)
  |  |  ------------------
  |  |  |  Branch (100:15): [Folded - Ignored]
  |  |  ------------------
  ------------------
  105|      0|   }
  106|       |
  107|  4.08k|   const size_t windows = round_up(scalar.bits(), WINDOW_BITS) / WINDOW_BITS;
  108|       |
  109|  4.08k|   const size_t elem_size = 2 * m_p_words;
  110|       |
  111|  4.08k|   BOTAN_ASSERT(windows <= m_W.size() / (3 * elem_size), "Precomputed sufficient values for scalar mult");
  ------------------
  |  |   51|  4.08k|   do {                                                                                 \
  |  |   52|  4.08k|      if(!(expr))                                                                       \
  |  |  ------------------
  |  |  |  Branch (52:10): [True: 0, False: 4.08k]
  |  |  ------------------
  |  |   53|  4.08k|         Botan::assertion_failure(#expr, assertion_made, __func__, __FILE__, __LINE__); \
  |  |   54|  4.08k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (54:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  112|       |
  113|  4.08k|   EC_Point R = m_base_point.zero();
  114|       |
  115|  4.08k|   if(ws.size() < EC_Point::WORKSPACE_SIZE) {
  ------------------
  |  Branch (115:7): [True: 0, False: 4.08k]
  ------------------
  116|      0|      ws.resize(EC_Point::WORKSPACE_SIZE);
  117|      0|   }
  118|       |
  119|       |   // the precomputed multiples are not secret so use std::vector
  120|  4.08k|   std::vector<word> Wt(elem_size);
  121|       |
  122|   788k|   for(size_t i = 0; i != windows; ++i) {
  ------------------
  |  Branch (122:22): [True: 784k, False: 4.08k]
  ------------------
  123|   784k|      const size_t window = windows - i - 1;
  124|   784k|      const size_t base_addr = (WINDOW_SIZE * window) * elem_size;
  125|       |
  126|   784k|      const word w = scalar.get_substring(WINDOW_BITS * window, WINDOW_BITS);
  127|       |
  128|   784k|      const auto w_is_1 = CT::Mask<word>::is_equal(w, 1);
  129|   784k|      const auto w_is_2 = CT::Mask<word>::is_equal(w, 2);
  130|   784k|      const auto w_is_3 = CT::Mask<word>::is_equal(w, 3);
  131|   784k|      const auto w_is_4 = CT::Mask<word>::is_equal(w, 4);
  132|   784k|      const auto w_is_5 = CT::Mask<word>::is_equal(w, 5);
  133|   784k|      const auto w_is_6 = CT::Mask<word>::is_equal(w, 6);
  134|   784k|      const auto w_is_7 = CT::Mask<word>::is_equal(w, 7);
  135|       |
  136|  10.1M|      for(size_t j = 0; j != elem_size; ++j) {
  ------------------
  |  Branch (136:25): [True: 9.41M, False: 784k]
  ------------------
  137|  9.41M|         const word w1 = w_is_1.if_set_return(m_W[base_addr + 0 * elem_size + j]);
  138|  9.41M|         const word w2 = w_is_2.if_set_return(m_W[base_addr + 1 * elem_size + j]);
  139|  9.41M|         const word w3 = w_is_3.if_set_return(m_W[base_addr + 2 * elem_size + j]);
  140|  9.41M|         const word w4 = w_is_4.if_set_return(m_W[base_addr + 3 * elem_size + j]);
  141|  9.41M|         const word w5 = w_is_5.if_set_return(m_W[base_addr + 4 * elem_size + j]);
  142|  9.41M|         const word w6 = w_is_6.if_set_return(m_W[base_addr + 5 * elem_size + j]);
  143|  9.41M|         const word w7 = w_is_7.if_set_return(m_W[base_addr + 6 * elem_size + j]);
  144|       |
  145|  9.41M|         Wt[j] = w1 | w2 | w3 | w4 | w5 | w6 | w7;
  146|  9.41M|      }
  147|       |
  148|   784k|      R.add_affine(&Wt[0], m_p_words, &Wt[m_p_words], m_p_words, ws);
  149|       |
  150|   784k|      if(i == 0 && rng.is_seeded()) {
  ------------------
  |  Branch (150:10): [True: 4.08k, False: 780k]
  |  Branch (150:20): [True: 4.08k, False: 0]
  ------------------
  151|       |         /*
  152|       |         * Since we start with the top bit of the exponent we know the
  153|       |         * first window must have a non-zero element, and thus R is
  154|       |         * now a point other than the point at infinity.
  155|       |         */
  156|  4.08k|         BOTAN_DEBUG_ASSERT(w != 0);
  ------------------
  |  |   99|  4.08k|      do {                          \
  |  |  100|  4.08k|      } while(0)
  |  |  ------------------
  |  |  |  Branch (100:15): [Folded - Ignored]
  |  |  ------------------
  ------------------
  157|  4.08k|         R.randomize_repr(rng, ws[0].get_word_vector());
  158|  4.08k|      }
  159|   784k|   }
  160|       |
  161|  4.08k|   BOTAN_DEBUG_ASSERT(R.on_the_curve());
  ------------------
  |  |   99|  4.08k|      do {                          \
  |  |  100|  4.08k|      } while(0)
  |  |  ------------------
  |  |  |  Branch (100:15): [Folded - Ignored]
  |  |  ------------------
  ------------------
  162|       |
  163|  4.08k|   return R;
  164|  4.08k|}
_ZN5Botan29EC_Point_Var_Point_PrecomputeC2ERKNS_8EC_PointERNS_21RandomNumberGeneratorERNSt3__16vectorINS_6BigIntENS6_9allocatorIS8_EEEE:
  169|  4.92k|      m_curve(point.get_curve()), m_p_words(m_curve.get_p().sig_words()), m_window_bits(4) {
  170|  4.92k|   if(ws.size() < EC_Point::WORKSPACE_SIZE) {
  ------------------
  |  Branch (170:7): [True: 0, False: 4.92k]
  ------------------
  171|      0|      ws.resize(EC_Point::WORKSPACE_SIZE);
  172|      0|   }
  173|       |
  174|  4.92k|   std::vector<EC_Point> U(static_cast<size_t>(1) << m_window_bits);
  175|  4.92k|   U[0] = point.zero();
  176|  4.92k|   U[1] = point;
  177|       |
  178|  39.3k|   for(size_t i = 2; i < U.size(); i += 2) {
  ------------------
  |  Branch (178:22): [True: 34.4k, False: 4.92k]
  ------------------
  179|  34.4k|      U[i] = U[i / 2].double_of(ws);
  180|  34.4k|      U[i + 1] = U[i].plus(point, ws);
  181|  34.4k|   }
  182|       |
  183|       |   // Hack to handle Blinded_Point_Multiply
  184|  4.92k|   if(rng.is_seeded()) {
  ------------------
  |  Branch (184:7): [True: 4.92k, False: 0]
  ------------------
  185|  4.92k|      BigInt& mask = ws[0];
  186|  4.92k|      BigInt& mask2 = ws[1];
  187|  4.92k|      BigInt& mask3 = ws[2];
  188|  4.92k|      BigInt& new_x = ws[3];
  189|  4.92k|      BigInt& new_y = ws[4];
  190|  4.92k|      BigInt& new_z = ws[5];
  191|  4.92k|      secure_vector<word>& tmp = ws[6].get_word_vector();
  192|       |
  193|  4.92k|      const CurveGFp& curve = U[0].get_curve();
  194|       |
  195|  4.92k|      const size_t p_bits = curve.get_p().bits();
  196|       |
  197|       |      // Skipping zero point since it can't be randomized
  198|  78.7k|      for(size_t i = 1; i != U.size(); ++i) {
  ------------------
  |  Branch (198:25): [True: 73.8k, False: 4.92k]
  ------------------
  199|  73.8k|         mask.randomize(rng, p_bits - 1, false);
  200|       |         // Easy way of ensuring mask != 0
  201|  73.8k|         mask.set_bit(0);
  202|       |
  203|  73.8k|         curve.sqr(mask2, mask, tmp);
  204|  73.8k|         curve.mul(mask3, mask, mask2, tmp);
  205|       |
  206|  73.8k|         curve.mul(new_x, U[i].get_x(), mask2, tmp);
  207|  73.8k|         curve.mul(new_y, U[i].get_y(), mask3, tmp);
  208|  73.8k|         curve.mul(new_z, U[i].get_z(), mask, tmp);
  209|       |
  210|  73.8k|         U[i].swap_coords(new_x, new_y, new_z);
  211|  73.8k|      }
  212|  4.92k|   }
  213|       |
  214|  4.92k|   m_T.resize(U.size() * 3 * m_p_words);
  215|       |
  216|  4.92k|   word* p = &m_T[0];
  217|  83.6k|   for(size_t i = 0; i != U.size(); ++i) {
  ------------------
  |  Branch (217:22): [True: 78.7k, False: 4.92k]
  ------------------
  218|  78.7k|      U[i].get_x().encode_words(p, m_p_words);
  219|  78.7k|      U[i].get_y().encode_words(p + m_p_words, m_p_words);
  220|  78.7k|      U[i].get_z().encode_words(p + 2 * m_p_words, m_p_words);
  221|  78.7k|      p += 3 * m_p_words;
  222|  78.7k|   }
  223|  4.92k|}
_ZNK5Botan29EC_Point_Var_Point_Precompute3mulERKNS_6BigIntERNS_21RandomNumberGeneratorES3_RNSt3__16vectorIS1_NS6_9allocatorIS1_EEEE:
  228|  4.92k|                                            std::vector<BigInt>& ws) const {
  229|  4.92k|   if(k.is_negative()) {
  ------------------
  |  Branch (229:7): [True: 0, False: 4.92k]
  ------------------
  230|      0|      throw Invalid_Argument("EC_Point_Var_Point_Precompute scalar must be positive");
  231|      0|   }
  232|  4.92k|   if(ws.size() < EC_Point::WORKSPACE_SIZE) {
  ------------------
  |  Branch (232:7): [True: 0, False: 4.92k]
  ------------------
  233|      0|      ws.resize(EC_Point::WORKSPACE_SIZE);
  234|      0|   }
  235|       |
  236|       |   // Choose a small mask m and use k' = k + m*order (Coron's 1st countermeasure)
  237|  4.92k|   const BigInt mask(rng, blinding_size(group_order), false);
  238|  4.92k|   const BigInt scalar = k + group_order * mask;
  239|       |
  240|  4.92k|   const size_t elem_size = 3 * m_p_words;
  241|  4.92k|   const size_t window_elems = static_cast<size_t>(1) << m_window_bits;
  242|       |
  243|  4.92k|   size_t windows = round_up(scalar.bits(), m_window_bits) / m_window_bits;
  244|  4.92k|   EC_Point R(m_curve);
  245|  4.92k|   secure_vector<word> e(elem_size);
  246|       |
  247|  4.92k|   if(windows > 0) {
  ------------------
  |  Branch (247:7): [True: 4.92k, False: 0]
  ------------------
  248|  4.92k|      windows--;
  249|       |
  250|  4.92k|      const uint32_t w = scalar.get_substring(windows * m_window_bits, m_window_bits);
  251|       |
  252|  4.92k|      clear_mem(e.data(), e.size());
  253|  78.7k|      for(size_t i = 1; i != window_elems; ++i) {
  ------------------
  |  Branch (253:25): [True: 73.8k, False: 4.92k]
  ------------------
  254|  73.8k|         const auto wmask = CT::Mask<word>::is_equal(w, i);
  255|       |
  256|  1.40M|         for(size_t j = 0; j != elem_size; ++j) {
  ------------------
  |  Branch (256:28): [True: 1.32M, False: 73.8k]
  ------------------
  257|  1.32M|            e[j] |= wmask.if_set_return(m_T[i * elem_size + j]);
  258|  1.32M|         }
  259|  73.8k|      }
  260|       |
  261|  4.92k|      R.add(&e[0], m_p_words, &e[m_p_words], m_p_words, &e[2 * m_p_words], m_p_words, ws);
  262|       |
  263|       |      /*
  264|       |      Randomize after adding the first nibble as before the addition R
  265|       |      is zero, and we cannot effectively randomize the point
  266|       |      representation of the zero point.
  267|       |      */
  268|  4.92k|      R.randomize_repr(rng, ws[0].get_word_vector());
  269|  4.92k|   }
  270|       |
  271|   708k|   while(windows) {
  ------------------
  |  Branch (271:10): [True: 703k, False: 4.92k]
  ------------------
  272|   703k|      R.mult2i(m_window_bits, ws);
  273|       |
  274|   703k|      const uint32_t w = scalar.get_substring((windows - 1) * m_window_bits, m_window_bits);
  275|       |
  276|   703k|      clear_mem(e.data(), e.size());
  277|  11.2M|      for(size_t i = 1; i != window_elems; ++i) {
  ------------------
  |  Branch (277:25): [True: 10.5M, False: 703k]
  ------------------
  278|  10.5M|         const auto wmask = CT::Mask<word>::is_equal(w, i);
  279|       |
  280|   200M|         for(size_t j = 0; j != elem_size; ++j) {
  ------------------
  |  Branch (280:28): [True: 189M, False: 10.5M]
  ------------------
  281|   189M|            e[j] |= wmask.if_set_return(m_T[i * elem_size + j]);
  282|   189M|         }
  283|  10.5M|      }
  284|       |
  285|   703k|      R.add(&e[0], m_p_words, &e[m_p_words], m_p_words, &e[2 * m_p_words], m_p_words, ws);
  286|       |
  287|   703k|      windows--;
  288|   703k|   }
  289|       |
  290|  4.92k|   BOTAN_DEBUG_ASSERT(R.on_the_curve());
  ------------------
  |  |   99|  4.92k|      do {                          \
  |  |  100|  4.92k|      } while(0)
  |  |  ------------------
  |  |  |  Branch (100:15): [Folded - Ignored]
  |  |  ------------------
  ------------------
  291|       |
  292|  4.92k|   return R;
  293|  4.92k|}
point_mul.cpp:_ZN5Botan12_GLOBAL__N_113blinding_sizeERKNS_6BigIntE:
   18|  9.00k|size_t blinding_size(const BigInt& group_order) {
   19|  9.00k|   return (group_order.bits() + 1) / 2;
   20|  9.00k|}

_ZN5Botan10ChaCha_RNGC2ENSt3__14spanIKhLm18446744073709551615EEE:
   18|      1|ChaCha_RNG::ChaCha_RNG(std::span<const uint8_t> seed) : Stateful_RNG() {
   19|      1|   m_hmac = MessageAuthenticationCode::create_or_throw("HMAC(SHA-256)");
   20|      1|   m_chacha = StreamCipher::create_or_throw("ChaCha(20)");
   21|      1|   clear();
   22|      1|   add_entropy(seed);
   23|      1|}
_ZN5Botan10ChaCha_RNG11clear_stateEv:
   48|      1|void ChaCha_RNG::clear_state() {
   49|      1|   m_hmac->set_key(std::vector<uint8_t>(m_hmac->output_length(), 0x00));
   50|      1|   m_chacha->set_key(m_hmac->final());
   51|      1|}
_ZN5Botan10ChaCha_RNG15generate_outputENSt3__14spanIhLm18446744073709551615EEENS2_IKhLm18446744073709551615EEE:
   53|  91.8k|void ChaCha_RNG::generate_output(std::span<uint8_t> output, std::span<const uint8_t> input) {
   54|  91.8k|   BOTAN_ASSERT_NOMSG(!output.empty());
  ------------------
  |  |   60|  91.8k|   do {                                                                     \
  |  |   61|  91.8k|      if(!(expr))                                                           \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 91.8k]
  |  |  ------------------
  |  |   62|  91.8k|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   63|  91.8k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (63:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   55|       |
   56|  91.8k|   if(!input.empty()) {
  ------------------
  |  Branch (56:7): [True: 0, False: 91.8k]
  ------------------
   57|      0|      update(input);
   58|      0|   }
   59|       |
   60|  91.8k|   m_chacha->write_keystream(output);
   61|  91.8k|}
_ZN5Botan10ChaCha_RNG6updateENSt3__14spanIKhLm18446744073709551615EEE:
   63|      1|void ChaCha_RNG::update(std::span<const uint8_t> input) {
   64|      1|   m_hmac->update(input);
   65|      1|   m_chacha->set_key(m_hmac->final());
   66|      1|   const auto mac_key = m_chacha->keystream_bytes(m_hmac->output_length());
   67|      1|   m_hmac->set_key(mac_key);
   68|      1|}
_ZNK5Botan10ChaCha_RNG14security_levelEv:
   70|      1|size_t ChaCha_RNG::security_level() const {
   71|      1|   return 256;
   72|      1|}

_ZN5Botan12Stateful_RNG5clearEv:
   14|      1|void Stateful_RNG::clear() {
   15|      1|   lock_guard_type<recursive_mutex_type> lock(m_mutex);
   16|      1|   m_reseed_counter = 0;
   17|      1|   m_last_pid = 0;
   18|      1|   clear_state();
   19|      1|}
_ZNK5Botan12Stateful_RNG9is_seededEv:
   26|   104k|bool Stateful_RNG::is_seeded() const {
   27|   104k|   lock_guard_type<recursive_mutex_type> lock(m_mutex);
   28|   104k|   return m_reseed_counter > 0;
   29|   104k|}
_ZN5Botan12Stateful_RNG23generate_batched_outputENSt3__14spanIhLm18446744073709551615EEENS2_IKhLm18446744073709551615EEE:
   38|  91.8k|void Stateful_RNG::generate_batched_output(std::span<uint8_t> output, std::span<const uint8_t> input) {
   39|  91.8k|   BOTAN_ASSERT_NOMSG(!output.empty());
  ------------------
  |  |   60|  91.8k|   do {                                                                     \
  |  |   61|  91.8k|      if(!(expr))                                                           \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 91.8k]
  |  |  ------------------
  |  |   62|  91.8k|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   63|  91.8k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (63:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   40|       |
   41|  91.8k|   const size_t max_per_request = max_number_of_bytes_per_request();
   42|       |
   43|  91.8k|   if(max_per_request == 0)  // no limit
  ------------------
  |  Branch (43:7): [True: 91.8k, False: 0]
  ------------------
   44|  91.8k|   {
   45|  91.8k|      reseed_check();
   46|  91.8k|      this->generate_output(output, input);
   47|  91.8k|   } else {
   48|      0|      while(!output.empty()) {
  ------------------
  |  Branch (48:13): [True: 0, False: 0]
  ------------------
   49|      0|         const size_t this_req = std::min(max_per_request, output.size());
   50|       |
   51|      0|         reseed_check();
   52|      0|         this->generate_output(output.subspan(0, this_req), input);
   53|       |
   54|       |         // only include the input for the first iteration
   55|      0|         input = {};
   56|       |
   57|      0|         output = output.subspan(this_req);
   58|      0|      }
   59|      0|   }
   60|  91.8k|}
_ZN5Botan12Stateful_RNG21fill_bytes_with_inputENSt3__14spanIhLm18446744073709551615EEENS2_IKhLm18446744073709551615EEE:
   62|  91.8k|void Stateful_RNG::fill_bytes_with_input(std::span<uint8_t> output, std::span<const uint8_t> input) {
   63|  91.8k|   lock_guard_type<recursive_mutex_type> lock(m_mutex);
   64|       |
   65|  91.8k|   if(output.empty()) {
  ------------------
  |  Branch (65:7): [True: 1, False: 91.8k]
  ------------------
   66|       |      // Special case for exclusively adding entropy to the stateful RNG.
   67|      1|      this->update(input);
   68|       |
   69|      1|      if(8 * input.size() >= security_level()) {
  ------------------
  |  Branch (69:10): [True: 1, False: 0]
  ------------------
   70|      1|         reset_reseed_counter();
   71|      1|      }
   72|  91.8k|   } else {
   73|  91.8k|      generate_batched_output(output, input);
   74|  91.8k|   }
   75|  91.8k|}
_ZN5Botan12Stateful_RNG20reset_reseed_counterEv:
   99|      1|void Stateful_RNG::reset_reseed_counter() {
  100|       |   // Lock is held whenever this function is called
  101|      1|   m_reseed_counter = 1;
  102|      1|}
_ZN5Botan12Stateful_RNG12reseed_checkEv:
  104|  91.8k|void Stateful_RNG::reseed_check() {
  105|       |   // Lock is held whenever this function is called
  106|       |
  107|  91.8k|   const uint32_t cur_pid = OS::get_process_id();
  108|       |
  109|  91.8k|   const bool fork_detected = (m_last_pid > 0) && (cur_pid != m_last_pid);
  ------------------
  |  Branch (109:31): [True: 0, False: 91.8k]
  |  Branch (109:51): [True: 0, False: 0]
  ------------------
  110|       |
  111|  91.8k|   if(is_seeded() == false || fork_detected || (m_reseed_interval > 0 && m_reseed_counter >= m_reseed_interval)) {
  ------------------
  |  Branch (111:7): [True: 0, False: 91.8k]
  |  Branch (111:31): [True: 0, False: 91.8k]
  |  Branch (111:49): [True: 0, False: 91.8k]
  |  Branch (111:74): [True: 0, False: 0]
  ------------------
  112|      0|      m_reseed_counter = 0;
  113|      0|      m_last_pid = cur_pid;
  114|       |
  115|      0|      if(m_underlying_rng) {
  ------------------
  |  Branch (115:10): [True: 0, False: 0]
  ------------------
  116|      0|         reseed_from_rng(*m_underlying_rng, security_level());
  117|      0|      }
  118|       |
  119|      0|      if(m_entropy_sources) {
  ------------------
  |  Branch (119:10): [True: 0, False: 0]
  ------------------
  120|      0|         reseed(*m_entropy_sources, security_level());
  121|      0|      }
  122|       |
  123|      0|      if(!is_seeded()) {
  ------------------
  |  Branch (123:10): [True: 0, False: 0]
  ------------------
  124|      0|         if(fork_detected) {
  ------------------
  |  Branch (124:13): [True: 0, False: 0]
  ------------------
  125|      0|            throw Invalid_State("Detected use of fork but cannot reseed DRBG");
  126|      0|         } else {
  127|      0|            throw PRNG_Unseeded(name());
  128|      0|         }
  129|      0|      }
  130|  91.8k|   } else {
  131|  91.8k|      BOTAN_ASSERT(m_reseed_counter != 0, "RNG is seeded");
  ------------------
  |  |   51|  91.8k|   do {                                                                                 \
  |  |   52|  91.8k|      if(!(expr))                                                                       \
  |  |  ------------------
  |  |  |  Branch (52:10): [True: 0, False: 91.8k]
  |  |  ------------------
  |  |   53|  91.8k|         Botan::assertion_failure(#expr, assertion_made, __func__, __FILE__, __LINE__); \
  |  |   54|  91.8k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (54:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  132|  91.8k|      m_reseed_counter += 1;
  133|  91.8k|   }
  134|  91.8k|}

_ZN5Botan6ChaChaC2Em:
   69|      1|ChaCha::ChaCha(size_t rounds) : m_rounds(rounds) {
   70|      1|   BOTAN_ARG_CHECK(m_rounds == 8 || m_rounds == 12 || m_rounds == 20, "ChaCha only supports 8, 12 or 20 rounds");
  ------------------
  |  |   30|      1|   do {                                                          \
  |  |   31|      4|      if(!(expr))                                                \
  |  |  ------------------
  |  |  |  Branch (31:12): [True: 0, False: 1]
  |  |  |  Branch (31:12): [True: 0, False: 1]
  |  |  |  Branch (31:12): [True: 1, False: 0]
  |  |  ------------------
  |  |   32|      1|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   33|      1|   } while(0)
  |  |  ------------------
  |  |  |  Branch (33:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   71|      1|}
_ZN5Botan6ChaCha11parallelismEv:
   73|      2|size_t ChaCha::parallelism() {
   74|      2|#if defined(BOTAN_HAS_CHACHA_AVX512)
   75|      2|   if(CPUID::has_avx512()) {
  ------------------
  |  Branch (75:7): [True: 0, False: 2]
  ------------------
   76|      0|      return 16;
   77|      0|   }
   78|      2|#endif
   79|       |
   80|      2|#if defined(BOTAN_HAS_CHACHA_AVX2)
   81|      2|   if(CPUID::has_avx2()) {
  ------------------
  |  Branch (81:7): [True: 2, False: 0]
  ------------------
   82|      2|      return 8;
   83|      2|   }
   84|      0|#endif
   85|       |
   86|      0|   return 4;
   87|      2|}
_ZN5Botan6ChaCha6chachaEPhmPjm:
  111|  8.18k|void ChaCha::chacha(uint8_t output[], size_t output_blocks, uint32_t state[16], size_t rounds) {
  112|  8.18k|   BOTAN_ASSERT(rounds % 2 == 0, "Valid rounds");
  ------------------
  |  |   51|  8.18k|   do {                                                                                 \
  |  |   52|  8.18k|      if(!(expr))                                                                       \
  |  |  ------------------
  |  |  |  Branch (52:10): [True: 0, False: 8.18k]
  |  |  ------------------
  |  |   53|  8.18k|         Botan::assertion_failure(#expr, assertion_made, __func__, __FILE__, __LINE__); \
  |  |   54|  8.18k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (54:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  113|       |
  114|  8.18k|#if defined(BOTAN_HAS_CHACHA_AVX512)
  115|  8.18k|   if(CPUID::has_avx512()) {
  ------------------
  |  Branch (115:7): [True: 0, False: 8.18k]
  ------------------
  116|      0|      while(output_blocks >= 16) {
  ------------------
  |  Branch (116:13): [True: 0, False: 0]
  ------------------
  117|      0|         ChaCha::chacha_avx512_x16(output, state, rounds);
  118|      0|         output += 16 * 64;
  119|      0|         output_blocks -= 16;
  120|      0|      }
  121|      0|   }
  122|  8.18k|#endif
  123|       |
  124|  8.18k|#if defined(BOTAN_HAS_CHACHA_AVX2)
  125|  8.18k|   if(CPUID::has_avx2()) {
  ------------------
  |  Branch (125:7): [True: 8.18k, False: 0]
  ------------------
  126|  16.3k|      while(output_blocks >= 8) {
  ------------------
  |  Branch (126:13): [True: 8.18k, False: 8.18k]
  ------------------
  127|  8.18k|         ChaCha::chacha_avx2_x8(output, state, rounds);
  128|  8.18k|         output += 8 * 64;
  129|  8.18k|         output_blocks -= 8;
  130|  8.18k|      }
  131|  8.18k|   }
  132|  8.18k|#endif
  133|       |
  134|  8.18k|#if defined(BOTAN_HAS_CHACHA_SIMD32)
  135|  8.18k|   if(CPUID::has_simd_32()) {
  ------------------
  |  Branch (135:7): [True: 8.18k, False: 0]
  ------------------
  136|  8.18k|      while(output_blocks >= 4) {
  ------------------
  |  Branch (136:13): [True: 0, False: 8.18k]
  ------------------
  137|      0|         ChaCha::chacha_simd32_x4(output, state, rounds);
  138|      0|         output += 4 * 64;
  139|      0|         output_blocks -= 4;
  140|      0|      }
  141|  8.18k|   }
  142|  8.18k|#endif
  143|       |
  144|       |   // TODO interleave rounds
  145|  8.18k|   for(size_t i = 0; i != output_blocks; ++i) {
  ------------------
  |  Branch (145:22): [True: 0, False: 8.18k]
  ------------------
  146|      0|      uint32_t x00 = state[0], x01 = state[1], x02 = state[2], x03 = state[3], x04 = state[4], x05 = state[5],
  147|      0|               x06 = state[6], x07 = state[7], x08 = state[8], x09 = state[9], x10 = state[10], x11 = state[11],
  148|      0|               x12 = state[12], x13 = state[13], x14 = state[14], x15 = state[15];
  149|       |
  150|      0|      for(size_t r = 0; r != rounds / 2; ++r) {
  ------------------
  |  Branch (150:25): [True: 0, False: 0]
  ------------------
  151|      0|         chacha_quarter_round(x00, x04, x08, x12);
  152|      0|         chacha_quarter_round(x01, x05, x09, x13);
  153|      0|         chacha_quarter_round(x02, x06, x10, x14);
  154|      0|         chacha_quarter_round(x03, x07, x11, x15);
  155|       |
  156|      0|         chacha_quarter_round(x00, x05, x10, x15);
  157|      0|         chacha_quarter_round(x01, x06, x11, x12);
  158|      0|         chacha_quarter_round(x02, x07, x08, x13);
  159|      0|         chacha_quarter_round(x03, x04, x09, x14);
  160|      0|      }
  161|       |
  162|      0|      x00 += state[0];
  163|      0|      x01 += state[1];
  164|      0|      x02 += state[2];
  165|      0|      x03 += state[3];
  166|      0|      x04 += state[4];
  167|      0|      x05 += state[5];
  168|      0|      x06 += state[6];
  169|      0|      x07 += state[7];
  170|      0|      x08 += state[8];
  171|      0|      x09 += state[9];
  172|      0|      x10 += state[10];
  173|      0|      x11 += state[11];
  174|      0|      x12 += state[12];
  175|      0|      x13 += state[13];
  176|      0|      x14 += state[14];
  177|      0|      x15 += state[15];
  178|       |
  179|      0|      store_le(x00, output + 64 * i + 4 * 0);
  180|      0|      store_le(x01, output + 64 * i + 4 * 1);
  181|      0|      store_le(x02, output + 64 * i + 4 * 2);
  182|      0|      store_le(x03, output + 64 * i + 4 * 3);
  183|      0|      store_le(x04, output + 64 * i + 4 * 4);
  184|      0|      store_le(x05, output + 64 * i + 4 * 5);
  185|      0|      store_le(x06, output + 64 * i + 4 * 6);
  186|      0|      store_le(x07, output + 64 * i + 4 * 7);
  187|      0|      store_le(x08, output + 64 * i + 4 * 8);
  188|      0|      store_le(x09, output + 64 * i + 4 * 9);
  189|      0|      store_le(x10, output + 64 * i + 4 * 10);
  190|      0|      store_le(x11, output + 64 * i + 4 * 11);
  191|      0|      store_le(x12, output + 64 * i + 4 * 12);
  192|      0|      store_le(x13, output + 64 * i + 4 * 13);
  193|      0|      store_le(x14, output + 64 * i + 4 * 14);
  194|      0|      store_le(x15, output + 64 * i + 4 * 15);
  195|       |
  196|      0|      state[12]++;
  197|      0|      state[13] += (state[12] == 0);
  198|      0|   }
  199|  8.18k|}
_ZN5Botan6ChaCha18generate_keystreamEPhm:
  224|  91.8k|void ChaCha::generate_keystream(uint8_t out[], size_t length) {
  225|  91.8k|   assert_key_material_set();
  226|       |
  227|   100k|   while(length >= m_buffer.size() - m_position) {
  ------------------
  |  Branch (227:10): [True: 8.18k, False: 91.8k]
  ------------------
  228|  8.18k|      const size_t available = m_buffer.size() - m_position;
  229|       |
  230|       |      // TODO: this could write directly to the output buffer
  231|       |      // instead of bouncing it through m_buffer first
  232|  8.18k|      copy_mem(out, &m_buffer[m_position], available);
  233|  8.18k|      chacha(m_buffer.data(), m_buffer.size() / 64, m_state.data(), m_rounds);
  234|       |
  235|  8.18k|      length -= available;
  236|  8.18k|      out += available;
  237|  8.18k|      m_position = 0;
  238|  8.18k|   }
  239|       |
  240|  91.8k|   copy_mem(out, &m_buffer[m_position], length);
  241|       |
  242|  91.8k|   m_position += length;
  243|  91.8k|}
_ZN5Botan6ChaCha16initialize_stateEv:
  245|      2|void ChaCha::initialize_state() {
  246|      2|   static const uint32_t TAU[] = {0x61707865, 0x3120646e, 0x79622d36, 0x6b206574};
  247|       |
  248|      2|   static const uint32_t SIGMA[] = {0x61707865, 0x3320646e, 0x79622d32, 0x6b206574};
  249|       |
  250|      2|   m_state[4] = m_key[0];
  251|      2|   m_state[5] = m_key[1];
  252|      2|   m_state[6] = m_key[2];
  253|      2|   m_state[7] = m_key[3];
  254|       |
  255|      2|   if(m_key.size() == 4) {
  ------------------
  |  Branch (255:7): [True: 0, False: 2]
  ------------------
  256|      0|      m_state[0] = TAU[0];
  257|      0|      m_state[1] = TAU[1];
  258|      0|      m_state[2] = TAU[2];
  259|      0|      m_state[3] = TAU[3];
  260|       |
  261|      0|      m_state[8] = m_key[0];
  262|      0|      m_state[9] = m_key[1];
  263|      0|      m_state[10] = m_key[2];
  264|      0|      m_state[11] = m_key[3];
  265|      2|   } else {
  266|      2|      m_state[0] = SIGMA[0];
  267|      2|      m_state[1] = SIGMA[1];
  268|      2|      m_state[2] = SIGMA[2];
  269|      2|      m_state[3] = SIGMA[3];
  270|       |
  271|      2|      m_state[8] = m_key[4];
  272|      2|      m_state[9] = m_key[5];
  273|      2|      m_state[10] = m_key[6];
  274|      2|      m_state[11] = m_key[7];
  275|      2|   }
  276|       |
  277|      2|   m_state[12] = 0;
  278|      2|   m_state[13] = 0;
  279|      2|   m_state[14] = 0;
  280|      2|   m_state[15] = 0;
  281|       |
  282|      2|   m_position = 0;
  283|      2|}
_ZNK5Botan6ChaCha19has_keying_materialEv:
  285|  91.8k|bool ChaCha::has_keying_material() const {
  286|  91.8k|   return !m_state.empty();
  287|  91.8k|}
_ZN5Botan6ChaCha12key_scheduleENSt3__14spanIKhLm18446744073709551615EEE:
  296|      2|void ChaCha::key_schedule(std::span<const uint8_t> key) {
  297|      2|   m_key.resize(key.size() / 4);
  298|      2|   load_le<uint32_t>(m_key.data(), key.data(), m_key.size());
  299|       |
  300|      2|   m_state.resize(16);
  301|       |
  302|      2|   const size_t chacha_block = 64;
  303|      2|   m_buffer.resize(parallelism() * chacha_block);
  304|       |
  305|      2|   set_iv(nullptr, 0);
  306|      2|}
_ZNK5Botan6ChaCha8key_specEv:
  312|      2|Key_Length_Specification ChaCha::key_spec() const {
  313|      2|   return Key_Length_Specification(16, 32, 16);
  314|      2|}
_ZNK5Botan6ChaCha15valid_iv_lengthEm:
  320|      2|bool ChaCha::valid_iv_length(size_t iv_len) const {
  321|      2|   return (iv_len == 0 || iv_len == 8 || iv_len == 12 || iv_len == 24);
  ------------------
  |  Branch (321:12): [True: 2, False: 0]
  |  Branch (321:27): [True: 0, False: 0]
  |  Branch (321:42): [True: 0, False: 0]
  |  Branch (321:58): [True: 0, False: 0]
  ------------------
  322|      2|}
_ZN5Botan6ChaCha12set_iv_bytesEPKhm:
  324|      2|void ChaCha::set_iv_bytes(const uint8_t iv[], size_t length) {
  325|      2|   assert_key_material_set();
  326|       |
  327|      2|   if(!valid_iv_length(length)) {
  ------------------
  |  Branch (327:7): [True: 0, False: 2]
  ------------------
  328|      0|      throw Invalid_IV_Length(name(), length);
  329|      0|   }
  330|       |
  331|      2|   initialize_state();
  332|       |
  333|      2|   if(length == 0) {
  ------------------
  |  Branch (333:7): [True: 2, False: 0]
  ------------------
  334|       |      // Treat zero length IV same as an all-zero IV
  335|      2|      m_state[14] = 0;
  336|      2|      m_state[15] = 0;
  337|      2|   } else if(length == 8) {
  ------------------
  |  Branch (337:14): [True: 0, False: 0]
  ------------------
  338|      0|      m_state[14] = load_le<uint32_t>(iv, 0);
  339|      0|      m_state[15] = load_le<uint32_t>(iv, 1);
  340|      0|   } else if(length == 12) {
  ------------------
  |  Branch (340:14): [True: 0, False: 0]
  ------------------
  341|      0|      m_state[13] = load_le<uint32_t>(iv, 0);
  342|      0|      m_state[14] = load_le<uint32_t>(iv, 1);
  343|      0|      m_state[15] = load_le<uint32_t>(iv, 2);
  344|      0|   } else if(length == 24) {
  ------------------
  |  Branch (344:14): [True: 0, False: 0]
  ------------------
  345|      0|      m_state[12] = load_le<uint32_t>(iv, 0);
  346|      0|      m_state[13] = load_le<uint32_t>(iv, 1);
  347|      0|      m_state[14] = load_le<uint32_t>(iv, 2);
  348|      0|      m_state[15] = load_le<uint32_t>(iv, 3);
  349|       |
  350|      0|      secure_vector<uint32_t> hc(8);
  351|      0|      hchacha(hc.data(), m_state.data(), m_rounds);
  352|       |
  353|      0|      m_state[4] = hc[0];
  354|      0|      m_state[5] = hc[1];
  355|      0|      m_state[6] = hc[2];
  356|      0|      m_state[7] = hc[3];
  357|      0|      m_state[8] = hc[4];
  358|      0|      m_state[9] = hc[5];
  359|      0|      m_state[10] = hc[6];
  360|      0|      m_state[11] = hc[7];
  361|      0|      m_state[12] = 0;
  362|      0|      m_state[13] = 0;
  363|      0|      m_state[14] = load_le<uint32_t>(iv, 4);
  364|      0|      m_state[15] = load_le<uint32_t>(iv, 5);
  365|      0|   }
  366|       |
  367|      2|   chacha(m_buffer.data(), m_buffer.size() / 64, m_state.data(), m_rounds);
  368|      2|   m_position = 0;
  369|      2|}

_ZN5Botan6ChaCha14chacha_avx2_x8EPhPjm:
   15|  8.18k|void ChaCha::chacha_avx2_x8(uint8_t output[64 * 8], uint32_t state[16], size_t rounds) {
   16|  8.18k|   SIMD_8x32::reset_registers();
   17|       |
   18|  8.18k|   BOTAN_ASSERT(rounds % 2 == 0, "Valid rounds");
  ------------------
  |  |   51|  8.18k|   do {                                                                                 \
  |  |   52|  8.18k|      if(!(expr))                                                                       \
  |  |  ------------------
  |  |  |  Branch (52:10): [True: 0, False: 8.18k]
  |  |  ------------------
  |  |   53|  8.18k|         Botan::assertion_failure(#expr, assertion_made, __func__, __FILE__, __LINE__); \
  |  |   54|  8.18k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (54:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   19|  8.18k|   const SIMD_8x32 CTR0 = SIMD_8x32(0, 1, 2, 3, 4, 5, 6, 7);
   20|       |
   21|  8.18k|   const uint32_t C = 0xFFFFFFFF - state[12];
   22|  8.18k|   const SIMD_8x32 CTR1 = SIMD_8x32(0, C < 1, C < 2, C < 3, C < 4, C < 5, C < 6, C < 7);
   23|       |
   24|  8.18k|   SIMD_8x32 R00 = SIMD_8x32::splat(state[0]);
   25|  8.18k|   SIMD_8x32 R01 = SIMD_8x32::splat(state[1]);
   26|  8.18k|   SIMD_8x32 R02 = SIMD_8x32::splat(state[2]);
   27|  8.18k|   SIMD_8x32 R03 = SIMD_8x32::splat(state[3]);
   28|  8.18k|   SIMD_8x32 R04 = SIMD_8x32::splat(state[4]);
   29|  8.18k|   SIMD_8x32 R05 = SIMD_8x32::splat(state[5]);
   30|  8.18k|   SIMD_8x32 R06 = SIMD_8x32::splat(state[6]);
   31|  8.18k|   SIMD_8x32 R07 = SIMD_8x32::splat(state[7]);
   32|  8.18k|   SIMD_8x32 R08 = SIMD_8x32::splat(state[8]);
   33|  8.18k|   SIMD_8x32 R09 = SIMD_8x32::splat(state[9]);
   34|  8.18k|   SIMD_8x32 R10 = SIMD_8x32::splat(state[10]);
   35|  8.18k|   SIMD_8x32 R11 = SIMD_8x32::splat(state[11]);
   36|  8.18k|   SIMD_8x32 R12 = SIMD_8x32::splat(state[12]) + CTR0;
   37|  8.18k|   SIMD_8x32 R13 = SIMD_8x32::splat(state[13]) + CTR1;
   38|  8.18k|   SIMD_8x32 R14 = SIMD_8x32::splat(state[14]);
   39|  8.18k|   SIMD_8x32 R15 = SIMD_8x32::splat(state[15]);
   40|       |
   41|  90.0k|   for(size_t r = 0; r != rounds / 2; ++r) {
  ------------------
  |  Branch (41:22): [True: 81.8k, False: 8.18k]
  ------------------
   42|  81.8k|      R00 += R04;
   43|  81.8k|      R01 += R05;
   44|  81.8k|      R02 += R06;
   45|  81.8k|      R03 += R07;
   46|       |
   47|  81.8k|      R12 ^= R00;
   48|  81.8k|      R13 ^= R01;
   49|  81.8k|      R14 ^= R02;
   50|  81.8k|      R15 ^= R03;
   51|       |
   52|  81.8k|      R12 = R12.rotl<16>();
   53|  81.8k|      R13 = R13.rotl<16>();
   54|  81.8k|      R14 = R14.rotl<16>();
   55|  81.8k|      R15 = R15.rotl<16>();
   56|       |
   57|  81.8k|      R08 += R12;
   58|  81.8k|      R09 += R13;
   59|  81.8k|      R10 += R14;
   60|  81.8k|      R11 += R15;
   61|       |
   62|  81.8k|      R04 ^= R08;
   63|  81.8k|      R05 ^= R09;
   64|  81.8k|      R06 ^= R10;
   65|  81.8k|      R07 ^= R11;
   66|       |
   67|  81.8k|      R04 = R04.rotl<12>();
   68|  81.8k|      R05 = R05.rotl<12>();
   69|  81.8k|      R06 = R06.rotl<12>();
   70|  81.8k|      R07 = R07.rotl<12>();
   71|       |
   72|  81.8k|      R00 += R04;
   73|  81.8k|      R01 += R05;
   74|  81.8k|      R02 += R06;
   75|  81.8k|      R03 += R07;
   76|       |
   77|  81.8k|      R12 ^= R00;
   78|  81.8k|      R13 ^= R01;
   79|  81.8k|      R14 ^= R02;
   80|  81.8k|      R15 ^= R03;
   81|       |
   82|  81.8k|      R12 = R12.rotl<8>();
   83|  81.8k|      R13 = R13.rotl<8>();
   84|  81.8k|      R14 = R14.rotl<8>();
   85|  81.8k|      R15 = R15.rotl<8>();
   86|       |
   87|  81.8k|      R08 += R12;
   88|  81.8k|      R09 += R13;
   89|  81.8k|      R10 += R14;
   90|  81.8k|      R11 += R15;
   91|       |
   92|  81.8k|      R04 ^= R08;
   93|  81.8k|      R05 ^= R09;
   94|  81.8k|      R06 ^= R10;
   95|  81.8k|      R07 ^= R11;
   96|       |
   97|  81.8k|      R04 = R04.rotl<7>();
   98|  81.8k|      R05 = R05.rotl<7>();
   99|  81.8k|      R06 = R06.rotl<7>();
  100|  81.8k|      R07 = R07.rotl<7>();
  101|       |
  102|  81.8k|      R00 += R05;
  103|  81.8k|      R01 += R06;
  104|  81.8k|      R02 += R07;
  105|  81.8k|      R03 += R04;
  106|       |
  107|  81.8k|      R15 ^= R00;
  108|  81.8k|      R12 ^= R01;
  109|  81.8k|      R13 ^= R02;
  110|  81.8k|      R14 ^= R03;
  111|       |
  112|  81.8k|      R15 = R15.rotl<16>();
  113|  81.8k|      R12 = R12.rotl<16>();
  114|  81.8k|      R13 = R13.rotl<16>();
  115|  81.8k|      R14 = R14.rotl<16>();
  116|       |
  117|  81.8k|      R10 += R15;
  118|  81.8k|      R11 += R12;
  119|  81.8k|      R08 += R13;
  120|  81.8k|      R09 += R14;
  121|       |
  122|  81.8k|      R05 ^= R10;
  123|  81.8k|      R06 ^= R11;
  124|  81.8k|      R07 ^= R08;
  125|  81.8k|      R04 ^= R09;
  126|       |
  127|  81.8k|      R05 = R05.rotl<12>();
  128|  81.8k|      R06 = R06.rotl<12>();
  129|  81.8k|      R07 = R07.rotl<12>();
  130|  81.8k|      R04 = R04.rotl<12>();
  131|       |
  132|  81.8k|      R00 += R05;
  133|  81.8k|      R01 += R06;
  134|  81.8k|      R02 += R07;
  135|  81.8k|      R03 += R04;
  136|       |
  137|  81.8k|      R15 ^= R00;
  138|  81.8k|      R12 ^= R01;
  139|  81.8k|      R13 ^= R02;
  140|  81.8k|      R14 ^= R03;
  141|       |
  142|  81.8k|      R15 = R15.rotl<8>();
  143|  81.8k|      R12 = R12.rotl<8>();
  144|  81.8k|      R13 = R13.rotl<8>();
  145|  81.8k|      R14 = R14.rotl<8>();
  146|       |
  147|  81.8k|      R10 += R15;
  148|  81.8k|      R11 += R12;
  149|  81.8k|      R08 += R13;
  150|  81.8k|      R09 += R14;
  151|       |
  152|  81.8k|      R05 ^= R10;
  153|  81.8k|      R06 ^= R11;
  154|  81.8k|      R07 ^= R08;
  155|  81.8k|      R04 ^= R09;
  156|       |
  157|  81.8k|      R05 = R05.rotl<7>();
  158|  81.8k|      R06 = R06.rotl<7>();
  159|  81.8k|      R07 = R07.rotl<7>();
  160|  81.8k|      R04 = R04.rotl<7>();
  161|  81.8k|   }
  162|       |
  163|  8.18k|   R00 += SIMD_8x32::splat(state[0]);
  164|  8.18k|   R01 += SIMD_8x32::splat(state[1]);
  165|  8.18k|   R02 += SIMD_8x32::splat(state[2]);
  166|  8.18k|   R03 += SIMD_8x32::splat(state[3]);
  167|  8.18k|   R04 += SIMD_8x32::splat(state[4]);
  168|  8.18k|   R05 += SIMD_8x32::splat(state[5]);
  169|  8.18k|   R06 += SIMD_8x32::splat(state[6]);
  170|  8.18k|   R07 += SIMD_8x32::splat(state[7]);
  171|  8.18k|   R08 += SIMD_8x32::splat(state[8]);
  172|  8.18k|   R09 += SIMD_8x32::splat(state[9]);
  173|  8.18k|   R10 += SIMD_8x32::splat(state[10]);
  174|  8.18k|   R11 += SIMD_8x32::splat(state[11]);
  175|  8.18k|   R12 += SIMD_8x32::splat(state[12]) + CTR0;
  176|  8.18k|   R13 += SIMD_8x32::splat(state[13]) + CTR1;
  177|  8.18k|   R14 += SIMD_8x32::splat(state[14]);
  178|  8.18k|   R15 += SIMD_8x32::splat(state[15]);
  179|       |
  180|  8.18k|   SIMD_8x32::transpose(R00, R01, R02, R03, R04, R05, R06, R07);
  181|  8.18k|   SIMD_8x32::transpose(R08, R09, R10, R11, R12, R13, R14, R15);
  182|       |
  183|  8.18k|   R00.store_le(output);
  184|  8.18k|   R08.store_le(output + 32 * 1);
  185|  8.18k|   R01.store_le(output + 32 * 2);
  186|  8.18k|   R09.store_le(output + 32 * 3);
  187|  8.18k|   R02.store_le(output + 32 * 4);
  188|  8.18k|   R10.store_le(output + 32 * 5);
  189|  8.18k|   R03.store_le(output + 32 * 6);
  190|  8.18k|   R11.store_le(output + 32 * 7);
  191|  8.18k|   R04.store_le(output + 32 * 8);
  192|  8.18k|   R12.store_le(output + 32 * 9);
  193|  8.18k|   R05.store_le(output + 32 * 10);
  194|  8.18k|   R13.store_le(output + 32 * 11);
  195|  8.18k|   R06.store_le(output + 32 * 12);
  196|  8.18k|   R14.store_le(output + 32 * 13);
  197|  8.18k|   R07.store_le(output + 32 * 14);
  198|  8.18k|   R15.store_le(output + 32 * 15);
  199|       |
  200|  8.18k|   SIMD_8x32::zero_registers();
  201|       |
  202|  8.18k|   state[12] += 8;
  203|  8.18k|   if(state[12] < 8) {
  ------------------
  |  Branch (203:7): [True: 0, False: 8.18k]
  ------------------
  204|      0|      state[13]++;
  205|      0|   }
  206|  8.18k|}

_ZN5Botan12StreamCipher6createENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEES5_:
   40|      1|std::unique_ptr<StreamCipher> StreamCipher::create(std::string_view algo_spec, std::string_view provider) {
   41|      1|#if defined(BOTAN_HAS_SHAKE_CIPHER)
   42|      1|   if(algo_spec == "SHAKE-128" || algo_spec == "SHAKE-128-XOF") {
  ------------------
  |  Branch (42:7): [True: 0, False: 1]
  |  Branch (42:35): [True: 0, False: 1]
  ------------------
   43|      0|      if(provider.empty() || provider == "base") {
  ------------------
  |  Branch (43:10): [True: 0, False: 0]
  |  Branch (43:30): [True: 0, False: 0]
  ------------------
   44|      0|         return std::make_unique<SHAKE_128_Cipher>();
   45|      0|      }
   46|      0|   }
   47|       |
   48|      1|   if(algo_spec == "SHAKE-256" || algo_spec == "SHAKE-256-XOF") {
  ------------------
  |  Branch (48:7): [True: 0, False: 1]
  |  Branch (48:35): [True: 0, False: 1]
  ------------------
   49|      0|      if(provider.empty() || provider == "base") {
  ------------------
  |  Branch (49:10): [True: 0, False: 0]
  |  Branch (49:30): [True: 0, False: 0]
  ------------------
   50|      0|         return std::make_unique<SHAKE_256_Cipher>();
   51|      0|      }
   52|      0|   }
   53|      1|#endif
   54|       |
   55|      1|#if defined(BOTAN_HAS_CHACHA)
   56|      1|   if(algo_spec == "ChaCha20") {
  ------------------
  |  Branch (56:7): [True: 0, False: 1]
  ------------------
   57|      0|      if(provider.empty() || provider == "base") {
  ------------------
  |  Branch (57:10): [True: 0, False: 0]
  |  Branch (57:30): [True: 0, False: 0]
  ------------------
   58|      0|         return std::make_unique<ChaCha>(20);
   59|      0|      }
   60|      0|   }
   61|      1|#endif
   62|       |
   63|      1|#if defined(BOTAN_HAS_SALSA20)
   64|      1|   if(algo_spec == "Salsa20") {
  ------------------
  |  Branch (64:7): [True: 0, False: 1]
  ------------------
   65|      0|      if(provider.empty() || provider == "base") {
  ------------------
  |  Branch (65:10): [True: 0, False: 0]
  |  Branch (65:30): [True: 0, False: 0]
  ------------------
   66|      0|         return std::make_unique<Salsa20>();
   67|      0|      }
   68|      0|   }
   69|      1|#endif
   70|       |
   71|      1|   const SCAN_Name req(algo_spec);
   72|       |
   73|      1|#if defined(BOTAN_HAS_CTR_BE)
   74|      1|   if((req.algo_name() == "CTR-BE" || req.algo_name() == "CTR") && req.arg_count_between(1, 2)) {
  ------------------
  |  Branch (74:8): [True: 0, False: 1]
  |  Branch (74:39): [True: 0, False: 1]
  |  Branch (74:68): [True: 0, False: 0]
  ------------------
   75|      0|      if(provider.empty() || provider == "base") {
  ------------------
  |  Branch (75:10): [True: 0, False: 0]
  |  Branch (75:30): [True: 0, False: 0]
  ------------------
   76|      0|         auto cipher = BlockCipher::create(req.arg(0));
   77|      0|         if(cipher) {
  ------------------
  |  Branch (77:13): [True: 0, False: 0]
  ------------------
   78|      0|            size_t ctr_size = req.arg_as_integer(1, cipher->block_size());
   79|      0|            return std::make_unique<CTR_BE>(std::move(cipher), ctr_size);
   80|      0|         }
   81|      0|      }
   82|      0|   }
   83|      1|#endif
   84|       |
   85|      1|#if defined(BOTAN_HAS_CHACHA)
   86|      1|   if(req.algo_name() == "ChaCha") {
  ------------------
  |  Branch (86:7): [True: 1, False: 0]
  ------------------
   87|      1|      if(provider.empty() || provider == "base") {
  ------------------
  |  Branch (87:10): [True: 1, False: 0]
  |  Branch (87:30): [True: 0, False: 0]
  ------------------
   88|      1|         return std::make_unique<ChaCha>(req.arg_as_integer(0, 20));
   89|      1|      }
   90|      1|   }
   91|      0|#endif
   92|       |
   93|      0|#if defined(BOTAN_HAS_OFB)
   94|      0|   if(req.algo_name() == "OFB" && req.arg_count() == 1) {
  ------------------
  |  Branch (94:7): [True: 0, False: 0]
  |  Branch (94:35): [True: 0, False: 0]
  ------------------
   95|      0|      if(provider.empty() || provider == "base") {
  ------------------
  |  Branch (95:10): [True: 0, False: 0]
  |  Branch (95:30): [True: 0, False: 0]
  ------------------
   96|      0|         if(auto cipher = BlockCipher::create(req.arg(0))) {
  ------------------
  |  Branch (96:18): [True: 0, False: 0]
  ------------------
   97|      0|            return std::make_unique<OFB>(std::move(cipher));
   98|      0|         }
   99|      0|      }
  100|      0|   }
  101|      0|#endif
  102|       |
  103|      0|#if defined(BOTAN_HAS_RC4)
  104|       |
  105|      0|   if(req.algo_name() == "RC4" || req.algo_name() == "ARC4" || req.algo_name() == "MARK-4") {
  ------------------
  |  Branch (105:7): [True: 0, False: 0]
  |  Branch (105:35): [True: 0, False: 0]
  |  Branch (105:64): [True: 0, False: 0]
  ------------------
  106|      0|      const size_t skip = (req.algo_name() == "MARK-4") ? 256 : req.arg_as_integer(0, 0);
  ------------------
  |  Branch (106:27): [True: 0, False: 0]
  ------------------
  107|       |
  108|      0|      if(provider.empty() || provider == "base") {
  ------------------
  |  Branch (108:10): [True: 0, False: 0]
  |  Branch (108:30): [True: 0, False: 0]
  ------------------
  109|      0|         return std::make_unique<RC4>(skip);
  110|      0|      }
  111|      0|   }
  112|       |
  113|      0|#endif
  114|       |
  115|      0|   BOTAN_UNUSED(req);
  ------------------
  |  |  118|      0|#define BOTAN_UNUSED Botan::ignore_params
  ------------------
  116|      0|   BOTAN_UNUSED(provider);
  ------------------
  |  |  118|      0|#define BOTAN_UNUSED Botan::ignore_params
  ------------------
  117|       |
  118|      0|   return nullptr;
  119|      0|}
_ZN5Botan12StreamCipher15create_or_throwENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEES5_:
  122|      1|std::unique_ptr<StreamCipher> StreamCipher::create_or_throw(std::string_view algo, std::string_view provider) {
  123|      1|   if(auto sc = StreamCipher::create(algo, provider)) {
  ------------------
  |  Branch (123:12): [True: 1, False: 0]
  ------------------
  124|      1|      return sc;
  125|      1|   }
  126|      0|   throw Lookup_Error("Stream cipher", algo, provider);
  127|      1|}

_ZN5Botan15allocate_memoryEmm:
   20|  2.93M|BOTAN_MALLOC_FN void* allocate_memory(size_t elems, size_t elem_size) {
   21|  2.93M|   if(elems == 0 || elem_size == 0) {
  ------------------
  |  Branch (21:7): [True: 0, False: 2.93M]
  |  Branch (21:21): [True: 0, False: 2.93M]
  ------------------
   22|      0|      return nullptr;
   23|      0|   }
   24|       |
   25|       |   // Some calloc implementations do not check for overflow (?!?)
   26|       |
   27|  2.93M|   if(!BOTAN_CHECKED_MUL(elems, elem_size).has_value()) {
  ------------------
  |  |   74|  2.93M|#define BOTAN_CHECKED_MUL(x, y) checked_mul(x, y)
  ------------------
  |  Branch (27:7): [True: 0, False: 2.93M]
  ------------------
   28|      0|      throw std::bad_alloc();
   29|      0|   }
   30|       |
   31|       |#if defined(BOTAN_HAS_LOCKING_ALLOCATOR)
   32|       |   if(void* p = mlock_allocator::instance().allocate(elems, elem_size)) {
   33|       |      return p;
   34|       |   }
   35|       |#endif
   36|       |
   37|       |#if defined(BOTAN_TARGET_OS_HAS_ALLOC_CONCEAL)
   38|       |   void* ptr = ::calloc_conceal(elems, elem_size);
   39|       |#else
   40|  2.93M|   void* ptr = std::calloc(elems, elem_size);  // NOLINT(*-no-malloc)
   41|  2.93M|#endif
   42|  2.93M|   if(!ptr) {
  ------------------
  |  Branch (42:7): [True: 0, False: 2.93M]
  ------------------
   43|      0|      [[unlikely]] throw std::bad_alloc();
   44|      0|   }
   45|  2.93M|   return ptr;
   46|  2.93M|}
_ZN5Botan17deallocate_memoryEPvmm:
   48|  2.93M|void deallocate_memory(void* p, size_t elems, size_t elem_size) {
   49|  2.93M|   if(p == nullptr) {
  ------------------
  |  Branch (49:7): [True: 0, False: 2.93M]
  ------------------
   50|      0|      [[unlikely]] return;
   51|      0|   }
   52|       |
   53|  2.93M|   secure_scrub_memory(p, elems * elem_size);
   54|       |
   55|       |#if defined(BOTAN_HAS_LOCKING_ALLOCATOR)
   56|       |   if(mlock_allocator::instance().deallocate(p, elems, elem_size)) {
   57|       |      return;
   58|       |   }
   59|       |#endif
   60|       |
   61|  2.93M|   std::free(p);  // NOLINT(*-no-malloc)
   62|  2.93M|}
_ZN5Botan20initialize_allocatorEv:
   64|      1|void initialize_allocator() {
   65|       |#if defined(BOTAN_HAS_LOCKING_ALLOCATOR)
   66|       |   mlock_allocator::instance();
   67|       |#endif
   68|      1|}

_ZN5Botan5CPUID11has_simd_32Ev:
   18|  8.18k|bool CPUID::has_simd_32() {
   19|  8.18k|#if defined(BOTAN_TARGET_SUPPORTS_SSE2)
   20|  8.18k|   return CPUID::has_sse2();
   21|       |#elif defined(BOTAN_TARGET_SUPPORTS_ALTIVEC)
   22|       |   return CPUID::has_altivec();
   23|       |#elif defined(BOTAN_TARGET_SUPPORTS_NEON)
   24|       |   return CPUID::has_neon();
   25|       |#else
   26|       |   return true;
   27|       |#endif
   28|  8.18k|}
_ZN5Botan5CPUID10CPUID_DataC2Ev:
  122|      1|CPUID::CPUID_Data::CPUID_Data() {
  123|      1|   m_processor_features = 0;
  124|       |
  125|      1|#if defined(BOTAN_TARGET_CPU_IS_PPC_FAMILY) || defined(BOTAN_TARGET_CPU_IS_ARM_FAMILY) || \
  126|      1|   defined(BOTAN_TARGET_CPU_IS_X86_FAMILY)
  127|       |
  128|      1|   m_processor_features = detect_cpu_features();
  129|       |
  130|      1|#endif
  131|       |
  132|      1|   m_processor_features |= CPUID::CPUID_INITIALIZED_BIT;
  133|       |
  134|      1|   if(runtime_check_if_big_endian()) {
  ------------------
  |  Branch (134:7): [True: 0, False: 1]
  ------------------
  135|      0|      m_processor_features |= CPUID::CPUID_IS_BIG_ENDIAN_BIT;
  136|      0|   }
  137|       |
  138|      1|   std::string clear_cpuid_env;
  139|      1|   if(OS::read_env_variable(clear_cpuid_env, "BOTAN_CLEAR_CPUID")) {
  ------------------
  |  Branch (139:7): [True: 0, False: 1]
  ------------------
  140|      0|      for(const auto& cpuid : split_on(clear_cpuid_env, ',')) {
  ------------------
  |  Branch (140:29): [True: 0, False: 0]
  ------------------
  141|      0|         for(auto& bit : CPUID::bit_from_string(cpuid)) {
  ------------------
  |  Branch (141:24): [True: 0, False: 0]
  ------------------
  142|      0|            const uint32_t cleared = ~static_cast<uint32_t>(bit);
  143|      0|            m_processor_features &= cleared;
  144|      0|         }
  145|      0|      }
  146|      0|   }
  147|      1|}
cpuid.cpp:_ZN5Botan12_GLOBAL__N_127runtime_check_if_big_endianEv:
   95|      1|bool runtime_check_if_big_endian() {
   96|       |   // Check runtime endian
   97|      1|   const uint32_t endian32 = 0x01234567;
   98|      1|   const uint8_t* e8 = reinterpret_cast<const uint8_t*>(&endian32);
   99|       |
  100|      1|   bool is_big_endian = false;
  101|       |
  102|      1|   if(e8[0] == 0x01 && e8[1] == 0x23 && e8[2] == 0x45 && e8[3] == 0x67) {
  ------------------
  |  Branch (102:7): [True: 0, False: 1]
  |  Branch (102:24): [True: 0, False: 0]
  |  Branch (102:41): [True: 0, False: 0]
  |  Branch (102:58): [True: 0, False: 0]
  ------------------
  103|      0|      is_big_endian = true;
  104|      1|   } else if(e8[0] == 0x67 && e8[1] == 0x45 && e8[2] == 0x23 && e8[3] == 0x01) {
  ------------------
  |  Branch (104:14): [True: 1, False: 0]
  |  Branch (104:31): [True: 1, False: 0]
  |  Branch (104:48): [True: 1, False: 0]
  |  Branch (104:65): [True: 1, False: 0]
  ------------------
  105|      1|      is_big_endian = false;
  106|      1|   } else {
  107|      0|      throw Internal_Error("Unexpected endian at runtime, neither big nor little");
  108|      0|   }
  109|       |
  110|       |   // If we were compiled with a known endian, verify it matches at runtime
  111|      1|#if defined(BOTAN_TARGET_CPU_IS_LITTLE_ENDIAN)
  112|      1|   BOTAN_ASSERT(!is_big_endian, "Build and runtime endian match");
  ------------------
  |  |   51|      1|   do {                                                                                 \
  |  |   52|      1|      if(!(expr))                                                                       \
  |  |  ------------------
  |  |  |  Branch (52:10): [True: 0, False: 1]
  |  |  ------------------
  |  |   53|      1|         Botan::assertion_failure(#expr, assertion_made, __func__, __FILE__, __LINE__); \
  |  |   54|      1|   } while(0)
  |  |  ------------------
  |  |  |  Branch (54:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  113|       |#elif defined(BOTAN_TARGET_CPU_IS_BIG_ENDIAN)
  114|       |   BOTAN_ASSERT(is_big_endian, "Build and runtime endian match");
  115|       |#endif
  116|       |
  117|      1|   return is_big_endian;
  118|      1|}

_ZN5Botan5CPUID10CPUID_Data19detect_cpu_featuresEv:
   71|      1|uint32_t CPUID::CPUID_Data::detect_cpu_features() {
   72|      1|   uint32_t features_detected = 0;
   73|      1|   uint32_t cpuid[4] = {0};
   74|      1|   bool has_os_ymm_support = false;
   75|      1|   bool has_os_zmm_support = false;
   76|       |
   77|       |   // CPUID 0: vendor identification, max sublevel
   78|      1|   invoke_cpuid(0, cpuid);
   79|       |
   80|      1|   const uint32_t max_supported_sublevel = cpuid[0];
   81|       |
   82|      1|   if(max_supported_sublevel >= 1) {
  ------------------
  |  Branch (82:7): [True: 1, False: 0]
  ------------------
   83|       |      // CPUID 1: feature bits
   84|      1|      invoke_cpuid(1, cpuid);
   85|      1|      const uint64_t flags0 = (static_cast<uint64_t>(cpuid[2]) << 32) | cpuid[3];
   86|       |
   87|      1|      enum x86_CPUID_1_bits : uint64_t {
   88|      1|         RDTSC = (1ULL << 4),
   89|      1|         SSE2 = (1ULL << 26),
   90|      1|         CLMUL = (1ULL << 33),
   91|      1|         SSSE3 = (1ULL << 41),
   92|      1|         AESNI = (1ULL << 57),
   93|      1|         OSXSAVE = (1ULL << 59),
   94|      1|         AVX = (1ULL << 60),
   95|      1|         RDRAND = (1ULL << 62)
   96|      1|      };
   97|       |
   98|      1|      if(flags0 & x86_CPUID_1_bits::RDTSC) {
  ------------------
  |  Branch (98:10): [True: 1, False: 0]
  ------------------
   99|      1|         features_detected |= CPUID::CPUID_RDTSC_BIT;
  100|      1|      }
  101|      1|      if(flags0 & x86_CPUID_1_bits::SSE2) {
  ------------------
  |  Branch (101:10): [True: 1, False: 0]
  ------------------
  102|      1|         features_detected |= CPUID::CPUID_SSE2_BIT;
  103|      1|      }
  104|      1|      if(flags0 & x86_CPUID_1_bits::CLMUL) {
  ------------------
  |  Branch (104:10): [True: 1, False: 0]
  ------------------
  105|      1|         features_detected |= CPUID::CPUID_CLMUL_BIT;
  106|      1|      }
  107|      1|      if(flags0 & x86_CPUID_1_bits::SSSE3) {
  ------------------
  |  Branch (107:10): [True: 1, False: 0]
  ------------------
  108|      1|         features_detected |= CPUID::CPUID_SSSE3_BIT;
  109|      1|      }
  110|      1|      if(flags0 & x86_CPUID_1_bits::AESNI) {
  ------------------
  |  Branch (110:10): [True: 1, False: 0]
  ------------------
  111|      1|         features_detected |= CPUID::CPUID_AESNI_BIT;
  112|      1|      }
  113|      1|      if(flags0 & x86_CPUID_1_bits::RDRAND) {
  ------------------
  |  Branch (113:10): [True: 1, False: 0]
  ------------------
  114|      1|         features_detected |= CPUID::CPUID_RDRAND_BIT;
  115|      1|      }
  116|       |
  117|      1|      if((flags0 & x86_CPUID_1_bits::AVX) && (flags0 & x86_CPUID_1_bits::OSXSAVE)) {
  ------------------
  |  Branch (117:10): [True: 1, False: 0]
  |  Branch (117:46): [True: 1, False: 0]
  ------------------
  118|      1|         const uint64_t xcr_flags = xgetbv();
  119|      1|         if((xcr_flags & 0x6) == 0x6) {
  ------------------
  |  Branch (119:13): [True: 1, False: 0]
  ------------------
  120|      1|            has_os_ymm_support = true;
  121|      1|            has_os_zmm_support = (xcr_flags & 0xE0) == 0xE0;
  122|      1|         }
  123|      1|      }
  124|      1|   }
  125|       |
  126|      1|   if(max_supported_sublevel >= 7) {
  ------------------
  |  Branch (126:7): [True: 1, False: 0]
  ------------------
  127|      1|      clear_mem(cpuid, 4);
  128|      1|      invoke_cpuid_sublevel(7, 0, cpuid);
  129|       |
  130|      1|      enum x86_CPUID_7_bits : uint64_t {
  131|      1|         BMI1 = (1ULL << 3),
  132|      1|         AVX2 = (1ULL << 5),
  133|      1|         BMI2 = (1ULL << 8),
  134|      1|         AVX512_F = (1ULL << 16),
  135|      1|         AVX512_DQ = (1ULL << 17),
  136|      1|         RDSEED = (1ULL << 18),
  137|      1|         ADX = (1ULL << 19),
  138|      1|         AVX512_IFMA = (1ULL << 21),
  139|      1|         SHA = (1ULL << 29),
  140|      1|         AVX512_BW = (1ULL << 30),
  141|      1|         AVX512_VL = (1ULL << 31),
  142|      1|         AVX512_VBMI = (1ULL << 33),
  143|      1|         AVX512_VBMI2 = (1ULL << 38),
  144|      1|         AVX512_VAES = (1ULL << 41),
  145|      1|         AVX512_VCLMUL = (1ULL << 42),
  146|      1|         AVX512_VBITALG = (1ULL << 44),
  147|      1|      };
  148|       |
  149|      1|      const uint64_t flags7 = (static_cast<uint64_t>(cpuid[2]) << 32) | cpuid[1];
  150|       |
  151|      1|      if((flags7 & x86_CPUID_7_bits::AVX2) && has_os_ymm_support) {
  ------------------
  |  Branch (151:10): [True: 1, False: 0]
  |  Branch (151:47): [True: 1, False: 0]
  ------------------
  152|      1|         features_detected |= CPUID::CPUID_AVX2_BIT;
  153|      1|      }
  154|      1|      if(flags7 & x86_CPUID_7_bits::RDSEED) {
  ------------------
  |  Branch (154:10): [True: 1, False: 0]
  ------------------
  155|      1|         features_detected |= CPUID::CPUID_RDSEED_BIT;
  156|      1|      }
  157|      1|      if(flags7 & x86_CPUID_7_bits::ADX) {
  ------------------
  |  Branch (157:10): [True: 1, False: 0]
  ------------------
  158|      1|         features_detected |= CPUID::CPUID_ADX_BIT;
  159|      1|      }
  160|      1|      if(flags7 & x86_CPUID_7_bits::SHA) {
  ------------------
  |  Branch (160:10): [True: 0, False: 1]
  ------------------
  161|      0|         features_detected |= CPUID::CPUID_SHA_BIT;
  162|      0|      }
  163|       |
  164|       |      /*
  165|       |      We only set the BMI bit if both BMI1 and BMI2 are supported, since
  166|       |      typically we want to use both extensions in the same code.
  167|       |      */
  168|      1|      if((flags7 & x86_CPUID_7_bits::BMI1) && (flags7 & x86_CPUID_7_bits::BMI2)) {
  ------------------
  |  Branch (168:10): [True: 1, False: 0]
  |  Branch (168:47): [True: 1, False: 0]
  ------------------
  169|      1|         features_detected |= CPUID::CPUID_BMI_BIT;
  170|      1|      }
  171|       |
  172|      1|      if((flags7 & x86_CPUID_7_bits::AVX512_F) && has_os_zmm_support) {
  ------------------
  |  Branch (172:10): [True: 0, False: 1]
  |  Branch (172:51): [True: 0, False: 0]
  ------------------
  173|      0|         const uint64_t AVX512_PROFILE_FLAGS = x86_CPUID_7_bits::AVX512_F | x86_CPUID_7_bits::AVX512_DQ |
  174|      0|                                               x86_CPUID_7_bits::AVX512_IFMA | x86_CPUID_7_bits::AVX512_BW |
  175|      0|                                               x86_CPUID_7_bits::AVX512_VL | x86_CPUID_7_bits::AVX512_VBMI |
  176|      0|                                               x86_CPUID_7_bits::AVX512_VBMI2 | x86_CPUID_7_bits::AVX512_VBITALG;
  177|       |
  178|       |         /*
  179|       |         We only enable AVX512 support if all of the above flags are available
  180|       |
  181|       |         This is more than we strictly need for most uses, however it also has
  182|       |         the effect of preventing execution of AVX512 codepaths on cores that
  183|       |         have serious downclocking problems when AVX512 code executes,
  184|       |         especially Intel Skylake.
  185|       |
  186|       |         VBMI2/VBITALG are the key flags here as they restrict us to Intel Ice
  187|       |         Lake/Rocket Lake, or AMD Zen4, all of which do not have penalties for
  188|       |         executing AVX512.
  189|       |
  190|       |         There is nothing stopping some future processor from supporting the
  191|       |         above flags and having AVX512 penalties, but maybe you should not have
  192|       |         bought such a processor.
  193|       |         */
  194|      0|         if((flags7 & AVX512_PROFILE_FLAGS) == AVX512_PROFILE_FLAGS) {
  ------------------
  |  Branch (194:13): [True: 0, False: 0]
  ------------------
  195|      0|            features_detected |= CPUID::CPUID_AVX512_BIT;
  196|       |
  197|      0|            if(flags7 & x86_CPUID_7_bits::AVX512_VAES) {
  ------------------
  |  Branch (197:16): [True: 0, False: 0]
  ------------------
  198|      0|               features_detected |= CPUID::CPUID_AVX512_AES_BIT;
  199|      0|            }
  200|      0|            if(flags7 & x86_CPUID_7_bits::AVX512_VCLMUL) {
  ------------------
  |  Branch (200:16): [True: 0, False: 0]
  ------------------
  201|      0|               features_detected |= CPUID::CPUID_AVX512_CLMUL_BIT;
  202|      0|            }
  203|      0|         }
  204|      0|      }
  205|      1|   }
  206|       |
  207|       |   /*
  208|       |   * If we don't have access to CPUID, we can still safely assume that
  209|       |   * any x86-64 processor has SSE2 and RDTSC
  210|       |   */
  211|      1|   #if defined(BOTAN_TARGET_ARCH_IS_X86_64)
  212|      1|   if(features_detected == 0) {
  ------------------
  |  Branch (212:7): [True: 0, False: 1]
  ------------------
  213|      0|      features_detected |= CPUID::CPUID_SSE2_BIT;
  214|      0|      features_detected |= CPUID::CPUID_RDTSC_BIT;
  215|      0|   }
  216|      1|   #endif
  217|       |
  218|      1|   return features_detected;
  219|      1|}
cpuid_x86.cpp:_ZN5Botan12_GLOBAL__N_112invoke_cpuidEjPj:
   33|      2|void invoke_cpuid(uint32_t type, uint32_t out[4]) {
   34|       |   #if defined(BOTAN_BUILD_COMPILER_IS_MSVC) || defined(BOTAN_BUILD_COMPILER_IS_INTEL)
   35|       |   __cpuid((int*)out, type);
   36|       |
   37|       |   #elif defined(BOTAN_BUILD_COMPILER_IS_GCC) || defined(BOTAN_BUILD_COMPILER_IS_CLANG)
   38|      2|   __get_cpuid(type, out, out + 1, out + 2, out + 3);
   39|       |
   40|       |   #elif defined(BOTAN_USE_GCC_INLINE_ASM)
   41|       |   asm("cpuid\n\t" : "=a"(out[0]), "=b"(out[1]), "=c"(out[2]), "=d"(out[3]) : "0"(type));
   42|       |
   43|       |   #else
   44|       |      #warning "No way of calling x86 cpuid instruction for this compiler"
   45|       |   clear_mem(out, 4);
   46|       |   #endif
   47|      2|}
cpuid_x86.cpp:_ZN5Botan12_GLOBAL__N_16xgetbvEv:
   49|      1|BOTAN_FUNC_ISA("xsave") uint64_t xgetbv() {
   50|      1|   return _xgetbv(0);
   51|      1|}
cpuid_x86.cpp:_ZN5Botan12_GLOBAL__N_121invoke_cpuid_sublevelEjjPj:
   53|      1|void invoke_cpuid_sublevel(uint32_t type, uint32_t level, uint32_t out[4]) {
   54|       |   #if defined(BOTAN_BUILD_COMPILER_IS_MSVC)
   55|       |   __cpuidex((int*)out, type, level);
   56|       |
   57|       |   #elif defined(BOTAN_BUILD_COMPILER_IS_GCC) || defined(BOTAN_BUILD_COMPILER_IS_CLANG)
   58|      1|   __cpuid_count(type, level, out[0], out[1], out[2], out[3]);
   59|       |
   60|       |   #elif defined(BOTAN_USE_GCC_INLINE_ASM)
   61|       |   asm("cpuid\n\t" : "=a"(out[0]), "=b"(out[1]), "=c"(out[2]), "=d"(out[3]) : "0"(type), "2"(level));
   62|       |
   63|       |   #else
   64|       |      #warning "No way of calling x86 cpuid instruction for this compiler"
   65|       |   clear_mem(out, 4);
   66|       |   #endif
   67|      1|}

_ZN5Botan9ExceptionC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
   71|  1.36k|Exception::Exception(std::string_view msg) : m_msg(msg) {}
_ZN5Botan16Invalid_ArgumentC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
   77|    837|Invalid_Argument::Invalid_Argument(std::string_view msg) : Exception(msg) {}

_ZN5Botan19secure_scrub_memoryEPvm:
   87|  2.93M|void secure_scrub_memory(void* ptr, size_t n) {
   88|       |#if defined(BOTAN_TARGET_OS_HAS_RTLSECUREZEROMEMORY)
   89|       |   ::RtlSecureZeroMemory(ptr, n);
   90|       |
   91|       |#elif defined(BOTAN_TARGET_OS_HAS_EXPLICIT_BZERO)
   92|  2.93M|   ::explicit_bzero(ptr, n);
   93|       |
   94|       |#elif defined(BOTAN_TARGET_OS_HAS_EXPLICIT_MEMSET)
   95|       |   (void)::explicit_memset(ptr, 0, n);
   96|       |
   97|       |#elif defined(BOTAN_USE_VOLATILE_MEMSET_FOR_ZERO) && (BOTAN_USE_VOLATILE_MEMSET_FOR_ZERO == 1)
   98|       |   /*
   99|       |   Call memset through a static volatile pointer, which the compiler
  100|       |   should not elide. This construct should be safe in conforming
  101|       |   compilers, but who knows. I did confirm that on x86-64 GCC 6.1 and
  102|       |   Clang 3.8 both create code that saves the memset address in the
  103|       |   data segment and unconditionally loads and jumps to that address.
  104|       |   */
  105|       |   static void* (*const volatile memset_ptr)(void*, int, size_t) = std::memset;
  106|       |   (memset_ptr)(ptr, 0, n);
  107|       |#else
  108|       |
  109|       |   volatile uint8_t* p = reinterpret_cast<volatile uint8_t*>(ptr);
  110|       |
  111|       |   for(size_t i = 0; i != n; ++i)
  112|       |      p[i] = 0;
  113|       |#endif
  114|  2.93M|}
_ZN5Botan2OS14get_process_idEv:
  116|  91.8k|uint32_t OS::get_process_id() {
  117|  91.8k|#if defined(BOTAN_TARGET_OS_HAS_POSIX1)
  118|  91.8k|   return ::getpid();
  119|       |#elif defined(BOTAN_TARGET_OS_HAS_WIN32)
  120|       |   return ::GetCurrentProcessId();
  121|       |#elif defined(BOTAN_TARGET_OS_IS_LLVM) || defined(BOTAN_TARGET_OS_IS_NONE)
  122|       |   return 0;  // truly no meaningful value
  123|       |#else
  124|       |   #error "Missing get_process_id"
  125|       |#endif
  126|  91.8k|}
_ZN5Botan2OS10get_auxvalEm:
  128|      1|unsigned long OS::get_auxval(unsigned long id) {
  129|      1|#if defined(BOTAN_TARGET_OS_HAS_GETAUXVAL)
  130|      1|   return ::getauxval(id);
  131|       |#elif defined(BOTAN_TARGET_OS_IS_ANDROID) && defined(BOTAN_TARGET_ARCH_IS_ARM32)
  132|       |
  133|       |   if(id == 0)
  134|       |      return 0;
  135|       |
  136|       |   char** p = environ;
  137|       |
  138|       |   while(*p++ != nullptr)
  139|       |      ;
  140|       |
  141|       |   Elf32_auxv_t* e = reinterpret_cast<Elf32_auxv_t*>(p);
  142|       |
  143|       |   while(e != nullptr) {
  144|       |      if(e->a_type == id)
  145|       |         return e->a_un.a_val;
  146|       |      e++;
  147|       |   }
  148|       |
  149|       |   return 0;
  150|       |#elif defined(BOTAN_TARGET_OS_HAS_ELF_AUX_INFO)
  151|       |   unsigned long auxinfo = 0;
  152|       |   ::elf_aux_info(static_cast<int>(id), &auxinfo, sizeof(auxinfo));
  153|       |   return auxinfo;
  154|       |#elif defined(BOTAN_TARGET_OS_HAS_AUXINFO)
  155|       |   for(const AuxInfo* auxinfo = static_cast<AuxInfo*>(::_dlauxinfo()); auxinfo != AT_NULL; ++auxinfo) {
  156|       |      if(id == auxinfo->a_type)
  157|       |         return auxinfo->a_v;
  158|       |   }
  159|       |
  160|       |   return 0;
  161|       |#else
  162|       |   BOTAN_UNUSED(id);
  163|       |   return 0;
  164|       |#endif
  165|      1|}
_ZN5Botan2OS27running_in_privileged_stateEv:
  167|      1|bool OS::running_in_privileged_state() {
  168|      1|#if defined(AT_SECURE)
  169|      1|   return OS::get_auxval(AT_SECURE) != 0;
  170|       |#elif defined(BOTAN_TARGET_OS_HAS_POSIX1)
  171|       |   return (::getuid() != ::geteuid()) || (::getgid() != ::getegid());
  172|       |#else
  173|       |   return false;
  174|       |#endif
  175|      1|}
_ZN5Botan2OS17read_env_variableERNSt3__112basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEENS1_17basic_string_viewIcS4_EE:
  409|      1|bool OS::read_env_variable(std::string& value_out, std::string_view name_view) {
  410|      1|   value_out = "";
  411|       |
  412|      1|   if(running_in_privileged_state()) {
  ------------------
  |  Branch (412:7): [True: 0, False: 1]
  ------------------
  413|      0|      return false;
  414|      0|   }
  415|       |
  416|       |#if defined(BOTAN_TARGET_OS_HAS_WIN32) && defined(BOTAN_BUILD_COMPILER_IS_MSVC)
  417|       |   const std::string name(name_view);
  418|       |   char val[128] = {0};
  419|       |   size_t req_size = 0;
  420|       |   if(getenv_s(&req_size, val, sizeof(val), name.c_str()) == 0) {
  421|       |      // Microsoft's implementation always writes a terminating \0,
  422|       |      // and includes it in the reported length of the environment variable
  423|       |      // if a value exists.
  424|       |      if(req_size > 0 && val[req_size - 1] == '\0') {
  425|       |         value_out = std::string(val);
  426|       |      } else {
  427|       |         value_out = std::string(val, req_size);
  428|       |      }
  429|       |      return true;
  430|       |   }
  431|       |#else
  432|      1|   const std::string name(name_view);
  433|      1|   if(const char* val = std::getenv(name.c_str())) {
  ------------------
  |  Branch (433:19): [True: 0, False: 1]
  ------------------
  434|      0|      value_out = val;
  435|      0|      return true;
  436|      0|   }
  437|      1|#endif
  438|       |
  439|      1|   return false;
  440|      1|}

_ZN5Botan9to_u32bitENSt3__117basic_string_viewIcNS0_11char_traitsIcEEEE:
   32|      1|uint32_t to_u32bit(std::string_view str_view) {
   33|      1|   const std::string str(str_view);
   34|       |
   35|       |   // std::stoul is not strict enough. Ensure that str is digit only [0-9]*
   36|      2|   for(const char chr : str) {
  ------------------
  |  Branch (36:23): [True: 2, False: 1]
  ------------------
   37|      2|      if(chr < '0' || chr > '9') {
  ------------------
  |  Branch (37:10): [True: 0, False: 2]
  |  Branch (37:23): [True: 0, False: 2]
  ------------------
   38|      0|         throw Invalid_Argument("to_u32bit invalid decimal string '" + str + "'");
   39|      0|      }
   40|      2|   }
   41|       |
   42|      1|   const unsigned long int x = std::stoul(str);
   43|       |
   44|      1|   if constexpr(sizeof(unsigned long int) > 4) {
  ------------------
  |  Branch (44:17): [Folded - Ignored]
  ------------------
   45|       |      // x might be uint64
   46|      1|      if(x > std::numeric_limits<uint32_t>::max()) {
  ------------------
  |  Branch (46:10): [True: 0, False: 1]
  ------------------
   47|      0|         throw Invalid_Argument("Integer value of " + str + " exceeds 32 bit range");
   48|      0|      }
   49|      1|   }
   50|       |
   51|      1|   return static_cast<uint32_t>(x);
   52|      1|}

_ZN5Botan9SCAN_NameC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
   58|      2|SCAN_Name::SCAN_Name(std::string_view algo_spec) : m_orig_algo_spec(algo_spec), m_alg_name(), m_args(), m_mode_info() {
   59|      2|   if(algo_spec.empty()) {
  ------------------
  |  Branch (59:7): [True: 0, False: 2]
  ------------------
   60|      0|      throw Invalid_Argument("Expected algorithm name, got empty string");
   61|      0|   }
   62|       |
   63|      2|   std::vector<std::pair<size_t, std::string>> name;
   64|      2|   size_t level = 0;
   65|      2|   std::pair<size_t, std::string> accum = std::make_pair(level, "");
   66|       |
   67|      2|   const std::string decoding_error = "Bad SCAN name '" + m_orig_algo_spec + "': ";
   68|       |
   69|     23|   for(char c : algo_spec) {
  ------------------
  |  Branch (69:15): [True: 23, False: 2]
  ------------------
   70|     23|      if(c == '/' || c == ',' || c == '(' || c == ')') {
  ------------------
  |  Branch (70:10): [True: 0, False: 23]
  |  Branch (70:22): [True: 0, False: 23]
  |  Branch (70:34): [True: 2, False: 21]
  |  Branch (70:46): [True: 2, False: 19]
  ------------------
   71|      4|         if(c == '(') {
  ------------------
  |  Branch (71:13): [True: 2, False: 2]
  ------------------
   72|      2|            ++level;
   73|      2|         } else if(c == ')') {
  ------------------
  |  Branch (73:20): [True: 2, False: 0]
  ------------------
   74|      2|            if(level == 0) {
  ------------------
  |  Branch (74:16): [True: 0, False: 2]
  ------------------
   75|      0|               throw Decoding_Error(decoding_error + "Mismatched parens");
   76|      0|            }
   77|      2|            --level;
   78|      2|         }
   79|       |
   80|      4|         if(c == '/' && level > 0) {
  ------------------
  |  Branch (80:13): [True: 0, False: 4]
  |  Branch (80:25): [True: 0, False: 0]
  ------------------
   81|      0|            accum.second.push_back(c);
   82|      4|         } else {
   83|      4|            if(!accum.second.empty()) {
  ------------------
  |  Branch (83:16): [True: 4, False: 0]
  ------------------
   84|      4|               name.push_back(accum);
   85|      4|            }
   86|      4|            accum = std::make_pair(level, "");
   87|      4|         }
   88|     19|      } else {
   89|     19|         accum.second.push_back(c);
   90|     19|      }
   91|     23|   }
   92|       |
   93|      2|   if(!accum.second.empty()) {
  ------------------
  |  Branch (93:7): [True: 0, False: 2]
  ------------------
   94|      0|      name.push_back(accum);
   95|      0|   }
   96|       |
   97|      2|   if(level != 0) {
  ------------------
  |  Branch (97:7): [True: 0, False: 2]
  ------------------
   98|      0|      throw Decoding_Error(decoding_error + "Missing close paren");
   99|      0|   }
  100|       |
  101|      2|   if(name.empty()) {
  ------------------
  |  Branch (101:7): [True: 0, False: 2]
  ------------------
  102|      0|      throw Decoding_Error(decoding_error + "Empty name");
  103|      0|   }
  104|       |
  105|      2|   m_alg_name = name[0].second;
  106|       |
  107|      2|   bool in_modes = false;
  108|       |
  109|      4|   for(size_t i = 1; i != name.size(); ++i) {
  ------------------
  |  Branch (109:22): [True: 2, False: 2]
  ------------------
  110|      2|      if(name[i].first == 0) {
  ------------------
  |  Branch (110:10): [True: 0, False: 2]
  ------------------
  111|      0|         m_mode_info.push_back(make_arg(name, i));
  112|      0|         in_modes = true;
  113|      2|      } else if(name[i].first == 1 && !in_modes) {
  ------------------
  |  Branch (113:17): [True: 2, False: 0]
  |  Branch (113:39): [True: 2, False: 0]
  ------------------
  114|      2|         m_args.push_back(make_arg(name, i));
  115|      2|      }
  116|      2|   }
  117|      2|}
_ZNK5Botan9SCAN_Name3argEm:
  119|      1|std::string SCAN_Name::arg(size_t i) const {
  120|      1|   if(i >= arg_count()) {
  ------------------
  |  Branch (120:7): [True: 0, False: 1]
  ------------------
  121|      0|      throw Invalid_Argument("SCAN_Name::arg " + std::to_string(i) + " out of range for '" + to_string() + "'");
  122|      0|   }
  123|      1|   return m_args[i];
  124|      1|}
_ZNK5Botan9SCAN_Name14arg_as_integerEmm:
  133|      1|size_t SCAN_Name::arg_as_integer(size_t i, size_t def_value) const {
  134|      1|   if(i >= arg_count()) {
  ------------------
  |  Branch (134:7): [True: 0, False: 1]
  ------------------
  135|      0|      return def_value;
  136|      0|   }
  137|      1|   return to_u32bit(m_args[i]);
  138|      1|}
scan_name.cpp:_ZN5Botan12_GLOBAL__N_18make_argERKNSt3__16vectorINS1_4pairImNS1_12basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEEEENS7_ISA_EEEEm:
   17|      2|std::string make_arg(const std::vector<std::pair<size_t, std::string>>& name, size_t start) {
   18|      2|   std::string output = name[start].second;
   19|      2|   size_t level = name[start].first;
   20|       |
   21|      2|   size_t paren_depth = 0;
   22|       |
   23|      2|   for(size_t i = start + 1; i != name.size(); ++i) {
  ------------------
  |  Branch (23:30): [True: 0, False: 2]
  ------------------
   24|      0|      if(name[i].first <= name[start].first) {
  ------------------
  |  Branch (24:10): [True: 0, False: 0]
  ------------------
   25|      0|         break;
   26|      0|      }
   27|       |
   28|      0|      if(name[i].first > level) {
  ------------------
  |  Branch (28:10): [True: 0, False: 0]
  ------------------
   29|      0|         output += "(" + name[i].second;
   30|      0|         ++paren_depth;
   31|      0|      } else if(name[i].first < level) {
  ------------------
  |  Branch (31:17): [True: 0, False: 0]
  ------------------
   32|      0|         for(size_t j = name[i].first; j < level; j++) {
  ------------------
  |  Branch (32:40): [True: 0, False: 0]
  ------------------
   33|      0|            output += ")";
   34|      0|            --paren_depth;
   35|      0|         }
   36|      0|         output += "," + name[i].second;
   37|      0|      } else {
   38|      0|         if(output[output.size() - 1] != '(') {
  ------------------
  |  Branch (38:13): [True: 0, False: 0]
  ------------------
   39|      0|            output += ",";
   40|      0|         }
   41|      0|         output += name[i].second;
   42|      0|      }
   43|       |
   44|      0|      level = name[i].first;
   45|      0|   }
   46|       |
   47|      2|   for(size_t i = 0; i != paren_depth; ++i) {
  ------------------
  |  Branch (47:22): [True: 0, False: 2]
  ------------------
   48|      0|      output += ")";
   49|      0|   }
   50|       |
   51|      2|   return output;
   52|      2|}

