_ZN5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EED2Ev:
   65|  39.5k|      ~AlignmentBuffer() { secure_scrub_memory(m_buffer.data(), m_buffer.size()); }
_ZN5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EEC2Ev:
   63|  8.62k|      AlignmentBuffer() : m_position(0) {}
_ZN5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE5clearEv:
   72|  42.6k|      void clear() {
   73|  42.6k|         clear_mem(m_buffer.data(), m_buffer.size());
   74|  42.6k|         m_position = 0;
   75|  42.6k|      }
_ZN5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE21handle_unaligned_dataERNS_12BufferSlicerE:
  167|  50.5k|      [[nodiscard]] std::optional<std::span<const T>> handle_unaligned_data(BufferSlicer& slicer) {
  168|       |         // When the final block is to be deferred, we would need to store and
  169|       |         // hold a buffer that contains exactly one block until more data is
  170|       |         // passed or it is explicitly consumed.
  171|  50.5k|         const size_t defer = (defers_final_block()) ? 1 : 0;
  ------------------
  |  Branch (171:31): [True: 0, False: 50.5k]
  ------------------
  172|       |
  173|  50.5k|         if(in_alignment() && slicer.remaining() >= m_buffer.size() + defer) {
  ------------------
  |  Branch (173:13): [True: 19.8k, False: 30.7k]
  |  Branch (173:31): [True: 761, False: 19.0k]
  ------------------
  174|       |            // We are currently in alignment and the passed-in data source
  175|       |            // contains enough data to benefit from aligned processing.
  176|       |            // Therefore, we don't copy anything into the intermittent buffer.
  177|    761|            return std::nullopt;
  178|    761|         }
  179|       |
  180|       |         // Fill the buffer with as much input data as needed to reach alignment
  181|       |         // or until the input source is depleted.
  182|  49.8k|         const auto elements_to_consume = std::min(m_buffer.size() - m_position, slicer.remaining());
  183|  49.8k|         append(slicer.take(elements_to_consume));
  184|       |
  185|       |         // If we collected enough data, we push out one full block. When
  186|       |         // deferring the final block is enabled, we additionally check that
  187|       |         // more input data is available to continue processing a consecutive
  188|       |         // block.
  189|  49.8k|         if(ready_to_consume() && (!defers_final_block() || !slicer.empty())) {
  ------------------
  |  Branch (189:13): [True: 14.5k, False: 35.2k]
  |  Branch (189:36): [True: 14.5k, False: 0]
  |  Branch (189:61): [True: 0, False: 0]
  ------------------
  190|  14.5k|            return consume();
  191|  35.2k|         } else {
  192|  35.2k|            return std::nullopt;
  193|  35.2k|         }
  194|  49.8k|      }
_ZNK5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE18defers_final_blockEv:
  234|  80.4k|      constexpr bool defers_final_block() const {
  235|  80.4k|         return FINAL_BLOCK_STRATEGY == AlignmentBufferFinalBlock::must_be_deferred;
  236|  80.4k|      }
_ZN5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE6appendENSt3__14spanIKhLm18446744073709551615EEE:
   91|  83.8k|      void append(std::span<const T> elements) {
   92|  83.8k|         BOTAN_ASSERT_NOMSG(elements.size() <= elements_until_alignment());
  ------------------
  |  |   60|  83.8k|   do {                                                                     \
  |  |   61|  83.8k|      if(!(expr))                                                           \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 83.8k]
  |  |  ------------------
  |  |   62|  83.8k|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   63|  83.8k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (63:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   93|  83.8k|         std::copy(elements.begin(), elements.end(), m_buffer.begin() + m_position);
   94|  83.8k|         m_position += elements.size();
   95|  83.8k|      }
_ZNK5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE24elements_until_alignmentEv:
  222|   189k|      size_t elements_until_alignment() const { return m_buffer.size() - m_position; }
_ZNK5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE16ready_to_consumeEv:
  232|   174k|      bool ready_to_consume() const { return m_position == m_buffer.size(); }
_ZN5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE7consumeEv:
  201|  52.3k|      [[nodiscard]] std::span<const T> consume() {
  202|  52.3k|         BOTAN_ASSERT_NOMSG(ready_to_consume());
  ------------------
  |  |   60|  52.3k|   do {                                                                     \
  |  |   61|  52.3k|      if(!(expr))                                                           \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 52.3k]
  |  |  ------------------
  |  |   62|  52.3k|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   63|  52.3k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (63:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  203|  52.3k|         m_position = 0;
  204|  52.3k|         return m_buffer;
  205|  52.3k|      }
_ZNK5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE12in_alignmentEv:
  227|   116k|      bool in_alignment() const { return m_position == 0; }
_ZNK5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE23aligned_data_to_processERNS_12BufferSlicerE:
  127|  15.3k|      [[nodiscard]] std::tuple<std::span<const uint8_t>, size_t> aligned_data_to_process(BufferSlicer& slicer) const {
  128|  15.3k|         BOTAN_ASSERT_NOMSG(in_alignment());
  ------------------
  |  |   60|  15.3k|   do {                                                                     \
  |  |   61|  15.3k|      if(!(expr))                                                           \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 15.3k]
  |  |  ------------------
  |  |   62|  15.3k|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   63|  15.3k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (63:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  129|       |
  130|       |         // When the final block is to be deferred, the last block must not be
  131|       |         // selected for processing if there is no (unaligned) extra input data.
  132|  15.3k|         const size_t defer = (defers_final_block()) ? 1 : 0;
  ------------------
  |  Branch (132:31): [True: 0, False: 15.3k]
  ------------------
  133|  15.3k|         const size_t full_blocks_to_process = (slicer.remaining() - defer) / m_buffer.size();
  134|  15.3k|         return {slicer.take(full_blocks_to_process * m_buffer.size()), full_blocks_to_process};
  135|  15.3k|      }
_ZN5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE18fill_up_with_zerosEv:
   80|  37.8k|      void fill_up_with_zeros() {
   81|  37.8k|         if(!ready_to_consume()) {
  ------------------
  |  Branch (81:13): [True: 37.6k, False: 247]
  ------------------
   82|  37.6k|            clear_mem(&m_buffer[m_position], elements_until_alignment());
   83|  37.6k|            m_position = m_buffer.size();
   84|  37.6k|         }
   85|  37.8k|      }
_ZN5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE20directly_modify_lastEm:
  114|  34.0k|      std::span<T> directly_modify_last(size_t elements) {
  115|  34.0k|         BOTAN_ASSERT_NOMSG(size() >= elements);
  ------------------
  |  |   60|  34.0k|   do {                                                                     \
  |  |   61|  34.0k|      if(!(expr))                                                           \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 34.0k]
  |  |  ------------------
  |  |   62|  34.0k|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   63|  34.0k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (63:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  116|  34.0k|         return std::span(m_buffer).last(elements);
  117|  34.0k|      }
_ZNK5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE4sizeEv:
  218|  34.0k|      constexpr size_t size() const { return m_buffer.size(); }

_ZN5Botan10ct_is_zeroIhEET_S1_:
   35|  63.0k|{
   36|  63.0k|   return expand_top_bit<T>(~x & (x - 1));
   37|  63.0k|}
_ZN5Botan14expand_top_bitIhEET_S1_:
   25|   147k|{
   26|   147k|   return static_cast<T>(0) - (a >> (sizeof(T) * 8 - 1));
   27|   147k|}
_ZN5Botan8high_bitIjEEmT_:
   60|     88|{
   61|     88|   size_t hb = 0;
   62|       |
   63|    528|   for(size_t s = 8 * sizeof(T) / 2; s > 0; s /= 2) {
  ------------------
  |  Branch (63:38): [True: 440, False: 88]
  ------------------
   64|    440|      const size_t z = s * ((~ct_is_zero(n >> s)) & 1);
   65|    440|      hb += z;
   66|    440|      n >>= z;
   67|    440|   }
   68|       |
   69|     88|   hb += n;
   70|       |
   71|     88|   return hb;
   72|     88|}
_ZN5Botan10ct_is_zeroIjEET_S1_:
   35|    440|{
   36|    440|   return expand_top_bit<T>(~x & (x - 1));
   37|    440|}
_ZN5Botan14expand_top_bitIjEET_S1_:
   25|    440|{
   26|    440|   return static_cast<T>(0) - (a >> (sizeof(T) * 8 - 1));
   27|    440|}
_ZN5Botan10ct_is_zeroImEET_S1_:
   35|  5.55k|{
   36|  5.55k|   return expand_top_bit<T>(~x & (x - 1));
   37|  5.55k|}
_ZN5Botan14expand_top_bitImEET_S1_:
   25|  5.55k|{
   26|  5.55k|   return static_cast<T>(0) - (a >> (sizeof(T) * 8 - 1));
   27|  5.55k|}
_ZN5Botan6chooseIjEET_S1_S1_S1_:
  180|  7.21M|inline constexpr T choose(T mask, T a, T b) {
  181|       |   //return (mask & a) | (~mask & b);
  182|  7.21M|   return (b ^ (mask & (a ^ b)));
  183|  7.21M|}
_ZN5Botan8majorityIjEET_S1_S1_S1_:
  186|  3.60M|inline constexpr T majority(T a, T b, T c) {
  187|       |   /*
  188|       |   Considering each bit of a, b, c individually
  189|       |
  190|       |   If a xor b is set, then c is the deciding vote.
  191|       |
  192|       |   If a xor b is not set then either a and b are both set or both unset.
  193|       |   In either case the value of c doesn't matter, and examining b (or a)
  194|       |   allows us to determine which case we are in.
  195|       |   */
  196|  3.60M|   return choose(a ^ b, c, b);
  197|  3.60M|}
_ZN5Botan6chooseIhEET_S1_S1_S1_:
  180|   141k|inline constexpr T choose(T mask, T a, T b) {
  181|       |   //return (mask & a) | (~mask & b);
  182|   141k|   return (b ^ (mask & (a ^ b)));
  183|   141k|}
_ZN5Botan8high_bitImEEmT_:
   60|    368|{
   61|    368|   size_t hb = 0;
   62|       |
   63|  2.57k|   for(size_t s = 8 * sizeof(T) / 2; s > 0; s /= 2) {
  ------------------
  |  Branch (63:38): [True: 2.20k, False: 368]
  ------------------
   64|  2.20k|      const size_t z = s * ((~ct_is_zero(n >> s)) & 1);
   65|  2.20k|      hb += z;
   66|  2.20k|      n >>= z;
   67|  2.20k|   }
   68|       |
   69|    368|   hb += n;
   70|       |
   71|    368|   return hb;
   72|    368|}

_ZN5Botan13reverse_bytesEt:
   19|  44.4k|inline constexpr uint16_t reverse_bytes(uint16_t x) {
   20|  44.4k|#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap16)
   21|  44.4k|   return __builtin_bswap16(x);
   22|       |#else
   23|       |   return static_cast<uint16_t>((x << 8) | (x >> 8));
   24|       |#endif
   25|  44.4k|}
_ZN5Botan13reverse_bytesEj:
   33|  1.17M|inline constexpr uint32_t reverse_bytes(uint32_t x) {
   34|  1.17M|#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap32)
   35|  1.17M|   return __builtin_bswap32(x);
   36|       |#else
   37|       |   // MSVC at least recognizes this as a bswap
   38|       |   return ((x & 0x000000FF) << 24) | ((x & 0x0000FF00) << 8) | ((x & 0x00FF0000) >> 8) | ((x & 0xFF000000) >> 24);
   39|       |#endif
   40|  1.17M|}
_ZN5Botan13reverse_bytesEm:
   48|  34.3k|inline constexpr uint64_t reverse_bytes(uint64_t x) {
   49|  34.3k|#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap64)
   50|  34.3k|   return __builtin_bswap64(x);
   51|       |#else
   52|       |   uint32_t hi = static_cast<uint32_t>(x >> 32);
   53|       |   uint32_t lo = static_cast<uint32_t>(x);
   54|       |
   55|       |   hi = reverse_bytes(hi);
   56|       |   lo = reverse_bytes(lo);
   57|       |
   58|       |   return (static_cast<uint64_t>(lo) << 32) | hi;
   59|       |#endif
   60|  34.3k|}

base64.cpp:_ZN5Botan11base_decodeIRNS_12_GLOBAL__N_16Base64EEEmOT_PhPKcmRmbb:
  118|    122|                   bool ignore_ws = true) {
  119|    122|   const size_t decoding_bytes_in = base.decoding_bytes_in();
  120|    122|   const size_t decoding_bytes_out = base.decoding_bytes_out();
  121|       |
  122|    122|   uint8_t* out_ptr = output;
  123|    122|   std::vector<uint8_t> decode_buf(decoding_bytes_in, 0);
  124|    122|   size_t decode_buf_pos = 0;
  125|    122|   size_t final_truncate = 0;
  126|       |
  127|    122|   clear_mem(output, base.decode_max_output(input_length));
  128|       |
  129|  18.6k|   for(size_t i = 0; i != input_length; ++i) {
  ------------------
  |  Branch (129:22): [True: 18.5k, False: 122]
  ------------------
  130|  18.5k|      const uint8_t bin = base.lookup_binary_value(input[i]);
  131|       |
  132|       |      // This call might throw Invalid_Argument
  133|  18.5k|      if(base.check_bad_char(bin, input[i], ignore_ws)) {
  ------------------
  |  Branch (133:10): [True: 12.6k, False: 5.88k]
  ------------------
  134|  12.6k|         decode_buf[decode_buf_pos] = bin;
  135|  12.6k|         ++decode_buf_pos;
  136|  12.6k|      }
  137|       |
  138|       |      /*
  139|       |      * If we're at the end of the input, pad with 0s and truncate
  140|       |      */
  141|  18.5k|      if(final_inputs && (i == input_length - 1)) {
  ------------------
  |  Branch (141:10): [True: 18.4k, False: 26]
  |  Branch (141:26): [True: 85, False: 18.3k]
  ------------------
  142|     85|         if(decode_buf_pos) {
  ------------------
  |  Branch (142:13): [True: 48, False: 37]
  ------------------
  143|    143|            for(size_t j = decode_buf_pos; j < decoding_bytes_in; ++j) {
  ------------------
  |  Branch (143:44): [True: 95, False: 48]
  ------------------
  144|     95|               decode_buf[j] = 0;
  145|     95|            }
  146|       |
  147|     48|            final_truncate = decoding_bytes_in - decode_buf_pos;
  148|     48|            decode_buf_pos = decoding_bytes_in;
  149|     48|         }
  150|     85|      }
  151|       |
  152|  18.5k|      if(decode_buf_pos == decoding_bytes_in) {
  ------------------
  |  Branch (152:10): [True: 3.17k, False: 15.3k]
  ------------------
  153|  3.17k|         base.decode(out_ptr, decode_buf.data());
  154|       |
  155|  3.17k|         out_ptr += decoding_bytes_out;
  156|  3.17k|         decode_buf_pos = 0;
  157|  3.17k|         input_consumed = i + 1;
  158|  3.17k|      }
  159|  18.5k|   }
  160|       |
  161|    493|   while(input_consumed < input_length && base.lookup_binary_value(input[input_consumed]) == 0x80) {
  ------------------
  |  Branch (161:10): [True: 388, False: 105]
  |  Branch (161:43): [True: 371, False: 17]
  ------------------
  162|    371|      ++input_consumed;
  163|    371|   }
  164|       |
  165|    122|   size_t written = (out_ptr - output) - base.bytes_to_remove(final_truncate);
  166|       |
  167|    122|   return written;
  168|    122|}
base64.cpp:_ZN5Botan18base_decode_to_vecINSt3__16vectorIhNS_16secure_allocatorIhEEEENS_12_GLOBAL__N_16Base64EEET_OT0_PKcmb:
  183|    122|Vector base_decode_to_vec(Base&& base, const char input[], size_t input_length, bool ignore_ws) {
  184|    122|   const size_t output_length = base.decode_max_output(input_length);
  185|    122|   Vector bin(output_length);
  186|       |
  187|    122|   const size_t written = base_decode_full(base, bin.data(), input, input_length, ignore_ws);
  188|       |
  189|    122|   bin.resize(written);
  190|    122|   return bin;
  191|    122|}
base64.cpp:_ZN5Botan16base_decode_fullIRNS_12_GLOBAL__N_16Base64EEEmOT_PhPKcmb:
  171|    122|size_t base_decode_full(Base&& base, uint8_t output[], const char input[], size_t input_length, bool ignore_ws) {
  172|    122|   size_t consumed = 0;
  173|    122|   const size_t written = base_decode(base, output, input, input_length, consumed, true, ignore_ws);
  174|       |
  175|    122|   if(consumed != input_length) {
  ------------------
  |  Branch (175:7): [True: 17, False: 105]
  ------------------
  176|     17|      throw Invalid_Argument(base.name() + " decoding failed, input did not have full bytes");
  177|     17|   }
  178|       |
  179|    105|   return written;
  180|    122|}

_ZN5Botan5CPUID13has_cpuid_bitENS0_10CPUID_bitsE:
  333|   163k|      static bool has_cpuid_bit(CPUID_bits elem) {
  334|   163k|         const uint32_t elem32 = static_cast<uint32_t>(elem);
  335|   163k|         return state().has_bit(elem32);
  336|   163k|      }
_ZN5Botan5CPUID5stateEv:
  362|   163k|      static CPUID_Data& state() {
  363|   163k|         static CPUID::CPUID_Data g_cpuid;
  364|   163k|         return g_cpuid;
  365|   163k|      }
_ZNK5Botan5CPUID10CPUID_Data7has_bitEj:
  350|   163k|            bool has_bit(uint32_t bit) const { return (m_processor_features & bit) == bit; }
_ZN5Botan5CPUID8has_sse2Ev:
  208|  54.8k|      static bool has_sse2() { return has_cpuid_bit(CPUID_SSE2_BIT); }
_ZN5Botan5CPUID8has_bmi2Ev:
  240|  54.2k|      static bool has_bmi2() { return has_cpuid_bit(CPUID_BMI_BIT); }
_ZN5Botan5CPUID13has_intel_shaEv:
  255|  54.5k|      static bool has_intel_sha() { return has_sse2() && has_cpuid_bit(CPUID_SHA_BIT); }
  ------------------
  |  Branch (255:44): [True: 54.5k, False: 0]
  |  Branch (255:58): [True: 0, False: 54.5k]
  ------------------

_ZN5Botan2CT8is_equalIhEENS0_4MaskIT_EEPKS3_S6_m:
  339|  6.34k|inline CT::Mask<T> is_equal(const T x[], const T y[], size_t len) {
  340|  6.34k|   volatile T difference = 0;
  341|       |
  342|   209k|   for(size_t i = 0; i != len; ++i) {
  ------------------
  |  Branch (342:22): [True: 203k, False: 6.34k]
  ------------------
  343|   203k|      difference = difference | (x[i] ^ y[i]);
  344|   203k|   }
  345|       |
  346|  6.34k|   return CT::Mask<T>::is_zero(difference);
  347|  6.34k|}
_ZN5Botan2CT4MaskIhE7is_zeroEh:
  123|  63.0k|      static Mask<T> is_zero(T x) { return Mask<T>(ct_is_zero<T>(x)); }
_ZN5Botan2CT4MaskIhEC2Eh:
  280|   208k|      Mask(T m) : m_mask(m) {}
_ZNK5Botan2CT4MaskIhE7as_boolEv:
  272|  10.8k|      bool as_bool() const { return unpoisoned_value() != 0; }
_ZNK5Botan2CT4MaskIhE16unpoisoned_valueEv:
  263|  10.8k|      T unpoisoned_value() const {
  264|  10.8k|         T r = value();
  265|  10.8k|         CT::unpoison(r);
  266|  10.8k|         return r;
  267|  10.8k|      }
_ZNK5Botan2CT4MaskIhE5valueEv:
  277|   208k|      T value() const { return m_mask; }
_ZN5Botan2CT8unpoisonIhEEvRT_:
   64|  10.8k|inline void unpoison(T& p) {
   65|       |#if defined(BOTAN_HAS_VALGRIND)
   66|       |   VALGRIND_MAKE_MEM_DEFINED(&p, sizeof(T));
   67|       |#else
   68|  10.8k|   BOTAN_UNUSED(p);
  ------------------
  |  |  118|  10.8k|#define BOTAN_UNUSED Botan::ignore_params
  ------------------
   69|  10.8k|#endif
   70|  10.8k|}
_ZN5Botan2CT4MaskIhE3setEv:
   99|  4.45k|      static Mask<T> set() { return Mask<T>(static_cast<T>(~0)); }
_ZN5Botan2CT4MaskIhE15is_within_rangeEhhh:
  150|  56.6k|      static Mask<T> is_within_range(T v, T l, T u) {
  151|       |         //return Mask<T>::is_gte(v, l) & Mask<T>::is_lte(v, u);
  152|       |
  153|  56.6k|         const T v_lt_l = v ^ ((v ^ l) | ((v - l) ^ v));
  154|  56.6k|         const T v_gt_u = u ^ ((u ^ v) | ((u - v) ^ u));
  155|  56.6k|         const T either = v_lt_l | v_gt_u;
  156|  56.6k|         return ~Mask<T>(expand_top_bit(either));
  157|  56.6k|      }
_ZNK5Botan2CT4MaskIhEcoEv:
  213|  56.6k|      Mask<T> operator~() const { return Mask<T>(~value()); }
_ZN5Botan2CT4MaskIhE9is_any_ofEhSt16initializer_listIhE:
  159|  18.8k|      static Mask<T> is_any_of(T v, std::initializer_list<T> accepted) {
  160|  18.8k|         T accept = 0;
  161|       |
  162|  75.5k|         for(auto a : accepted) {
  ------------------
  |  Branch (162:21): [True: 75.5k, False: 18.8k]
  ------------------
  163|  75.5k|            const T diff = a ^ v;
  164|  75.5k|            const T eq_zero = ~diff & (diff - 1);
  165|  75.5k|            accept |= eq_zero;
  166|  75.5k|         }
  167|       |
  168|  18.8k|         return Mask<T>(expand_top_bit(accept));
  169|  18.8k|      }
_ZN5Botan2CT4MaskIhE5is_ltEhh:
  133|  9.04k|      static Mask<T> is_lt(T x, T y) { return Mask<T>(expand_top_bit<T>(x ^ ((x ^ y) | ((x - y) ^ x)))); }
_ZNK5Botan2CT4MaskIhE6selectEhh:
  228|   141k|      T select(T x, T y) const { return choose(value(), x, y); }
_ZN5Botan2CT8unpoisonImEEvRT_:
   64|    415|inline void unpoison(T& p) {
   65|       |#if defined(BOTAN_HAS_VALGRIND)
   66|       |   VALGRIND_MAKE_MEM_DEFINED(&p, sizeof(T));
   67|       |#else
   68|    415|   BOTAN_UNUSED(p);
  ------------------
  |  |  118|    415|#define BOTAN_UNUSED Botan::ignore_params
  ------------------
   69|    415|#endif
   70|    415|}
_ZN5Botan2CT8unpoisonIKmEEvRT_:
   64|    368|inline void unpoison(T& p) {
   65|       |#if defined(BOTAN_HAS_VALGRIND)
   66|       |   VALGRIND_MAKE_MEM_DEFINED(&p, sizeof(T));
   67|       |#else
   68|    368|   BOTAN_UNUSED(p);
  ------------------
  |  |  118|    368|#define BOTAN_UNUSED Botan::ignore_params
  ------------------
   69|    368|#endif
   70|    368|}
_ZN5Botan2CT4MaskIhE8is_equalEhh:
  128|  56.6k|      static Mask<T> is_equal(T x, T y) { return Mask<T>::is_zero(static_cast<T>(x ^ y)); }

_ZN5Botan8FE_25519C2ESt16initializer_listIiE:
   37|  1.53k|      FE_25519(std::initializer_list<int32_t> x) {
   38|  1.53k|         if(x.size() != 10) {
  ------------------
  |  Branch (38:13): [True: 0, False: 1.53k]
  ------------------
   39|      0|            throw Invalid_Argument("Invalid FE_25519 initializer list");
   40|      0|         }
   41|  1.53k|         copy_mem(m_fe, x.begin(), 10);
   42|  1.53k|      }

_ZN5Botan3fmtIJPKcNSt3__117basic_string_viewIcNS3_11char_traitsIcEEEEEEENS3_12basic_stringIcS6_NS3_9allocatorIcEEEES7_DpRKT_:
   53|    738|std::string fmt(std::string_view format, const T&... args) {
   54|    738|   std::ostringstream oss;
   55|    738|   oss.imbue(std::locale::classic());
   56|    738|   fmt_detail::do_fmt(oss, format, args...);
   57|    738|   return oss.str();
   58|    738|}
_ZN5Botan10fmt_detail6do_fmtIPKcJNSt3__117basic_string_viewIcNS4_11char_traitsIcEEEEEEEvRNS4_19basic_ostringstreamIcS7_NS4_9allocatorIcEEEES8_RKT_DpRKT0_:
   25|    738|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|    738|   size_t i = 0;
   27|       |
   28|  6.24k|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 6.24k, False: 0]
  ------------------
   29|  6.24k|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 738, False: 5.50k]
  |  Branch (29:30): [True: 738, False: 0]
  |  Branch (29:59): [True: 738, False: 0]
  ------------------
   30|    738|         oss << val;
   31|    738|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|  5.50k|      } else {
   33|  5.50k|         oss << format[i];
   34|  5.50k|      }
   35|       |
   36|  5.50k|      i += 1;
   37|  5.50k|   }
   38|    738|}
_ZN5Botan10fmt_detail6do_fmtINSt3__117basic_string_viewIcNS2_11char_traitsIcEEEEJEEEvRNS2_19basic_ostringstreamIcS5_NS2_9allocatorIcEEEES6_RKT_DpRKT0_:
   25|  3.70k|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|  3.70k|   size_t i = 0;
   27|       |
   28|  37.9k|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 37.9k, False: 0]
  ------------------
   29|  37.9k|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 3.70k, False: 34.2k]
  |  Branch (29:30): [True: 3.70k, False: 0]
  |  Branch (29:59): [True: 3.70k, False: 0]
  ------------------
   30|  3.70k|         oss << val;
   31|  3.70k|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|  34.2k|      } else {
   33|  34.2k|         oss << format[i];
   34|  34.2k|      }
   35|       |
   36|  34.2k|      i += 1;
   37|  34.2k|   }
   38|  3.70k|}
_ZN5Botan10fmt_detail6do_fmtERNSt3__119basic_ostringstreamIcNS1_11char_traitsIcEENS1_9allocatorIcEEEENS1_17basic_string_viewIcS4_EE:
   20|  5.77k|inline void do_fmt(std::ostringstream& oss, std::string_view format) {
   21|  5.77k|   oss << format;
   22|  5.77k|}
_ZN5Botan3fmtIJNSt3__117basic_string_viewIcNS1_11char_traitsIcEEEEEEENS1_12basic_stringIcS4_NS1_9allocatorIcEEEES5_DpRKT_:
   53|  2.96k|std::string fmt(std::string_view format, const T&... args) {
   54|  2.96k|   std::ostringstream oss;
   55|  2.96k|   oss.imbue(std::locale::classic());
   56|  2.96k|   fmt_detail::do_fmt(oss, format, args...);
   57|  2.96k|   return oss.str();
   58|  2.96k|}
_ZN5Botan3fmtIJNSt3__112basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEEEEES7_NS1_17basic_string_viewIcS4_EEDpRKT_:
   53|    213|std::string fmt(std::string_view format, const T&... args) {
   54|    213|   std::ostringstream oss;
   55|    213|   oss.imbue(std::locale::classic());
   56|    213|   fmt_detail::do_fmt(oss, format, args...);
   57|    213|   return oss.str();
   58|    213|}
_ZN5Botan10fmt_detail6do_fmtINSt3__112basic_stringIcNS2_11char_traitsIcEENS2_9allocatorIcEEEEJEEEvRNS2_19basic_ostringstreamIcS5_S7_EENS2_17basic_string_viewIcS5_EERKT_DpRKT0_:
   25|    213|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|    213|   size_t i = 0;
   27|       |
   28|  2.78k|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 2.78k, False: 0]
  ------------------
   29|  2.78k|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 213, False: 2.56k]
  |  Branch (29:30): [True: 213, False: 0]
  |  Branch (29:59): [True: 213, False: 0]
  ------------------
   30|    213|         oss << val;
   31|    213|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|  2.56k|      } else {
   33|  2.56k|         oss << format[i];
   34|  2.56k|      }
   35|       |
   36|  2.56k|      i += 1;
   37|  2.56k|   }
   38|    213|}
_ZN5Botan3fmtIJPKcS2_S2_EEENSt3__112basic_stringIcNS3_11char_traitsIcEENS3_9allocatorIcEEEENS3_17basic_string_viewIcS6_EEDpRKT_:
   53|     72|std::string fmt(std::string_view format, const T&... args) {
   54|     72|   std::ostringstream oss;
   55|     72|   oss.imbue(std::locale::classic());
   56|     72|   fmt_detail::do_fmt(oss, format, args...);
   57|     72|   return oss.str();
   58|     72|}
_ZN5Botan10fmt_detail6do_fmtIPKcJS3_S3_EEEvRNSt3__119basic_ostringstreamIcNS4_11char_traitsIcEENS4_9allocatorIcEEEENS4_17basic_string_viewIcS7_EERKT_DpRKT0_:
   25|     72|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|     72|   size_t i = 0;
   27|       |
   28|    352|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 352, False: 0]
  ------------------
   29|    352|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 72, False: 280]
  |  Branch (29:30): [True: 72, False: 0]
  |  Branch (29:59): [True: 72, False: 0]
  ------------------
   30|     72|         oss << val;
   31|     72|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|    280|      } else {
   33|    280|         oss << format[i];
   34|    280|      }
   35|       |
   36|    280|      i += 1;
   37|    280|   }
   38|     72|}
_ZN5Botan10fmt_detail6do_fmtIPKcJS3_EEEvRNSt3__119basic_ostringstreamIcNS4_11char_traitsIcEENS4_9allocatorIcEEEENS4_17basic_string_viewIcS7_EERKT_DpRKT0_:
   25|     72|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|     72|   size_t i = 0;
   27|       |
   28|    500|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 500, False: 0]
  ------------------
   29|    500|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 72, False: 428]
  |  Branch (29:30): [True: 72, False: 0]
  |  Branch (29:59): [True: 72, False: 0]
  ------------------
   30|     72|         oss << val;
   31|     72|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|    428|      } else {
   33|    428|         oss << format[i];
   34|    428|      }
   35|       |
   36|    428|      i += 1;
   37|    428|   }
   38|     72|}
_ZN5Botan10fmt_detail6do_fmtIPKcJEEEvRNSt3__119basic_ostringstreamIcNS4_11char_traitsIcEENS4_9allocatorIcEEEENS4_17basic_string_viewIcS7_EERKT_DpRKT0_:
   25|  1.67k|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|  1.67k|   size_t i = 0;
   27|       |
   28|  22.5k|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 22.5k, False: 0]
  ------------------
   29|  22.5k|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 1.67k, False: 20.9k]
  |  Branch (29:30): [True: 1.67k, False: 0]
  |  Branch (29:59): [True: 1.67k, False: 0]
  ------------------
   30|  1.67k|         oss << val;
   31|  1.67k|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|  20.9k|      } else {
   33|  20.9k|         oss << format[i];
   34|  20.9k|      }
   35|       |
   36|  20.9k|      i += 1;
   37|  20.9k|   }
   38|  1.67k|}
_ZN5Botan3fmtIJNSt3__117basic_string_viewIcNS1_11char_traitsIcEEEEPKcEEENS1_12basic_stringIcS4_NS1_9allocatorIcEEEES5_DpRKT_:
   53|  1.59k|std::string fmt(std::string_view format, const T&... args) {
   54|  1.59k|   std::ostringstream oss;
   55|  1.59k|   oss.imbue(std::locale::classic());
   56|  1.59k|   fmt_detail::do_fmt(oss, format, args...);
   57|  1.59k|   return oss.str();
   58|  1.59k|}
_ZN5Botan10fmt_detail6do_fmtINSt3__117basic_string_viewIcNS2_11char_traitsIcEEEEJPKcEEEvRNS2_19basic_ostringstreamIcS5_NS2_9allocatorIcEEEES6_RKT_DpRKT0_:
   25|  1.59k|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|  1.59k|   size_t i = 0;
   27|       |
   28|  1.59k|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 1.59k, False: 0]
  ------------------
   29|  1.59k|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 1.59k, False: 0]
  |  Branch (29:30): [True: 1.59k, False: 0]
  |  Branch (29:59): [True: 1.59k, False: 0]
  ------------------
   30|  1.59k|         oss << val;
   31|  1.59k|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|  1.59k|      } else {
   33|      0|         oss << format[i];
   34|      0|      }
   35|       |
   36|      0|      i += 1;
   37|      0|   }
   38|  1.59k|}
_ZN5Botan3fmtIJNSt3__117basic_string_viewIcNS1_11char_traitsIcEEEEjEEENS1_12basic_stringIcS4_NS1_9allocatorIcEEEES5_DpRKT_:
   53|    101|std::string fmt(std::string_view format, const T&... args) {
   54|    101|   std::ostringstream oss;
   55|    101|   oss.imbue(std::locale::classic());
   56|    101|   fmt_detail::do_fmt(oss, format, args...);
   57|    101|   return oss.str();
   58|    101|}
_ZN5Botan10fmt_detail6do_fmtINSt3__117basic_string_viewIcNS2_11char_traitsIcEEEEJjEEEvRNS2_19basic_ostringstreamIcS5_NS2_9allocatorIcEEEES6_RKT_DpRKT0_:
   25|    101|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|    101|   size_t i = 0;
   27|       |
   28|    101|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 101, False: 0]
  ------------------
   29|    101|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 101, False: 0]
  |  Branch (29:30): [True: 101, False: 0]
  |  Branch (29:59): [True: 101, False: 0]
  ------------------
   30|    101|         oss << val;
   31|    101|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|    101|      } else {
   33|      0|         oss << format[i];
   34|      0|      }
   35|       |
   36|      0|      i += 1;
   37|      0|   }
   38|    101|}
_ZN5Botan10fmt_detail6do_fmtIjJEEEvRNSt3__119basic_ostringstreamIcNS2_11char_traitsIcEENS2_9allocatorIcEEEENS2_17basic_string_viewIcS5_EERKT_DpRKT0_:
   25|    184|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|    184|   size_t i = 0;
   27|       |
   28|  3.12k|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 3.12k, False: 0]
  ------------------
   29|  3.12k|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 184, False: 2.94k]
  |  Branch (29:30): [True: 184, False: 0]
  |  Branch (29:59): [True: 184, False: 0]
  ------------------
   30|    184|         oss << val;
   31|    184|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|  2.94k|      } else {
   33|  2.94k|         oss << format[i];
   34|  2.94k|      }
   35|       |
   36|  2.94k|      i += 1;
   37|  2.94k|   }
   38|    184|}
_ZN5Botan3fmtIJjEEENSt3__112basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEENS1_17basic_string_viewIcS4_EEDpRKT_:
   53|     83|std::string fmt(std::string_view format, const T&... args) {
   54|     83|   std::ostringstream oss;
   55|     83|   oss.imbue(std::locale::classic());
   56|     83|   fmt_detail::do_fmt(oss, format, args...);
   57|     83|   return oss.str();
   58|     83|}
_ZN5Botan3fmtIJmPKcEEENSt3__112basic_stringIcNS3_11char_traitsIcEENS3_9allocatorIcEEEENS3_17basic_string_viewIcS6_EEDpRKT_:
   53|      3|std::string fmt(std::string_view format, const T&... args) {
   54|      3|   std::ostringstream oss;
   55|      3|   oss.imbue(std::locale::classic());
   56|      3|   fmt_detail::do_fmt(oss, format, args...);
   57|      3|   return oss.str();
   58|      3|}
_ZN5Botan10fmt_detail6do_fmtImJPKcEEEvRNSt3__119basic_ostringstreamIcNS4_11char_traitsIcEENS4_9allocatorIcEEEENS4_17basic_string_viewIcS7_EERKT_DpRKT0_:
   25|      3|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|      3|   size_t i = 0;
   27|       |
   28|     42|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 42, False: 0]
  ------------------
   29|     42|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 3, False: 39]
  |  Branch (29:30): [True: 3, False: 0]
  |  Branch (29:59): [True: 3, False: 0]
  ------------------
   30|      3|         oss << val;
   31|      3|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|     39|      } else {
   33|     39|         oss << format[i];
   34|     39|      }
   35|       |
   36|     39|      i += 1;
   37|     39|   }
   38|      3|}

_ZN5Botan11make_uint16Ehh:
   50|   224k|inline constexpr uint16_t make_uint16(uint8_t i0, uint8_t i1) {
   51|   224k|   return static_cast<uint16_t>((static_cast<uint16_t>(i0) << 8) | i1);
   52|   224k|}
_ZN5Botan11make_uint32Ehhhh:
   62|  40.6k|inline constexpr uint32_t make_uint32(uint8_t i0, uint8_t i1, uint8_t i2, uint8_t i3) {
   63|  40.6k|   return ((static_cast<uint32_t>(i0) << 24) | (static_cast<uint32_t>(i1) << 16) | (static_cast<uint32_t>(i2) << 8) |
   64|  40.6k|           (static_cast<uint32_t>(i3)));
   65|  40.6k|}
_ZN5Botan7load_beIhEET_PKhm:
  226|  3.63M|inline constexpr T load_be(const uint8_t in[], size_t off) {
  227|       |   // asserts that *in points to the correct amount of memory
  228|  3.63M|   return load_be<T>(std::span<const uint8_t, sizeof(T)>(in + off * sizeof(T), sizeof(T)));
  229|  3.63M|}
_ZN5Botan7load_beIhNSt3__14spanIKhLm1EEEEET_OT0_:
   92|  3.63M|inline constexpr T load_be(InR&& in_range) {
   93|  3.63M|   ranges::assert_exact_byte_length<sizeof(T)>(in_range);
   94|  3.63M|   std::span in{in_range};
   95|  3.63M|   if constexpr(sizeof(T) == 1) {
  ------------------
  |  Branch (95:17): [Folded - Ignored]
  ------------------
   96|  3.63M|      return static_cast<T>(in[0]);
   97|  3.63M|   } else {
   98|       |#if defined(BOTAN_TARGET_CPU_IS_BIG_ENDIAN)
   99|       |      return typecast_copy<T>(in);
  100|       |#elif defined(BOTAN_TARGET_CPU_IS_LITTLE_ENDIAN)
  101|  3.63M|      return reverse_bytes(typecast_copy<T>(in));
  102|       |#else
  103|       |      return [&]<size_t... i>(std::index_sequence<i...>) {
  104|       |         return ((static_cast<T>(in[i]) << ((sizeof(T) - i - 1) * 8)) | ...);
  105|       |      }
  106|       |      (std::make_index_sequence<sizeof(T)>());
  107|       |#endif
  108|  3.63M|   }
  109|  3.63M|}
_ZN5Botan12get_byte_varImEEhmT_:
   27|    202|inline constexpr uint8_t get_byte_var(size_t byte_num, T input) {
   28|    202|   return static_cast<uint8_t>(input >> (((~byte_num) & (sizeof(T) - 1)) << 3));
   29|    202|}
_ZN5Botan8store_beIjEEvT_Ph:
  408|   271k|inline constexpr void store_be(T in, uint8_t out[sizeof(T)]) {
  409|   271k|   store_be(in, std::span<uint8_t, sizeof(T)>(out, sizeof(T)));
  410|   271k|}
_ZN5Botan8store_beIjNSt3__14spanIhLm4EEEEEvT_OT0_:
  358|   271k|inline constexpr void store_be(T in, OutR&& out_range) {
  359|   271k|   ranges::assert_exact_byte_length<sizeof(T)>(out_range);
  360|   271k|   std::span out{out_range};
  361|   271k|   if constexpr(sizeof(T) == 1) {
  ------------------
  |  Branch (361:17): [Folded - Ignored]
  ------------------
  362|   271k|      out[0] = static_cast<uint8_t>(in);
  363|   271k|   } else {
  364|       |#if defined(BOTAN_TARGET_CPU_IS_BIG_ENDIAN)
  365|       |      typecast_copy(out, in);
  366|       |#elif defined(BOTAN_TARGET_CPU_IS_LITTLE_ENDIAN)
  367|   271k|      typecast_copy(out, reverse_bytes(in));
  368|       |#else
  369|       |      [&]<size_t... i>(std::index_sequence<i...>) {
  370|       |         ((out[i] = get_byte<i>(in)), ...);
  371|       |      }
  372|       |      (std::make_index_sequence<sizeof(T)>());
  373|       |#endif
  374|   271k|   }
  375|   271k|}
_ZN5Botan7load_beItEET_PKhm:
  226|  44.4k|inline constexpr T load_be(const uint8_t in[], size_t off) {
  227|       |   // asserts that *in points to the correct amount of memory
  228|  44.4k|   return load_be<T>(std::span<const uint8_t, sizeof(T)>(in + off * sizeof(T), sizeof(T)));
  229|  44.4k|}
_ZN5Botan7load_beItNSt3__14spanIKhLm2EEEEET_OT0_:
   92|  44.4k|inline constexpr T load_be(InR&& in_range) {
   93|  44.4k|   ranges::assert_exact_byte_length<sizeof(T)>(in_range);
   94|  44.4k|   std::span in{in_range};
   95|  44.4k|   if constexpr(sizeof(T) == 1) {
  ------------------
  |  Branch (95:17): [Folded - Ignored]
  ------------------
   96|  44.4k|      return static_cast<T>(in[0]);
   97|  44.4k|   } else {
   98|       |#if defined(BOTAN_TARGET_CPU_IS_BIG_ENDIAN)
   99|       |      return typecast_copy<T>(in);
  100|       |#elif defined(BOTAN_TARGET_CPU_IS_LITTLE_ENDIAN)
  101|  44.4k|      return reverse_bytes(typecast_copy<T>(in));
  102|       |#else
  103|       |      return [&]<size_t... i>(std::index_sequence<i...>) {
  104|       |         return ((static_cast<T>(in[i]) << ((sizeof(T) - i - 1) * 8)) | ...);
  105|       |      }
  106|       |      (std::make_index_sequence<sizeof(T)>());
  107|       |#endif
  108|  44.4k|   }
  109|  44.4k|}
_ZN5Botan8store_beImEEvT_Ph:
  408|  34.0k|inline constexpr void store_be(T in, uint8_t out[sizeof(T)]) {
  409|  34.0k|   store_be(in, std::span<uint8_t, sizeof(T)>(out, sizeof(T)));
  410|  34.0k|}
_ZN5Botan8store_beImNSt3__14spanIhLm8EEEEEvT_OT0_:
  358|  34.0k|inline constexpr void store_be(T in, OutR&& out_range) {
  359|  34.0k|   ranges::assert_exact_byte_length<sizeof(T)>(out_range);
  360|  34.0k|   std::span out{out_range};
  361|  34.0k|   if constexpr(sizeof(T) == 1) {
  ------------------
  |  Branch (361:17): [Folded - Ignored]
  ------------------
  362|  34.0k|      out[0] = static_cast<uint8_t>(in);
  363|  34.0k|   } else {
  364|       |#if defined(BOTAN_TARGET_CPU_IS_BIG_ENDIAN)
  365|       |      typecast_copy(out, in);
  366|       |#elif defined(BOTAN_TARGET_CPU_IS_LITTLE_ENDIAN)
  367|  34.0k|      typecast_copy(out, reverse_bytes(in));
  368|       |#else
  369|       |      [&]<size_t... i>(std::index_sequence<i...>) {
  370|       |         ((out[i] = get_byte<i>(in)), ...);
  371|       |      }
  372|       |      (std::make_index_sequence<sizeof(T)>());
  373|       |#endif
  374|  34.0k|   }
  375|  34.0k|}
_ZN5Botan7load_beImEET_PKhm:
  226|    294|inline constexpr T load_be(const uint8_t in[], size_t off) {
  227|       |   // asserts that *in points to the correct amount of memory
  228|    294|   return load_be<T>(std::span<const uint8_t, sizeof(T)>(in + off * sizeof(T), sizeof(T)));
  229|    294|}
_ZN5Botan7load_beImNSt3__14spanIKhLm8EEEEET_OT0_:
   92|    294|inline constexpr T load_be(InR&& in_range) {
   93|    294|   ranges::assert_exact_byte_length<sizeof(T)>(in_range);
   94|    294|   std::span in{in_range};
   95|    294|   if constexpr(sizeof(T) == 1) {
  ------------------
  |  Branch (95:17): [Folded - Ignored]
  ------------------
   96|    294|      return static_cast<T>(in[0]);
   97|    294|   } else {
   98|       |#if defined(BOTAN_TARGET_CPU_IS_BIG_ENDIAN)
   99|       |      return typecast_copy<T>(in);
  100|       |#elif defined(BOTAN_TARGET_CPU_IS_LITTLE_ENDIAN)
  101|    294|      return reverse_bytes(typecast_copy<T>(in));
  102|       |#else
  103|       |      return [&]<size_t... i>(std::index_sequence<i...>) {
  104|       |         return ((static_cast<T>(in[i]) << ((sizeof(T) - i - 1) * 8)) | ...);
  105|       |      }
  106|       |      (std::make_index_sequence<sizeof(T)>());
  107|       |#endif
  108|    294|   }
  109|    294|}
_ZN5Botan7load_beIjEET_PKhm:
  226|   901k|inline constexpr T load_be(const uint8_t in[], size_t off) {
  227|       |   // asserts that *in points to the correct amount of memory
  228|   901k|   return load_be<T>(std::span<const uint8_t, sizeof(T)>(in + off * sizeof(T), sizeof(T)));
  229|   901k|}
_ZN5Botan7load_beIjNSt3__14spanIKhLm4EEEEET_OT0_:
   92|   901k|inline constexpr T load_be(InR&& in_range) {
   93|   901k|   ranges::assert_exact_byte_length<sizeof(T)>(in_range);
   94|   901k|   std::span in{in_range};
   95|   901k|   if constexpr(sizeof(T) == 1) {
  ------------------
  |  Branch (95:17): [Folded - Ignored]
  ------------------
   96|   901k|      return static_cast<T>(in[0]);
   97|   901k|   } else {
   98|       |#if defined(BOTAN_TARGET_CPU_IS_BIG_ENDIAN)
   99|       |      return typecast_copy<T>(in);
  100|       |#elif defined(BOTAN_TARGET_CPU_IS_LITTLE_ENDIAN)
  101|   901k|      return reverse_bytes(typecast_copy<T>(in));
  102|       |#else
  103|       |      return [&]<size_t... i>(std::index_sequence<i...>) {
  104|       |         return ((static_cast<T>(in[i]) << ((sizeof(T) - i - 1) * 8)) | ...);
  105|       |      }
  106|       |      (std::make_index_sequence<sizeof(T)>());
  107|       |#endif
  108|   901k|   }
  109|   901k|}
_ZN5Botan8get_byteILm0EmEEhT0_:
   39|  1.77k|{
   40|  1.77k|   const size_t shift = ((~B) & (sizeof(T) - 1)) << 3;
   41|  1.77k|   return static_cast<uint8_t>((input >> shift) & 0xFF);
   42|  1.77k|}
_ZN5Botan15copy_out_vec_beIjNS_16secure_allocatorIjEEEEvPhmRKNSt3__16vectorIT_T0_EE:
  521|  34.0k|void copy_out_vec_be(uint8_t out[], size_t out_bytes, const std::vector<T, Alloc>& in) {
  522|  34.0k|   copy_out_be(out, out_bytes, in.data());
  523|  34.0k|}
_ZN5Botan11copy_out_beIjEEvPhmPKT_:
  507|  34.0k|void copy_out_be(uint8_t out[], size_t out_bytes, const T in[]) {
  508|   305k|   while(out_bytes >= sizeof(T)) {
  ------------------
  |  Branch (508:10): [True: 271k, False: 34.0k]
  ------------------
  509|   271k|      store_be(in[0], out);
  510|   271k|      out += sizeof(T);
  511|   271k|      out_bytes -= sizeof(T);
  512|   271k|      in += 1;
  513|   271k|   }
  514|       |
  515|  34.0k|   for(size_t i = 0; i != out_bytes; ++i) {
  ------------------
  |  Branch (515:22): [True: 0, False: 34.0k]
  ------------------
  516|      0|      out[i] = get_byte_var(i % 8, in[0]);
  517|      0|   }
  518|  34.0k|}

_ZN5Botan18MerkleDamgard_HashINS_5SHA_1EEC2Ev:
   42|    174|      MerkleDamgard_Hash() { clear(); }
_ZN5Botan18MerkleDamgard_HashINS_5SHA_1EE5clearEv:
   70|    348|      void clear() {
   71|    348|         MD::init(m_digest);
   72|    348|         m_buffer.clear();
   73|    348|         m_count = 0;
   74|    348|      }
_ZN5Botan18MerkleDamgard_HashINS_7SHA_256EEC2Ev:
   42|  8.45k|      MerkleDamgard_Hash() { clear(); }
_ZN5Botan18MerkleDamgard_HashINS_7SHA_256EE5clearEv:
   70|  42.3k|      void clear() {
   71|  42.3k|         MD::init(m_digest);
   72|  42.3k|         m_buffer.clear();
   73|  42.3k|         m_count = 0;
   74|  42.3k|      }
_ZN5Botan18MerkleDamgard_HashINS_5SHA_1EE6updateENSt3__14spanIKhLm18446744073709551615EEE:
   44|    174|      void update(std::span<const uint8_t> input) {
   45|    174|         BufferSlicer in(input);
   46|       |
   47|    430|         while(!in.empty()) {
  ------------------
  |  Branch (47:16): [True: 256, False: 174]
  ------------------
   48|    256|            if(const auto one_block = m_buffer.handle_unaligned_data(in)) {
  ------------------
  |  Branch (48:27): [True: 0, False: 256]
  ------------------
   49|      0|               MD::compress_n(m_digest, one_block.value(), 1);
   50|      0|            }
   51|       |
   52|    256|            if(m_buffer.in_alignment()) {
  ------------------
  |  Branch (52:16): [True: 87, False: 169]
  ------------------
   53|     87|               const auto [aligned_data, full_blocks] = m_buffer.aligned_data_to_process(in);
   54|     87|               if(full_blocks > 0) {
  ------------------
  |  Branch (54:19): [True: 87, False: 0]
  ------------------
   55|     87|                  MD::compress_n(m_digest, aligned_data, full_blocks);
   56|     87|               }
   57|     87|            }
   58|    256|         }
   59|       |
   60|    174|         m_count += input.size();
   61|    174|      }
_ZN5Botan18MerkleDamgard_HashINS_5SHA_1EE5finalENSt3__14spanIhLm18446744073709551615EEE:
   63|    174|      void final(std::span<uint8_t> output) {
   64|    174|         append_padding_bit();
   65|    174|         append_counter_and_finalize();
   66|    174|         copy_output(output);
   67|    174|         clear();
   68|    174|      }
_ZN5Botan18MerkleDamgard_HashINS_5SHA_1EE18append_padding_bitEv:
   77|    174|      void append_padding_bit() {
   78|    174|         BOTAN_ASSERT_NOMSG(!m_buffer.ready_to_consume());
  ------------------
  |  |   60|    174|   do {                                                                     \
  |  |   61|    174|      if(!(expr))                                                           \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 174]
  |  |  ------------------
  |  |   62|    174|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   63|    174|   } while(0)
  |  |  ------------------
  |  |  |  Branch (63:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   79|    174|         if constexpr(MD::bit_endianness == MD_Endian::Big) {
  ------------------
  |  Branch (79:23): [Folded - Ignored]
  ------------------
   80|    174|            const uint8_t final_byte = 0x80;
   81|    174|            m_buffer.append({&final_byte, 1});
   82|    174|         } else {
   83|    174|            const uint8_t final_byte = 0x01;
   84|    174|            m_buffer.append({&final_byte, 1});
   85|    174|         }
   86|    174|      }
_ZN5Botan18MerkleDamgard_HashINS_5SHA_1EE27append_counter_and_finalizeEv:
   88|    174|      void append_counter_and_finalize() {
   89|       |         // Compress the remaining data if the final data block does not provide
   90|       |         // enough space for the counter bytes.
   91|    174|         if(m_buffer.elements_until_alignment() < MD::ctr_bytes) {
  ------------------
  |  Branch (91:13): [True: 0, False: 174]
  ------------------
   92|      0|            m_buffer.fill_up_with_zeros();
   93|      0|            MD::compress_n(m_digest, m_buffer.consume(), 1);
   94|      0|         }
   95|       |
   96|       |         // Make sure that any remaining bytes in the very last block are zero.
   97|    174|         BOTAN_ASSERT_NOMSG(m_buffer.elements_until_alignment() >= MD::ctr_bytes);
  ------------------
  |  |   60|    174|   do {                                                                     \
  |  |   61|    174|      if(!(expr))                                                           \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 174]
  |  |  ------------------
  |  |   62|    174|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   63|    174|   } while(0)
  |  |  ------------------
  |  |  |  Branch (63:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   98|    174|         m_buffer.fill_up_with_zeros();
   99|       |
  100|       |         // Replace a bunch of the right-most zero-padding with the counter bytes.
  101|    174|         const uint64_t bit_count = m_count * 8;
  102|    174|         auto last_bytes = m_buffer.directly_modify_last(sizeof(bit_count));
  103|    174|         if constexpr(MD::byte_endianness == MD_Endian::Big) {
  ------------------
  |  Branch (103:23): [Folded - Ignored]
  ------------------
  104|    174|            store_be(bit_count, last_bytes.data());
  105|    174|         } else {
  106|    174|            store_le(bit_count, last_bytes.data());
  107|    174|         }
  108|       |
  109|       |         // Compress the very last block.
  110|    174|         MD::compress_n(m_digest, m_buffer.consume(), 1);
  111|    174|      }
_ZN5Botan18MerkleDamgard_HashINS_5SHA_1EE11copy_outputENSt3__14spanIhLm18446744073709551615EEE:
  113|    174|      void copy_output(std::span<uint8_t> output) {
  114|    174|         BOTAN_ASSERT_NOMSG(output.size() >= MD::output_bytes);
  ------------------
  |  |   60|    174|   do {                                                                     \
  |  |   61|    174|      if(!(expr))                                                           \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 174]
  |  |  ------------------
  |  |   62|    174|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   63|    174|   } while(0)
  |  |  ------------------
  |  |  |  Branch (63:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  115|       |
  116|    174|         if constexpr(MD::byte_endianness == MD_Endian::Big) {
  ------------------
  |  Branch (116:23): [Folded - Ignored]
  ------------------
  117|    174|            copy_out_vec_be(output.data(), MD::output_bytes, m_digest);
  118|    174|         } else {
  119|    174|            copy_out_vec_le(output.data(), MD::output_bytes, m_digest);
  120|    174|         }
  121|    174|      }
_ZN5Botan18MerkleDamgard_HashINS_7SHA_256EE6updateENSt3__14spanIKhLm18446744073709551615EEE:
   44|  36.5k|      void update(std::span<const uint8_t> input) {
   45|  36.5k|         BufferSlicer in(input);
   46|       |
   47|  86.8k|         while(!in.empty()) {
  ------------------
  |  Branch (47:16): [True: 50.3k, False: 36.5k]
  ------------------
   48|  50.3k|            if(const auto one_block = m_buffer.handle_unaligned_data(in)) {
  ------------------
  |  Branch (48:27): [True: 14.5k, False: 35.7k]
  ------------------
   49|  14.5k|               MD::compress_n(m_digest, one_block.value(), 1);
   50|  14.5k|            }
   51|       |
   52|  50.3k|            if(m_buffer.in_alignment()) {
  ------------------
  |  Branch (52:16): [True: 15.2k, False: 35.1k]
  ------------------
   53|  15.2k|               const auto [aligned_data, full_blocks] = m_buffer.aligned_data_to_process(in);
   54|  15.2k|               if(full_blocks > 0) {
  ------------------
  |  Branch (54:19): [True: 2.07k, False: 13.1k]
  ------------------
   55|  2.07k|                  MD::compress_n(m_digest, aligned_data, full_blocks);
   56|  2.07k|               }
   57|  15.2k|            }
   58|  50.3k|         }
   59|       |
   60|  36.5k|         m_count += input.size();
   61|  36.5k|      }
_ZN5Botan18MerkleDamgard_HashINS_7SHA_256EE5finalENSt3__14spanIhLm18446744073709551615EEE:
   63|  33.8k|      void final(std::span<uint8_t> output) {
   64|  33.8k|         append_padding_bit();
   65|  33.8k|         append_counter_and_finalize();
   66|  33.8k|         copy_output(output);
   67|  33.8k|         clear();
   68|  33.8k|      }
_ZN5Botan18MerkleDamgard_HashINS_7SHA_256EE18append_padding_bitEv:
   77|  33.8k|      void append_padding_bit() {
   78|  33.8k|         BOTAN_ASSERT_NOMSG(!m_buffer.ready_to_consume());
  ------------------
  |  |   60|  33.8k|   do {                                                                     \
  |  |   61|  33.8k|      if(!(expr))                                                           \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 33.8k]
  |  |  ------------------
  |  |   62|  33.8k|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   63|  33.8k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (63:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   79|  33.8k|         if constexpr(MD::bit_endianness == MD_Endian::Big) {
  ------------------
  |  Branch (79:23): [Folded - Ignored]
  ------------------
   80|  33.8k|            const uint8_t final_byte = 0x80;
   81|  33.8k|            m_buffer.append({&final_byte, 1});
   82|  33.8k|         } else {
   83|  33.8k|            const uint8_t final_byte = 0x01;
   84|  33.8k|            m_buffer.append({&final_byte, 1});
   85|  33.8k|         }
   86|  33.8k|      }
_ZN5Botan18MerkleDamgard_HashINS_7SHA_256EE27append_counter_and_finalizeEv:
   88|  33.8k|      void append_counter_and_finalize() {
   89|       |         // Compress the remaining data if the final data block does not provide
   90|       |         // enough space for the counter bytes.
   91|  33.8k|         if(m_buffer.elements_until_alignment() < MD::ctr_bytes) {
  ------------------
  |  Branch (91:13): [True: 3.80k, False: 30.0k]
  ------------------
   92|  3.80k|            m_buffer.fill_up_with_zeros();
   93|  3.80k|            MD::compress_n(m_digest, m_buffer.consume(), 1);
   94|  3.80k|         }
   95|       |
   96|       |         // Make sure that any remaining bytes in the very last block are zero.
   97|  33.8k|         BOTAN_ASSERT_NOMSG(m_buffer.elements_until_alignment() >= MD::ctr_bytes);
  ------------------
  |  |   60|  33.8k|   do {                                                                     \
  |  |   61|  33.8k|      if(!(expr))                                                           \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 33.8k]
  |  |  ------------------
  |  |   62|  33.8k|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   63|  33.8k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (63:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   98|  33.8k|         m_buffer.fill_up_with_zeros();
   99|       |
  100|       |         // Replace a bunch of the right-most zero-padding with the counter bytes.
  101|  33.8k|         const uint64_t bit_count = m_count * 8;
  102|  33.8k|         auto last_bytes = m_buffer.directly_modify_last(sizeof(bit_count));
  103|  33.8k|         if constexpr(MD::byte_endianness == MD_Endian::Big) {
  ------------------
  |  Branch (103:23): [Folded - Ignored]
  ------------------
  104|  33.8k|            store_be(bit_count, last_bytes.data());
  105|  33.8k|         } else {
  106|  33.8k|            store_le(bit_count, last_bytes.data());
  107|  33.8k|         }
  108|       |
  109|       |         // Compress the very last block.
  110|  33.8k|         MD::compress_n(m_digest, m_buffer.consume(), 1);
  111|  33.8k|      }
_ZN5Botan18MerkleDamgard_HashINS_7SHA_256EE11copy_outputENSt3__14spanIhLm18446744073709551615EEE:
  113|  33.8k|      void copy_output(std::span<uint8_t> output) {
  114|  33.8k|         BOTAN_ASSERT_NOMSG(output.size() >= MD::output_bytes);
  ------------------
  |  |   60|  33.8k|   do {                                                                     \
  |  |   61|  33.8k|      if(!(expr))                                                           \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 33.8k]
  |  |  ------------------
  |  |   62|  33.8k|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   63|  33.8k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (63:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  115|       |
  116|  33.8k|         if constexpr(MD::byte_endianness == MD_Endian::Big) {
  ------------------
  |  Branch (116:23): [Folded - Ignored]
  ------------------
  117|  33.8k|            copy_out_vec_be(output.data(), MD::output_bytes, m_digest);
  118|  33.8k|         } else {
  119|  33.8k|            copy_out_vec_le(output.data(), MD::output_bytes, m_digest);
  120|  33.8k|         }
  121|  33.8k|      }

_ZN5Botan4rotrILm18EjEET0_S1_:
   35|  3.60M|{
   36|  3.60M|   return static_cast<T>((input >> ROT) | (input << (8 * sizeof(T) - ROT)));
   37|  3.60M|}
_ZN5Botan4rotrILm6EjEET0_S1_:
   35|  3.60M|{
   36|  3.60M|   return static_cast<T>((input >> ROT) | (input << (8 * sizeof(T) - ROT)));
   37|  3.60M|}
_ZN5Botan4rotlILm5EjEET0_S1_:
   23|  20.8k|{
   24|  20.8k|   return static_cast<T>((input << ROT) | (input >> (8 * sizeof(T) - ROT)));
   25|  20.8k|}
_ZN5Botan4rotrILm2EjEET0_S1_:
   35|  3.60M|{
   36|  3.60M|   return static_cast<T>((input >> ROT) | (input << (8 * sizeof(T) - ROT)));
   37|  3.60M|}
_ZN5Botan4rotrILm22EjEET0_S1_:
   35|  3.60M|{
   36|  3.60M|   return static_cast<T>((input >> ROT) | (input << (8 * sizeof(T) - ROT)));
   37|  3.60M|}
_ZN5Botan4rotrILm7EjEET0_S1_:
   35|  3.60M|{
   36|  3.60M|   return static_cast<T>((input >> ROT) | (input << (8 * sizeof(T) - ROT)));
   37|  3.60M|}
_ZN5Botan4rotrILm13EjEET0_S1_:
   35|  3.60M|{
   36|  3.60M|   return static_cast<T>((input >> ROT) | (input << (8 * sizeof(T) - ROT)));
   37|  3.60M|}
_ZN5Botan3rhoILm2ELm13ELm22EjEET2_S1_:
   51|  3.60M|inline constexpr T rho(T x) {
   52|  3.60M|   return rotr<R1>(x) ^ rotr<R2>(x) ^ rotr<R3>(x);
   53|  3.60M|}
_ZN5Botan3rhoILm6ELm11ELm25EjEET2_S1_:
   51|  3.60M|inline constexpr T rho(T x) {
   52|  3.60M|   return rotr<R1>(x) ^ rotr<R2>(x) ^ rotr<R3>(x);
   53|  3.60M|}
_ZN5Botan4rotrILm11EjEET0_S1_:
   35|  3.60M|{
   36|  3.60M|   return static_cast<T>((input >> ROT) | (input << (8 * sizeof(T) - ROT)));
   37|  3.60M|}
_ZN5Botan4rotrILm25EjEET0_S1_:
   35|  3.60M|{
   36|  3.60M|   return static_cast<T>((input >> ROT) | (input << (8 * sizeof(T) - ROT)));
   37|  3.60M|}
_ZN5Botan5sigmaILm7ELm18ELm3EjEET2_S1_:
   43|  3.60M|inline constexpr T sigma(T x) {
   44|  3.60M|   return rotr<R1>(x) ^ rotr<R2>(x) ^ (x >> S);
   45|  3.60M|}
_ZN5Botan5sigmaILm17ELm19ELm10EjEET2_S1_:
   43|  3.60M|inline constexpr T sigma(T x) {
   44|  3.60M|   return rotr<R1>(x) ^ rotr<R2>(x) ^ (x >> S);
   45|  3.60M|}
_ZN5Botan4rotrILm17EjEET0_S1_:
   35|  3.60M|{
   36|  3.60M|   return static_cast<T>((input >> ROT) | (input << (8 * sizeof(T) - ROT)));
   37|  3.60M|}
_ZN5Botan4rotrILm19EjEET0_S1_:
   35|  3.60M|{
   36|  3.60M|   return static_cast<T>((input >> ROT) | (input << (8 * sizeof(T) - ROT)));
   37|  3.60M|}
_ZN5Botan4rotlILm30EjEET0_S1_:
   23|  20.8k|{
   24|  20.8k|   return static_cast<T>((input << ROT) | (input >> (8 * sizeof(T) - ROT)));
   25|  20.8k|}

_ZN5Botan8round_upEmm:
   21|  1.06k|inline size_t round_up(size_t n, size_t align_to) {
   22|  1.06k|   BOTAN_ARG_CHECK(align_to != 0, "align_to must not be 0");
  ------------------
  |  |   30|  1.06k|   do {                                                          \
  |  |   31|  1.06k|      if(!(expr))                                                \
  |  |  ------------------
  |  |  |  Branch (31:10): [True: 0, False: 1.06k]
  |  |  ------------------
  |  |   32|  1.06k|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   33|  1.06k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (33:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   23|       |
   24|  1.06k|   if(n % align_to) {
  ------------------
  |  Branch (24:7): [True: 894, False: 166]
  ------------------
   25|    894|      n += align_to - (n % align_to);
   26|    894|   }
   27|  1.06k|   return n;
   28|  1.06k|}

_ZN5Botan11checked_mulEmm:
   47|   114k|inline std::optional<size_t> checked_mul(size_t x, size_t y) {
   48|   114k|#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_add_overflow)
   49|   114k|   size_t z;
   50|   114k|   if(__builtin_mul_overflow(x, y, &z)) [[unlikely]]
  ------------------
  |  Branch (50:7): [True: 0, False: 114k]
  ------------------
   51|       |#elif defined(_MSC_VER)
   52|       |   size_t z;
   53|       |   if(SizeTMult(x, y, &z) != S_OK) [[unlikely]]
   54|       |#else
   55|       |   size_t z = x * y;
   56|       |   if(y && z / y != x) [[unlikely]]
   57|       |#endif
   58|      0|   {
   59|      0|      return std::nullopt;
   60|      0|   }
   61|   114k|   return z;
   62|   114k|}
_ZN5Botan11checked_addEmmPKci:
   30|   101k|inline size_t checked_add(size_t x, size_t y, const char* file, int line) {
   31|   101k|#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_add_overflow)
   32|   101k|   size_t z;
   33|   101k|   if(__builtin_add_overflow(x, y, &z)) [[unlikely]]
  ------------------
  |  Branch (33:7): [True: 0, False: 101k]
  ------------------
   34|       |#elif defined(_MSC_VER)
   35|       |   size_t z;
   36|       |   if(SizeTAdd(x, y, &z) != S_OK) [[unlikely]]
   37|       |#else
   38|       |   size_t z = x + y;
   39|       |   if(z < x) [[unlikely]]
   40|       |#endif
   41|      0|   {
   42|      0|      throw Integer_Overflow_Detected(file, line);
   43|      0|   }
   44|   101k|   return z;
   45|   101k|}

_ZNK5Botan5SHA_113output_lengthEv:
   34|    174|      size_t output_length() const override { return 20; }

_ZNK5Botan7SHA_25613output_lengthEv:
   75|  33.8k|      size_t output_length() const override { return output_bytes; }

_ZN5Botan9SHA2_32_FEjjjRjjjjS0_S0_jjjj:
   31|  3.60M|                                  uint32_t magic) {
   32|  3.60M|   uint32_t A_rho = rho<2, 13, 22>(A);
   33|  3.60M|   uint32_t E_rho = rho<6, 11, 25>(E);
   34|  3.60M|   uint32_t M2_sigma = sigma<17, 19, 10>(M2);
   35|  3.60M|   uint32_t M4_sigma = sigma<7, 18, 3>(M4);
   36|  3.60M|   H += magic + E_rho + choose(E, F, G) + M1;
   37|  3.60M|   D += H;
   38|  3.60M|   H += A_rho + majority(A, B, C);
   39|  3.60M|   M1 += M2_sigma + M3 + M4_sigma;
   40|  3.60M|}

_ZN5Botan9SIMD_4x325splatEj:
  129|  1.04k|      static SIMD_4x32 splat(uint32_t B) noexcept {
  130|  1.04k|#if defined(BOTAN_SIMD_USE_SSE2)
  131|  1.04k|         return SIMD_4x32(_mm_set1_epi32(B));
  132|       |#elif defined(BOTAN_SIMD_USE_NEON)
  133|       |         return SIMD_4x32(vdupq_n_u32(B));
  134|       |#else
  135|       |         return SIMD_4x32(B, B, B, B);
  136|       |#endif
  137|  1.04k|      }
_ZN5Botan9SIMD_4x32C2EDv2_x:
  597|  28.1k|      explicit SIMD_4x32(native_simd_type x) noexcept : m_simd(x) {}
_ZN5Botan9SIMD_4x327load_beEPKv:
  172|  1.04k|      static SIMD_4x32 load_be(const void* in) noexcept {
  173|  1.04k|#if defined(BOTAN_SIMD_USE_SSE2)
  174|  1.04k|         return load_le(in).bswap();
  175|       |
  176|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  177|       |         uint32_t R[4];
  178|       |         Botan::load_be(R, static_cast<const uint8_t*>(in), 4);
  179|       |         return SIMD_4x32(R);
  180|       |
  181|       |#elif defined(BOTAN_SIMD_USE_NEON)
  182|       |         SIMD_4x32 l(vld1q_u32(static_cast<const uint32_t*>(in)));
  183|       |         return CPUID::is_little_endian() ? l.bswap() : l;
  184|       |#endif
  185|  1.04k|      }
_ZN5Botan9SIMD_4x327load_leEPKv:
  156|  1.04k|      static SIMD_4x32 load_le(const void* in) noexcept {
  157|  1.04k|#if defined(BOTAN_SIMD_USE_SSE2)
  158|  1.04k|         return SIMD_4x32(_mm_loadu_si128(reinterpret_cast<const __m128i*>(in)));
  159|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  160|       |         uint32_t R[4];
  161|       |         Botan::load_le(R, static_cast<const uint8_t*>(in), 4);
  162|       |         return SIMD_4x32(R);
  163|       |#elif defined(BOTAN_SIMD_USE_NEON)
  164|       |         SIMD_4x32 l(vld1q_u32(static_cast<const uint32_t*>(in)));
  165|       |         return CPUID::is_big_endian() ? l.bswap() : l;
  166|       |#endif
  167|  1.04k|      }
_ZNK5Botan9SIMD_4x325bswapEv:
  474|  1.04k|      SIMD_4x32 bswap() const noexcept {
  475|  1.04k|#if defined(BOTAN_SIMD_USE_SSE2)
  476|       |
  477|  1.04k|         __m128i T = m_simd;
  478|  1.04k|         T = _mm_shufflehi_epi16(T, _MM_SHUFFLE(2, 3, 0, 1));
  479|  1.04k|         T = _mm_shufflelo_epi16(T, _MM_SHUFFLE(2, 3, 0, 1));
  480|  1.04k|         return SIMD_4x32(_mm_or_si128(_mm_srli_epi16(T, 8), _mm_slli_epi16(T, 8)));
  481|       |
  482|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  483|       |         return SIMD_4x32(vec_revb(m_simd));
  484|       |
  485|       |#elif defined(BOTAN_SIMD_USE_NEON)
  486|       |         return SIMD_4x32(vreinterpretq_u32_u8(vrev32q_u8(vreinterpretq_u8_u32(m_simd))));
  487|       |#endif
  488|  1.04k|      }
_ZN5Botan9SIMD_4x32eOERKS0_:
  383|  16.7k|      void operator^=(const SIMD_4x32& other) noexcept {
  384|  16.7k|#if defined(BOTAN_SIMD_USE_SSE2)
  385|  16.7k|         m_simd = _mm_xor_si128(m_simd, other.m_simd);
  386|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  387|       |         m_simd = vec_xor(m_simd, other.m_simd);
  388|       |#elif defined(BOTAN_SIMD_USE_NEON)
  389|       |         m_simd = veorq_u32(m_simd, other.m_simd);
  390|       |#endif
  391|  16.7k|      }
_ZNK5Botan9SIMD_4x328store_leEPh:
  196|  5.22k|      void store_le(uint8_t out[]) const noexcept {
  197|  5.22k|#if defined(BOTAN_SIMD_USE_SSE2)
  198|       |
  199|  5.22k|         _mm_storeu_si128(reinterpret_cast<__m128i*>(out), raw());
  200|       |
  201|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  202|       |
  203|       |         union {
  204|       |               __vector unsigned int V;
  205|       |               uint32_t R[4];
  206|       |         } vec;
  207|       |
  208|       |         vec.V = raw();
  209|       |         Botan::store_le(out, vec.R[0], vec.R[1], vec.R[2], vec.R[3]);
  210|       |
  211|       |#elif defined(BOTAN_SIMD_USE_NEON)
  212|       |         if(CPUID::is_little_endian()) {
  213|       |            vst1q_u8(out, vreinterpretq_u8_u32(m_simd));
  214|       |         } else {
  215|       |            vst1q_u8(out, vreinterpretq_u8_u32(bswap().m_simd));
  216|       |         }
  217|       |#endif
  218|  5.22k|      }
_ZNK5Botan9SIMD_4x323rawEv:
  595|  26.1k|      native_simd_type raw() const noexcept { return m_simd; }
_ZNK5Botan9SIMD_4x324rotlILm1EEES0_v:
  281|  4.17k|      {
  282|  4.17k|#if defined(BOTAN_SIMD_USE_SSE2)
  283|       |
  284|  4.17k|         return SIMD_4x32(_mm_or_si128(_mm_slli_epi32(m_simd, static_cast<int>(ROT)),
  285|  4.17k|                                       _mm_srli_epi32(m_simd, static_cast<int>(32 - ROT))));
  286|       |
  287|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  288|       |
  289|       |         const unsigned int r = static_cast<unsigned int>(ROT);
  290|       |         __vector unsigned int rot = {r, r, r, r};
  291|       |         return SIMD_4x32(vec_rl(m_simd, rot));
  292|       |
  293|       |#elif defined(BOTAN_SIMD_USE_NEON)
  294|       |
  295|       |   #if defined(BOTAN_TARGET_ARCH_IS_ARM64)
  296|       |
  297|       |         if constexpr(ROT == 8) {
  298|       |            const uint8_t maskb[16] = {3, 0, 1, 2, 7, 4, 5, 6, 11, 8, 9, 10, 15, 12, 13, 14};
  299|       |            const uint8x16_t mask = vld1q_u8(maskb);
  300|       |            return SIMD_4x32(vreinterpretq_u32_u8(vqtbl1q_u8(vreinterpretq_u8_u32(m_simd), mask)));
  301|       |         } else if constexpr(ROT == 16) {
  302|       |            return SIMD_4x32(vreinterpretq_u32_u16(vrev32q_u16(vreinterpretq_u16_u32(m_simd))));
  303|       |         }
  304|       |   #endif
  305|       |         return SIMD_4x32(
  306|       |            vorrq_u32(vshlq_n_u32(m_simd, static_cast<int>(ROT)), vshrq_n_u32(m_simd, static_cast<int>(32 - ROT))));
  307|       |#endif
  308|  4.17k|      }
_ZNK5Botan9SIMD_4x324rotlILm2EEES0_v:
  281|  4.17k|      {
  282|  4.17k|#if defined(BOTAN_SIMD_USE_SSE2)
  283|       |
  284|  4.17k|         return SIMD_4x32(_mm_or_si128(_mm_slli_epi32(m_simd, static_cast<int>(ROT)),
  285|  4.17k|                                       _mm_srli_epi32(m_simd, static_cast<int>(32 - ROT))));
  286|       |
  287|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  288|       |
  289|       |         const unsigned int r = static_cast<unsigned int>(ROT);
  290|       |         __vector unsigned int rot = {r, r, r, r};
  291|       |         return SIMD_4x32(vec_rl(m_simd, rot));
  292|       |
  293|       |#elif defined(BOTAN_SIMD_USE_NEON)
  294|       |
  295|       |   #if defined(BOTAN_TARGET_ARCH_IS_ARM64)
  296|       |
  297|       |         if constexpr(ROT == 8) {
  298|       |            const uint8_t maskb[16] = {3, 0, 1, 2, 7, 4, 5, 6, 11, 8, 9, 10, 15, 12, 13, 14};
  299|       |            const uint8x16_t mask = vld1q_u8(maskb);
  300|       |            return SIMD_4x32(vreinterpretq_u32_u8(vqtbl1q_u8(vreinterpretq_u8_u32(m_simd), mask)));
  301|       |         } else if constexpr(ROT == 16) {
  302|       |            return SIMD_4x32(vreinterpretq_u32_u16(vrev32q_u16(vreinterpretq_u16_u32(m_simd))));
  303|       |         }
  304|       |   #endif
  305|       |         return SIMD_4x32(
  306|       |            vorrq_u32(vshlq_n_u32(m_simd, static_cast<int>(ROT)), vshrq_n_u32(m_simd, static_cast<int>(32 - ROT))));
  307|       |#endif
  308|  4.17k|      }
_ZN5Botan9SIMD_4x32C2Ejjjj:
  113|     96|      SIMD_4x32(uint32_t B0, uint32_t B1, uint32_t B2, uint32_t B3) noexcept {
  114|     96|#if defined(BOTAN_SIMD_USE_SSE2)
  115|     96|         m_simd = _mm_set_epi32(B3, B2, B1, B0);
  116|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  117|       |         __vector unsigned int val = {B0, B1, B2, B3};
  118|       |         m_simd = val;
  119|       |#elif defined(BOTAN_SIMD_USE_NEON)
  120|       |         // Better way to do this?
  121|       |         const uint32_t B[4] = {B0, B1, B2, B3};
  122|       |         m_simd = vld1q_u32(B);
  123|       |#endif
  124|     96|      }
_ZN5Botan9SIMD_4x328splat_u8Eh:
  142|      2|      static SIMD_4x32 splat_u8(uint8_t B) noexcept {
  143|      2|#if defined(BOTAN_SIMD_USE_SSE2)
  144|      2|         return SIMD_4x32(_mm_set1_epi8(B));
  145|       |#elif defined(BOTAN_SIMD_USE_NEON)
  146|       |         return SIMD_4x32(vreinterpretq_u32_u8(vdupq_n_u8(B)));
  147|       |#else
  148|       |         const uint32_t B4 = make_uint32(B, B, B, B);
  149|       |         return SIMD_4x32(B4, B4, B4, B4);
  150|       |#endif
  151|      2|      }
_ZNK5Botan9SIMD_4x328store_leEPj:
  187|  5.22k|      void store_le(uint32_t out[4]) const noexcept { this->store_le(reinterpret_cast<uint8_t*>(out)); }
_ZNK5Botan9SIMD_4x32plERKS0_:
  321|  5.22k|      SIMD_4x32 operator+(const SIMD_4x32& other) const noexcept {
  322|  5.22k|         SIMD_4x32 retval(*this);
  323|  5.22k|         retval += other;
  324|  5.22k|         return retval;
  325|  5.22k|      }
_ZN5Botan9SIMD_4x32pLERKS0_:
  363|  5.22k|      void operator+=(const SIMD_4x32& other) noexcept {
  364|  5.22k|#if defined(BOTAN_SIMD_USE_SSE2)
  365|  5.22k|         m_simd = _mm_add_epi32(m_simd, other.m_simd);
  366|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  367|       |         m_simd = vec_add(m_simd, other.m_simd);
  368|       |#elif defined(BOTAN_SIMD_USE_NEON)
  369|       |         m_simd = vaddq_u32(m_simd, other.m_simd);
  370|       |#endif
  371|  5.22k|      }
_ZNK5Botan9SIMD_4x3217shift_elems_rightILm1EEES0_v:
  514|  4.17k|      {
  515|  4.17k|#if defined(BOTAN_SIMD_USE_SSE2)
  516|  4.17k|         return SIMD_4x32(_mm_srli_si128(raw(), 4 * I));
  517|       |#elif defined(BOTAN_SIMD_USE_NEON)
  518|       |         return SIMD_4x32(vextq_u32(raw(), vdupq_n_u32(0), I));
  519|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  520|       |         const __vector unsigned int zero = vec_splat_u32(0);
  521|       |
  522|       |         const __vector unsigned char shuf[3] = {
  523|       |            {4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19},
  524|       |            {8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23},
  525|       |            {12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27},
  526|       |         };
  527|       |
  528|       |         return SIMD_4x32(vec_perm(raw(), zero, shuf[I - 1]));
  529|       |#endif
  530|  4.17k|      }
_ZNK5Botan9SIMD_4x3216shift_elems_leftILm3EEES0_v:
  493|  4.17k|      {
  494|  4.17k|#if defined(BOTAN_SIMD_USE_SSE2)
  495|  4.17k|         return SIMD_4x32(_mm_slli_si128(raw(), 4 * I));
  496|       |#elif defined(BOTAN_SIMD_USE_NEON)
  497|       |         return SIMD_4x32(vextq_u32(vdupq_n_u32(0), raw(), 4 - I));
  498|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  499|       |         const __vector unsigned int zero = vec_splat_u32(0);
  500|       |
  501|       |         const __vector unsigned char shuf[3] = {
  502|       |            {16, 17, 18, 19, 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11},
  503|       |            {16, 17, 18, 19, 20, 21, 22, 23, 0, 1, 2, 3, 4, 5, 6, 7},
  504|       |            {16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 0, 1, 2, 3},
  505|       |         };
  506|       |
  507|       |         return SIMD_4x32(vec_perm(raw(), zero, shuf[I - 1]));
  508|       |#endif
  509|  4.17k|      }

_ZN5Botan12value_existsINS_3TLS16Signature_SchemeES2_EEbRKNSt3__16vectorIT_NS3_9allocatorIS5_EEEERKT0_:
  117|  1.69k|bool value_exists(const std::vector<T>& vec, const OT& val) {
  118|  8.77k|   for(size_t i = 0; i != vec.size(); ++i) {
  ------------------
  |  Branch (118:22): [True: 8.75k, False: 22]
  ------------------
  119|  8.75k|      if(vec[i] == val) {
  ------------------
  |  Branch (119:10): [True: 1.66k, False: 7.08k]
  ------------------
  120|  1.66k|         return true;
  121|  1.66k|      }
  122|  8.75k|   }
  123|     22|   return false;
  124|  1.69k|}
_ZN5Botan12BufferSlicerC2ENSt3__14spanIKhLm18446744073709551615EEE:
  143|  91.2k|      BufferSlicer(std::span<const uint8_t> buffer) : m_remaining(buffer) {}
_ZN5Botan12BufferSlicer4takeEm:
  155|   121k|      std::span<const uint8_t> take(const size_t count) {
  156|   121k|         BOTAN_STATE_CHECK(remaining() >= count);
  ------------------
  |  |   42|   121k|   do {                                                         \
  |  |   43|   121k|      if(!(expr))                                               \
  |  |  ------------------
  |  |  |  Branch (43:10): [True: 0, False: 121k]
  |  |  ------------------
  |  |   44|   121k|         Botan::throw_invalid_state(#expr, __func__, __FILE__); \
  |  |   45|   121k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (45:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  157|   121k|         auto result = m_remaining.first(count);
  158|   121k|         m_remaining = m_remaining.subspan(count);
  159|   121k|         return result;
  160|   121k|      }
_ZNK5Botan12BufferSlicer9remainingEv:
  184|   206k|      size_t remaining() const { return m_remaining.size(); }
_ZNK5Botan12BufferSlicer5emptyEv:
  186|  87.3k|      bool empty() const { return m_remaining.empty(); }
_ZN5Botan12value_existsINS_3TLS12Group_ParamsES2_EEbRKNSt3__16vectorIT_NS3_9allocatorIS5_EEEERKT0_:
  117|  4.32k|bool value_exists(const std::vector<T>& vec, const OT& val) {
  118|   116k|   for(size_t i = 0; i != vec.size(); ++i) {
  ------------------
  |  Branch (118:22): [True: 113k, False: 3.27k]
  ------------------
  119|   113k|      if(vec[i] == val) {
  ------------------
  |  Branch (119:10): [True: 1.04k, False: 112k]
  ------------------
  120|  1.04k|         return true;
  121|  1.04k|      }
  122|   113k|   }
  123|  3.27k|   return false;
  124|  4.32k|}
_ZN5Botan13generalize_toINSt3__17variantIJNS_3TLS15Client_Hello_13ENS3_15Client_Hello_12ENS3_15Server_Hello_13ENS3_15Server_Hello_12ENS3_19Hello_Retry_RequestENS3_20Encrypted_ExtensionsENS3_14Certificate_13ENS3_22Certificate_Request_13ENS3_21Certificate_Verify_13ENS3_11Finished_13EEEEJS4_S5_EEET_NS2_IJDpT0_EEE:
  314|  7.80k|constexpr GeneralVariantT generalize_to(std::variant<SpecialTs...> specific) noexcept {
  315|  7.80k|   static_assert(
  316|  7.80k|      is_generalizable_to<GeneralVariantT>(specific),
  317|  7.80k|      "Desired general type must be implicitly constructible by all types of the specialized std::variant<>");
  318|  7.80k|   return std::visit([](auto s) -> GeneralVariantT { return s; }, std::move(specific));
  319|  7.80k|}
_ZZN5Botan13generalize_toINSt3__17variantIJNS_3TLS15Client_Hello_13ENS3_15Client_Hello_12ENS3_15Server_Hello_13ENS3_15Server_Hello_12ENS3_19Hello_Retry_RequestENS3_20Encrypted_ExtensionsENS3_14Certificate_13ENS3_22Certificate_Request_13ENS3_21Certificate_Verify_13ENS3_11Finished_13EEEEJS4_S5_EEET_NS2_IJDpT0_EEEENKUlSF_E_clIS4_EESE_SF_:
  318|    526|   return std::visit([](auto s) -> GeneralVariantT { return s; }, std::move(specific));
_ZZN5Botan13generalize_toINSt3__17variantIJNS_3TLS15Client_Hello_13ENS3_15Client_Hello_12ENS3_15Server_Hello_13ENS3_15Server_Hello_12ENS3_19Hello_Retry_RequestENS3_20Encrypted_ExtensionsENS3_14Certificate_13ENS3_22Certificate_Request_13ENS3_21Certificate_Verify_13ENS3_11Finished_13EEEEJS4_S5_EEET_NS2_IJDpT0_EEEENKUlSF_E_clIS5_EESE_SF_:
  318|  7.27k|   return std::visit([](auto s) -> GeneralVariantT { return s; }, std::move(specific));
_ZN5Botan13generalize_toINSt3__17variantIJNS_3TLS15Client_Hello_13ENS3_15Client_Hello_12ENS3_15Server_Hello_13ENS3_15Server_Hello_12ENS3_19Hello_Retry_RequestENS3_20Encrypted_ExtensionsENS3_14Certificate_13ENS3_22Certificate_Request_13ENS3_21Certificate_Verify_13ENS3_11Finished_13EEEEJS8_S6_S7_EEET_NS2_IJDpT0_EEE:
  314|  6.12k|constexpr GeneralVariantT generalize_to(std::variant<SpecialTs...> specific) noexcept {
  315|  6.12k|   static_assert(
  316|  6.12k|      is_generalizable_to<GeneralVariantT>(specific),
  317|  6.12k|      "Desired general type must be implicitly constructible by all types of the specialized std::variant<>");
  318|  6.12k|   return std::visit([](auto s) -> GeneralVariantT { return s; }, std::move(specific));
  319|  6.12k|}
_ZZN5Botan13generalize_toINSt3__17variantIJNS_3TLS15Client_Hello_13ENS3_15Client_Hello_12ENS3_15Server_Hello_13ENS3_15Server_Hello_12ENS3_19Hello_Retry_RequestENS3_20Encrypted_ExtensionsENS3_14Certificate_13ENS3_22Certificate_Request_13ENS3_21Certificate_Verify_13ENS3_11Finished_13EEEEJS8_S6_S7_EEET_NS2_IJDpT0_EEEENKUlSF_E_clIS6_EESE_SF_:
  318|    445|   return std::visit([](auto s) -> GeneralVariantT { return s; }, std::move(specific));
_ZZN5Botan13generalize_toINSt3__17variantIJNS_3TLS15Client_Hello_13ENS3_15Client_Hello_12ENS3_15Server_Hello_13ENS3_15Server_Hello_12ENS3_19Hello_Retry_RequestENS3_20Encrypted_ExtensionsENS3_14Certificate_13ENS3_22Certificate_Request_13ENS3_21Certificate_Verify_13ENS3_11Finished_13EEEEJS8_S6_S7_EEET_NS2_IJDpT0_EEEENKUlSF_E_clIS7_EESE_SF_:
  318|  5.67k|   return std::visit([](auto s) -> GeneralVariantT { return s; }, std::move(specific));

_ZN5Botan3TLS15Handshake_LayerC2ENS0_15Connection_SideE:
   41|  7.09k|            m_certificate_type(Certificate_Type::X509) {}

_ZN5Botan3TLS15TLS_Data_ReaderC2EPKcNSt3__14spanIKhLm18446744073709551615EEE:
   27|   125k|            m_typename(type), m_buf(buf_in), m_offset(0) {}
_ZN5Botan3TLS15TLS_Data_Reader12get_uint16_tEv:
   66|   224k|      uint16_t get_uint16_t() {
   67|   224k|         assert_at_least(2);
   68|   224k|         uint16_t result = make_uint16(m_buf[m_offset], m_buf[m_offset + 1]);
   69|   224k|         m_offset += 2;
   70|   224k|         return result;
   71|   224k|      }
_ZNK5Botan3TLS15TLS_Data_Reader15assert_at_leastEm:
  160|   730k|      void assert_at_least(size_t n) const {
  161|   730k|         if(m_buf.size() - m_offset < n) {
  ------------------
  |  Branch (161:13): [True: 596, False: 729k]
  ------------------
  162|    596|            throw_decode_error("Expected " + std::to_string(n) + " bytes remaining, only " +
  163|    596|                               std::to_string(m_buf.size() - m_offset) + " left");
  164|    596|         }
  165|   730k|      }
_ZNK5Botan3TLS15TLS_Data_Reader18throw_decode_errorENSt3__117basic_string_viewIcNS2_11char_traitsIcEEEE:
  167|    688|      [[noreturn]] void throw_decode_error(std::string_view why) const {
  168|    688|         throw Decoding_Error(fmt("Invalid {}: {}", m_typename, why));
  169|    688|      }
_ZNK5Botan3TLS15TLS_Data_Reader11assert_doneEv:
   29|  52.6k|      void assert_done() const {
   30|  52.6k|         if(has_remaining()) {
  ------------------
  |  Branch (30:13): [True: 53, False: 52.6k]
  ------------------
   31|     53|            throw_decode_error("Extra bytes at end of message");
   32|     53|         }
   33|  52.6k|      }
_ZNK5Botan3TLS15TLS_Data_Reader13has_remainingEv:
   39|   186k|      bool has_remaining() const { return (remaining_bytes() > 0); }
_ZNK5Botan3TLS15TLS_Data_Reader15remaining_bytesEv:
   37|   334k|      size_t remaining_bytes() const { return m_buf.size() - m_offset; }
_ZN5Botan3TLS15TLS_Data_Reader9get_rangeIhEENSt3__16vectorIT_NS3_9allocatorIS5_EEEEmmm:
  105|  21.6k|      std::vector<T> get_range(size_t len_bytes, size_t min_elems, size_t max_elems) {
  106|  21.6k|         const size_t num_elems = get_num_elems(len_bytes, sizeof(T), min_elems, max_elems);
  107|       |
  108|  21.6k|         return get_elem<T, std::vector<T>>(num_elems);
  109|  21.6k|      }
_ZN5Botan3TLS15TLS_Data_Reader13get_num_elemsEmmmm:
  144|  45.3k|      size_t get_num_elems(size_t len_bytes, size_t T_size, size_t min_elems, size_t max_elems) {
  145|  45.3k|         const size_t byte_length = get_length_field(len_bytes);
  146|       |
  147|  45.3k|         if(byte_length % T_size != 0) {
  ------------------
  |  Branch (147:13): [True: 11, False: 45.3k]
  ------------------
  148|     11|            throw_decode_error("Size isn't multiple of T");
  149|     11|         }
  150|       |
  151|  45.3k|         const size_t num_elems = byte_length / T_size;
  152|       |
  153|  45.3k|         if(num_elems < min_elems || num_elems > max_elems) {
  ------------------
  |  Branch (153:13): [True: 72, False: 45.2k]
  |  Branch (153:38): [True: 13, False: 45.2k]
  ------------------
  154|     28|            throw_decode_error("Length field outside parameters");
  155|     28|         }
  156|       |
  157|  45.3k|         return num_elems;
  158|  45.3k|      }
_ZN5Botan3TLS15TLS_Data_Reader16get_length_fieldEm:
  130|  62.8k|      size_t get_length_field(size_t len_bytes) {
  131|  62.8k|         assert_at_least(len_bytes);
  132|       |
  133|  62.8k|         if(len_bytes == 1) {
  ------------------
  |  Branch (133:13): [True: 38.0k, False: 24.8k]
  ------------------
  134|  38.0k|            return get_byte();
  135|  38.0k|         } else if(len_bytes == 2) {
  ------------------
  |  Branch (135:20): [True: 23.1k, False: 1.67k]
  ------------------
  136|  23.1k|            return get_uint16_t();
  137|  23.1k|         } else if(len_bytes == 3) {
  ------------------
  |  Branch (137:20): [True: 1.57k, False: 97]
  ------------------
  138|  1.57k|            return get_uint24_t();
  139|  1.57k|         }
  140|       |
  141|     97|         throw_decode_error("Bad length size");
  142|     97|      }
_ZN5Botan3TLS15TLS_Data_Reader8get_byteEv:
   78|   145k|      uint8_t get_byte() {
   79|   145k|         assert_at_least(1);
   80|   145k|         uint8_t result = m_buf[m_offset];
   81|   145k|         m_offset += 1;
   82|   145k|         return result;
   83|   145k|      }
_ZN5Botan3TLS15TLS_Data_Reader12get_uint24_tEv:
   59|  37.2k|      uint32_t get_uint24_t() {
   60|  37.2k|         assert_at_least(3);
   61|  37.2k|         uint32_t result = make_uint32(0, m_buf[m_offset], m_buf[m_offset + 1], m_buf[m_offset + 2]);
   62|  37.2k|         m_offset += 3;
   63|  37.2k|         return result;
   64|  37.2k|      }
_ZN5Botan3TLS15TLS_Data_Reader8get_elemIhNSt3__16vectorIhNS3_9allocatorIhEEEEEET0_m:
   86|   184k|      Container get_elem(size_t num_elems) {
   87|   184k|         assert_at_least(num_elems * sizeof(T));
   88|       |
   89|   184k|         Container result(num_elems);
   90|       |
   91|  3.82M|         for(size_t i = 0; i != num_elems; ++i) {
  ------------------
  |  Branch (91:28): [True: 3.63M, False: 184k]
  ------------------
   92|  3.63M|            result[i] = load_be<T>(&m_buf[m_offset], i);
   93|  3.63M|         }
   94|       |
   95|   184k|         m_offset += num_elems * sizeof(T);
   96|       |
   97|   184k|         return result;
   98|   184k|      }
_ZNK5Botan3TLS15TLS_Data_Reader11read_so_farEv:
   35|   135k|      size_t read_so_far() const { return m_offset; }
_ZN5Botan3TLS15TLS_Data_Reader13get_remainingEv:
   41|  2.68k|      std::vector<uint8_t> get_remaining() { return std::vector<uint8_t>(m_buf.begin() + m_offset, m_buf.end()); }
_ZN5Botan3TLS15TLS_Data_Reader20get_data_read_so_farEv:
   43|  2.69k|      std::vector<uint8_t> get_data_read_so_far() {
   44|  2.69k|         return std::vector<uint8_t>(m_buf.begin(), m_buf.begin() + m_offset);
   45|  2.69k|      }
_ZN5Botan3TLS15TLS_Data_Reader12discard_nextEm:
   47|  61.5k|      void discard_next(size_t bytes) {
   48|  61.5k|         assert_at_least(bytes);
   49|  61.5k|         m_offset += bytes;
   50|  61.5k|      }
_ZN5Botan3TLS15TLS_Data_Reader12get_uint32_tEv:
   52|  3.46k|      uint32_t get_uint32_t() {
   53|  3.46k|         assert_at_least(4);
   54|  3.46k|         uint32_t result = make_uint32(m_buf[m_offset], m_buf[m_offset + 1], m_buf[m_offset + 2], m_buf[m_offset + 3]);
   55|  3.46k|         m_offset += 4;
   56|  3.46k|         return result;
   57|  3.46k|      }
_ZNK5Botan3TLS15TLS_Data_Reader13peek_uint16_tEv:
   73|    970|      uint16_t peek_uint16_t() const {
   74|    970|         assert_at_least(2);
   75|    970|         return make_uint16(m_buf[m_offset], m_buf[m_offset + 1]);
   76|    970|      }
_ZN5Botan3TLS15TLS_Data_Reader20get_tls_length_valueEm:
  100|  17.5k|      std::vector<uint8_t> get_tls_length_value(size_t len_bytes) {
  101|  17.5k|         return get_fixed<uint8_t>(get_length_field(len_bytes));
  102|  17.5k|      }
_ZN5Botan3TLS15TLS_Data_Reader10get_stringEmmm:
  118|  5.33k|      std::string get_string(size_t len_bytes, size_t min_bytes, size_t max_bytes) {
  119|  5.33k|         std::vector<uint8_t> v = get_range_vector<uint8_t>(len_bytes, min_bytes, max_bytes);
  120|       |
  121|  5.33k|         return std::string(cast_uint8_ptr_to_char(v.data()), v.size());
  122|  5.33k|      }
_ZN5Botan3TLS15TLS_Data_Reader9get_fixedIhEENSt3__16vectorIT_NS3_9allocatorIS5_EEEEm:
  125|   148k|      std::vector<T> get_fixed(size_t size) {
  126|   148k|         return get_elem<T, std::vector<T>>(size);
  127|   148k|      }
_ZN5Botan3TLS15TLS_Data_Reader16get_range_vectorIhEENSt3__16vectorIT_NS3_9allocatorIS5_EEEEmmm:
  112|  13.7k|      std::vector<T> get_range_vector(size_t len_bytes, size_t min_elems, size_t max_elems) {
  113|  13.7k|         const size_t num_elems = get_num_elems(len_bytes, sizeof(T), min_elems, max_elems);
  114|       |
  115|  13.7k|         return get_elem<T, std::vector<T>>(num_elems);
  116|  13.7k|      }
_ZN5Botan3TLS15TLS_Data_Reader16get_range_vectorItEENSt3__16vectorIT_NS3_9allocatorIS5_EEEEmmm:
  112|  8.43k|      std::vector<T> get_range_vector(size_t len_bytes, size_t min_elems, size_t max_elems) {
  113|  8.43k|         const size_t num_elems = get_num_elems(len_bytes, sizeof(T), min_elems, max_elems);
  114|       |
  115|  8.43k|         return get_elem<T, std::vector<T>>(num_elems);
  116|  8.43k|      }
_ZN5Botan3TLS15TLS_Data_Reader8get_elemItNSt3__16vectorItNS3_9allocatorItEEEEEET0_m:
   86|  9.94k|      Container get_elem(size_t num_elems) {
   87|  9.94k|         assert_at_least(num_elems * sizeof(T));
   88|       |
   89|  9.94k|         Container result(num_elems);
   90|       |
   91|  52.7k|         for(size_t i = 0; i != num_elems; ++i) {
  ------------------
  |  Branch (91:28): [True: 42.8k, False: 9.94k]
  ------------------
   92|  42.8k|            result[i] = load_be<T>(&m_buf[m_offset], i);
   93|  42.8k|         }
   94|       |
   95|  9.94k|         m_offset += num_elems * sizeof(T);
   96|       |
   97|  9.94k|         return result;
   98|  9.94k|      }
_ZN5Botan3TLS15TLS_Data_Reader9get_rangeItEENSt3__16vectorIT_NS3_9allocatorIS5_EEEEmmm:
  105|  1.54k|      std::vector<T> get_range(size_t len_bytes, size_t min_elems, size_t max_elems) {
  106|  1.54k|         const size_t num_elems = get_num_elems(len_bytes, sizeof(T), min_elems, max_elems);
  107|       |
  108|  1.54k|         return get_elem<T, std::vector<T>>(num_elems);
  109|  1.54k|      }

_ZN5Botan3TLS21Transcript_Hash_StateD2Ev:
   32|  5.58k|      ~Transcript_Hash_State() = default;

_ZN5Botan11ASN1_ObjectD2Ev:
  120|  40.7k|      virtual ~ASN1_Object() = default;
_ZN5Botan10BER_ObjectC2Ev:
  128|  56.2k|      BER_Object() : m_type_tag(ASN1_Type::NoObject), m_class_tag(ASN1_Class::Universal) {}
_ZNK5Botan10BER_Object6is_setEv:
  138|  72.7k|      bool is_set() const { return m_type_tag != ASN1_Type::NoObject; }
_ZNK5Botan10BER_Object7taggingEv:
  140|  40.9k|      uint32_t tagging() const { return type_tag() | class_tag(); }
_ZNK5Botan10BER_Object8type_tagEv:
  142|  40.9k|      ASN1_Type type_tag() const { return m_type_tag; }
_ZNK5Botan10BER_Object9class_tagEv:
  144|  40.9k|      ASN1_Class class_tag() const { return m_class_tag; }
_ZNK5Botan10BER_Object4typeEv:
  146|  9.28k|      ASN1_Type type() const { return m_type_tag; }
_ZNK5Botan10BER_Object4bitsEv:
  150|   253k|      const uint8_t* bits() const { return m_value.data(); }
_ZNK5Botan10BER_Object6lengthEv:
  152|   561k|      size_t length() const { return m_value.size(); }
_ZN5Botan10BER_Object12mutable_bitsEm:
  169|  34.9k|      uint8_t* mutable_bits(size_t length) {
  170|  34.9k|         m_value.resize(length);
  171|  34.9k|         return m_value.data();
  172|  34.9k|      }
_ZN5Botan3OIDC2ESt16initializer_listIjE:
  229|    281|      explicit OID(std::initializer_list<uint32_t> init) : m_id(init) {
  230|    281|         BOTAN_ARG_CHECK(m_id.size() > 2 && m_id[0] <= 2 && (m_id[0] != 2 || m_id[1] <= 39), "Invalid OID");
  ------------------
  |  |   30|    281|   do {                                                          \
  |  |   31|  1.47k|      if(!(expr))                                                \
  |  |  ------------------
  |  |  |  Branch (31:12): [True: 281, False: 0]
  |  |  |  Branch (31:12): [True: 281, False: 0]
  |  |  |  Branch (31:12): [True: 208, False: 73]
  |  |  |  Branch (31:12): [True: 73, False: 0]
  |  |  ------------------
  |  |   32|    281|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   33|    281|   } while(0)
  |  |  ------------------
  |  |  |  Branch (33:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  231|    281|      }
_ZNK5Botan3OID14get_componentsEv:
  277|    405|      const std::vector<uint32_t>& get_components() const { return m_id; }
_ZNK5Botan3OIDeqERKS0_:
  309|    211|      bool operator==(const OID& other) const { return m_id == other.m_id; }
_ZNK5Botan11ASN1_String5emptyEv:
  419|  4.17k|      bool empty() const { return m_utf8_str.empty(); }
_ZNK5Botan19AlgorithmIdentifier3oidEv:
  455|    769|      const OID& oid() const { return m_oid; }
_ZNK5Botan19AlgorithmIdentifier10parametersEv:
  457|    423|      const std::vector<uint8_t>& parameters() const { return m_parameters; }
_ZNK5Botan19AlgorithmIdentifier20parameters_are_emptyEv:
  469|    239|      bool parameters_are_empty() const { return m_parameters.empty(); }
_ZNK5Botan19AlgorithmIdentifier28parameters_are_null_or_emptyEv:
  471|    239|      bool parameters_are_null_or_empty() const { return parameters_are_empty() || parameters_are_null(); }
  ------------------
  |  Branch (471:58): [True: 49, False: 190]
  |  Branch (471:84): [True: 22, False: 168]
  ------------------
_ZN5BotanorENS_10ASN1_ClassES0_:
   78|  16.8k|inline ASN1_Class operator|(ASN1_Class x, ASN1_Class y) {
   79|  16.8k|   return static_cast<ASN1_Class>(static_cast<uint32_t>(x) | static_cast<uint32_t>(y));
   80|  16.8k|}
_ZN5BotanorENS_9ASN1_TypeENS_10ASN1_ClassE:
   82|  40.9k|inline uint32_t operator|(ASN1_Type x, ASN1_Class y) {
   83|  40.9k|   return static_cast<uint32_t>(x) | static_cast<uint32_t>(y);
   84|  40.9k|}
_ZN5BotanorENS_10ASN1_ClassENS_9ASN1_TypeE:
   86|  5.87k|inline uint32_t operator|(ASN1_Class x, ASN1_Type y) {
   87|  5.87k|   return static_cast<uint32_t>(x) | static_cast<uint32_t>(y);
   88|  5.87k|}
_ZN5BotanneERKNS_3OIDES2_:
  326|    211|inline bool operator!=(const OID& a, const OID& b) {
  327|    211|   return !(a == b);
  328|    211|}
_ZN5Botan11ASN1_ObjectC2ERKS0_:
  118|  14.4k|      ASN1_Object(const ASN1_Object&) = default;
_ZN5Botan11ASN1_ObjectC2Ev:
  117|  26.3k|      ASN1_Object() = default;
_ZN5Botan19AlgorithmIdentifierC2Ev:
  447|  2.97k|      AlgorithmIdentifier() = default;
_ZN5Botan3OIDC2Ev:
  218|  7.42k|      explicit OID() = default;
_ZN5Botan9ASN1_TimeC2Ev:
  362|  1.18k|      ASN1_Time() = default;
_ZN5Botan10BER_ObjectaSEOS0_:
  136|  2.43k|      BER_Object& operator=(BER_Object&& other) = default;
_ZN5Botan10BER_ObjectC2EOS0_:
  134|  15.4k|      BER_Object(BER_Object&& other) = default;

_ZN5Botan12ignore_paramIRmEEvOT_:
  111|    415|void ignore_param(T&&) {}
_ZN5Botan13ignore_paramsIJRhEEEvDpOT_:
  114|  10.8k|void ignore_params(T&&... args) {
  115|  10.8k|   (ignore_param(args), ...);
  116|  10.8k|}
_ZN5Botan12ignore_paramIRhEEvOT_:
  111|  10.8k|void ignore_param(T&&) {}
_ZN5Botan13ignore_paramsIJRmEEEvDpOT_:
  114|    415|void ignore_params(T&&... args) {
  115|    415|   (ignore_param(args), ...);
  116|    415|}
_ZN5Botan13ignore_paramsIJRKmEEEvDpOT_:
  114|    368|void ignore_params(T&&... args) {
  115|    368|   (ignore_param(args), ...);
  116|    368|}
_ZN5Botan12ignore_paramIRKmEEvOT_:
  111|    368|void ignore_param(T&&) {}

_ZN5Botan11BER_DecoderC2ERKNS_10BER_ObjectE:
   52|      4|      BER_Decoder(const BER_Object& obj) : BER_Decoder(obj.bits(), obj.length()) {}
_ZN5Botan11BER_DecoderC2EONS_10BER_ObjectE:
   57|    130|      BER_Decoder(BER_Object&& obj) : BER_Decoder(std::move(obj), nullptr) {}
_ZN5Botan11BER_Decoder8get_nextERNS_10BER_ObjectE:
   69|    431|      BER_Decoder& get_next(BER_Object& ber) {
   70|    431|         ber = get_next_object();
   71|    431|         return (*this);
   72|    431|      }
_ZN5Botan11BER_Decoder14start_sequenceEv:
  113|  13.5k|      BER_Decoder start_sequence() { return start_cons(ASN1_Type::Sequence, ASN1_Class::Universal); }
_ZN5Botan11BER_Decoder9start_setEv:
  115|  1.99k|      BER_Decoder start_set() { return start_cons(ASN1_Type::Set, ASN1_Class::Universal); }
_ZN5Botan11BER_Decoder6decodeERm:
  181|    130|      BER_Decoder& decode(size_t& out) { return decode(out, ASN1_Type::Integer, ASN1_Class::Universal); }
_ZN5Botan11BER_Decoder6decodeERNS_6BigIntE:
  186|    468|      BER_Decoder& decode(BigInt& out) { return decode(out, ASN1_Type::Integer, ASN1_Class::Universal); }
_ZN5Botan11BER_Decoder6decodeINSt3__19allocatorIhEEEERS0_RNS2_6vectorIhT_EENS_9ASN1_TypeE:
  198|  1.06k|      BER_Decoder& decode(std::vector<uint8_t, Alloc>& out, ASN1_Type real_type) {
  199|  1.06k|         return decode(out, real_type, real_type, ASN1_Class::Universal);
  200|  1.06k|      }
_ZN5Botan11BER_Decoder9raw_bytesINSt3__19allocatorIhEEEERS0_RNS2_6vectorIhT_EE:
  162|  6.62k|      BER_Decoder& raw_bytes(std::vector<uint8_t, Alloc>& out) {
  163|  6.62k|         out.clear();
  164|  6.62k|         uint8_t buf;
  165|   158k|         while(m_source->read_byte(buf)) {
  ------------------
  |  Branch (165:16): [True: 151k, False: 6.62k]
  ------------------
  166|   151k|            out.push_back(buf);
  167|   151k|         }
  168|  6.62k|         return (*this);
  169|  6.62k|      }
_ZN5Botan11BER_Decoder15decode_optionalImEERS0_RT_NS_9ASN1_TypeENS_10ASN1_ClassERKS3_:
  317|    593|BER_Decoder& BER_Decoder::decode_optional(T& out, ASN1_Type type_tag, ASN1_Class class_tag, const T& default_value) {
  318|    593|   BER_Object obj = get_next_object();
  319|       |
  320|    593|   if(obj.is_a(type_tag, class_tag)) {
  ------------------
  |  Branch (320:7): [True: 130, False: 463]
  ------------------
  321|    130|      if(class_tag == ASN1_Class::ExplicitContextSpecific) {
  ------------------
  |  Branch (321:10): [True: 130, False: 0]
  ------------------
  322|    130|         BER_Decoder(std::move(obj)).decode(out).verify_end();
  323|    130|      } else {
  324|      0|         push_back(std::move(obj));
  325|      0|         decode(out, type_tag, class_tag);
  326|      0|      }
  327|    463|   } else {
  328|    463|      out = default_value;
  329|    463|      push_back(std::move(obj));
  330|    463|   }
  331|       |
  332|    593|   return (*this);
  333|    593|}
_ZN5Botan11BER_Decoder22decode_optional_stringINSt3__19allocatorIhEEEERS0_RNS2_6vectorIhT_EENS_9ASN1_TypeEjNS_10ASN1_ClassE:
  275|    432|                                          ASN1_Class class_tag = ASN1_Class::ContextSpecific) {
  276|    432|         BER_Object obj = get_next_object();
  277|       |
  278|    432|         ASN1_Type type_tag = static_cast<ASN1_Type>(expected_tag);
  279|       |
  280|    432|         if(obj.is_a(type_tag, class_tag)) {
  ------------------
  |  Branch (280:13): [True: 8, False: 424]
  ------------------
  281|      8|            if(class_tag == ASN1_Class::ExplicitContextSpecific) {
  ------------------
  |  Branch (281:16): [True: 0, False: 8]
  ------------------
  282|      0|               BER_Decoder(std::move(obj)).decode(out, real_type).verify_end();
  283|      8|            } else {
  284|      8|               push_back(std::move(obj));
  285|      8|               decode(out, real_type, type_tag, class_tag);
  286|      8|            }
  287|    424|         } else {
  288|    424|            out.clear();
  289|    424|            push_back(std::move(obj));
  290|    424|         }
  291|       |
  292|    432|         return (*this);
  293|    432|      }

_ZN5Botan6BigIntD2Ev:
  148|  1.17k|      ~BigInt() { const_time_unpoison(); }
_ZN5Botan6BigIntaSEOS0_:
  153|    454|      BigInt& operator=(BigInt&& other) {
  154|    454|         if(this != &other) {
  ------------------
  |  Branch (154:13): [True: 454, False: 0]
  ------------------
  155|    454|            this->swap(other);
  156|    454|         }
  157|       |
  158|    454|         return (*this);
  159|    454|      }
_ZN5Botan6BigInt4swapERS0_:
  170|    454|      void swap(BigInt& other) {
  171|    454|         m_data.swap(other.m_data);
  172|    454|         std::swap(m_signedness, other.m_signedness);
  173|    454|      }
_ZN5Botan6BigInt5clearEv:
  370|    529|      void clear() {
  371|    529|         m_data.set_to_zero();
  372|    529|         m_signedness = Positive;
  373|    529|      }
_ZNK5Botan6BigInt7is_zeroEv:
  428|    247|      bool is_zero() const { return (sig_words() == 0); }
_ZNK5Botan6BigInt7word_atEm:
  518|    562|      word word_at(size_t n) const { return m_data.get_word_at(n); }
_ZNK5Botan6BigInt11is_negativeEv:
  528|    310|      bool is_negative() const { return (sign() == Negative); }
_ZNK5Botan6BigInt4signEv:
  540|    557|      Sign sign() const { return (m_signedness); }
_ZNK5Botan6BigInt12reverse_signEv:
  545|    247|      Sign reverse_sign() const {
  546|    247|         if(sign() == Positive) {
  ------------------
  |  Branch (546:13): [True: 247, False: 0]
  ------------------
  547|    247|            return Negative;
  548|    247|         }
  549|      0|         return Positive;
  550|    247|      }
_ZN5Botan6BigInt9flip_signEv:
  555|    247|      void flip_sign() { set_sign(reverse_sign()); }
_ZN5Botan6BigInt8set_signENS0_4SignE:
  561|    247|      void set_sign(Sign sign) {
  562|    247|         if(sign == Negative && is_zero()) {
  ------------------
  |  Branch (562:13): [True: 247, False: 0]
  |  Branch (562:33): [True: 0, False: 247]
  ------------------
  563|      0|            sign = Positive;
  564|      0|         }
  565|       |
  566|    247|         m_signedness = sign;
  567|    247|      }
_ZNK5Botan6BigInt9sig_wordsEv:
  584|  1.07k|      size_t sig_words() const { return m_data.sig_words(); }
_ZNK5Botan6BigInt19const_time_unpoisonEv:
  726|  1.17k|      void const_time_unpoison() const {}
_ZN5Botan6BigInt6encodeERKS0_:
  753|    181|      static std::vector<uint8_t> encode(const BigInt& n) {
  754|    181|         std::vector<uint8_t> output(n.bytes());
  755|    181|         n.binary_encode(output.data());
  756|    181|         return output;
  757|    181|      }
_ZNK5Botan6BigInt4Data11get_word_atEm:
  848|    562|            word get_word_at(size_t n) const {
  849|    562|               if(n < m_reg.size()) {
  ------------------
  |  Branch (849:19): [True: 550, False: 12]
  ------------------
  850|    550|                  return m_reg[n];
  851|    550|               }
  852|     12|               return 0;
  853|    562|            }
_ZN5Botan6BigInt4Data11set_to_zeroEv:
  871|    529|            void set_to_zero() {
  872|    529|               m_reg.resize(m_reg.capacity());
  873|    529|               clear_mem(m_reg.data(), m_reg.size());
  874|    529|               m_sig_words = 0;
  875|    529|            }
_ZN5Botan6BigInt4Data4swapERS1_:
  921|    454|            void swap(Data& other) {
  922|    454|               m_reg.swap(other.m_reg);
  923|    454|               std::swap(m_sig_words, other.m_sig_words);
  924|    454|            }
_ZN5Botan6BigInt4Data4swapERNSt3__16vectorImNS_16secure_allocatorImEEEE:
  926|    454|            void swap(secure_vector<word>& reg) {
  927|    454|               m_reg.swap(reg);
  928|    454|               invalidate_sig_words();
  929|    454|            }
_ZNK5Botan6BigInt4Data20invalidate_sig_wordsEv:
  931|    454|            void invalidate_sig_words() const { m_sig_words = sig_words_npos; }
_ZNK5Botan6BigInt4Data9sig_wordsEv:
  933|  1.07k|            size_t sig_words() const {
  934|  1.07k|               if(m_sig_words == sig_words_npos) {
  ------------------
  |  Branch (934:19): [True: 415, False: 657]
  ------------------
  935|    415|                  m_sig_words = calc_sig_words();
  936|    657|               } else {
  937|    657|                  BOTAN_DEBUG_ASSERT(m_sig_words == calc_sig_words());
  ------------------
  |  |   99|    657|      do {                          \
  |  |  100|    657|      } while(0)
  |  |  ------------------
  |  |  |  Branch (100:15): [Folded - Ignored]
  |  |  ------------------
  ------------------
  938|    657|               }
  939|  1.07k|               return m_sig_words;
  940|  1.07k|            }
_ZN5Botan6BigIntC2Ev:
   40|    723|      BigInt() = default;

_ZN5Botan20Buffered_Computation6updateEPKhm:
   35|  31.1k|      void update(const uint8_t in[], size_t length) { add_data({in, length}); }
_ZN5Botan20Buffered_Computation6updateENSt3__14spanIKhLm18446744073709551615EEE:
   41|  5.64k|      void update(std::span<const uint8_t> in) { add_data(in); }
_ZN5Botan20Buffered_Computation12final_stdvecEv:
   84|  33.8k|      std::vector<uint8_t> final_stdvec() { return final<std::vector<uint8_t>>(); }
_ZN5Botan20Buffered_Computation5finalINSt3__16vectorIhNS2_9allocatorIhEEEEEET_v:
   78|  33.8k|      T final() {
   79|  33.8k|         T output(output_length());
   80|  33.8k|         final_result(output);
   81|  33.8k|         return output;
   82|  33.8k|      }
_ZN5Botan20Buffered_Computation5finalINSt3__16vectorIhNS_16secure_allocatorIhEEEEEET_v:
   78|    174|      T final() {
   79|    174|         T output(output_length());
   80|    174|         final_result(output);
   81|    174|         return output;
   82|    174|      }
_ZN5Botan20Buffered_ComputationD2Ev:
  134|  39.5k|      virtual ~Buffered_Computation() = default;
_ZN5Botan20Buffered_Computation7processINSt3__16vectorIhNS_16secure_allocatorIhEEEEEET_PKhm:
  105|    174|      T process(const uint8_t in[], size_t length) {
  106|    174|         update(in, length);
  107|    174|         return final<T>();
  108|    174|      }

_ZN5Botan6ranges24assert_exact_byte_lengthILm1ERNSt3__14spanIKhLm1EEEEEvOT0_:
   86|  3.63M|inline constexpr void assert_exact_byte_length(R&& r) {
   87|  3.63M|   const std::span s{r};
   88|  3.63M|   if constexpr(decltype(s)::extent != std::dynamic_extent) {
  ------------------
  |  Branch (88:17): [Folded - Ignored]
  ------------------
   89|  3.63M|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   90|  3.63M|   } else {
   91|  3.63M|      BOTAN_ASSERT(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   92|  3.63M|   }
   93|  3.63M|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm4ERNSt3__14spanIhLm4EEEEEvOT0_:
   86|   271k|inline constexpr void assert_exact_byte_length(R&& r) {
   87|   271k|   const std::span s{r};
   88|   271k|   if constexpr(decltype(s)::extent != std::dynamic_extent) {
  ------------------
  |  Branch (88:17): [Folded - Ignored]
  ------------------
   89|   271k|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   90|   271k|   } else {
   91|   271k|      BOTAN_ASSERT(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   92|   271k|   }
   93|   271k|}
_ZN5Botan6ranges25assert_equal_byte_lengthsIRNSt3__14spanIhLm4EEEJRNS3_IKjLm1EEEEEEvOT_DpOT0_:
  107|   271k|{
  108|   271k|   const std::span s0{r0};
  109|       |
  110|   271k|   if constexpr(decltype(s0)::extent != std::dynamic_extent) {
  ------------------
  |  Branch (110:17): [Folded - Ignored]
  ------------------
  111|   271k|      constexpr size_t expected_size = s0.size_bytes();
  112|   271k|      (assert_exact_byte_length<expected_size>(rs), ...);
  113|   271k|   } else {
  114|   271k|      const size_t expected_size = s0.size_bytes();
  115|   271k|      BOTAN_ARG_CHECK(((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...),
  116|   271k|                      "memory regions don't have equal lengths");
  117|   271k|   }
  118|   271k|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm4ERNSt3__14spanIKjLm1EEEEEvOT0_:
   86|   271k|inline constexpr void assert_exact_byte_length(R&& r) {
   87|   271k|   const std::span s{r};
   88|   271k|   if constexpr(decltype(s)::extent != std::dynamic_extent) {
  ------------------
  |  Branch (88:17): [Folded - Ignored]
  ------------------
   89|   271k|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   90|   271k|   } else {
   91|   271k|      BOTAN_ASSERT(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   92|   271k|   }
   93|   271k|}
_ZN5Botan6ranges10size_bytesIRNSt3__14spanIhLm4EEEEEmOT_:
   73|   271k|inline constexpr size_t size_bytes(spanable_range auto&& r) {
   74|   271k|   return std::span{r}.size_bytes();
   75|   271k|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm2ERNSt3__14spanIKhLm2EEEEEvOT0_:
   86|  88.9k|inline constexpr void assert_exact_byte_length(R&& r) {
   87|  88.9k|   const std::span s{r};
   88|  88.9k|   if constexpr(decltype(s)::extent != std::dynamic_extent) {
  ------------------
  |  Branch (88:17): [Folded - Ignored]
  ------------------
   89|  88.9k|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   90|  88.9k|   } else {
   91|  88.9k|      BOTAN_ASSERT(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   92|  88.9k|   }
   93|  88.9k|}
_ZN5Botan6ranges25assert_equal_byte_lengthsIRNSt3__14spanItLm1EEEJRNS3_IKhLm2EEEEEEvOT_DpOT0_:
  107|  44.4k|{
  108|  44.4k|   const std::span s0{r0};
  109|       |
  110|  44.4k|   if constexpr(decltype(s0)::extent != std::dynamic_extent) {
  ------------------
  |  Branch (110:17): [Folded - Ignored]
  ------------------
  111|  44.4k|      constexpr size_t expected_size = s0.size_bytes();
  112|  44.4k|      (assert_exact_byte_length<expected_size>(rs), ...);
  113|  44.4k|   } else {
  114|  44.4k|      const size_t expected_size = s0.size_bytes();
  115|  44.4k|      BOTAN_ARG_CHECK(((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...),
  116|  44.4k|                      "memory regions don't have equal lengths");
  117|  44.4k|   }
  118|  44.4k|}
_ZN5Botan6ranges10size_bytesIRNSt3__14spanItLm1EEEEEmOT_:
   73|  44.4k|inline constexpr size_t size_bytes(spanable_range auto&& r) {
   74|  44.4k|   return std::span{r}.size_bytes();
   75|  44.4k|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm8ERNSt3__14spanIhLm8EEEEEvOT0_:
   86|  34.0k|inline constexpr void assert_exact_byte_length(R&& r) {
   87|  34.0k|   const std::span s{r};
   88|  34.0k|   if constexpr(decltype(s)::extent != std::dynamic_extent) {
  ------------------
  |  Branch (88:17): [Folded - Ignored]
  ------------------
   89|  34.0k|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   90|  34.0k|   } else {
   91|  34.0k|      BOTAN_ASSERT(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   92|  34.0k|   }
   93|  34.0k|}
_ZN5Botan6ranges25assert_equal_byte_lengthsIRNSt3__14spanIhLm8EEEJRNS3_IKmLm1EEEEEEvOT_DpOT0_:
  107|  34.0k|{
  108|  34.0k|   const std::span s0{r0};
  109|       |
  110|  34.0k|   if constexpr(decltype(s0)::extent != std::dynamic_extent) {
  ------------------
  |  Branch (110:17): [Folded - Ignored]
  ------------------
  111|  34.0k|      constexpr size_t expected_size = s0.size_bytes();
  112|  34.0k|      (assert_exact_byte_length<expected_size>(rs), ...);
  113|  34.0k|   } else {
  114|  34.0k|      const size_t expected_size = s0.size_bytes();
  115|  34.0k|      BOTAN_ARG_CHECK(((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...),
  116|  34.0k|                      "memory regions don't have equal lengths");
  117|  34.0k|   }
  118|  34.0k|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm8ERNSt3__14spanIKmLm1EEEEEvOT0_:
   86|  34.0k|inline constexpr void assert_exact_byte_length(R&& r) {
   87|  34.0k|   const std::span s{r};
   88|  34.0k|   if constexpr(decltype(s)::extent != std::dynamic_extent) {
  ------------------
  |  Branch (88:17): [Folded - Ignored]
  ------------------
   89|  34.0k|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   90|  34.0k|   } else {
   91|  34.0k|      BOTAN_ASSERT(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   92|  34.0k|   }
   93|  34.0k|}
_ZN5Botan6ranges10size_bytesIRNSt3__14spanIhLm8EEEEEmOT_:
   73|  34.0k|inline constexpr size_t size_bytes(spanable_range auto&& r) {
   74|  34.0k|   return std::span{r}.size_bytes();
   75|  34.0k|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm8ERNSt3__14spanIKhLm8EEEEEvOT0_:
   86|    588|inline constexpr void assert_exact_byte_length(R&& r) {
   87|    588|   const std::span s{r};
   88|    588|   if constexpr(decltype(s)::extent != std::dynamic_extent) {
  ------------------
  |  Branch (88:17): [Folded - Ignored]
  ------------------
   89|    588|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   90|    588|   } else {
   91|    588|      BOTAN_ASSERT(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   92|    588|   }
   93|    588|}
_ZN5Botan6ranges25assert_equal_byte_lengthsIRNSt3__14spanImLm1EEEJRNS3_IKhLm8EEEEEEvOT_DpOT0_:
  107|    294|{
  108|    294|   const std::span s0{r0};
  109|       |
  110|    294|   if constexpr(decltype(s0)::extent != std::dynamic_extent) {
  ------------------
  |  Branch (110:17): [Folded - Ignored]
  ------------------
  111|    294|      constexpr size_t expected_size = s0.size_bytes();
  112|    294|      (assert_exact_byte_length<expected_size>(rs), ...);
  113|    294|   } else {
  114|    294|      const size_t expected_size = s0.size_bytes();
  115|    294|      BOTAN_ARG_CHECK(((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...),
  116|    294|                      "memory regions don't have equal lengths");
  117|    294|   }
  118|    294|}
_ZN5Botan6ranges10size_bytesIRNSt3__14spanImLm1EEEEEmOT_:
   73|    294|inline constexpr size_t size_bytes(spanable_range auto&& r) {
   74|    294|   return std::span{r}.size_bytes();
   75|    294|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm4ERNSt3__14spanIKhLm4EEEEEvOT0_:
   86|  1.80M|inline constexpr void assert_exact_byte_length(R&& r) {
   87|  1.80M|   const std::span s{r};
   88|  1.80M|   if constexpr(decltype(s)::extent != std::dynamic_extent) {
  ------------------
  |  Branch (88:17): [Folded - Ignored]
  ------------------
   89|  1.80M|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   90|  1.80M|   } else {
   91|  1.80M|      BOTAN_ASSERT(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   92|  1.80M|   }
   93|  1.80M|}
_ZN5Botan6ranges25assert_equal_byte_lengthsIRNSt3__14spanIjLm1EEEJRNS3_IKhLm4EEEEEEvOT_DpOT0_:
  107|   901k|{
  108|   901k|   const std::span s0{r0};
  109|       |
  110|   901k|   if constexpr(decltype(s0)::extent != std::dynamic_extent) {
  ------------------
  |  Branch (110:17): [Folded - Ignored]
  ------------------
  111|   901k|      constexpr size_t expected_size = s0.size_bytes();
  112|   901k|      (assert_exact_byte_length<expected_size>(rs), ...);
  113|   901k|   } else {
  114|   901k|      const size_t expected_size = s0.size_bytes();
  115|   901k|      BOTAN_ARG_CHECK(((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...),
  116|   901k|                      "memory regions don't have equal lengths");
  117|   901k|   }
  118|   901k|}
_ZN5Botan6ranges10size_bytesIRNSt3__14spanIjLm1EEEEEmOT_:
   73|   901k|inline constexpr size_t size_bytes(spanable_range auto&& r) {
   74|   901k|   return std::span{r}.size_bytes();
   75|   901k|}

_ZN5Botan17DataSource_MemoryC2ERKNSt3__16vectorIhNS1_9allocatorIhEEEE:
  136|    223|      explicit DataSource_Memory(const std::vector<uint8_t>& in) : m_source(in.begin(), in.end()), m_offset(0) {}
_ZN5Botan10DataSourceC2Ev:
   91|  42.4k|      DataSource() = default;
_ZN5Botan10DataSourceD2Ev:
   92|  42.4k|      virtual ~DataSource() = default;
_ZN5Botan17DataSource_MemoryC2EPKhm:
  118|  10.7k|      DataSource_Memory(const uint8_t in[], size_t length) : m_source(in, in + length), m_offset(0) {}
_ZN5Botan17DataSource_MemoryC2ENSt3__16vectorIhNS_16secure_allocatorIhEEEE:
  124|  16.6k|      explicit DataSource_Memory(secure_vector<uint8_t> in) : m_source(std::move(in)), m_offset(0) {}

_ZN5Botan11DER_Encoder14start_sequenceEv:
   65|    951|      DER_Encoder& start_sequence() { return start_cons(ASN1_Type::Sequence, ASN1_Class::Universal); }
_ZN5Botan11DER_Encoder10add_objectENS_9ASN1_TypeENS_10ASN1_ClassERKNSt3__16vectorIhNS3_9allocatorIhEEEE:
  163|     87|      DER_Encoder& add_object(ASN1_Type type_tag, ASN1_Class class_tag, const std::vector<uint8_t>& rep) {
  164|     87|         return add_object(type_tag, class_tag, rep.data(), rep.size());
  165|     87|      }
_ZN5Botan11DER_Encoder10add_objectENS_9ASN1_TypeENS_10ASN1_ClassERKNSt3__16vectorIhNS_16secure_allocatorIhEEEE:
  167|     87|      DER_Encoder& add_object(ASN1_Type type_tag, ASN1_Class class_tag, const secure_vector<uint8_t>& rep) {
  168|     87|         return add_object(type_tag, class_tag, rep.data(), rep.size());
  169|     87|      }
_ZN5Botan11DER_Encoder12DER_SequenceC2EOS1_:
  192|  1.94k|                  m_set_contents(std::move(seq.m_set_contents)) {}
_ZN5Botan11DER_Encoder6encodeINSt3__19allocatorIhEEEERS0_RKNS2_6vectorIhT_EENS_9ASN1_TypeE:
   99|     87|      DER_Encoder& encode(const std::vector<uint8_t, Alloc>& vec, ASN1_Type real_type) {
  100|     87|         return encode(vec.data(), vec.size(), real_type);
  101|     87|      }
_ZN5Botan11DER_Encoder9raw_bytesINSt3__19allocatorIhEEEERS0_RKNS2_6vectorIhT_EE:
   88|    223|      DER_Encoder& raw_bytes(const std::vector<uint8_t, Alloc>& val) {
   89|    223|         return raw_bytes(val.data(), val.size());
   90|    223|      }

_ZNK5Botan9Exception4whatEv:
   93|  1.59k|      const char* what() const noexcept override { return m_msg.c_str(); }
_ZN5Botan13Invalid_StateC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
  208|     14|      explicit Invalid_State(std::string_view err) : Exception(err) {}

_ZN5Botan10hex_encodeENSt3__14spanIKhLm18446744073709551615EEEb:
   43|    174|inline std::string hex_encode(std::span<const uint8_t> input, bool uppercase = true) {
   44|    174|   return hex_encode(input.data(), input.size(), uppercase);
   45|    174|}

_ZN5Botan11clear_bytesEPvm:
  103|  80.9k|inline constexpr void clear_bytes(void* ptr, size_t bytes) {
  104|  80.9k|   if(bytes > 0) {
  ------------------
  |  Branch (104:7): [True: 80.3k, False: 540]
  ------------------
  105|  80.3k|      std::memset(ptr, 0, bytes);
  106|  80.3k|   }
  107|  80.9k|}
_ZN5Botan22cast_uint8_ptr_to_charEPKh:
  276|  2.53k|inline const char* cast_uint8_ptr_to_char(const uint8_t* b) {
  277|  2.53k|   return reinterpret_cast<const char*>(b);
  278|  2.53k|}
_ZN5Botan22cast_uint8_ptr_to_charEPh:
  284|  5.28k|inline char* cast_uint8_ptr_to_char(uint8_t* b) {
  285|  5.28k|   return reinterpret_cast<char*>(b);
  286|  5.28k|}
_ZN5Botan9clear_memImEEvPT_m:
  120|    529|inline constexpr void clear_mem(T* ptr, size_t n) {
  121|    529|   clear_bytes(ptr, sizeof(T) * n);
  122|    529|}
_ZN5Botan13typecast_copyIRNSt3__14spanIhLm4EEEjEEvOT_RKT0_:
  199|   271k|inline constexpr void typecast_copy(ToR&& out, const FromT& in) {
  200|   271k|   typecast_copy(out, std::span<const FromT, 1>(&in, 1));
  201|   271k|}
_ZN5Botan13typecast_copyIRNSt3__14spanIhLm4EEENS2_IKjLm1EEEEEvOT_OT0_:
  176|   271k|inline constexpr void typecast_copy(ToR&& out, FromR&& in) {
  177|   271k|   ranges::assert_equal_byte_lengths(out, in);
  178|   271k|   std::memcpy(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  179|   271k|}
_ZN5Botan13typecast_copyItRNSt3__14spanIKhLm2EEEEET_OT0_:
  209|  44.4k|inline constexpr ToT typecast_copy(FromR&& src) noexcept {
  210|  44.4k|   ToT dst;
  211|  44.4k|   typecast_copy(dst, src);
  212|  44.4k|   return dst;
  213|  44.4k|}
_ZN5Botan13typecast_copyItRNSt3__14spanIKhLm2EEEEEvRT_OT0_:
  188|  44.4k|inline constexpr void typecast_copy(ToT& out, FromR&& in) noexcept {
  189|  44.4k|   typecast_copy(std::span<ToT, 1>(&out, 1), in);
  190|  44.4k|}
_ZN5Botan13typecast_copyINSt3__14spanItLm1EEERNS2_IKhLm2EEEEEvOT_OT0_:
  176|  44.4k|inline constexpr void typecast_copy(ToR&& out, FromR&& in) {
  177|  44.4k|   ranges::assert_equal_byte_lengths(out, in);
  178|  44.4k|   std::memcpy(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  179|  44.4k|}
_ZN5Botan13typecast_copyIRNSt3__14spanIhLm8EEEmEEvOT_RKT0_:
  199|  34.0k|inline constexpr void typecast_copy(ToR&& out, const FromT& in) {
  200|  34.0k|   typecast_copy(out, std::span<const FromT, 1>(&in, 1));
  201|  34.0k|}
_ZN5Botan13typecast_copyIRNSt3__14spanIhLm8EEENS2_IKmLm1EEEEEvOT_OT0_:
  176|  34.0k|inline constexpr void typecast_copy(ToR&& out, FromR&& in) {
  177|  34.0k|   ranges::assert_equal_byte_lengths(out, in);
  178|  34.0k|   std::memcpy(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  179|  34.0k|}
_ZN5Botan13typecast_copyImRNSt3__14spanIKhLm8EEEEET_OT0_:
  209|    294|inline constexpr ToT typecast_copy(FromR&& src) noexcept {
  210|    294|   ToT dst;
  211|    294|   typecast_copy(dst, src);
  212|    294|   return dst;
  213|    294|}
_ZN5Botan13typecast_copyImRNSt3__14spanIKhLm8EEEEEvRT_OT0_:
  188|    294|inline constexpr void typecast_copy(ToT& out, FromR&& in) noexcept {
  189|    294|   typecast_copy(std::span<ToT, 1>(&out, 1), in);
  190|    294|}
_ZN5Botan13typecast_copyINSt3__14spanImLm1EEERNS2_IKhLm8EEEEEvOT_OT0_:
  176|    294|inline constexpr void typecast_copy(ToR&& out, FromR&& in) {
  177|    294|   ranges::assert_equal_byte_lengths(out, in);
  178|    294|   std::memcpy(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  179|    294|}
_ZN5Botan8copy_memIhEEvPT_PKS1_m:
  146|   495k|inline constexpr void copy_mem(T* out, const T* in, size_t n) {
  147|   495k|   BOTAN_ASSERT_IMPLICATION(n > 0, in != nullptr && out != nullptr, "If n > 0 then args are not null");
  ------------------
  |  |   78|   495k|   do {                                                                                          \
  |  |   79|   928k|      if((expr1) && !(expr2))                                                                    \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 464k, False: 31.4k]
  |  |  |  Branch (79:23): [True: 464k, False: 0]
  |  |  |  Branch (79:23): [True: 464k, False: 0]
  |  |  ------------------
  |  |   80|   495k|         Botan::assertion_failure(#expr1 " implies " #expr2, msg, __func__, __FILE__, __LINE__); \
  |  |   81|   495k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (81:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  148|       |
  149|   495k|   if(in != nullptr && out != nullptr && n > 0) {
  ------------------
  |  Branch (149:7): [True: 488k, False: 7.45k]
  |  Branch (149:24): [True: 479k, False: 8.80k]
  |  Branch (149:42): [True: 464k, False: 15.1k]
  ------------------
  150|   464k|      std::memmove(out, in, sizeof(T) * n);
  151|   464k|   }
  152|   495k|}
_ZN5Botan13typecast_copyIjRNSt3__14spanIKhLm4EEEEET_OT0_:
  209|   901k|inline constexpr ToT typecast_copy(FromR&& src) noexcept {
  210|   901k|   ToT dst;
  211|   901k|   typecast_copy(dst, src);
  212|   901k|   return dst;
  213|   901k|}
_ZN5Botan13typecast_copyIjRNSt3__14spanIKhLm4EEEEEvRT_OT0_:
  188|   901k|inline constexpr void typecast_copy(ToT& out, FromR&& in) noexcept {
  189|   901k|   typecast_copy(std::span<ToT, 1>(&out, 1), in);
  190|   901k|}
_ZN5Botan13typecast_copyINSt3__14spanIjLm1EEERNS2_IKhLm4EEEEEvOT_OT0_:
  176|   901k|inline constexpr void typecast_copy(ToR&& out, FromR&& in) {
  177|   901k|   ranges::assert_equal_byte_lengths(out, in);
  178|   901k|   std::memcpy(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  179|   901k|}
_ZN5Botan9clear_memIhEEvPT_m:
  120|  80.4k|inline constexpr void clear_mem(T* ptr, size_t n) {
  121|  80.4k|   clear_bytes(ptr, sizeof(T) * n);
  122|  80.4k|}
_ZN5Botan9clear_memIjEEvPT_m:
  120|      1|inline constexpr void clear_mem(T* ptr, size_t n) {
  121|      1|   clear_bytes(ptr, sizeof(T) * n);
  122|      1|}
_ZN5Botan8copy_memIiEEvPT_PKS1_m:
  146|  1.53k|inline constexpr void copy_mem(T* out, const T* in, size_t n) {
  147|  1.53k|   BOTAN_ASSERT_IMPLICATION(n > 0, in != nullptr && out != nullptr, "If n > 0 then args are not null");
  ------------------
  |  |   78|  1.53k|   do {                                                                                          \
  |  |   79|  3.07k|      if((expr1) && !(expr2))                                                                    \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 1.53k, False: 0]
  |  |  |  Branch (79:23): [True: 1.53k, False: 0]
  |  |  |  Branch (79:23): [True: 1.53k, False: 0]
  |  |  ------------------
  |  |   80|  1.53k|         Botan::assertion_failure(#expr1 " implies " #expr2, msg, __func__, __FILE__, __LINE__); \
  |  |   81|  1.53k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (81:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  148|       |
  149|  1.53k|   if(in != nullptr && out != nullptr && n > 0) {
  ------------------
  |  Branch (149:7): [True: 1.53k, False: 0]
  |  Branch (149:24): [True: 1.53k, False: 0]
  |  Branch (149:42): [True: 1.53k, False: 0]
  ------------------
  150|  1.53k|      std::memmove(out, in, sizeof(T) * n);
  151|  1.53k|   }
  152|  1.53k|}

_ZN5Botan22create_hex_fingerprintENSt3__14spanIKhLm18446744073709551615EEENS0_17basic_string_viewIcNS0_11char_traitsIcEEEE:
  386|    174|inline std::string create_hex_fingerprint(std::span<const uint8_t> vec, std::string_view hash_name) {
  387|    174|   return create_hex_fingerprint(vec.data(), vec.size(), hash_name);
  388|    174|}
_ZN5Botan14Asymmetric_KeyD2Ev:
   61|      6|      virtual ~Asymmetric_Key() = default;

_ZN5Botan15Key_ConstraintsC2Ev:
  143|    593|      Key_Constraints() : m_value(0) {}

_ZNK5Botan7X509_DN8get_bitsEv:
   62|    362|      const std::vector<uint8_t>& get_bits() const { return m_dn_bits; }
_ZN5Botan15NameConstraintsC2Ev:
  299|    593|      NameConstraints() : m_permitted_subtrees(), m_excluded_subtrees() {}
_ZN5Botan7X509_DNC2Ev:
   39|  5.15k|      X509_DN() = default;
_ZN5Botan10ExtensionsC2Ev:
  517|    593|      Extensions() = default;
_ZNK5Botan10Extensions23get_extension_object_asINS_14Cert_Extension9Key_UsageEEEPKT_RKNS_3OIDE:
  397|    136|      const T* get_extension_object_as(const OID& oid = T::static_oid()) const {
  398|    136|         if(const Certificate_Extension* extn = get_extension_object(oid)) {
  ------------------
  |  Branch (398:42): [True: 0, False: 136]
  ------------------
  399|       |            // Unknown_Extension oid_name is empty
  400|      0|            if(extn->oid_name().empty()) {
  ------------------
  |  Branch (400:16): [True: 0, False: 0]
  ------------------
  401|      0|               return nullptr;
  402|      0|            } else if(const T* extn_as_T = dynamic_cast<const T*>(extn)) {
  ------------------
  |  Branch (402:32): [True: 0, False: 0]
  ------------------
  403|      0|               return extn_as_T;
  404|      0|            } else {
  405|      0|               throw Decoding_Error("Exception::get_extension_object_as dynamic_cast failed");
  406|      0|            }
  407|      0|         }
  408|       |
  409|    136|         return nullptr;
  410|    136|      }
_ZNK5Botan10Extensions23get_extension_object_asINS_14Cert_Extension14Subject_Key_IDEEEPKT_RKNS_3OIDE:
  397|    136|      const T* get_extension_object_as(const OID& oid = T::static_oid()) const {
  398|    136|         if(const Certificate_Extension* extn = get_extension_object(oid)) {
  ------------------
  |  Branch (398:42): [True: 0, False: 136]
  ------------------
  399|       |            // Unknown_Extension oid_name is empty
  400|      0|            if(extn->oid_name().empty()) {
  ------------------
  |  Branch (400:16): [True: 0, False: 0]
  ------------------
  401|      0|               return nullptr;
  402|      0|            } else if(const T* extn_as_T = dynamic_cast<const T*>(extn)) {
  ------------------
  |  Branch (402:32): [True: 0, False: 0]
  ------------------
  403|      0|               return extn_as_T;
  404|      0|            } else {
  405|      0|               throw Decoding_Error("Exception::get_extension_object_as dynamic_cast failed");
  406|      0|            }
  407|      0|         }
  408|       |
  409|    136|         return nullptr;
  410|    136|      }
_ZNK5Botan10Extensions23get_extension_object_asINS_14Cert_Extension16Authority_Key_IDEEEPKT_RKNS_3OIDE:
  397|    136|      const T* get_extension_object_as(const OID& oid = T::static_oid()) const {
  398|    136|         if(const Certificate_Extension* extn = get_extension_object(oid)) {
  ------------------
  |  Branch (398:42): [True: 0, False: 136]
  ------------------
  399|       |            // Unknown_Extension oid_name is empty
  400|      0|            if(extn->oid_name().empty()) {
  ------------------
  |  Branch (400:16): [True: 0, False: 0]
  ------------------
  401|      0|               return nullptr;
  402|      0|            } else if(const T* extn_as_T = dynamic_cast<const T*>(extn)) {
  ------------------
  |  Branch (402:32): [True: 0, False: 0]
  ------------------
  403|      0|               return extn_as_T;
  404|      0|            } else {
  405|      0|               throw Decoding_Error("Exception::get_extension_object_as dynamic_cast failed");
  406|      0|            }
  407|      0|         }
  408|       |
  409|    136|         return nullptr;
  410|    136|      }
_ZNK5Botan10Extensions23get_extension_object_asINS_14Cert_Extension16Name_ConstraintsEEEPKT_RKNS_3OIDE:
  397|    136|      const T* get_extension_object_as(const OID& oid = T::static_oid()) const {
  398|    136|         if(const Certificate_Extension* extn = get_extension_object(oid)) {
  ------------------
  |  Branch (398:42): [True: 0, False: 136]
  ------------------
  399|       |            // Unknown_Extension oid_name is empty
  400|      0|            if(extn->oid_name().empty()) {
  ------------------
  |  Branch (400:16): [True: 0, False: 0]
  ------------------
  401|      0|               return nullptr;
  402|      0|            } else if(const T* extn_as_T = dynamic_cast<const T*>(extn)) {
  ------------------
  |  Branch (402:32): [True: 0, False: 0]
  ------------------
  403|      0|               return extn_as_T;
  404|      0|            } else {
  405|      0|               throw Decoding_Error("Exception::get_extension_object_as dynamic_cast failed");
  406|      0|            }
  407|      0|         }
  408|       |
  409|    136|         return nullptr;
  410|    136|      }
_ZNK5Botan10Extensions23get_extension_object_asINS_14Cert_Extension17Basic_ConstraintsEEEPKT_RKNS_3OIDE:
  397|    136|      const T* get_extension_object_as(const OID& oid = T::static_oid()) const {
  398|    136|         if(const Certificate_Extension* extn = get_extension_object(oid)) {
  ------------------
  |  Branch (398:42): [True: 0, False: 136]
  ------------------
  399|       |            // Unknown_Extension oid_name is empty
  400|      0|            if(extn->oid_name().empty()) {
  ------------------
  |  Branch (400:16): [True: 0, False: 0]
  ------------------
  401|      0|               return nullptr;
  402|      0|            } else if(const T* extn_as_T = dynamic_cast<const T*>(extn)) {
  ------------------
  |  Branch (402:32): [True: 0, False: 0]
  ------------------
  403|      0|               return extn_as_T;
  404|      0|            } else {
  405|      0|               throw Decoding_Error("Exception::get_extension_object_as dynamic_cast failed");
  406|      0|            }
  407|      0|         }
  408|       |
  409|    136|         return nullptr;
  410|    136|      }
_ZNK5Botan10Extensions23get_extension_object_asINS_14Cert_Extension23Issuer_Alternative_NameEEEPKT_RKNS_3OIDE:
  397|    136|      const T* get_extension_object_as(const OID& oid = T::static_oid()) const {
  398|    136|         if(const Certificate_Extension* extn = get_extension_object(oid)) {
  ------------------
  |  Branch (398:42): [True: 0, False: 136]
  ------------------
  399|       |            // Unknown_Extension oid_name is empty
  400|      0|            if(extn->oid_name().empty()) {
  ------------------
  |  Branch (400:16): [True: 0, False: 0]
  ------------------
  401|      0|               return nullptr;
  402|      0|            } else if(const T* extn_as_T = dynamic_cast<const T*>(extn)) {
  ------------------
  |  Branch (402:32): [True: 0, False: 0]
  ------------------
  403|      0|               return extn_as_T;
  404|      0|            } else {
  405|      0|               throw Decoding_Error("Exception::get_extension_object_as dynamic_cast failed");
  406|      0|            }
  407|      0|         }
  408|       |
  409|    136|         return nullptr;
  410|    136|      }
_ZNK5Botan10Extensions23get_extension_object_asINS_14Cert_Extension24Subject_Alternative_NameEEEPKT_RKNS_3OIDE:
  397|    136|      const T* get_extension_object_as(const OID& oid = T::static_oid()) const {
  398|    136|         if(const Certificate_Extension* extn = get_extension_object(oid)) {
  ------------------
  |  Branch (398:42): [True: 0, False: 136]
  ------------------
  399|       |            // Unknown_Extension oid_name is empty
  400|      0|            if(extn->oid_name().empty()) {
  ------------------
  |  Branch (400:16): [True: 0, False: 0]
  ------------------
  401|      0|               return nullptr;
  402|      0|            } else if(const T* extn_as_T = dynamic_cast<const T*>(extn)) {
  ------------------
  |  Branch (402:32): [True: 0, False: 0]
  ------------------
  403|      0|               return extn_as_T;
  404|      0|            } else {
  405|      0|               throw Decoding_Error("Exception::get_extension_object_as dynamic_cast failed");
  406|      0|            }
  407|      0|         }
  408|       |
  409|    136|         return nullptr;
  410|    136|      }
_ZNK5Botan10Extensions23get_extension_object_asINS_14Cert_Extension18Extended_Key_UsageEEEPKT_RKNS_3OIDE:
  397|    136|      const T* get_extension_object_as(const OID& oid = T::static_oid()) const {
  398|    136|         if(const Certificate_Extension* extn = get_extension_object(oid)) {
  ------------------
  |  Branch (398:42): [True: 0, False: 136]
  ------------------
  399|       |            // Unknown_Extension oid_name is empty
  400|      0|            if(extn->oid_name().empty()) {
  ------------------
  |  Branch (400:16): [True: 0, False: 0]
  ------------------
  401|      0|               return nullptr;
  402|      0|            } else if(const T* extn_as_T = dynamic_cast<const T*>(extn)) {
  ------------------
  |  Branch (402:32): [True: 0, False: 0]
  ------------------
  403|      0|               return extn_as_T;
  404|      0|            } else {
  405|      0|               throw Decoding_Error("Exception::get_extension_object_as dynamic_cast failed");
  406|      0|            }
  407|      0|         }
  408|       |
  409|    136|         return nullptr;
  410|    136|      }
_ZNK5Botan10Extensions23get_extension_object_asINS_14Cert_Extension20Certificate_PoliciesEEEPKT_RKNS_3OIDE:
  397|    136|      const T* get_extension_object_as(const OID& oid = T::static_oid()) const {
  398|    136|         if(const Certificate_Extension* extn = get_extension_object(oid)) {
  ------------------
  |  Branch (398:42): [True: 0, False: 136]
  ------------------
  399|       |            // Unknown_Extension oid_name is empty
  400|      0|            if(extn->oid_name().empty()) {
  ------------------
  |  Branch (400:16): [True: 0, False: 0]
  ------------------
  401|      0|               return nullptr;
  402|      0|            } else if(const T* extn_as_T = dynamic_cast<const T*>(extn)) {
  ------------------
  |  Branch (402:32): [True: 0, False: 0]
  ------------------
  403|      0|               return extn_as_T;
  404|      0|            } else {
  405|      0|               throw Decoding_Error("Exception::get_extension_object_as dynamic_cast failed");
  406|      0|            }
  407|      0|         }
  408|       |
  409|    136|         return nullptr;
  410|    136|      }
_ZNK5Botan10Extensions23get_extension_object_asINS_14Cert_Extension28Authority_Information_AccessEEEPKT_RKNS_3OIDE:
  397|    136|      const T* get_extension_object_as(const OID& oid = T::static_oid()) const {
  398|    136|         if(const Certificate_Extension* extn = get_extension_object(oid)) {
  ------------------
  |  Branch (398:42): [True: 0, False: 136]
  ------------------
  399|       |            // Unknown_Extension oid_name is empty
  400|      0|            if(extn->oid_name().empty()) {
  ------------------
  |  Branch (400:16): [True: 0, False: 0]
  ------------------
  401|      0|               return nullptr;
  402|      0|            } else if(const T* extn_as_T = dynamic_cast<const T*>(extn)) {
  ------------------
  |  Branch (402:32): [True: 0, False: 0]
  ------------------
  403|      0|               return extn_as_T;
  404|      0|            } else {
  405|      0|               throw Decoding_Error("Exception::get_extension_object_as dynamic_cast failed");
  406|      0|            }
  407|      0|         }
  408|       |
  409|    136|         return nullptr;
  410|    136|      }
_ZNK5Botan10Extensions23get_extension_object_asINS_14Cert_Extension23CRL_Distribution_PointsEEEPKT_RKNS_3OIDE:
  397|    136|      const T* get_extension_object_as(const OID& oid = T::static_oid()) const {
  398|    136|         if(const Certificate_Extension* extn = get_extension_object(oid)) {
  ------------------
  |  Branch (398:42): [True: 0, False: 136]
  ------------------
  399|       |            // Unknown_Extension oid_name is empty
  400|      0|            if(extn->oid_name().empty()) {
  ------------------
  |  Branch (400:16): [True: 0, False: 0]
  ------------------
  401|      0|               return nullptr;
  402|      0|            } else if(const T* extn_as_T = dynamic_cast<const T*>(extn)) {
  ------------------
  |  Branch (402:32): [True: 0, False: 0]
  ------------------
  403|      0|               return extn_as_T;
  404|      0|            } else {
  405|      0|               throw Decoding_Error("Exception::get_extension_object_as dynamic_cast failed");
  406|      0|            }
  407|      0|         }
  408|       |
  409|    136|         return nullptr;
  410|    136|      }

_ZN5Botan16secure_allocatorIhE8allocateEm:
   45|  74.0k|      T* allocate(std::size_t n) { return static_cast<T*>(allocate_memory(n, sizeof(T))); }
_ZN5Botan16secure_allocatorIhE10deallocateEPhm:
   47|  74.0k|      void deallocate(T* p, std::size_t n) { deallocate_memory(p, n, sizeof(T)); }
_ZN5BotanneIhhEEbRKNS_16secure_allocatorIT_EERKNS1_IT0_EE:
   56|  2.43k|inline bool operator!=(const secure_allocator<T>&, const secure_allocator<U>&) {
   57|  2.43k|   return false;
   58|  2.43k|}
_ZN5Botan16secure_allocatorImE10deallocateEPmm:
   47|    454|      void deallocate(T* p, std::size_t n) { deallocate_memory(p, n, sizeof(T)); }
_ZN5Botan16secure_allocatorImE8allocateEm:
   45|    454|      T* allocate(std::size_t n) { return static_cast<T*>(allocate_memory(n, sizeof(T))); }
_ZN5BotanpLIhNS_16secure_allocatorIhEEmEERNSt3__16vectorIT_T0_EES8_RKNS3_4pairIPS5_T1_EE:
   98|  12.7k|std::vector<T, Alloc>& operator+=(std::vector<T, Alloc>& out, const std::pair<T*, L>& in) {
   99|  12.7k|   out.insert(out.end(), in.first, in.first + in.second);
  100|  12.7k|   return out;
  101|  12.7k|}
_ZN5BotanpLIhNS_16secure_allocatorIhEEmEERNSt3__16vectorIT_T0_EES8_RKNS3_4pairIPKS5_T1_EE:
   92|  1.64k|std::vector<T, Alloc>& operator+=(std::vector<T, Alloc>& out, const std::pair<const T*, L>& in) {
   93|  1.64k|   out.insert(out.end(), in.first, in.first + in.second);
   94|  1.64k|   return out;
   95|  1.64k|}
_ZN5Botan16secure_allocatorIjE10deallocateEPjm:
   47|  39.5k|      void deallocate(T* p, std::size_t n) { deallocate_memory(p, n, sizeof(T)); }
_ZN5Botan16secure_allocatorIjE8allocateEm:
   45|  39.5k|      T* allocate(std::size_t n) { return static_cast<T*>(allocate_memory(n, sizeof(T))); }

_ZN5Botan6detail11Strong_BaseINSt3__16vectorIhNS2_9allocatorIhEEEEEC2Ev:
   42|  14.8k|      Strong_Base() = default;
_ZN5Botan6detail11Strong_BaseINSt3__16vectorIhNS2_9allocatorIhEEEEEC2ES6_:
   48|  15.3k|      constexpr explicit Strong_Base(T v) : m_value(std::move(v)) {}
_ZN5Botan6detail11Strong_BaseINSt3__16vectorIhNS2_9allocatorIhEEEEEaSEOS7_:
   46|  14.7k|      Strong_Base& operator=(Strong_Base&&) noexcept = default;

_ZN5Botan3TLS12Group_ParamsC2Ev:
  149|  4.29k|      constexpr Group_Params() : m_code(Group_Params_Code::NONE) {}
_ZN5Botan3TLS12Group_ParamsC2Et:
  153|  8.60k|      constexpr Group_Params(uint16_t code) : m_code(static_cast<Group_Params_Code>(code)) {}
_ZNK5Botan3TLS12Group_ParamseqES1_:
  162|   126k|      constexpr bool operator==(Group_Params other) const { return m_code == other.m_code; }

_ZN5Botan3TLS13TLS_ExceptionC2ENS0_9AlertTypeENSt3__117basic_string_viewIcNS3_11char_traitsIcEEEE:
   24|  2.59k|            Exception(err_msg), m_alert_type(type) {}

_ZNK5Botan3TLS9Extension14is_implementedEv:
  116|    303|      virtual bool is_implemented() const { return true; }
_ZN5Botan3TLS21Server_Name_Indicator11static_typeEv:
  126|  29.7k|      static Extension_Code static_type() { return Extension_Code::ServerNameIndication; }
_ZNK5Botan3TLS21Server_Name_Indicator4typeEv:
  128|  29.7k|      Extension_Code type() const override { return static_type(); }
_ZN5Botan3TLS23Renegotiation_Extension11static_typeEv:
  149|  4.71k|      static Extension_Code static_type() { return Extension_Code::SafeRenegotiation; }
_ZNK5Botan3TLS23Renegotiation_Extension4typeEv:
  151|  3.10k|      Extension_Code type() const override { return static_type(); }
_ZNK5Botan3TLS23Renegotiation_Extension18renegotiation_infoEv:
  159|     67|      const std::vector<uint8_t>& renegotiation_info() const { return m_reneg_data; }
_ZN5Botan3TLS39Application_Layer_Protocol_Notification11static_typeEv:
  174|  17.6k|      static Extension_Code static_type() { return Extension_Code::ApplicationLayerProtocolNegotiation; }
_ZNK5Botan3TLS39Application_Layer_Protocol_Notification4typeEv:
  176|  17.6k|      Extension_Code type() const override { return static_type(); }
_ZN5Botan3TLS23Client_Certificate_Type11static_typeEv:
  259|  2.24k|      static Extension_Code static_type() { return Extension_Code::ClientCertificateType; }
_ZNK5Botan3TLS23Client_Certificate_Type4typeEv:
  261|  2.24k|      Extension_Code type() const override { return static_type(); }
_ZN5Botan3TLS23Server_Certificate_Type11static_typeEv:
  273|  2.15k|      static Extension_Code static_type() { return Extension_Code::ServerCertificateType; }
_ZNK5Botan3TLS23Server_Certificate_Type4typeEv:
  275|  2.15k|      Extension_Code type() const override { return static_type(); }
_ZN5Botan3TLS24Session_Ticket_Extension11static_typeEv:
  283|  5.42k|      static Extension_Code static_type() { return Extension_Code::SessionTicket; }
_ZNK5Botan3TLS24Session_Ticket_Extension4typeEv:
  285|  5.42k|      Extension_Code type() const override { return static_type(); }
_ZN5Botan3TLS16Supported_Groups11static_typeEv:
  320|  13.7k|      static Extension_Code static_type() { return Extension_Code::SupportedGroups; }
_ZNK5Botan3TLS16Supported_Groups4typeEv:
  322|  12.0k|      Extension_Code type() const override { return static_type(); }
_ZN5Botan3TLS23Supported_Point_Formats11static_typeEv:
  358|  2.22k|      static Extension_Code static_type() { return Extension_Code::EcPointFormats; }
_ZNK5Botan3TLS23Supported_Point_Formats4typeEv:
  360|  2.22k|      Extension_Code type() const override { return static_type(); }
_ZN5Botan3TLS20Signature_Algorithms11static_typeEv:
  381|  13.8k|      static Extension_Code static_type() { return Extension_Code::SignatureAlgorithms; }
_ZNK5Botan3TLS20Signature_Algorithms4typeEv:
  383|  11.7k|      Extension_Code type() const override { return static_type(); }
_ZN5Botan3TLS25Signature_Algorithms_Cert11static_typeEv:
  414|    967|      static Extension_Code static_type() { return Extension_Code::CertSignatureAlgorithms; }
_ZNK5Botan3TLS25Signature_Algorithms_Cert4typeEv:
  416|    967|      Extension_Code type() const override { return static_type(); }
_ZN5Botan3TLS24SRTP_Protection_Profiles11static_typeEv:
  437|  1.80k|      static Extension_Code static_type() { return Extension_Code::UseSrtp; }
_ZNK5Botan3TLS24SRTP_Protection_Profiles4typeEv:
  439|  1.80k|      Extension_Code type() const override { return static_type(); }
_ZN5Botan3TLS22Extended_Master_Secret11static_typeEv:
  462|  2.65k|      static Extension_Code static_type() { return Extension_Code::ExtendedMasterSecret; }
_ZNK5Botan3TLS22Extended_Master_Secret4typeEv:
  464|  2.65k|      Extension_Code type() const override { return static_type(); }
_ZN5Botan3TLS16Encrypt_then_MAC11static_typeEv:
  480|  4.37k|      static Extension_Code static_type() { return Extension_Code::EncryptThenMac; }
_ZNK5Botan3TLS16Encrypt_then_MAC4typeEv:
  482|  4.37k|      Extension_Code type() const override { return static_type(); }
_ZN5Botan3TLS26Certificate_Status_Request11static_typeEv:
  500|  6.91k|      static Extension_Code static_type() { return Extension_Code::CertificateStatusRequest; }
_ZNK5Botan3TLS26Certificate_Status_Request4typeEv:
  502|  6.91k|      Extension_Code type() const override { return static_type(); }
_ZN5Botan3TLS18Supported_Versions11static_typeEv:
  538|  38.4k|      static Extension_Code static_type() { return Extension_Code::SupportedVersions; }
_ZNK5Botan3TLS18Supported_Versions4typeEv:
  540|  15.1k|      Extension_Code type() const override { return static_type(); }
_ZNK5Botan3TLS18Supported_Versions8versionsEv:
  554|    502|      const std::vector<Protocol_Version>& versions() const { return m_versions; }
_ZN5Botan3TLS17Record_Size_Limit11static_typeEv:
  569|  4.34k|      static Extension_Code static_type() { return Extension_Code::RecordSizeLimit; }
_ZNK5Botan3TLS17Record_Size_Limit4typeEv:
  571|  4.34k|      Extension_Code type() const override { return static_type(); }
_ZN5Botan3TLS6Cookie11static_typeEv:
  595|  4.72k|      static Extension_Code static_type() { return Extension_Code::Cookie; }
_ZNK5Botan3TLS6Cookie4typeEv:
  597|  4.72k|      Extension_Code type() const override { return static_type(); }
_ZN5Botan3TLS22PSK_Key_Exchange_Modes11static_typeEv:
  618|  3.70k|      static Extension_Code static_type() { return Extension_Code::PskKeyExchangeModes; }
_ZNK5Botan3TLS22PSK_Key_Exchange_Modes4typeEv:
  620|  3.57k|      Extension_Code type() const override { return static_type(); }
_ZN5Botan3TLS23Certificate_Authorities11static_typeEv:
  641|  5.43k|      static Extension_Code static_type() { return Extension_Code::CertificateAuthorities; }
_ZNK5Botan3TLS23Certificate_Authorities4typeEv:
  643|  5.43k|      Extension_Code type() const override { return static_type(); }
_ZN5Botan3TLS3PSK11static_typeEv:
  663|  4.01k|      static Extension_Code static_type() { return Extension_Code::PresharedKey; }
_ZNK5Botan3TLS3PSK4typeEv:
  665|  2.68k|      Extension_Code type() const override { return static_type(); }
_ZN5Botan3TLS9Key_Share11static_typeEv:
  763|  17.4k|      static Extension_Code static_type() { return Extension_Code::KeyShare; }
_ZNK5Botan3TLS9Key_Share4typeEv:
  765|  15.3k|      Extension_Code type() const override { return static_type(); }
_ZN5Botan3TLS19EarlyDataIndication11static_typeEv:
  857|  5.71k|      static Extension_Code static_type() { return Extension_Code::EarlyData; }
_ZNK5Botan3TLS19EarlyDataIndication4typeEv:
  859|  5.71k|      Extension_Code type() const override { return static_type(); }
_ZNK5Botan3TLS17Unknown_Extension4typeEv:
  896|   537k|      Extension_Code type() const override { return m_type; }
_ZNK5Botan3TLS17Unknown_Extension14is_implementedEv:
  898|  22.2k|      bool is_implemented() const override { return false; }
_ZNK5Botan3TLS10Extensions3allEv:
  912|    113|      const std::vector<std::unique_ptr<Extension>>& all() const { return m_extensions; }
_ZNK5Botan3TLS10Extensions3hasENS0_14Extension_CodeE:
  924|   104k|      bool has(Extension_Code type) const { return get(type) != nullptr; }
_ZN5Botan3TLS10Extensions3addEPNS0_9ExtensionE:
  932|  1.53k|      void add(Extension* extn) { add(std::unique_ptr<Extension>(extn)); }
_ZZNK5Botan3TLS10Extensions3getENS0_14Extension_CodeEENKUlRKT_E_clINSt3__110unique_ptrINS0_9ExtensionENS8_14default_deleteISA_EEEEEEDaS5_:
  936|   613k|            m_extensions.cbegin(), m_extensions.cend(), [type](const auto& ext) { return ext->type() == type; });
_ZNK5Botan3TLS10Extensions3getENS0_14Extension_CodeE:
  934|   159k|      Extension* get(Extension_Code type) const {
  935|   159k|         const auto i = std::find_if(
  936|   159k|            m_extensions.cbegin(), m_extensions.cend(), [type](const auto& ext) { return ext->type() == type; });
  937|       |
  938|   159k|         return (i != m_extensions.end()) ? i->get() : nullptr;
  ------------------
  |  Branch (938:17): [True: 33.1k, False: 126k]
  ------------------
  939|   159k|      }
_ZNK5Botan3TLS10Extensions42contains_implemented_extensions_other_thanERKNSt3__13setINS0_14Extension_CodeENS2_4lessIS4_EENS2_9allocatorIS4_EEEE:
  958|  9.23k|      bool contains_implemented_extensions_other_than(const std::set<Extension_Code>& allowed_extensions) const {
  959|  9.23k|         return contains_other_than(allowed_extensions, true);
  960|  9.23k|      }
_ZN5Botan3TLS9ExtensionD2Ev:
  118|  53.6k|      virtual ~Extension() = default;
_ZN5Botan3TLS23Renegotiation_ExtensionC2Ev:
  153|  1.53k|      Renegotiation_Extension() = default;
_ZNK5Botan3TLS10Extensions3hasINS0_18Supported_VersionsEEEbv:
  920|  21.7k|      bool has() const {
  921|  21.7k|         return get<T>() != nullptr;
  922|  21.7k|      }
_ZNK5Botan3TLS10Extensions3getINS0_18Supported_VersionsEEEPT_v:
  915|  23.3k|      T* get() const {
  916|  23.3k|         return dynamic_cast<T*>(get(T::static_type()));
  917|  23.3k|      }
_ZN5Botan3TLS10ExtensionsC2Ev:
  995|  26.7k|      Extensions() = default;
_ZNK5Botan3TLS10Extensions3getINS0_20Signature_AlgorithmsEEEPT_v:
  915|  2.03k|      T* get() const {
  916|  2.03k|         return dynamic_cast<T*>(get(T::static_type()));
  917|  2.03k|      }
_ZNK5Botan3TLS10Extensions3getINS0_16Supported_GroupsEEEPT_v:
  915|  1.60k|      T* get() const {
  916|  1.60k|         return dynamic_cast<T*>(get(T::static_type()));
  917|  1.60k|      }
_ZNK5Botan3TLS10Extensions3getINS0_23Renegotiation_ExtensionEEEPT_v:
  915|  1.60k|      T* get() const {
  916|  1.60k|         return dynamic_cast<T*>(get(T::static_type()));
  917|  1.60k|      }
_ZNK5Botan3TLS10Extensions3hasINS0_20Signature_AlgorithmsEEEbv:
  920|  2.03k|      bool has() const {
  921|  2.03k|         return get<T>() != nullptr;
  922|  2.03k|      }
_ZNK5Botan3TLS10Extensions3hasINS0_3PSKEEEbv:
  920|  1.32k|      bool has() const {
  921|  1.32k|         return get<T>() != nullptr;
  922|  1.32k|      }
_ZNK5Botan3TLS10Extensions3hasINS0_22PSK_Key_Exchange_ModesEEEbv:
  920|    132|      bool has() const {
  921|    132|         return get<T>() != nullptr;
  922|    132|      }
_ZNK5Botan3TLS10Extensions3getINS0_22PSK_Key_Exchange_ModesEEEPT_v:
  915|    132|      T* get() const {
  916|    132|         return dynamic_cast<T*>(get(T::static_type()));
  917|    132|      }
_ZNK5Botan3TLS10Extensions3hasINS0_16Supported_GroupsEEEbv:
  920|  1.13k|      bool has() const {
  921|  1.13k|         return get<T>() != nullptr;
  922|  1.13k|      }
_ZNK5Botan3TLS10Extensions3hasINS0_9Key_ShareEEEbv:
  920|  1.58k|      bool has() const {
  921|  1.58k|         return get<T>() != nullptr;
  922|  1.58k|      }
_ZNK5Botan3TLS10Extensions3getINS0_9Key_ShareEEEPT_v:
  915|  2.06k|      T* get() const {
  916|  2.06k|         return dynamic_cast<T*>(get(T::static_type()));
  917|  2.06k|      }
_ZNK5Botan3TLS10Extensions3getINS0_3PSKEEEPT_v:
  915|  1.32k|      T* get() const {
  916|  1.32k|         return dynamic_cast<T*>(get(T::static_type()));
  917|  1.32k|      }
_ZN5Botan3TLS10ExtensionsC2EOS1_:
  998|  8.93k|      Extensions(Extensions&&) = default;

_ZN5Botan3TLS17Handshake_MessageD2Ev:
   50|   105k|      virtual ~Handshake_Message() = default;
_ZN5Botan3TLS17Handshake_MessageC2Ev:
   51|  33.3k|      Handshake_Message() = default;
_ZN5Botan3TLS17Handshake_MessageC2EOS1_:
   53|  71.7k|      Handshake_Message(Handshake_Message&&) = default;

_ZNK5Botan3TLS20Encrypted_Extensions4typeEv:
  470|  8.65k|      Handshake_Type type() const override { return Handshake_Type::EncryptedExtensions; }

_ZN5Botan3TLS11PskIdentityC2ENSt3__16vectorIhNS2_9allocatorIhEEEEj:
   36|  3.45k|            m_identity(std::move(identity)), m_obfuscated_age(obfuscated_age) {}

_ZNK5Botan3TLS16Signature_SchemeeqERKS1_:
   91|  8.75k|      bool operator==(const Signature_Scheme& rhs) const { return m_code == rhs.m_code; }

_ZN5Botan3TLS16Protocol_VersionC2Ev:
   49|  14.8k|      Protocol_Version() : m_version(0) {}
_ZN5Botan3TLS16Protocol_VersionC2Et:
   51|  56.7k|      explicit Protocol_Version(uint16_t code) : m_version(code) {}
_ZN5Botan3TLS16Protocol_VersionC2ENS0_12Version_CodeE:
   56|  36.4k|      Protocol_Version(Version_Code named_version) : Protocol_Version(static_cast<uint16_t>(named_version)) {}
_ZN5Botan3TLS16Protocol_VersionC2Ehh:
   63|  14.8k|            Protocol_Version(static_cast<uint16_t>((static_cast<uint16_t>(major) << 8) | minor)) {}
_ZNK5Botan3TLS16Protocol_Version13major_versionEv:
   78|  83.0k|      uint8_t major_version() const { return static_cast<uint8_t>(m_version >> 8); }
_ZNK5Botan3TLS16Protocol_Version13minor_versionEv:
   83|    118|      uint8_t minor_version() const { return static_cast<uint8_t>(m_version & 0xFF); }
_ZNK5Botan3TLS16Protocol_VersioneqERKS1_:
  113|  37.0k|      bool operator==(const Protocol_Version& other) const { return (m_version == other.m_version); }
_ZNK5Botan3TLS16Protocol_VersionneERKS1_:
  118|  1.07k|      bool operator!=(const Protocol_Version& other) const { return (m_version != other.m_version); }
_ZNK5Botan3TLS16Protocol_VersiongeERKS1_:
  128|  11.6k|      bool operator>=(const Protocol_Version& other) const { return (*this == other || *this > other); }
  ------------------
  |  Branch (128:70): [True: 2, False: 11.6k]
  |  Branch (128:88): [True: 3.03k, False: 8.58k]
  ------------------
_ZNK5Botan3TLS16Protocol_VersionltERKS1_:
  133|  10.8k|      bool operator<(const Protocol_Version& other) const { return !(*this >= other); }
_ZNK5Botan3TLS16Protocol_VersionleERKS1_:
  138|  21.6k|      bool operator<=(const Protocol_Version& other) const { return (*this == other || *this < other); }
  ------------------
  |  Branch (138:70): [True: 10.7k, False: 10.8k]
  |  Branch (138:88): [True: 7.88k, False: 3.01k]
  ------------------

_ZN5Botan14Cert_Extension9Key_Usage10static_oidEv:
   66|    136|      static OID static_oid() { return OID("2.5.29.15"); }
_ZN5Botan14Cert_Extension14Subject_Key_ID10static_oidEv:
   98|    136|      static OID static_oid() { return OID("2.5.29.14"); }
_ZN5Botan14Cert_Extension16Authority_Key_ID10static_oidEv:
  128|    136|      static OID static_oid() { return OID("2.5.29.35"); }
_ZN5Botan14Cert_Extension16Name_Constraints10static_oidEv:
  250|    136|      static OID static_oid() { return OID("2.5.29.30"); }
_ZN5Botan14Cert_Extension17Basic_Constraints10static_oidEv:
   37|    136|      static OID static_oid() { return OID("2.5.29.19"); }
_ZN5Botan14Cert_Extension23Issuer_Alternative_Name10static_oidEv:
  178|    136|      static OID static_oid() { return OID("2.5.29.18"); }
_ZN5Botan14Cert_Extension24Subject_Alternative_Name10static_oidEv:
  150|    136|      static OID static_oid() { return OID("2.5.29.17"); }
_ZN5Botan14Cert_Extension18Extended_Key_Usage10static_oidEv:
  214|    136|      static OID static_oid() { return OID("2.5.29.37"); }
_ZN5Botan14Cert_Extension20Certificate_Policies10static_oidEv:
  280|    136|      static OID static_oid() { return OID("2.5.29.32"); }
_ZN5Botan14Cert_Extension28Authority_Information_Access10static_oidEv:
  318|    136|      static OID static_oid() { return OID("1.3.6.1.5.5.7.1.1"); }
_ZN5Botan14Cert_Extension23CRL_Distribution_Points10static_oidEv:
  424|    136|      static OID static_oid() { return OID("2.5.29.31"); }

_ZN5Botan4X5098load_keyERKNSt3__16vectorIhNS1_9allocatorIhEEEE:
   58|    223|inline std::unique_ptr<Public_Key> load_key(const std::vector<uint8_t>& enc) {
   59|    223|   DataSource_Memory source(enc);
   60|    223|   return X509::load_key(source);
   61|    223|}

_ZN5Botan11X509_ObjectD2Ev:
  103|  1.65k|      ~X509_Object() override = default;
_ZNK5Botan11X509_Object9signatureEv:
   37|     87|      const std::vector<uint8_t>& signature() const { return m_sig; }
_ZNK5Botan11X509_Object11signed_bodyEv:
   42|    729|      const std::vector<uint8_t>& signed_body() const { return m_tbs_bits; }
_ZNK5Botan11X509_Object19signature_algorithmEv:
   47|    347|      const AlgorithmIdentifier& signature_algorithm() const { return m_sig_algo; }
_ZN5Botan11X509_ObjectC2ERKS0_:
   96|     87|      X509_Object(const X509_Object&) = default;
_ZN5Botan11X509_ObjectC2Ev:
  121|  1.56k|      X509_Object() = default;

_ZN5Botan16X509_CertificateC2ERKS0_:
  405|     87|      X509_Certificate(const X509_Certificate& other) = default;

LLVMFuzzerInitialize:
   24|      2|extern "C" int LLVMFuzzerInitialize(int*, char***) {
   25|       |   /*
   26|       |   * This disables the mlock pool, as overwrites within the pool are
   27|       |   * opaque to ASan or other instrumentation.
   28|       |   */
   29|      2|   ::setenv("BOTAN_MLOCK_POOL_SIZE", "0", 1);
   30|      2|   return 0;
   31|      2|}
LLVMFuzzerTestOneInput:
   34|  5.59k|extern "C" int LLVMFuzzerTestOneInput(const uint8_t in[], size_t len) {
   35|  5.59k|   if(len <= max_fuzzer_input_size) {
  ------------------
  |  Branch (35:7): [True: 5.58k, False: 9]
  ------------------
   36|  5.58k|      fuzz(in, len);
   37|  5.58k|   }
   38|  5.59k|   return 0;
   39|  5.59k|}

_Z4fuzzPKhm:
   24|  5.58k|void fuzz(const uint8_t in[], size_t len) {
   25|  5.58k|   static Botan::TLS::Default_Policy policy;
   26|       |
   27|  5.58k|   try {
   28|  5.58k|      auto hl1 = prepare(std::span(in, len));
   29|  5.58k|      Botan::TLS::Transcript_Hash_State ths("SHA-256");
   30|  35.4k|      while(hl1.next_message(policy, ths).has_value()) {};
  ------------------
  |  Branch (30:13): [True: 29.9k, False: 5.58k]
  ------------------
   31|       |
   32|  5.58k|      auto hl2 = prepare(std::span(in, len));
   33|  5.58k|      while(hl2.next_post_handshake_message(policy).has_value()) {};
  ------------------
  |  Branch (33:13): [True: 0, False: 5.58k]
  ------------------
   34|  5.58k|   } catch(Botan::Exception& e) {}
   35|  5.58k|}
tls_13_handshake_layer.cpp:_ZN12_GLOBAL__N_17prepareENSt3__14spanIKhLm18446744073709551615EEE:
   16|  7.09k|Botan::TLS::Handshake_Layer prepare(std::span<const uint8_t> data) {
   17|  7.09k|   Botan::TLS::Handshake_Layer hl(Botan::TLS::Connection_Side::Client);
   18|  7.09k|   hl.copy_data(data);
   19|  7.09k|   return hl;
   20|  7.09k|}

_ZNK5Botan19AlgorithmIdentifier19parameters_are_nullEv:
   50|    190|bool AlgorithmIdentifier::parameters_are_null() const {
   51|    190|   return (m_parameters.size() == 2 && (m_parameters[0] == 0x05) && (m_parameters[1] == 0x00));
  ------------------
  |  Branch (51:12): [True: 87, False: 103]
  |  Branch (51:40): [True: 40, False: 47]
  |  Branch (51:69): [True: 22, False: 18]
  ------------------
   52|    190|}
_ZN5BotaneqERKNS_19AlgorithmIdentifierES2_:
   54|    211|bool operator==(const AlgorithmIdentifier& a1, const AlgorithmIdentifier& a2) {
   55|    211|   if(a1.oid() != a2.oid()) {
  ------------------
  |  Branch (55:7): [True: 9, False: 202]
  ------------------
   56|      9|      return false;
   57|      9|   }
   58|       |
   59|       |   /*
   60|       |   * Treat NULL and empty as equivalent
   61|       |   */
   62|    202|   if(a1.parameters_are_null_or_empty() && a2.parameters_are_null_or_empty()) {
  ------------------
  |  Branch (62:7): [True: 37, False: 165]
  |  Branch (62:44): [True: 34, False: 3]
  ------------------
   63|     34|      return true;
   64|     34|   }
   65|       |
   66|    168|   return (a1.parameters() == a2.parameters());
   67|    202|}
_ZN5BotanneERKNS_19AlgorithmIdentifierES2_:
   69|    211|bool operator!=(const AlgorithmIdentifier& a1, const AlgorithmIdentifier& a2) {
   70|    211|   return !(a1 == a2);
   71|    211|}
_ZNK5Botan19AlgorithmIdentifier11encode_intoERNS_11DER_EncoderE:
   76|    136|void AlgorithmIdentifier::encode_into(DER_Encoder& codec) const {
   77|    136|   codec.start_sequence().encode(oid()).raw_bytes(parameters()).end_cons();
   78|    136|}
_ZN5Botan19AlgorithmIdentifier11decode_fromERNS_11BER_DecoderE:
   83|  1.60k|void AlgorithmIdentifier::decode_from(BER_Decoder& codec) {
   84|  1.60k|   codec.start_sequence().decode(m_oid).raw_bytes(m_parameters).end_cons();
   85|  1.60k|}

_ZNK5Botan11ASN1_Object10BER_encodeEv:
   19|    136|std::vector<uint8_t> ASN1_Object::BER_encode() const {
   20|    136|   std::vector<uint8_t> output;
   21|    136|   DER_Encoder der(output);
   22|    136|   this->encode_into(der);
   23|    136|   return output;
   24|    136|}
_ZNK5Botan10BER_Object11assert_is_aENS_9ASN1_TypeENS_10ASN1_ClassENSt3__117basic_string_viewIcNS3_11char_traitsIcEEEE:
   29|  17.0k|void BER_Object::assert_is_a(ASN1_Type expected_type_tag, ASN1_Class expected_class_tag, std::string_view descr) const {
   30|  17.0k|   if(this->is_a(expected_type_tag, expected_class_tag) == false) {
  ------------------
  |  Branch (30:7): [True: 572, False: 16.4k]
  ------------------
   31|    572|      std::stringstream msg;
   32|       |
   33|    572|      msg << "Tag mismatch when decoding " << descr << " got ";
   34|       |
   35|    572|      if(m_class_tag == ASN1_Class::NoObject && m_type_tag == ASN1_Type::NoObject) {
  ------------------
  |  Branch (35:10): [True: 251, False: 321]
  |  Branch (35:49): [True: 251, False: 0]
  ------------------
   36|    251|         msg << "EOF";
   37|    321|      } else {
   38|    321|         if(m_class_tag == ASN1_Class::Universal || m_class_tag == ASN1_Class::Constructed) {
  ------------------
  |  Branch (38:13): [True: 81, False: 240]
  |  Branch (38:53): [True: 170, False: 70]
  ------------------
   39|    251|            msg << asn1_tag_to_string(m_type_tag);
   40|    251|         } else {
   41|     70|            msg << std::to_string(static_cast<uint32_t>(m_type_tag));
   42|     70|         }
   43|       |
   44|    321|         msg << "/" << asn1_class_to_string(m_class_tag);
   45|    321|      }
   46|       |
   47|    572|      msg << " expected ";
   48|       |
   49|    572|      if(expected_class_tag == ASN1_Class::Universal || expected_class_tag == ASN1_Class::Constructed) {
  ------------------
  |  Branch (49:10): [True: 116, False: 456]
  |  Branch (49:57): [True: 456, False: 0]
  ------------------
   50|    572|         msg << asn1_tag_to_string(expected_type_tag);
   51|    572|      } else {
   52|      0|         msg << std::to_string(static_cast<uint32_t>(expected_type_tag));
   53|      0|      }
   54|       |
   55|    572|      msg << "/" << asn1_class_to_string(expected_class_tag);
   56|       |
   57|    572|      throw BER_Decoding_Error(msg.str());
   58|    572|   }
   59|  17.0k|}
_ZNK5Botan10BER_Object4is_aENS_9ASN1_TypeENS_10ASN1_ClassE:
   61|  18.2k|bool BER_Object::is_a(ASN1_Type expected_type_tag, ASN1_Class expected_class_tag) const {
   62|  18.2k|   return (m_type_tag == expected_type_tag && m_class_tag == expected_class_tag);
  ------------------
  |  Branch (62:12): [True: 16.6k, False: 1.60k]
  |  Branch (62:47): [True: 16.6k, False: 23]
  ------------------
   63|  18.2k|}
_ZNK5Botan10BER_Object4is_aEiNS_10ASN1_ClassE:
   65|    170|bool BER_Object::is_a(int expected_type_tag, ASN1_Class expected_class_tag) const {
   66|    170|   return is_a(ASN1_Type(expected_type_tag), expected_class_tag);
   67|    170|}
_ZN5Botan10BER_Object11set_taggingENS_9ASN1_TypeENS_10ASN1_ClassE:
   69|  36.1k|void BER_Object::set_tagging(ASN1_Type type_tag, ASN1_Class class_tag) {
   70|  36.1k|   m_type_tag = type_tag;
   71|  36.1k|   m_class_tag = class_tag;
   72|  36.1k|}
_ZN5Botan20asn1_class_to_stringENS_10ASN1_ClassE:
   74|    893|std::string asn1_class_to_string(ASN1_Class type) {
   75|    893|   switch(type) {
   76|    197|      case ASN1_Class::Universal:
  ------------------
  |  Branch (76:7): [True: 197, False: 696]
  ------------------
   77|    197|         return "UNIVERSAL";
   78|    626|      case ASN1_Class::Constructed:
  ------------------
  |  Branch (78:7): [True: 626, False: 267]
  ------------------
   79|    626|         return "CONSTRUCTED";
   80|     19|      case ASN1_Class::ContextSpecific:
  ------------------
  |  Branch (80:7): [True: 19, False: 874]
  ------------------
   81|     19|         return "CONTEXT_SPECIFIC";
   82|     14|      case ASN1_Class::Application:
  ------------------
  |  Branch (82:7): [True: 14, False: 879]
  ------------------
   83|     14|         return "APPLICATION";
   84|      9|      case ASN1_Class::Private:
  ------------------
  |  Branch (84:7): [True: 9, False: 884]
  ------------------
   85|      9|         return "PRIVATE";
   86|      0|      case ASN1_Class::NoObject:
  ------------------
  |  Branch (86:7): [True: 0, False: 893]
  ------------------
   87|      0|         return "NO_OBJECT";
   88|     28|      default:
  ------------------
  |  Branch (88:7): [True: 28, False: 865]
  ------------------
   89|     28|         return "CLASS(" + std::to_string(static_cast<size_t>(type)) + ")";
   90|    893|   }
   91|    893|}
_ZN5Botan18asn1_tag_to_stringENS_9ASN1_TypeE:
   93|    823|std::string asn1_tag_to_string(ASN1_Type type) {
   94|    823|   switch(type) {
   95|    451|      case ASN1_Type::Sequence:
  ------------------
  |  Branch (95:7): [True: 451, False: 372]
  ------------------
   96|    451|         return "SEQUENCE";
   97|       |
   98|     26|      case ASN1_Type::Set:
  ------------------
  |  Branch (98:7): [True: 26, False: 797]
  ------------------
   99|     26|         return "SET";
  100|       |
  101|      2|      case ASN1_Type::PrintableString:
  ------------------
  |  Branch (101:7): [True: 2, False: 821]
  ------------------
  102|      2|         return "PRINTABLE STRING";
  103|       |
  104|      3|      case ASN1_Type::NumericString:
  ------------------
  |  Branch (104:7): [True: 3, False: 820]
  ------------------
  105|      3|         return "NUMERIC STRING";
  106|       |
  107|      7|      case ASN1_Type::Ia5String:
  ------------------
  |  Branch (107:7): [True: 7, False: 816]
  ------------------
  108|      7|         return "IA5 STRING";
  109|       |
  110|      3|      case ASN1_Type::TeletexString:
  ------------------
  |  Branch (110:7): [True: 3, False: 820]
  ------------------
  111|      3|         return "T61 STRING";
  112|       |
  113|      2|      case ASN1_Type::Utf8String:
  ------------------
  |  Branch (113:7): [True: 2, False: 821]
  ------------------
  114|      2|         return "UTF8 STRING";
  115|       |
  116|      3|      case ASN1_Type::VisibleString:
  ------------------
  |  Branch (116:7): [True: 3, False: 820]
  ------------------
  117|      3|         return "VISIBLE STRING";
  118|       |
  119|      3|      case ASN1_Type::BmpString:
  ------------------
  |  Branch (119:7): [True: 3, False: 820]
  ------------------
  120|      3|         return "BMP STRING";
  121|       |
  122|      2|      case ASN1_Type::UniversalString:
  ------------------
  |  Branch (122:7): [True: 2, False: 821]
  ------------------
  123|      2|         return "UNIVERSAL STRING";
  124|       |
  125|      3|      case ASN1_Type::UtcTime:
  ------------------
  |  Branch (125:7): [True: 3, False: 820]
  ------------------
  126|      3|         return "UTC TIME";
  127|       |
  128|      4|      case ASN1_Type::GeneralizedTime:
  ------------------
  |  Branch (128:7): [True: 4, False: 819]
  ------------------
  129|      4|         return "GENERALIZED TIME";
  130|       |
  131|      2|      case ASN1_Type::OctetString:
  ------------------
  |  Branch (131:7): [True: 2, False: 821]
  ------------------
  132|      2|         return "OCTET STRING";
  133|       |
  134|     52|      case ASN1_Type::BitString:
  ------------------
  |  Branch (134:7): [True: 52, False: 771]
  ------------------
  135|     52|         return "BIT STRING";
  136|       |
  137|      3|      case ASN1_Type::Enumerated:
  ------------------
  |  Branch (137:7): [True: 3, False: 820]
  ------------------
  138|      3|         return "ENUMERATED";
  139|       |
  140|     73|      case ASN1_Type::Integer:
  ------------------
  |  Branch (140:7): [True: 73, False: 750]
  ------------------
  141|     73|         return "INTEGER";
  142|       |
  143|      1|      case ASN1_Type::Null:
  ------------------
  |  Branch (143:7): [True: 1, False: 822]
  ------------------
  144|      1|         return "NULL";
  145|       |
  146|      8|      case ASN1_Type::ObjectId:
  ------------------
  |  Branch (146:7): [True: 8, False: 815]
  ------------------
  147|      8|         return "OBJECT";
  148|       |
  149|     10|      case ASN1_Type::Boolean:
  ------------------
  |  Branch (149:7): [True: 10, False: 813]
  ------------------
  150|     10|         return "BOOLEAN";
  151|       |
  152|      1|      case ASN1_Type::NoObject:
  ------------------
  |  Branch (152:7): [True: 1, False: 822]
  ------------------
  153|      1|         return "NO_OBJECT";
  154|       |
  155|    164|      default:
  ------------------
  |  Branch (155:7): [True: 164, False: 659]
  ------------------
  156|    164|         return "TAG(" + std::to_string(static_cast<uint32_t>(type)) + ")";
  157|    823|   }
  158|    823|}
_ZN5Botan18BER_Decoding_ErrorC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
  163|  1.16k|BER_Decoding_Error::BER_Decoding_Error(std::string_view str) : Decoding_Error(fmt("BER: {}", str)) {}
_ZN5Botan11BER_Bad_TagC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEEj:
  165|    101|BER_Bad_Tag::BER_Bad_Tag(std::string_view str, uint32_t tagging) : BER_Decoding_Error(fmt("{}: {}", str, tagging)) {}
_ZN5Botan4ASN115put_in_sequenceERKNSt3__16vectorIhNS1_9allocatorIhEEEE:
  172|    543|std::vector<uint8_t> put_in_sequence(const std::vector<uint8_t>& contents) {
  173|    543|   return ASN1::put_in_sequence(contents.data(), contents.size());
  174|    543|}
_ZN5Botan4ASN115put_in_sequenceEPKhm:
  176|    543|std::vector<uint8_t> put_in_sequence(const uint8_t bits[], size_t len) {
  177|    543|   std::vector<uint8_t> output;
  178|    543|   DER_Encoder(output).start_sequence().raw_bytes(bits, len).end_cons();
  179|    543|   return output;
  180|    543|}
_ZN5Botan4ASN19to_stringERKNS_10BER_ObjectE:
  185|  2.53k|std::string to_string(const BER_Object& obj) {
  186|  2.53k|   return std::string(cast_uint8_ptr_to_char(obj.bits()), obj.length());
  187|  2.53k|}
_ZN5Botan4ASN19maybe_BERERNS_10DataSourceE:
  192|  1.78k|bool maybe_BER(DataSource& source) {
  193|  1.78k|   uint8_t first_u8;
  194|  1.78k|   if(!source.peek_byte(first_u8)) {
  ------------------
  |  Branch (194:7): [True: 1, False: 1.78k]
  ------------------
  195|      1|      BOTAN_ASSERT_EQUAL(source.read_byte(first_u8), 0, "Expected EOF");
  ------------------
  |  |   69|      1|   do {                                                                                                \
  |  |   70|      1|      if((expr1) != (expr2))                                                                           \
  |  |  ------------------
  |  |  |  Branch (70:10): [True: 0, False: 1]
  |  |  ------------------
  |  |   71|      1|         Botan::assertion_failure(#expr1 " == " #expr2, assertion_made, __func__, __FILE__, __LINE__); \
  |  |   72|      1|   } while(0)
  |  |  ------------------
  |  |  |  Branch (72:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  196|      1|      throw Stream_IO_Error("ASN1::maybe_BER: Source was empty");
  197|      1|   }
  198|       |
  199|  1.78k|   const auto cons_seq = static_cast<uint8_t>(ASN1_Class::Constructed) | static_cast<uint8_t>(ASN1_Type::Sequence);
  200|  1.78k|   if(first_u8 == cons_seq) {
  ------------------
  |  Branch (200:7): [True: 1.56k, False: 219]
  ------------------
  201|  1.56k|      return true;
  202|  1.56k|   }
  203|    219|   return false;
  204|  1.78k|}

_ZN5Botan3OIDC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
   96|  1.49k|OID::OID(std::string_view oid_str) {
   97|  1.49k|   if(!oid_str.empty()) {
  ------------------
  |  Branch (97:7): [True: 1.49k, False: 0]
  ------------------
   98|  1.49k|      m_id = parse_oid_str(oid_str);
   99|  1.49k|      if(m_id.size() < 2 || m_id[0] > 2 || (m_id[0] < 2 && m_id[1] > 39)) {
  ------------------
  |  Branch (99:10): [True: 0, False: 1.49k]
  |  Branch (99:29): [True: 0, False: 1.49k]
  |  Branch (99:45): [True: 136, False: 1.36k]
  |  Branch (99:60): [True: 0, False: 136]
  ------------------
  100|      0|         throw Decoding_Error(fmt("Invalid OID '{}'", oid_str));
  101|      0|      }
  102|  1.49k|   }
  103|  1.49k|}
_ZNK5Botan3OID9to_stringEv:
  108|    405|std::string OID::to_string() const {
  109|    405|   std::ostringstream out;
  110|    405|   out << (*this);
  111|    405|   return out.str();
  112|    405|}
_ZNK5Botan3OID19to_formatted_stringEv:
  114|    211|std::string OID::to_formatted_string() const {
  115|    211|   std::string s = this->human_name_or_empty();
  116|    211|   if(!s.empty()) {
  ------------------
  |  Branch (116:7): [True: 17, False: 194]
  ------------------
  117|     17|      return s;
  118|     17|   }
  119|    194|   return this->to_string();
  120|    211|}
_ZNK5Botan3OID19human_name_or_emptyEv:
  122|    211|std::string OID::human_name_or_empty() const {
  123|    211|   return OID_Map::global_registry().oid2str(*this);
  124|    211|}
_ZN5BotanlsERNSt3__113basic_ostreamIcNS0_11char_traitsIcEEEERKNS_3OIDE:
  140|    405|std::ostream& operator<<(std::ostream& out, const OID& oid) {
  141|    405|   const auto& val = oid.get_components();
  142|       |
  143|  2.11k|   for(size_t i = 0; i != val.size(); ++i) {
  ------------------
  |  Branch (143:22): [True: 1.70k, False: 405]
  ------------------
  144|       |      // avoid locale issues with integer formatting
  145|  1.70k|      out << std::to_string(val[i]);
  146|  1.70k|      if(i != val.size() - 1) {
  ------------------
  |  Branch (146:10): [True: 1.30k, False: 405]
  ------------------
  147|  1.30k|         out << ".";
  148|  1.30k|      }
  149|  1.70k|   }
  150|       |
  151|    405|   return out;
  152|    405|}
_ZNK5Botan3OID11encode_intoERNS_11DER_EncoderE:
  157|    136|void OID::encode_into(DER_Encoder& der) const {
  158|    136|   if(m_id.size() < 2) {
  ------------------
  |  Branch (158:7): [True: 0, False: 136]
  ------------------
  159|      0|      throw Invalid_Argument("OID::encode_into: OID is invalid");
  160|      0|   }
  161|       |
  162|    136|   std::vector<uint8_t> encoding;
  163|       |
  164|    136|   if(m_id[0] > 2 || m_id[1] >= 40) {
  ------------------
  |  Branch (164:7): [True: 49, False: 87]
  |  Branch (164:22): [True: 0, False: 87]
  ------------------
  165|     49|      throw Encoding_Error("Invalid OID prefix, cannot encode");
  166|     49|   }
  167|       |
  168|     87|   encoding.push_back(static_cast<uint8_t>(40 * m_id[0] + m_id[1]));
  169|       |
  170|    214|   for(size_t i = 2; i != m_id.size(); ++i) {
  ------------------
  |  Branch (170:22): [True: 127, False: 87]
  ------------------
  171|    127|      if(m_id[i] == 0) {
  ------------------
  |  Branch (171:10): [True: 39, False: 88]
  ------------------
  172|     39|         encoding.push_back(0);
  173|     88|      } else {
  174|     88|         size_t blocks = high_bit(m_id[i]) + 6;
  175|     88|         blocks = (blocks - (blocks % 7)) / 7;
  176|       |
  177|     88|         BOTAN_ASSERT(blocks > 0, "Math works");
  ------------------
  |  |   51|     88|   do {                                                                                 \
  |  |   52|     88|      if(!(expr))                                                                       \
  |  |  ------------------
  |  |  |  Branch (52:10): [True: 0, False: 88]
  |  |  ------------------
  |  |   53|     88|         Botan::assertion_failure(#expr, assertion_made, __func__, __FILE__, __LINE__); \
  |  |   54|     88|   } while(0)
  |  |  ------------------
  |  |  |  Branch (54:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  178|       |
  179|    190|         for(size_t j = 0; j != blocks - 1; ++j) {
  ------------------
  |  Branch (179:28): [True: 102, False: 88]
  ------------------
  180|    102|            encoding.push_back(0x80 | ((m_id[i] >> 7 * (blocks - j - 1)) & 0x7F));
  181|    102|         }
  182|     88|         encoding.push_back(m_id[i] & 0x7F);
  183|     88|      }
  184|    127|   }
  185|     87|   der.add_object(ASN1_Type::ObjectId, ASN1_Class::Universal, encoding);
  186|     87|}
_ZN5Botan3OID11decode_fromERNS_11BER_DecoderE:
  191|  5.88k|void OID::decode_from(BER_Decoder& decoder) {
  192|  5.88k|   BER_Object obj = decoder.get_next_object();
  193|  5.88k|   if(obj.tagging() != (ASN1_Class::Universal | ASN1_Type::ObjectId)) {
  ------------------
  |  Branch (193:7): [True: 70, False: 5.81k]
  ------------------
  194|     70|      throw BER_Bad_Tag("Error decoding OID, unknown tag", obj.tagging());
  195|     70|   }
  196|       |
  197|  5.81k|   const size_t length = obj.length();
  198|  5.81k|   const uint8_t* bits = obj.bits();
  199|       |
  200|  5.81k|   if(length < 2 && !(length == 1 && bits[0] == 0)) {
  ------------------
  |  Branch (200:7): [True: 490, False: 5.32k]
  |  Branch (200:23): [True: 488, False: 2]
  |  Branch (200:38): [True: 479, False: 9]
  ------------------
  201|     11|      throw BER_Decoding_Error("OID encoding is too short");
  202|     11|   }
  203|       |
  204|  5.80k|   m_id.clear();
  205|  5.80k|   m_id.push_back(bits[0] / 40);
  206|  5.80k|   m_id.push_back(bits[0] % 40);
  207|       |
  208|  5.80k|   size_t i = 0;
  209|  29.3k|   while(i != length - 1) {
  ------------------
  |  Branch (209:10): [True: 23.6k, False: 5.77k]
  ------------------
  210|  23.6k|      uint32_t component = 0;
  211|  30.1k|      while(i != length - 1) {
  ------------------
  |  Branch (211:13): [True: 27.2k, False: 2.91k]
  ------------------
  212|  27.2k|         ++i;
  213|       |
  214|  27.2k|         if(component >> (32 - 7)) {
  ------------------
  |  Branch (214:13): [True: 27, False: 27.1k]
  ------------------
  215|     27|            throw Decoding_Error("OID component overflow");
  216|     27|         }
  217|       |
  218|  27.1k|         component = (component << 7) + (bits[i] & 0x7F);
  219|       |
  220|  27.1k|         if(!(bits[i] & 0x80)) {
  ------------------
  |  Branch (220:13): [True: 20.6k, False: 6.51k]
  ------------------
  221|  20.6k|            break;
  222|  20.6k|         }
  223|  27.1k|      }
  224|  23.5k|      m_id.push_back(component);
  225|  23.5k|   }
  226|  5.80k|}
asn1_oid.cpp:_ZN5Botan12_GLOBAL__N_113parse_oid_strENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
   24|  1.49k|std::vector<uint32_t> parse_oid_str(std::string_view oid) {
   25|  1.49k|   try {
   26|  1.49k|      std::string elem;
   27|  1.49k|      std::vector<uint32_t> oid_elems;
   28|       |
   29|  14.5k|      for(char c : oid) {
  ------------------
  |  Branch (29:18): [True: 14.5k, False: 1.49k]
  ------------------
   30|  14.5k|         if(c == '.') {
  ------------------
  |  Branch (30:13): [True: 5.16k, False: 9.38k]
  ------------------
   31|  5.16k|            if(elem.empty()) {
  ------------------
  |  Branch (31:16): [True: 0, False: 5.16k]
  ------------------
   32|      0|               return std::vector<uint32_t>();
   33|      0|            }
   34|  5.16k|            oid_elems.push_back(to_u32bit(elem));
   35|  5.16k|            elem.clear();
   36|  9.38k|         } else {
   37|  9.38k|            elem += c;
   38|  9.38k|         }
   39|  14.5k|      }
   40|       |
   41|  1.49k|      if(!elem.empty()) {
  ------------------
  |  Branch (41:10): [True: 1.49k, False: 0]
  ------------------
   42|  1.49k|         oid_elems.push_back(to_u32bit(elem));
   43|  1.49k|      }
   44|       |
   45|  1.49k|      return oid_elems;
   46|  1.49k|   } catch(Invalid_Argument&)  // thrown by to_u32bit
   47|  1.49k|   {
   48|      0|      return std::vector<uint32_t>();
   49|      0|   }
   50|  1.49k|}

_ZN5Botan11ASN1_StringC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEENS_9ASN1_TypeE:
   64|  4.45k|ASN1_String::ASN1_String(std::string_view str, ASN1_Type t) : m_utf8_str(str), m_tag(t) {
   65|  4.45k|   if(!is_utf8_subset_string_type(m_tag)) {
  ------------------
  |  Branch (65:7): [True: 0, False: 4.45k]
  ------------------
   66|      0|      throw Invalid_Argument("ASN1_String only supports encoding to UTF-8 or a UTF-8 subset");
   67|      0|   }
   68|  4.45k|}
_ZN5Botan11ASN1_StringC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
   70|  4.45k|ASN1_String::ASN1_String(std::string_view str) : ASN1_String(str, choose_encoding(str)) {}
_ZN5Botan11ASN1_String11decode_fromERNS_11BER_DecoderE:
   88|  4.37k|void ASN1_String::decode_from(BER_Decoder& source) {
   89|  4.37k|   BER_Object obj = source.get_next_object();
   90|       |
   91|  4.37k|   if(!is_asn1_string_type(obj.type())) {
  ------------------
  |  Branch (91:7): [True: 83, False: 4.29k]
  ------------------
   92|     83|      auto typ = static_cast<uint32_t>(obj.type());
   93|     83|      throw Decoding_Error(fmt("ASN1_String: Unknown string type {}", typ));
   94|     83|   }
   95|       |
   96|  4.29k|   m_tag = obj.type();
   97|  4.29k|   m_data.assign(obj.bits(), obj.bits() + obj.length());
   98|       |
   99|  4.29k|   if(m_tag == ASN1_Type::BmpString) {
  ------------------
  |  Branch (99:7): [True: 332, False: 3.96k]
  ------------------
  100|    332|      m_utf8_str = ucs2_to_utf8(m_data.data(), m_data.size());
  101|  3.96k|   } else if(m_tag == ASN1_Type::UniversalString) {
  ------------------
  |  Branch (101:14): [True: 688, False: 3.27k]
  ------------------
  102|    688|      m_utf8_str = ucs4_to_utf8(m_data.data(), m_data.size());
  103|  3.27k|   } else if(m_tag == ASN1_Type::TeletexString) {
  ------------------
  |  Branch (103:14): [True: 1.28k, False: 1.99k]
  ------------------
  104|       |      /*
  105|       |      TeletexString is nominally ITU T.61 not ISO-8859-1 but it seems
  106|       |      the majority of implementations actually used that charset here.
  107|       |      */
  108|  1.28k|      m_utf8_str = latin1_to_utf8(m_data.data(), m_data.size());
  109|  1.99k|   } else {
  110|       |      // All other supported string types are UTF-8 or some subset thereof
  111|  1.99k|      m_utf8_str = ASN1::to_string(obj);
  112|  1.99k|   }
  113|  4.29k|}
asn1_str.cpp:_ZN5Botan12_GLOBAL__N_119is_asn1_string_typeENS_9ASN1_TypeE:
   52|  4.36k|bool is_asn1_string_type(ASN1_Type tag) {
   53|  4.36k|   return (is_utf8_subset_string_type(tag) || tag == ASN1_Type::TeletexString || tag == ASN1_Type::BmpString ||
  ------------------
  |  Branch (53:12): [True: 1.98k, False: 2.38k]
  |  Branch (53:47): [True: 1.28k, False: 1.10k]
  |  Branch (53:82): [True: 332, False: 771]
  ------------------
   54|  4.36k|           tag == ASN1_Type::UniversalString);
  ------------------
  |  Branch (54:12): [True: 688, False: 83]
  ------------------
   55|  4.36k|}
asn1_str.cpp:_ZN5Botan12_GLOBAL__N_126is_utf8_subset_string_typeENS_9ASN1_TypeE:
   47|  8.82k|bool is_utf8_subset_string_type(ASN1_Type tag) {
   48|  8.82k|   return (tag == ASN1_Type::NumericString || tag == ASN1_Type::PrintableString || tag == ASN1_Type::VisibleString ||
  ------------------
  |  Branch (48:12): [True: 245, False: 8.57k]
  |  Branch (48:47): [True: 4.99k, False: 3.58k]
  |  Branch (48:84): [True: 328, False: 3.25k]
  ------------------
   49|  8.82k|           tag == ASN1_Type::Ia5String || tag == ASN1_Type::Utf8String);
  ------------------
  |  Branch (49:12): [True: 836, False: 2.42k]
  |  Branch (49:43): [True: 34, False: 2.38k]
  ------------------
   50|  8.82k|}
asn1_str.cpp:_ZN5Botan12_GLOBAL__N_115choose_encodingENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
   23|  4.45k|ASN1_Type choose_encoding(std::string_view str) {
   24|  4.45k|   auto all_printable = CT::Mask<uint8_t>::set();
   25|       |
   26|  4.45k|   for(size_t i = 0; i != str.size(); ++i) {
  ------------------
  |  Branch (26:22): [True: 0, False: 4.45k]
  ------------------
   27|      0|      const uint8_t c = static_cast<uint8_t>(str[i]);
   28|       |
   29|      0|      auto is_alpha_lower = CT::Mask<uint8_t>::is_within_range(c, 'a', 'z');
   30|      0|      auto is_alpha_upper = CT::Mask<uint8_t>::is_within_range(c, 'A', 'Z');
   31|      0|      auto is_decimal = CT::Mask<uint8_t>::is_within_range(c, '0', '9');
   32|       |
   33|      0|      auto is_print_punc = CT::Mask<uint8_t>::is_any_of(c, {' ', '(', ')', '+', ',', '-', '.', '/', ':', '=', '?'});
   34|       |
   35|      0|      auto is_printable = is_alpha_lower | is_alpha_upper | is_decimal | is_print_punc;
   36|       |
   37|      0|      all_printable &= is_printable;
   38|      0|   }
   39|       |
   40|  4.45k|   if(all_printable.as_bool()) {
  ------------------
  |  Branch (40:7): [True: 4.45k, False: 0]
  ------------------
   41|  4.45k|      return ASN1_Type::PrintableString;
   42|  4.45k|   } else {
   43|      0|      return ASN1_Type::Utf8String;
   44|      0|   }
   45|  4.45k|}

_ZN5Botan9ASN1_Time11decode_fromERNS_11BER_DecoderE:
   53|    556|void ASN1_Time::decode_from(BER_Decoder& source) {
   54|    556|   BER_Object ber_time = source.get_next_object();
   55|       |
   56|    556|   set_to(ASN1::to_string(ber_time), ber_time.type());
   57|    556|}
_ZN5Botan9ASN1_Time6set_toENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEENS_9ASN1_TypeE:
  157|    556|void ASN1_Time::set_to(std::string_view t_spec, ASN1_Type spec_tag) {
  158|    556|   BOTAN_ARG_CHECK(spec_tag == ASN1_Type::UtcTime || spec_tag == ASN1_Type::GeneralizedTime,
  ------------------
  |  |   30|    556|   do {                                                          \
  |  |   31|  1.09k|      if(!(expr))                                                \
  |  |  ------------------
  |  |  |  Branch (31:12): [True: 19, False: 537]
  |  |  |  Branch (31:12): [True: 502, False: 35]
  |  |  ------------------
  |  |   32|    556|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   33|    556|   } while(0)
  |  |  ------------------
  |  |  |  Branch (33:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  159|    556|                   "Invalid tag for ASN1_Time");
  160|       |
  161|    556|   if(spec_tag == ASN1_Type::GeneralizedTime) {
  ------------------
  |  Branch (161:7): [True: 502, False: 54]
  ------------------
  162|    502|      BOTAN_ARG_CHECK(t_spec.size() == 15, "Invalid GeneralizedTime input string");
  ------------------
  |  |   30|    502|   do {                                                          \
  |  |   31|    502|      if(!(expr))                                                \
  |  |  ------------------
  |  |  |  Branch (31:10): [True: 3, False: 499]
  |  |  ------------------
  |  |   32|    502|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   33|    502|   } while(0)
  |  |  ------------------
  |  |  |  Branch (33:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  163|    502|   } else if(spec_tag == ASN1_Type::UtcTime) {
  ------------------
  |  Branch (163:14): [True: 19, False: 35]
  ------------------
  164|     19|      BOTAN_ARG_CHECK(t_spec.size() == 13, "Invalid UTCTime input string");
  ------------------
  |  |   30|     19|   do {                                                          \
  |  |   31|     19|      if(!(expr))                                                \
  |  |  ------------------
  |  |  |  Branch (31:10): [True: 7, False: 12]
  |  |  ------------------
  |  |   32|     19|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   33|     19|   } while(0)
  |  |  ------------------
  |  |  |  Branch (33:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  165|     19|   }
  166|       |
  167|    556|   BOTAN_ARG_CHECK(t_spec.back() == 'Z', "Botan does not support ASN1 times with timezones other than Z");
  ------------------
  |  |   30|    556|   do {                                                          \
  |  |   31|    556|      if(!(expr))                                                \
  |  |  ------------------
  |  |  |  Branch (31:10): [True: 13, False: 543]
  |  |  ------------------
  |  |   32|    556|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   33|    556|   } while(0)
  |  |  ------------------
  |  |  |  Branch (33:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  168|       |
  169|    556|   const size_t field_len = 2;
  170|       |
  171|    556|   const size_t year_start = 0;
  172|    556|   const size_t year_len = (spec_tag == ASN1_Type::UtcTime) ? 2 : 4;
  ------------------
  |  Branch (172:28): [True: 12, False: 544]
  ------------------
  173|    556|   const size_t month_start = year_start + year_len;
  174|    556|   const size_t day_start = month_start + field_len;
  175|    556|   const size_t hour_start = day_start + field_len;
  176|    556|   const size_t min_start = hour_start + field_len;
  177|    556|   const size_t sec_start = min_start + field_len;
  178|       |
  179|    556|   m_year = to_u32bit(t_spec.substr(year_start, year_len));
  180|    556|   m_month = to_u32bit(t_spec.substr(month_start, field_len));
  181|    556|   m_day = to_u32bit(t_spec.substr(day_start, field_len));
  182|    556|   m_hour = to_u32bit(t_spec.substr(hour_start, field_len));
  183|    556|   m_minute = to_u32bit(t_spec.substr(min_start, field_len));
  184|    556|   m_second = to_u32bit(t_spec.substr(sec_start, field_len));
  185|    556|   m_tag = spec_tag;
  186|       |
  187|    556|   if(spec_tag == ASN1_Type::UtcTime) {
  ------------------
  |  Branch (187:7): [True: 11, False: 545]
  ------------------
  188|     11|      if(m_year >= 50) {
  ------------------
  |  Branch (188:10): [True: 5, False: 6]
  ------------------
  189|      5|         m_year += 1900;
  190|      6|      } else {
  191|      6|         m_year += 2000;
  192|      6|      }
  193|     11|   }
  194|       |
  195|    556|   if(!passes_sanity_check()) {
  ------------------
  |  Branch (195:7): [True: 28, False: 528]
  ------------------
  196|     28|      throw Invalid_Argument(fmt("ASN1_Time string '{}' does not seem to be valid", t_spec));
  197|     28|   }
  198|    556|}
_ZNK5Botan9ASN1_Time19passes_sanity_checkEv:
  203|    489|bool ASN1_Time::passes_sanity_check() const {
  204|       |   // AppVeyor's trust store includes a cert with expiration date in 3016 ...
  205|    489|   if(m_year < 1950 || m_year > 3100) {
  ------------------
  |  Branch (205:7): [True: 6, False: 483]
  |  Branch (205:24): [True: 3, False: 480]
  ------------------
  206|      9|      return false;
  207|      9|   }
  208|    480|   if(m_month == 0 || m_month > 12) {
  ------------------
  |  Branch (208:7): [True: 1, False: 479]
  |  Branch (208:23): [True: 5, False: 474]
  ------------------
  209|      6|      return false;
  210|      6|   }
  211|       |
  212|    474|   const uint32_t days_in_month[12] = {31, 28 + 1, 31, 30, 31, 30, 31, 31, 30, 31, 30, 31};
  213|       |
  214|    474|   if(m_day == 0 || m_day > days_in_month[m_month - 1]) {
  ------------------
  |  Branch (214:7): [True: 1, False: 473]
  |  Branch (214:21): [True: 3, False: 470]
  ------------------
  215|      4|      return false;
  216|      4|   }
  217|       |
  218|    470|   if(m_month == 2 && m_day == 29) {
  ------------------
  |  Branch (218:7): [True: 82, False: 388]
  |  Branch (218:23): [True: 25, False: 57]
  ------------------
  219|     25|      if(m_year % 4 != 0) {
  ------------------
  |  Branch (219:10): [True: 1, False: 24]
  ------------------
  220|      1|         return false;  // not a leap year
  221|      1|      }
  222|       |
  223|     24|      if(m_year % 100 == 0 && m_year % 400 != 0) {
  ------------------
  |  Branch (223:10): [True: 5, False: 19]
  |  Branch (223:31): [True: 2, False: 3]
  ------------------
  224|      2|         return false;
  225|      2|      }
  226|     24|   }
  227|       |
  228|    467|   if(m_hour >= 24 || m_minute >= 60 || m_second > 60) {
  ------------------
  |  Branch (228:7): [True: 1, False: 466]
  |  Branch (228:23): [True: 1, False: 465]
  |  Branch (228:41): [True: 3, False: 462]
  ------------------
  229|      5|      return false;
  230|      5|   }
  231|       |
  232|    462|   if(m_tag == ASN1_Type::UtcTime) {
  ------------------
  |  Branch (232:7): [True: 8, False: 454]
  ------------------
  233|       |      /*
  234|       |      UTCTime limits the value of components such that leap seconds
  235|       |      are not covered. See "UNIVERSAL 23" in "Information technology
  236|       |      Abstract Syntax Notation One (ASN.1): Specification of basic notation"
  237|       |
  238|       |      http://www.itu.int/ITU-T/studygroups/com17/languages/
  239|       |      */
  240|      8|      if(m_second > 59) {
  ------------------
  |  Branch (240:10): [True: 1, False: 7]
  ------------------
  241|      1|         return false;
  242|      1|      }
  243|      8|   }
  244|       |
  245|    461|   return true;
  246|    462|}

_ZNK5Botan11BER_Decoder10more_itemsEv:
  195|  12.2k|bool BER_Decoder::more_items() const {
  196|  12.2k|   if(m_source->end_of_data() && !m_pushed.is_set()) {
  ------------------
  |  Branch (196:7): [True: 5.84k, False: 6.45k]
  |  Branch (196:34): [True: 5.84k, False: 0]
  ------------------
  197|  5.84k|      return false;
  198|  5.84k|   }
  199|  6.45k|   return true;
  200|  12.2k|}
_ZN5Botan11BER_Decoder10verify_endEv:
  205|     15|BER_Decoder& BER_Decoder::verify_end() {
  206|     15|   return verify_end("BER_Decoder::verify_end called, but data remains");
  207|     15|}
_ZN5Botan11BER_Decoder10verify_endENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
  212|    228|BER_Decoder& BER_Decoder::verify_end(std::string_view err) {
  213|    228|   if(!m_source->end_of_data() || m_pushed.is_set()) {
  ------------------
  |  Branch (213:7): [True: 10, False: 218]
  |  Branch (213:35): [True: 0, False: 218]
  ------------------
  214|     10|      throw Decoding_Error(err);
  215|     10|   }
  216|    218|   return (*this);
  217|    228|}
_ZN5Botan11BER_Decoder15get_next_objectEv:
  231|  29.4k|BER_Object BER_Decoder::get_next_object() {
  232|  29.4k|   BER_Object next;
  233|       |
  234|  29.4k|   if(m_pushed.is_set()) {
  ------------------
  |  Branch (234:7): [True: 553, False: 28.9k]
  ------------------
  235|    553|      std::swap(next, m_pushed);
  236|    553|      return next;
  237|    553|   }
  238|       |
  239|  36.1k|   for(;;) {
  240|  36.1k|      ASN1_Type type_tag;
  241|  36.1k|      ASN1_Class class_tag;
  242|  36.1k|      decode_tag(m_source, type_tag, class_tag);
  243|  36.1k|      next.set_tagging(type_tag, class_tag);
  244|  36.1k|      if(next.is_set() == false) {  // no more objects
  ------------------
  |  Branch (244:10): [True: 787, False: 35.3k]
  ------------------
  245|    787|         return next;
  246|    787|      }
  247|       |
  248|  35.3k|      size_t field_size;
  249|  35.3k|      const size_t length = decode_length(m_source, field_size, ALLOWED_EOC_NESTINGS);
  250|  35.3k|      if(!m_source->check_available(length)) {
  ------------------
  |  Branch (250:10): [True: 168, False: 35.1k]
  ------------------
  251|    168|         throw BER_Decoding_Error("Value truncated");
  252|    168|      }
  253|       |
  254|  35.1k|      uint8_t* out = next.mutable_bits(length);
  255|  35.1k|      if(m_source->read(out, length) != length) {
  ------------------
  |  Branch (255:10): [True: 0, False: 35.1k]
  ------------------
  256|      0|         throw BER_Decoding_Error("Value truncated");
  257|      0|      }
  258|       |
  259|  35.1k|      if(next.tagging() == static_cast<uint32_t>(ASN1_Type::Eoc)) {
  ------------------
  |  Branch (259:10): [True: 7.17k, False: 27.9k]
  ------------------
  260|  7.17k|         continue;
  261|  27.9k|      } else {
  262|  27.9k|         break;
  263|  27.9k|      }
  264|  35.1k|   }
  265|       |
  266|  27.9k|   return next;
  267|  28.9k|}
_ZN5Botan11BER_Decoder9push_backEONS_10BER_ObjectE:
  279|    894|void BER_Decoder::push_back(BER_Object&& obj) {
  280|    894|   if(m_pushed.is_set()) {
  ------------------
  |  Branch (280:7): [True: 0, False: 894]
  ------------------
  281|      0|      throw Invalid_State("BER_Decoder: Only one push back is allowed");
  282|      0|   }
  283|    894|   m_pushed = std::move(obj);
  284|    894|}
_ZN5Botan11BER_Decoder10start_consENS_9ASN1_TypeENS_10ASN1_ClassE:
  286|  15.5k|BER_Decoder BER_Decoder::start_cons(ASN1_Type type_tag, ASN1_Class class_tag) {
  287|  15.5k|   BER_Object obj = get_next_object();
  288|  15.5k|   obj.assert_is_a(type_tag, class_tag | ASN1_Class::Constructed);
  289|  15.5k|   return BER_Decoder(std::move(obj), this);
  290|  15.5k|}
_ZN5Botan11BER_Decoder8end_consEv:
  295|  11.8k|BER_Decoder& BER_Decoder::end_cons() {
  296|  11.8k|   if(!m_parent) {
  ------------------
  |  Branch (296:7): [True: 0, False: 11.8k]
  ------------------
  297|      0|      throw Invalid_State("BER_Decoder::end_cons called with null parent");
  298|      0|   }
  299|  11.8k|   if(!m_source->end_of_data()) {
  ------------------
  |  Branch (299:7): [True: 65, False: 11.8k]
  ------------------
  300|     65|      throw Decoding_Error("BER_Decoder::end_cons called with data left");
  301|     65|   }
  302|  11.8k|   return (*m_parent);
  303|  11.8k|}
_ZN5Botan11BER_DecoderC2EONS_10BER_ObjectEPS0_:
  305|  14.8k|BER_Decoder::BER_Decoder(BER_Object&& obj, BER_Decoder* parent) {
  306|  14.8k|   m_data_src = std::make_unique<DataSource_BERObject>(std::move(obj));
  307|  14.8k|   m_source = m_data_src.get();
  308|  14.8k|   m_parent = parent;
  309|  14.8k|}
_ZN5Botan11BER_DecoderC2ERNS_10DataSourceE:
  314|  1.53k|BER_Decoder::BER_Decoder(DataSource& src) {
  315|  1.53k|   m_source = &src;
  316|  1.53k|}
_ZN5Botan11BER_DecoderC2EPKhm:
  321|  3.97k|BER_Decoder::BER_Decoder(const uint8_t data[], size_t length) {
  322|  3.97k|   m_data_src = std::make_unique<DataSource_Memory>(data, length);
  323|  3.97k|   m_source = m_data_src.get();
  324|  3.97k|}
_ZN5Botan11BER_DecoderC2ERKNSt3__16vectorIhNS1_9allocatorIhEEEE:
  337|  5.20k|BER_Decoder::BER_Decoder(const std::vector<uint8_t>& data) {
  338|  5.20k|   m_data_src = std::make_unique<DataSource_Memory>(data.data(), data.size());
  339|  5.20k|   m_source = m_data_src.get();
  340|  5.20k|}
_ZN5Botan11BER_Decoder6decodeERNS_11ASN1_ObjectENS_9ASN1_TypeENS_10ASN1_ClassE:
  356|  16.9k|BER_Decoder& BER_Decoder::decode(ASN1_Object& obj, ASN1_Type /*unused*/, ASN1_Class /*unused*/) {
  357|  16.9k|   obj.decode_from(*this);
  358|  16.9k|   return (*this);
  359|  16.9k|}
_ZN5Botan11BER_Decoder6decodeERmNS_9ASN1_TypeENS_10ASN1_ClassE:
  398|    130|BER_Decoder& BER_Decoder::decode(size_t& out, ASN1_Type type_tag, ASN1_Class class_tag) {
  399|    130|   BigInt integer;
  400|    130|   decode(integer, type_tag, class_tag);
  401|       |
  402|    130|   if(integer.is_negative()) {
  ------------------
  |  Branch (402:7): [True: 34, False: 96]
  ------------------
  403|     34|      throw BER_Decoding_Error("Decoded small integer value was negative");
  404|     34|   }
  405|       |
  406|     96|   if(integer.bits() > 32) {
  ------------------
  |  Branch (406:7): [True: 82, False: 14]
  ------------------
  407|     82|      throw BER_Decoding_Error("Decoded integer value larger than expected");
  408|     82|   }
  409|       |
  410|     14|   out = 0;
  411|     66|   for(size_t i = 0; i != 4; ++i) {
  ------------------
  |  Branch (411:22): [True: 52, False: 14]
  ------------------
  412|     52|      out = (out << 8) | integer.byte_at(3 - i);
  413|     52|   }
  414|       |
  415|     14|   return (*this);
  416|     96|}
_ZN5Botan11BER_Decoder6decodeERNS_6BigIntENS_9ASN1_TypeENS_10ASN1_ClassE:
  444|    598|BER_Decoder& BER_Decoder::decode(BigInt& out, ASN1_Type type_tag, ASN1_Class class_tag) {
  445|    598|   BER_Object obj = get_next_object();
  446|    598|   obj.assert_is_a(type_tag, class_tag);
  447|       |
  448|    598|   if(obj.length() == 0) {
  ------------------
  |  Branch (448:7): [True: 75, False: 523]
  ------------------
  449|     75|      out.clear();
  450|    523|   } else {
  451|    523|      const bool negative = (obj.bits()[0] & 0x80) ? true : false;
  ------------------
  |  Branch (451:29): [True: 247, False: 276]
  ------------------
  452|       |
  453|    523|      if(negative) {
  ------------------
  |  Branch (453:10): [True: 247, False: 276]
  ------------------
  454|    247|         secure_vector<uint8_t> vec(obj.bits(), obj.bits() + obj.length());
  455|    505|         for(size_t i = obj.length(); i > 0; --i) {
  ------------------
  |  Branch (455:39): [True: 505, False: 0]
  ------------------
  456|    505|            if(vec[i - 1]--) {
  ------------------
  |  Branch (456:16): [True: 247, False: 258]
  ------------------
  457|    247|               break;
  458|    247|            }
  459|    505|         }
  460|  1.88k|         for(size_t i = 0; i != obj.length(); ++i) {
  ------------------
  |  Branch (460:28): [True: 1.64k, False: 247]
  ------------------
  461|  1.64k|            vec[i] = ~vec[i];
  462|  1.64k|         }
  463|    247|         out = BigInt(vec.data(), vec.size());
  464|    247|         out.flip_sign();
  465|    276|      } else {
  466|    276|         out = BigInt(obj.bits(), obj.length());
  467|    276|      }
  468|    523|   }
  469|       |
  470|    598|   return (*this);
  471|    598|}
_ZN5Botan11BER_Decoder6decodeERNSt3__16vectorIhNS1_9allocatorIhEEEENS_9ASN1_TypeES7_NS_10ASN1_ClassE:
  521|  1.07k|                                 ASN1_Class class_tag) {
  522|  1.07k|   if(real_type != ASN1_Type::OctetString && real_type != ASN1_Type::BitString) {
  ------------------
  |  Branch (522:7): [True: 1.07k, False: 0]
  |  Branch (522:46): [True: 0, False: 1.07k]
  ------------------
  523|      0|      throw BER_Bad_Tag("Bad tag for {BIT,OCTET} STRING", static_cast<uint32_t>(real_type));
  524|      0|   }
  525|       |
  526|  1.07k|   asn1_decode_binary_string(buffer, get_next_object(), real_type, type_tag, class_tag);
  527|  1.07k|   return (*this);
  528|  1.07k|}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_110decode_tagEPNS_10DataSourceERNS_9ASN1_TypeERNS_10ASN1_ClassE:
   29|  81.4k|size_t decode_tag(DataSource* ber, ASN1_Type& type_tag, ASN1_Class& class_tag) {
   30|  81.4k|   uint8_t b;
   31|  81.4k|   if(!ber->read_byte(b)) {
  ------------------
  |  Branch (31:7): [True: 12.0k, False: 69.4k]
  ------------------
   32|  12.0k|      type_tag = ASN1_Type::NoObject;
   33|  12.0k|      class_tag = ASN1_Class::NoObject;
   34|  12.0k|      return 0;
   35|  12.0k|   }
   36|       |
   37|  69.4k|   if((b & 0x1F) != 0x1F) {
  ------------------
  |  Branch (37:7): [True: 67.9k, False: 1.46k]
  ------------------
   38|  67.9k|      type_tag = ASN1_Type(b & 0x1F);
   39|  67.9k|      class_tag = ASN1_Class(b & 0xE0);
   40|  67.9k|      return 1;
   41|  67.9k|   }
   42|       |
   43|  1.46k|   size_t tag_bytes = 1;
   44|  1.46k|   class_tag = ASN1_Class(b & 0xE0);
   45|       |
   46|  1.46k|   size_t tag_buf = 0;
   47|  4.01k|   while(true) {
  ------------------
  |  Branch (47:10): [Folded - Ignored]
  ------------------
   48|  4.01k|      if(!ber->read_byte(b)) {
  ------------------
  |  Branch (48:10): [True: 10, False: 4.00k]
  ------------------
   49|     10|         throw BER_Decoding_Error("Long-form tag truncated");
   50|     10|      }
   51|  4.00k|      if(tag_buf & 0xFF000000) {
  ------------------
  |  Branch (51:10): [True: 12, False: 3.99k]
  ------------------
   52|     12|         throw BER_Decoding_Error("Long-form tag overflowed 32 bits");
   53|     12|      }
   54|  3.99k|      ++tag_bytes;
   55|  3.99k|      tag_buf = (tag_buf << 7) | (b & 0x7F);
   56|  3.99k|      if((b & 0x80) == 0) {
  ------------------
  |  Branch (56:10): [True: 1.44k, False: 2.55k]
  ------------------
   57|  1.44k|         break;
   58|  1.44k|      }
   59|  3.99k|   }
   60|  1.44k|   type_tag = ASN1_Type(tag_buf);
   61|  1.44k|   return tag_bytes;
   62|  1.46k|}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_113decode_lengthEPNS_10DataSourceERmm:
   72|  69.3k|size_t decode_length(DataSource* ber, size_t& field_size, size_t allow_indef) {
   73|  69.3k|   uint8_t b;
   74|  69.3k|   if(!ber->read_byte(b)) {
  ------------------
  |  Branch (74:7): [True: 113, False: 69.2k]
  ------------------
   75|    113|      throw BER_Decoding_Error("Length field not found");
   76|    113|   }
   77|  69.2k|   field_size = 1;
   78|  69.2k|   if((b & 0x80) == 0) {
  ------------------
  |  Branch (78:7): [True: 51.8k, False: 17.3k]
  ------------------
   79|  51.8k|      return b;
   80|  51.8k|   }
   81|       |
   82|  17.3k|   field_size += (b & 0x7F);
   83|  17.3k|   if(field_size > 5) {
  ------------------
  |  Branch (83:7): [True: 25, False: 17.3k]
  ------------------
   84|     25|      throw BER_Decoding_Error("Length field is too large");
   85|     25|   }
   86|       |
   87|  17.3k|   if(field_size == 1) {
  ------------------
  |  Branch (87:7): [True: 16.5k, False: 793]
  ------------------
   88|  16.5k|      if(allow_indef == 0) {
  ------------------
  |  Branch (88:10): [True: 1, False: 16.5k]
  ------------------
   89|      1|         throw BER_Decoding_Error("Nested EOC markers too deep, rejecting to avoid stack exhaustion");
   90|  16.5k|      } else {
   91|  16.5k|         return find_eoc(ber, allow_indef - 1);
   92|  16.5k|      }
   93|  16.5k|   }
   94|       |
   95|    793|   size_t length = 0;
   96|       |
   97|  2.53k|   for(size_t i = 0; i != field_size - 1; ++i) {
  ------------------
  |  Branch (97:22): [True: 1.77k, False: 766]
  ------------------
   98|  1.77k|      if(get_byte<0>(length) != 0) {
  ------------------
  |  Branch (98:10): [True: 0, False: 1.77k]
  ------------------
   99|      0|         throw BER_Decoding_Error("Field length overflow");
  100|      0|      }
  101|  1.77k|      if(!ber->read_byte(b)) {
  ------------------
  |  Branch (101:10): [True: 27, False: 1.74k]
  ------------------
  102|     27|         throw BER_Decoding_Error("Corrupted length field");
  103|     27|      }
  104|  1.74k|      length = (length << 8) | b;
  105|  1.74k|   }
  106|    766|   return length;
  107|    793|}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_18find_eocEPNS_10DataSourceEm:
  112|  16.5k|size_t find_eoc(DataSource* ber, size_t allow_indef) {
  113|  16.5k|   secure_vector<uint8_t> buffer(BOTAN_DEFAULT_BUFFER_SIZE), data;
  ------------------
  |  |  388|  16.5k|#define BOTAN_DEFAULT_BUFFER_SIZE 4096
  ------------------
  114|       |
  115|  29.3k|   while(true) {
  ------------------
  |  Branch (115:10): [Folded - Ignored]
  ------------------
  116|  29.3k|      const size_t got = ber->peek(buffer.data(), buffer.size(), data.size());
  117|  29.3k|      if(got == 0) {
  ------------------
  |  Branch (117:10): [True: 16.5k, False: 12.7k]
  ------------------
  118|  16.5k|         break;
  119|  16.5k|      }
  120|       |
  121|  12.7k|      data += std::make_pair(buffer.data(), got);
  122|  12.7k|   }
  123|       |
  124|  16.5k|   DataSource_Memory source(data);
  125|  16.5k|   data.clear();
  126|       |
  127|  16.5k|   size_t length = 0;
  128|  45.5k|   while(true) {
  ------------------
  |  Branch (128:10): [Folded - Ignored]
  ------------------
  129|  45.3k|      ASN1_Type type_tag;
  130|  45.3k|      ASN1_Class class_tag;
  131|  45.3k|      size_t tag_size = decode_tag(&source, type_tag, class_tag);
  132|  45.3k|      if(type_tag == ASN1_Type::NoObject) {
  ------------------
  |  Branch (132:10): [True: 11.3k, False: 34.0k]
  ------------------
  133|  11.3k|         break;
  134|  11.3k|      }
  135|       |
  136|  34.0k|      size_t length_size = 0;
  137|  34.0k|      size_t item_size = decode_length(&source, length_size, allow_indef);
  138|  34.0k|      source.discard_next(item_size);
  139|       |
  140|  34.0k|      length = BOTAN_CHECKED_ADD(length, item_size);
  ------------------
  |  |   73|  34.0k|#define BOTAN_CHECKED_ADD(x, y) checked_add(x, y, __FILE__, __LINE__)
  ------------------
  141|  34.0k|      length = BOTAN_CHECKED_ADD(length, tag_size);
  ------------------
  |  |   73|  34.0k|#define BOTAN_CHECKED_ADD(x, y) checked_add(x, y, __FILE__, __LINE__)
  ------------------
  142|  34.0k|      length = BOTAN_CHECKED_ADD(length, length_size);
  ------------------
  |  |   73|  34.0k|#define BOTAN_CHECKED_ADD(x, y) checked_add(x, y, __FILE__, __LINE__)
  ------------------
  143|       |
  144|  34.0k|      if(type_tag == ASN1_Type::Eoc && class_tag == ASN1_Class::Universal) {
  ------------------
  |  Branch (144:10): [True: 7.37k, False: 26.6k]
  |  Branch (144:40): [True: 5.04k, False: 2.33k]
  ------------------
  145|  5.04k|         break;
  146|  5.04k|      }
  147|  34.0k|   }
  148|  16.5k|   return length;
  149|  16.5k|}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_120DataSource_BERObjectC2EONS_10BER_ObjectE:
  183|  14.8k|      explicit DataSource_BERObject(BER_Object&& obj) : m_obj(std::move(obj)), m_offset(0) {}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_120DataSource_BERObject4readEPhm:
  153|   230k|      size_t read(uint8_t out[], size_t length) override {
  154|   230k|         BOTAN_ASSERT_NOMSG(m_offset <= m_obj.length());
  ------------------
  |  |   60|   230k|   do {                                                                     \
  |  |   61|   230k|      if(!(expr))                                                           \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 230k]
  |  |  ------------------
  |  |   62|   230k|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   63|   230k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (63:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  155|   230k|         const size_t got = std::min<size_t>(m_obj.length() - m_offset, length);
  156|   230k|         copy_mem(out, m_obj.bits() + m_offset, got);
  157|   230k|         m_offset += got;
  158|   230k|         return got;
  159|   230k|      }
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_120DataSource_BERObject15check_availableEm:
  174|  23.5k|      bool check_available(size_t n) override {
  175|  23.5k|         BOTAN_ASSERT_NOMSG(m_offset <= m_obj.length());
  ------------------
  |  |   60|  23.5k|   do {                                                                     \
  |  |   61|  23.5k|      if(!(expr))                                                           \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 23.5k]
  |  |  ------------------
  |  |   62|  23.5k|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   63|  23.5k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (63:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  176|  23.5k|         return (n <= (m_obj.length() - m_offset));
  177|  23.5k|      }
ber_dec.cpp:_ZNK5Botan12_GLOBAL__N_120DataSource_BERObject4peekEPhmm:
  161|  7.34k|      size_t peek(uint8_t out[], size_t length, size_t peek_offset) const override {
  162|  7.34k|         BOTAN_ASSERT_NOMSG(m_offset <= m_obj.length());
  ------------------
  |  |   60|  7.34k|   do {                                                                     \
  |  |   61|  7.34k|      if(!(expr))                                                           \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 7.34k]
  |  |  ------------------
  |  |   62|  7.34k|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   63|  7.34k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (63:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  163|  7.34k|         const size_t bytes_left = m_obj.length() - m_offset;
  164|       |
  165|  7.34k|         if(peek_offset >= bytes_left) {
  ------------------
  |  Branch (165:13): [True: 4.39k, False: 2.94k]
  ------------------
  166|  4.39k|            return 0;
  167|  4.39k|         }
  168|       |
  169|  2.94k|         const size_t got = std::min(bytes_left - peek_offset, length);
  170|  2.94k|         copy_mem(out, m_obj.bits() + m_offset + peek_offset, got);
  171|  2.94k|         return got;
  172|  7.34k|      }
ber_dec.cpp:_ZNK5Botan12_GLOBAL__N_120DataSource_BERObject11end_of_dataEv:
  179|  18.0k|      bool end_of_data() const override { return get_bytes_read() == m_obj.length(); }
ber_dec.cpp:_ZNK5Botan12_GLOBAL__N_120DataSource_BERObject14get_bytes_readEv:
  181|  18.0k|      size_t get_bytes_read() const override { return m_offset; }
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_125asn1_decode_binary_stringINSt3__19allocatorIhEEEEvRNS2_6vectorIhT_EERKNS_10BER_ObjectENS_9ASN1_TypeESC_NS_10ASN1_ClassE:
  480|  1.07k|                               ASN1_Class class_tag) {
  481|  1.07k|   obj.assert_is_a(type_tag, class_tag);
  482|       |
  483|  1.07k|   if(real_type == ASN1_Type::OctetString) {
  ------------------
  |  Branch (483:7): [True: 0, False: 1.07k]
  ------------------
  484|      0|      buffer.assign(obj.bits(), obj.bits() + obj.length());
  485|  1.07k|   } else {
  486|  1.07k|      if(obj.length() == 0) {
  ------------------
  |  Branch (486:10): [True: 1, False: 1.07k]
  ------------------
  487|      1|         throw BER_Decoding_Error("Invalid BIT STRING");
  488|      1|      }
  489|  1.07k|      if(obj.bits()[0] >= 8) {
  ------------------
  |  Branch (489:10): [True: 6, False: 1.06k]
  ------------------
  490|      6|         throw BER_Decoding_Error("Bad number of unused bits in BIT STRING");
  491|      6|      }
  492|       |
  493|  1.06k|      buffer.resize(obj.length() - 1);
  494|       |
  495|  1.06k|      if(obj.length() > 1) {
  ------------------
  |  Branch (495:10): [True: 795, False: 273]
  ------------------
  496|    795|         copy_mem(buffer.data(), obj.bits() + 1, obj.length() - 1);
  497|    795|      }
  498|  1.06k|   }
  499|  1.07k|}

_ZN5Botan11DER_EncoderC2ERNSt3__16vectorIhNS1_9allocatorIhEEEE:
   71|    679|DER_Encoder::DER_Encoder(std::vector<uint8_t>& vec) {
   72|    679|   m_append_output = [&vec](const uint8_t b[], size_t l) { vec.insert(vec.end(), b, b + l); };
   73|    679|}
_ZN5Botan11DER_Encoder12DER_Sequence13push_contentsERS0_:
   78|    853|void DER_Encoder::DER_Sequence::push_contents(DER_Encoder& der) {
   79|    853|   const auto real_class_tag = m_class_tag | ASN1_Class::Constructed;
   80|       |
   81|    853|   if(m_type_tag == ASN1_Type::Set) {
  ------------------
  |  Branch (81:7): [True: 0, False: 853]
  ------------------
   82|      0|      std::sort(m_set_contents.begin(), m_set_contents.end());
   83|      0|      for(const auto& set_elem : m_set_contents) {
  ------------------
  |  Branch (83:32): [True: 0, False: 0]
  ------------------
   84|      0|         m_contents += set_elem;
   85|      0|      }
   86|      0|      m_set_contents.clear();
   87|      0|   }
   88|       |
   89|    853|   der.add_object(m_type_tag, real_class_tag, m_contents.data(), m_contents.size());
   90|    853|   m_contents.clear();
   91|    853|}
_ZN5Botan11DER_Encoder12DER_Sequence9add_bytesEPKhm:
   96|    766|void DER_Encoder::DER_Sequence::add_bytes(const uint8_t data[], size_t length) {
   97|    766|   if(m_type_tag == ASN1_Type::Set) {
  ------------------
  |  Branch (97:7): [True: 0, False: 766]
  ------------------
   98|      0|      m_set_contents.push_back(secure_vector<uint8_t>(data, data + length));
   99|    766|   } else {
  100|    766|      m_contents += std::make_pair(data, length);
  101|    766|   }
  102|    766|}
_ZN5Botan11DER_Encoder12DER_Sequence9add_bytesEPKhmS3_m:
  104|    397|void DER_Encoder::DER_Sequence::add_bytes(const uint8_t hdr[], size_t hdr_len, const uint8_t val[], size_t val_len) {
  105|    397|   if(m_type_tag == ASN1_Type::Set) {
  ------------------
  |  Branch (105:7): [True: 0, False: 397]
  ------------------
  106|      0|      secure_vector<uint8_t> m;
  107|      0|      m.reserve(hdr_len + val_len);
  108|      0|      m += std::make_pair(hdr, hdr_len);
  109|      0|      m += std::make_pair(val, val_len);
  110|      0|      m_set_contents.push_back(std::move(m));
  111|    397|   } else {
  112|    397|      m_contents += std::make_pair(hdr, hdr_len);
  113|    397|      m_contents += std::make_pair(val, val_len);
  114|    397|   }
  115|    397|}
_ZN5Botan11DER_Encoder12DER_SequenceC2ENS_9ASN1_TypeENS_10ASN1_ClassE:
  127|    951|DER_Encoder::DER_Sequence::DER_Sequence(ASN1_Type t1, ASN1_Class t2) : m_type_tag(t1), m_class_tag(t2) {}
_ZN5Botan11DER_Encoder10start_consENS_9ASN1_TypeENS_10ASN1_ClassE:
  163|    951|DER_Encoder& DER_Encoder::start_cons(ASN1_Type type_tag, ASN1_Class class_tag) {
  164|    951|   m_subsequences.push_back(DER_Sequence(type_tag, class_tag));
  165|    951|   return (*this);
  166|    951|}
_ZN5Botan11DER_Encoder8end_consEv:
  171|    853|DER_Encoder& DER_Encoder::end_cons() {
  172|    853|   if(m_subsequences.empty()) {
  ------------------
  |  Branch (172:7): [True: 0, False: 853]
  ------------------
  173|      0|      throw Invalid_State("DER_Encoder::end_cons: No such sequence");
  174|      0|   }
  175|       |
  176|    853|   DER_Sequence last_seq = std::move(m_subsequences[m_subsequences.size() - 1]);
  177|    853|   m_subsequences.pop_back();
  178|    853|   last_seq.push_contents(*this);
  179|       |
  180|    853|   return (*this);
  181|    853|}
_ZN5Botan11DER_Encoder9raw_bytesEPKhm:
  207|    766|DER_Encoder& DER_Encoder::raw_bytes(const uint8_t bytes[], size_t length) {
  208|    766|   if(!m_subsequences.empty()) {
  ------------------
  |  Branch (208:7): [True: 766, False: 0]
  ------------------
  209|    766|      m_subsequences[m_subsequences.size() - 1].add_bytes(bytes, length);
  210|    766|   } else if(m_append_output) {
  ------------------
  |  Branch (210:14): [True: 0, False: 0]
  ------------------
  211|      0|      m_append_output(bytes, length);
  212|      0|   } else {
  213|      0|      m_default_outbuf += std::make_pair(bytes, length);
  214|      0|   }
  215|       |
  216|    766|   return (*this);
  217|    766|}
_ZN5Botan11DER_Encoder10add_objectENS_9ASN1_TypeENS_10ASN1_ClassEPKhm:
  222|  1.02k|DER_Encoder& DER_Encoder::add_object(ASN1_Type type_tag, ASN1_Class class_tag, const uint8_t rep[], size_t length) {
  223|  1.02k|   std::vector<uint8_t> hdr;
  224|  1.02k|   encode_tag(hdr, type_tag, class_tag);
  225|  1.02k|   encode_length(hdr, length);
  226|       |
  227|  1.02k|   if(!m_subsequences.empty()) {
  ------------------
  |  Branch (227:7): [True: 397, False: 630]
  ------------------
  228|    397|      m_subsequences[m_subsequences.size() - 1].add_bytes(hdr.data(), hdr.size(), rep, length);
  229|    630|   } else if(m_append_output) {
  ------------------
  |  Branch (229:14): [True: 630, False: 0]
  ------------------
  230|    630|      m_append_output(hdr.data(), hdr.size());
  231|    630|      m_append_output(rep, length);
  232|    630|   } else {
  233|      0|      m_default_outbuf += hdr;
  234|      0|      m_default_outbuf += std::make_pair(rep, length);
  235|      0|   }
  236|       |
  237|  1.02k|   return (*this);
  238|  1.02k|}
_ZN5Botan11DER_Encoder6encodeEPKhmNS_9ASN1_TypeE:
  271|     87|DER_Encoder& DER_Encoder::encode(const uint8_t bytes[], size_t length, ASN1_Type real_type) {
  272|     87|   return encode(bytes, length, real_type, real_type, ASN1_Class::Universal);
  273|     87|}
_ZN5Botan11DER_Encoder6encodeEPKhmNS_9ASN1_TypeES3_NS_10ASN1_ClassE:
  319|     87|   const uint8_t bytes[], size_t length, ASN1_Type real_type, ASN1_Type type_tag, ASN1_Class class_tag) {
  320|     87|   if(real_type != ASN1_Type::OctetString && real_type != ASN1_Type::BitString) {
  ------------------
  |  Branch (320:7): [True: 87, False: 0]
  |  Branch (320:46): [True: 0, False: 87]
  ------------------
  321|      0|      throw Invalid_Argument("DER_Encoder: Invalid tag for byte/bit string");
  322|      0|   }
  323|       |
  324|     87|   if(real_type == ASN1_Type::BitString) {
  ------------------
  |  Branch (324:7): [True: 87, False: 0]
  ------------------
  325|     87|      secure_vector<uint8_t> encoded;
  326|     87|      encoded.push_back(0);
  327|     87|      encoded += std::make_pair(bytes, length);
  328|     87|      return add_object(type_tag, class_tag, encoded);
  329|     87|   } else {
  330|      0|      return add_object(type_tag, class_tag, bytes, length);
  331|      0|   }
  332|     87|}
_ZN5Botan11DER_Encoder6encodeERKNS_11ASN1_ObjectE:
  334|    272|DER_Encoder& DER_Encoder::encode(const ASN1_Object& obj) {
  335|    272|   obj.encode_into(*this);
  336|    272|   return (*this);
  337|    272|}
der_enc.cpp:_ZN5Botan12_GLOBAL__N_110encode_tagERNSt3__16vectorIhNS1_9allocatorIhEEEENS_9ASN1_TypeENS_10ASN1_ClassE:
   24|  1.02k|void encode_tag(std::vector<uint8_t>& encoded_tag, ASN1_Type type_tag_e, ASN1_Class class_tag_e) {
   25|  1.02k|   const uint32_t type_tag = static_cast<uint32_t>(type_tag_e);
   26|  1.02k|   const uint32_t class_tag = static_cast<uint32_t>(class_tag_e);
   27|       |
   28|  1.02k|   if((class_tag | 0xE0) != 0xE0) {
  ------------------
  |  Branch (28:7): [True: 0, False: 1.02k]
  ------------------
   29|      0|      throw Encoding_Error(fmt("DER_Encoder: Invalid class tag {}", std::to_string(class_tag)));
   30|      0|   }
   31|       |
   32|  1.02k|   if(type_tag <= 30) {
  ------------------
  |  Branch (32:7): [True: 1.02k, False: 0]
  ------------------
   33|  1.02k|      encoded_tag.push_back(static_cast<uint8_t>(type_tag | class_tag));
   34|  1.02k|   } else {
   35|      0|      size_t blocks = high_bit(static_cast<uint32_t>(type_tag)) + 6;
   36|      0|      blocks = (blocks - (blocks % 7)) / 7;
   37|       |
   38|      0|      BOTAN_ASSERT_NOMSG(blocks > 0);
  ------------------
  |  |   60|      0|   do {                                                                     \
  |  |   61|      0|      if(!(expr))                                                           \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 0]
  |  |  ------------------
  |  |   62|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   63|      0|   } while(0)
  |  |  ------------------
  |  |  |  Branch (63:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   39|       |
   40|      0|      encoded_tag.push_back(static_cast<uint8_t>(class_tag | 0x1F));
   41|      0|      for(size_t i = 0; i != blocks - 1; ++i) {
  ------------------
  |  Branch (41:25): [True: 0, False: 0]
  ------------------
   42|      0|         encoded_tag.push_back(0x80 | ((type_tag >> 7 * (blocks - i - 1)) & 0x7F));
   43|      0|      }
   44|      0|      encoded_tag.push_back(type_tag & 0x7F);
   45|      0|   }
   46|  1.02k|}
der_enc.cpp:_ZN5Botan12_GLOBAL__N_113encode_lengthERNSt3__16vectorIhNS1_9allocatorIhEEEEm:
   51|  1.02k|void encode_length(std::vector<uint8_t>& encoded_length, size_t length) {
   52|  1.02k|   if(length <= 127) {
  ------------------
  |  Branch (52:7): [True: 1.02k, False: 0]
  ------------------
   53|  1.02k|      encoded_length.push_back(static_cast<uint8_t>(length));
   54|  1.02k|   } else {
   55|      0|      const size_t bytes_needed = significant_bytes(length);
   56|       |
   57|      0|      encoded_length.push_back(static_cast<uint8_t>(0x80 | bytes_needed));
   58|       |
   59|      0|      for(size_t i = sizeof(length) - bytes_needed; i < sizeof(length); ++i) {
  ------------------
  |  Branch (59:53): [True: 0, False: 0]
  ------------------
   60|      0|         encoded_length.push_back(get_byte_var(i, length));
   61|      0|      }
   62|      0|   }
   63|  1.02k|}
der_enc.cpp:_ZZN5Botan11DER_EncoderC1ERNSt3__16vectorIhNS1_9allocatorIhEEEEENK3$_1clEPKhm:
   72|  1.26k|   m_append_output = [&vec](const uint8_t b[], size_t l) { vec.insert(vec.end(), b, b + l); };

_ZN5Botan7OID_MapC2Ev:
   11|      1|OID_Map::OID_Map() {
   12|      1|   m_str2oid = OID_Map::load_str2oid_map();
   13|      1|   m_oid2str = OID_Map::load_oid2str_map();
   14|      1|}
_ZN5Botan7OID_Map15global_registryEv:
   16|    211|OID_Map& OID_Map::global_registry() {
   17|    211|   static OID_Map g_map;
   18|    211|   return g_map;
   19|    211|}
_ZN5Botan7OID_Map7oid2strERKNS_3OIDE:
   56|    211|std::string OID_Map::oid2str(const OID& oid) {
   57|    211|   const std::string oid_str = oid.to_string();
   58|       |
   59|    211|   lock_guard_type<mutex_type> lock(m_mutex);
   60|       |
   61|    211|   auto i = m_oid2str.find(oid_str);
   62|    211|   if(i != m_oid2str.end()) {
  ------------------
  |  Branch (62:7): [True: 17, False: 194]
  ------------------
   63|     17|      return i->second;
   64|     17|   }
   65|       |
   66|    194|   return "";
   67|    211|}

_ZN5Botan7OID_Map16load_oid2str_mapEv:
   17|      1|std::unordered_map<std::string, std::string> OID_Map::load_oid2str_map() {
   18|      1|   return std::unordered_map<std::string, std::string>{
   19|       |
   20|      1|      {"0.3.4401.5.3.1.9.26", "Camellia-192/GCM"},
   21|      1|      {"0.3.4401.5.3.1.9.46", "Camellia-256/GCM"},
   22|      1|      {"0.3.4401.5.3.1.9.6", "Camellia-128/GCM"},
   23|      1|      {"0.4.0.127.0.15.1.1.13.0", "XMSS"},
   24|      1|      {"1.0.14888.3.0.5", "ECKCDSA"},
   25|      1|      {"1.2.156.10197.1.104.100", "SM4/OCB"},
   26|      1|      {"1.2.156.10197.1.104.2", "SM4/CBC"},
   27|      1|      {"1.2.156.10197.1.104.8", "SM4/GCM"},
   28|      1|      {"1.2.156.10197.1.301", "sm2p256v1"},
   29|      1|      {"1.2.156.10197.1.301.1", "SM2"},
   30|      1|      {"1.2.156.10197.1.301.2", "SM2_Kex"},
   31|      1|      {"1.2.156.10197.1.301.3", "SM2_Enc"},
   32|      1|      {"1.2.156.10197.1.401", "SM3"},
   33|      1|      {"1.2.156.10197.1.501", "SM2_Sig/SM3"},
   34|      1|      {"1.2.156.10197.1.504", "RSA/EMSA3(SM3)"},
   35|      1|      {"1.2.250.1.223.101.256.1", "frp256v1"},
   36|      1|      {"1.2.392.200011.61.1.1.1.2", "Camellia-128/CBC"},
   37|      1|      {"1.2.392.200011.61.1.1.1.3", "Camellia-192/CBC"},
   38|      1|      {"1.2.392.200011.61.1.1.1.4", "Camellia-256/CBC"},
   39|      1|      {"1.2.410.200004.1.100.4.3", "ECKCDSA/SHA-1"},
   40|      1|      {"1.2.410.200004.1.100.4.4", "ECKCDSA/SHA-224"},
   41|      1|      {"1.2.410.200004.1.100.4.5", "ECKCDSA/SHA-256"},
   42|      1|      {"1.2.410.200004.1.4", "SEED/CBC"},
   43|      1|      {"1.2.643.100.1", "GOST.OGRN"},
   44|      1|      {"1.2.643.100.111", "GOST.SubjectSigningTool"},
   45|      1|      {"1.2.643.100.112", "GOST.IssuerSigningTool"},
   46|      1|      {"1.2.643.2.2.19", "GOST-34.10"},
   47|      1|      {"1.2.643.2.2.3", "GOST-34.10/GOST-R-34.11-94"},
   48|      1|      {"1.2.643.2.2.35.1", "gost_256A"},
   49|      1|      {"1.2.643.2.2.36.0", "gost_256A"},
   50|      1|      {"1.2.643.3.131.1.1", "GOST.INN"},
   51|      1|      {"1.2.643.7.1.1.1.1", "GOST-34.10-2012-256"},
   52|      1|      {"1.2.643.7.1.1.1.2", "GOST-34.10-2012-512"},
   53|      1|      {"1.2.643.7.1.1.2.2", "Streebog-256"},
   54|      1|      {"1.2.643.7.1.1.2.3", "Streebog-512"},
   55|      1|      {"1.2.643.7.1.1.3.2", "GOST-34.10-2012-256/Streebog-256"},
   56|      1|      {"1.2.643.7.1.1.3.3", "GOST-34.10-2012-512/Streebog-512"},
   57|      1|      {"1.2.643.7.1.2.1.1.1", "gost_256A"},
   58|      1|      {"1.2.643.7.1.2.1.1.2", "gost_256B"},
   59|      1|      {"1.2.643.7.1.2.1.2.1", "gost_512A"},
   60|      1|      {"1.2.643.7.1.2.1.2.2", "gost_512B"},
   61|      1|      {"1.2.840.10040.4.1", "DSA"},
   62|      1|      {"1.2.840.10040.4.3", "DSA/SHA-1"},
   63|      1|      {"1.2.840.10045.2.1", "ECDSA"},
   64|      1|      {"1.2.840.10045.3.1.1", "secp192r1"},
   65|      1|      {"1.2.840.10045.3.1.2", "x962_p192v2"},
   66|      1|      {"1.2.840.10045.3.1.3", "x962_p192v3"},
   67|      1|      {"1.2.840.10045.3.1.4", "x962_p239v1"},
   68|      1|      {"1.2.840.10045.3.1.5", "x962_p239v2"},
   69|      1|      {"1.2.840.10045.3.1.6", "x962_p239v3"},
   70|      1|      {"1.2.840.10045.3.1.7", "secp256r1"},
   71|      1|      {"1.2.840.10045.4.1", "ECDSA/SHA-1"},
   72|      1|      {"1.2.840.10045.4.3.1", "ECDSA/SHA-224"},
   73|      1|      {"1.2.840.10045.4.3.2", "ECDSA/SHA-256"},
   74|      1|      {"1.2.840.10045.4.3.3", "ECDSA/SHA-384"},
   75|      1|      {"1.2.840.10045.4.3.4", "ECDSA/SHA-512"},
   76|      1|      {"1.2.840.10046.2.1", "DH"},
   77|      1|      {"1.2.840.113533.7.66.10", "CAST-128/CBC"},
   78|      1|      {"1.2.840.113533.7.66.15", "KeyWrap.CAST-128"},
   79|      1|      {"1.2.840.113549.1.1.1", "RSA"},
   80|      1|      {"1.2.840.113549.1.1.10", "RSA/EMSA4"},
   81|      1|      {"1.2.840.113549.1.1.11", "RSA/EMSA3(SHA-256)"},
   82|      1|      {"1.2.840.113549.1.1.12", "RSA/EMSA3(SHA-384)"},
   83|      1|      {"1.2.840.113549.1.1.13", "RSA/EMSA3(SHA-512)"},
   84|      1|      {"1.2.840.113549.1.1.14", "RSA/EMSA3(SHA-224)"},
   85|      1|      {"1.2.840.113549.1.1.16", "RSA/EMSA3(SHA-512-256)"},
   86|      1|      {"1.2.840.113549.1.1.4", "RSA/EMSA3(MD5)"},
   87|      1|      {"1.2.840.113549.1.1.5", "RSA/EMSA3(SHA-1)"},
   88|      1|      {"1.2.840.113549.1.1.7", "RSA/OAEP"},
   89|      1|      {"1.2.840.113549.1.1.8", "MGF1"},
   90|      1|      {"1.2.840.113549.1.5.12", "PKCS5.PBKDF2"},
   91|      1|      {"1.2.840.113549.1.5.13", "PBE-PKCS5v20"},
   92|      1|      {"1.2.840.113549.1.9.1", "PKCS9.EmailAddress"},
   93|      1|      {"1.2.840.113549.1.9.14", "PKCS9.ExtensionRequest"},
   94|      1|      {"1.2.840.113549.1.9.16.3.18", "ChaCha20Poly1305"},
   95|      1|      {"1.2.840.113549.1.9.16.3.6", "KeyWrap.TripleDES"},
   96|      1|      {"1.2.840.113549.1.9.16.3.8", "Compression.Zlib"},
   97|      1|      {"1.2.840.113549.1.9.2", "PKCS9.UnstructuredName"},
   98|      1|      {"1.2.840.113549.1.9.3", "PKCS9.ContentType"},
   99|      1|      {"1.2.840.113549.1.9.4", "PKCS9.MessageDigest"},
  100|      1|      {"1.2.840.113549.1.9.7", "PKCS9.ChallengePassword"},
  101|      1|      {"1.2.840.113549.2.10", "HMAC(SHA-384)"},
  102|      1|      {"1.2.840.113549.2.11", "HMAC(SHA-512)"},
  103|      1|      {"1.2.840.113549.2.13", "HMAC(SHA-512-256)"},
  104|      1|      {"1.2.840.113549.2.5", "MD5"},
  105|      1|      {"1.2.840.113549.2.7", "HMAC(SHA-1)"},
  106|      1|      {"1.2.840.113549.2.8", "HMAC(SHA-224)"},
  107|      1|      {"1.2.840.113549.2.9", "HMAC(SHA-256)"},
  108|      1|      {"1.2.840.113549.3.7", "TripleDES/CBC"},
  109|      1|      {"1.3.101.110", "Curve25519"},
  110|      1|      {"1.3.101.112", "Ed25519"},
  111|      1|      {"1.3.132.0.10", "secp256k1"},
  112|      1|      {"1.3.132.0.30", "secp160r2"},
  113|      1|      {"1.3.132.0.31", "secp192k1"},
  114|      1|      {"1.3.132.0.32", "secp224k1"},
  115|      1|      {"1.3.132.0.33", "secp224r1"},
  116|      1|      {"1.3.132.0.34", "secp384r1"},
  117|      1|      {"1.3.132.0.35", "secp521r1"},
  118|      1|      {"1.3.132.0.8", "secp160r1"},
  119|      1|      {"1.3.132.0.9", "secp160k1"},
  120|      1|      {"1.3.132.1.12", "ECDH"},
  121|      1|      {"1.3.14.3.2.26", "SHA-1"},
  122|      1|      {"1.3.14.3.2.7", "DES/CBC"},
  123|      1|      {"1.3.36.3.2.1", "RIPEMD-160"},
  124|      1|      {"1.3.36.3.3.1.2", "RSA/EMSA3(RIPEMD-160)"},
  125|      1|      {"1.3.36.3.3.2.5.2.1", "ECGDSA"},
  126|      1|      {"1.3.36.3.3.2.5.4.1", "ECGDSA/RIPEMD-160"},
  127|      1|      {"1.3.36.3.3.2.5.4.2", "ECGDSA/SHA-1"},
  128|      1|      {"1.3.36.3.3.2.5.4.3", "ECGDSA/SHA-224"},
  129|      1|      {"1.3.36.3.3.2.5.4.4", "ECGDSA/SHA-256"},
  130|      1|      {"1.3.36.3.3.2.5.4.5", "ECGDSA/SHA-384"},
  131|      1|      {"1.3.36.3.3.2.5.4.6", "ECGDSA/SHA-512"},
  132|      1|      {"1.3.36.3.3.2.8.1.1.1", "brainpool160r1"},
  133|      1|      {"1.3.36.3.3.2.8.1.1.11", "brainpool384r1"},
  134|      1|      {"1.3.36.3.3.2.8.1.1.13", "brainpool512r1"},
  135|      1|      {"1.3.36.3.3.2.8.1.1.3", "brainpool192r1"},
  136|      1|      {"1.3.36.3.3.2.8.1.1.5", "brainpool224r1"},
  137|      1|      {"1.3.36.3.3.2.8.1.1.7", "brainpool256r1"},
  138|      1|      {"1.3.36.3.3.2.8.1.1.9", "brainpool320r1"},
  139|      1|      {"1.3.6.1.4.1.11591.15.1", "OpenPGP.Ed25519"},
  140|      1|      {"1.3.6.1.4.1.11591.4.11", "Scrypt"},
  141|      1|      {"1.3.6.1.4.1.25258.1.10.1", "Dilithium-4x4-AES-r3"},
  142|      1|      {"1.3.6.1.4.1.25258.1.10.2", "Dilithium-6x5-AES-r3"},
  143|      1|      {"1.3.6.1.4.1.25258.1.10.3", "Dilithium-8x7-AES-r3"},
  144|      1|      {"1.3.6.1.4.1.25258.1.11.1", "Kyber-512-90s-r3"},
  145|      1|      {"1.3.6.1.4.1.25258.1.11.2", "Kyber-768-90s-r3"},
  146|      1|      {"1.3.6.1.4.1.25258.1.11.3", "Kyber-1024-90s-r3"},
  147|      1|      {"1.3.6.1.4.1.25258.1.12.1.1", "SphincsPlus-shake-128s-r3.1"},
  148|      1|      {"1.3.6.1.4.1.25258.1.12.1.2", "SphincsPlus-shake-128f-r3.1"},
  149|      1|      {"1.3.6.1.4.1.25258.1.12.1.3", "SphincsPlus-shake-192s-r3.1"},
  150|      1|      {"1.3.6.1.4.1.25258.1.12.1.4", "SphincsPlus-shake-192f-r3.1"},
  151|      1|      {"1.3.6.1.4.1.25258.1.12.1.5", "SphincsPlus-shake-256s-r3.1"},
  152|      1|      {"1.3.6.1.4.1.25258.1.12.1.6", "SphincsPlus-shake-256f-r3.1"},
  153|      1|      {"1.3.6.1.4.1.25258.1.12.2.1", "SphincsPlus-sha2-128s-r3.1"},
  154|      1|      {"1.3.6.1.4.1.25258.1.12.2.2", "SphincsPlus-sha2-128f-r3.1"},
  155|      1|      {"1.3.6.1.4.1.25258.1.12.2.3", "SphincsPlus-sha2-192s-r3.1"},
  156|      1|      {"1.3.6.1.4.1.25258.1.12.2.4", "SphincsPlus-sha2-192f-r3.1"},
  157|      1|      {"1.3.6.1.4.1.25258.1.12.2.5", "SphincsPlus-sha2-256s-r3.1"},
  158|      1|      {"1.3.6.1.4.1.25258.1.12.2.6", "SphincsPlus-sha2-256f-r3.1"},
  159|      1|      {"1.3.6.1.4.1.25258.1.12.3.1", "SphincsPlus-haraka-128s-r3.1"},
  160|      1|      {"1.3.6.1.4.1.25258.1.12.3.2", "SphincsPlus-haraka-128f-r3.1"},
  161|      1|      {"1.3.6.1.4.1.25258.1.12.3.3", "SphincsPlus-haraka-192s-r3.1"},
  162|      1|      {"1.3.6.1.4.1.25258.1.12.3.4", "SphincsPlus-haraka-192f-r3.1"},
  163|      1|      {"1.3.6.1.4.1.25258.1.12.3.5", "SphincsPlus-haraka-256s-r3.1"},
  164|      1|      {"1.3.6.1.4.1.25258.1.12.3.6", "SphincsPlus-haraka-256f-r3.1"},
  165|      1|      {"1.3.6.1.4.1.25258.1.14.1", "FrodoKEM-640-SHAKE"},
  166|      1|      {"1.3.6.1.4.1.25258.1.14.2", "FrodoKEM-976-SHAKE"},
  167|      1|      {"1.3.6.1.4.1.25258.1.14.3", "FrodoKEM-1344-SHAKE"},
  168|      1|      {"1.3.6.1.4.1.25258.1.15.1", "FrodoKEM-640-AES"},
  169|      1|      {"1.3.6.1.4.1.25258.1.15.2", "FrodoKEM-976-AES"},
  170|      1|      {"1.3.6.1.4.1.25258.1.15.3", "FrodoKEM-1344-AES"},
  171|      1|      {"1.3.6.1.4.1.25258.1.16.1", "eFrodoKEM-640-SHAKE"},
  172|      1|      {"1.3.6.1.4.1.25258.1.16.2", "eFrodoKEM-976-SHAKE"},
  173|      1|      {"1.3.6.1.4.1.25258.1.16.3", "eFrodoKEM-1344-SHAKE"},
  174|      1|      {"1.3.6.1.4.1.25258.1.17.1", "eFrodoKEM-640-AES"},
  175|      1|      {"1.3.6.1.4.1.25258.1.17.2", "eFrodoKEM-976-AES"},
  176|      1|      {"1.3.6.1.4.1.25258.1.17.3", "eFrodoKEM-1344-AES"},
  177|      1|      {"1.3.6.1.4.1.25258.1.3", "McEliece"},
  178|      1|      {"1.3.6.1.4.1.25258.1.5", "XMSS-draft6"},
  179|      1|      {"1.3.6.1.4.1.25258.1.6.1", "GOST-34.10-2012-256/SHA-256"},
  180|      1|      {"1.3.6.1.4.1.25258.1.7.1", "Kyber-512-r3"},
  181|      1|      {"1.3.6.1.4.1.25258.1.7.2", "Kyber-768-r3"},
  182|      1|      {"1.3.6.1.4.1.25258.1.7.3", "Kyber-1024-r3"},
  183|      1|      {"1.3.6.1.4.1.25258.1.8", "XMSS-draft12"},
  184|      1|      {"1.3.6.1.4.1.25258.1.9.1", "Dilithium-4x4-r3"},
  185|      1|      {"1.3.6.1.4.1.25258.1.9.2", "Dilithium-6x5-r3"},
  186|      1|      {"1.3.6.1.4.1.25258.1.9.3", "Dilithium-8x7-r3"},
  187|      1|      {"1.3.6.1.4.1.25258.3.1", "Serpent/CBC"},
  188|      1|      {"1.3.6.1.4.1.25258.3.101", "Serpent/GCM"},
  189|      1|      {"1.3.6.1.4.1.25258.3.102", "Twofish/GCM"},
  190|      1|      {"1.3.6.1.4.1.25258.3.2", "Threefish-512/CBC"},
  191|      1|      {"1.3.6.1.4.1.25258.3.2.1", "AES-128/OCB"},
  192|      1|      {"1.3.6.1.4.1.25258.3.2.2", "AES-192/OCB"},
  193|      1|      {"1.3.6.1.4.1.25258.3.2.3", "AES-256/OCB"},
  194|      1|      {"1.3.6.1.4.1.25258.3.2.4", "Serpent/OCB"},
  195|      1|      {"1.3.6.1.4.1.25258.3.2.5", "Twofish/OCB"},
  196|      1|      {"1.3.6.1.4.1.25258.3.2.6", "Camellia-128/OCB"},
  197|      1|      {"1.3.6.1.4.1.25258.3.2.7", "Camellia-192/OCB"},
  198|      1|      {"1.3.6.1.4.1.25258.3.2.8", "Camellia-256/OCB"},
  199|      1|      {"1.3.6.1.4.1.25258.3.3", "Twofish/CBC"},
  200|      1|      {"1.3.6.1.4.1.25258.3.4.1", "AES-128/SIV"},
  201|      1|      {"1.3.6.1.4.1.25258.3.4.2", "AES-192/SIV"},
  202|      1|      {"1.3.6.1.4.1.25258.3.4.3", "AES-256/SIV"},
  203|      1|      {"1.3.6.1.4.1.25258.3.4.4", "Serpent/SIV"},
  204|      1|      {"1.3.6.1.4.1.25258.3.4.5", "Twofish/SIV"},
  205|      1|      {"1.3.6.1.4.1.25258.3.4.6", "Camellia-128/SIV"},
  206|      1|      {"1.3.6.1.4.1.25258.3.4.7", "Camellia-192/SIV"},
  207|      1|      {"1.3.6.1.4.1.25258.3.4.8", "Camellia-256/SIV"},
  208|      1|      {"1.3.6.1.4.1.25258.3.4.9", "SM4/SIV"},
  209|      1|      {"1.3.6.1.4.1.3029.1.2.1", "ElGamal"},
  210|      1|      {"1.3.6.1.4.1.3029.1.5.1", "OpenPGP.Curve25519"},
  211|      1|      {"1.3.6.1.4.1.311.20.2.2", "Microsoft SmartcardLogon"},
  212|      1|      {"1.3.6.1.4.1.311.20.2.3", "Microsoft UPN"},
  213|      1|      {"1.3.6.1.4.1.8301.3.1.2.9.0.38", "secp521r1"},
  214|      1|      {"1.3.6.1.5.5.7.1.1", "PKIX.AuthorityInformationAccess"},
  215|      1|      {"1.3.6.1.5.5.7.3.1", "PKIX.ServerAuth"},
  216|      1|      {"1.3.6.1.5.5.7.3.2", "PKIX.ClientAuth"},
  217|      1|      {"1.3.6.1.5.5.7.3.3", "PKIX.CodeSigning"},
  218|      1|      {"1.3.6.1.5.5.7.3.4", "PKIX.EmailProtection"},
  219|      1|      {"1.3.6.1.5.5.7.3.5", "PKIX.IPsecEndSystem"},
  220|      1|      {"1.3.6.1.5.5.7.3.6", "PKIX.IPsecTunnel"},
  221|      1|      {"1.3.6.1.5.5.7.3.7", "PKIX.IPsecUser"},
  222|      1|      {"1.3.6.1.5.5.7.3.8", "PKIX.TimeStamping"},
  223|      1|      {"1.3.6.1.5.5.7.3.9", "PKIX.OCSPSigning"},
  224|      1|      {"1.3.6.1.5.5.7.48.1", "PKIX.OCSP"},
  225|      1|      {"1.3.6.1.5.5.7.48.1.1", "PKIX.OCSP.BasicResponse"},
  226|      1|      {"1.3.6.1.5.5.7.48.1.5", "PKIX.OCSP.NoCheck"},
  227|      1|      {"1.3.6.1.5.5.7.48.2", "PKIX.CertificateAuthorityIssuers"},
  228|      1|      {"1.3.6.1.5.5.7.8.5", "PKIX.XMPPAddr"},
  229|      1|      {"2.16.840.1.101.3.4.1.2", "AES-128/CBC"},
  230|      1|      {"2.16.840.1.101.3.4.1.22", "AES-192/CBC"},
  231|      1|      {"2.16.840.1.101.3.4.1.25", "KeyWrap.AES-192"},
  232|      1|      {"2.16.840.1.101.3.4.1.26", "AES-192/GCM"},
  233|      1|      {"2.16.840.1.101.3.4.1.27", "AES-192/CCM"},
  234|      1|      {"2.16.840.1.101.3.4.1.42", "AES-256/CBC"},
  235|      1|      {"2.16.840.1.101.3.4.1.45", "KeyWrap.AES-256"},
  236|      1|      {"2.16.840.1.101.3.4.1.46", "AES-256/GCM"},
  237|      1|      {"2.16.840.1.101.3.4.1.47", "AES-256/CCM"},
  238|      1|      {"2.16.840.1.101.3.4.1.5", "KeyWrap.AES-128"},
  239|      1|      {"2.16.840.1.101.3.4.1.6", "AES-128/GCM"},
  240|      1|      {"2.16.840.1.101.3.4.1.7", "AES-128/CCM"},
  241|      1|      {"2.16.840.1.101.3.4.2.1", "SHA-256"},
  242|      1|      {"2.16.840.1.101.3.4.2.10", "SHA-3(512)"},
  243|      1|      {"2.16.840.1.101.3.4.2.11", "SHAKE-128"},
  244|      1|      {"2.16.840.1.101.3.4.2.12", "SHAKE-256"},
  245|      1|      {"2.16.840.1.101.3.4.2.2", "SHA-384"},
  246|      1|      {"2.16.840.1.101.3.4.2.3", "SHA-512"},
  247|      1|      {"2.16.840.1.101.3.4.2.4", "SHA-224"},
  248|      1|      {"2.16.840.1.101.3.4.2.6", "SHA-512-256"},
  249|      1|      {"2.16.840.1.101.3.4.2.7", "SHA-3(224)"},
  250|      1|      {"2.16.840.1.101.3.4.2.8", "SHA-3(256)"},
  251|      1|      {"2.16.840.1.101.3.4.2.9", "SHA-3(384)"},
  252|      1|      {"2.16.840.1.101.3.4.3.1", "DSA/SHA-224"},
  253|      1|      {"2.16.840.1.101.3.4.3.10", "ECDSA/SHA-3(256)"},
  254|      1|      {"2.16.840.1.101.3.4.3.11", "ECDSA/SHA-3(384)"},
  255|      1|      {"2.16.840.1.101.3.4.3.12", "ECDSA/SHA-3(512)"},
  256|      1|      {"2.16.840.1.101.3.4.3.13", "RSA/EMSA3(SHA-3(224))"},
  257|      1|      {"2.16.840.1.101.3.4.3.14", "RSA/EMSA3(SHA-3(256))"},
  258|      1|      {"2.16.840.1.101.3.4.3.15", "RSA/EMSA3(SHA-3(384))"},
  259|      1|      {"2.16.840.1.101.3.4.3.16", "RSA/EMSA3(SHA-3(512))"},
  260|      1|      {"2.16.840.1.101.3.4.3.2", "DSA/SHA-256"},
  261|      1|      {"2.16.840.1.101.3.4.3.3", "DSA/SHA-384"},
  262|      1|      {"2.16.840.1.101.3.4.3.4", "DSA/SHA-512"},
  263|      1|      {"2.16.840.1.101.3.4.3.5", "DSA/SHA-3(224)"},
  264|      1|      {"2.16.840.1.101.3.4.3.6", "DSA/SHA-3(256)"},
  265|      1|      {"2.16.840.1.101.3.4.3.7", "DSA/SHA-3(384)"},
  266|      1|      {"2.16.840.1.101.3.4.3.8", "DSA/SHA-3(512)"},
  267|      1|      {"2.16.840.1.101.3.4.3.9", "ECDSA/SHA-3(224)"},
  268|      1|      {"2.16.840.1.113730.1.13", "Certificate Comment"},
  269|      1|      {"2.5.29.14", "X509v3.SubjectKeyIdentifier"},
  270|      1|      {"2.5.29.15", "X509v3.KeyUsage"},
  271|      1|      {"2.5.29.16", "X509v3.PrivateKeyUsagePeriod"},
  272|      1|      {"2.5.29.17", "X509v3.SubjectAlternativeName"},
  273|      1|      {"2.5.29.18", "X509v3.IssuerAlternativeName"},
  274|      1|      {"2.5.29.19", "X509v3.BasicConstraints"},
  275|      1|      {"2.5.29.20", "X509v3.CRLNumber"},
  276|      1|      {"2.5.29.21", "X509v3.ReasonCode"},
  277|      1|      {"2.5.29.23", "X509v3.HoldInstructionCode"},
  278|      1|      {"2.5.29.24", "X509v3.InvalidityDate"},
  279|      1|      {"2.5.29.28", "X509v3.CRLIssuingDistributionPoint"},
  280|      1|      {"2.5.29.30", "X509v3.NameConstraints"},
  281|      1|      {"2.5.29.31", "X509v3.CRLDistributionPoints"},
  282|      1|      {"2.5.29.32", "X509v3.CertificatePolicies"},
  283|      1|      {"2.5.29.32.0", "X509v3.AnyPolicy"},
  284|      1|      {"2.5.29.35", "X509v3.AuthorityKeyIdentifier"},
  285|      1|      {"2.5.29.36", "X509v3.PolicyConstraints"},
  286|      1|      {"2.5.29.37", "X509v3.ExtendedKeyUsage"},
  287|      1|      {"2.5.4.10", "X520.Organization"},
  288|      1|      {"2.5.4.11", "X520.OrganizationalUnit"},
  289|      1|      {"2.5.4.12", "X520.Title"},
  290|      1|      {"2.5.4.3", "X520.CommonName"},
  291|      1|      {"2.5.4.4", "X520.Surname"},
  292|      1|      {"2.5.4.42", "X520.GivenName"},
  293|      1|      {"2.5.4.43", "X520.Initials"},
  294|      1|      {"2.5.4.44", "X520.GenerationalQualifier"},
  295|      1|      {"2.5.4.46", "X520.DNQualifier"},
  296|      1|      {"2.5.4.5", "X520.SerialNumber"},
  297|      1|      {"2.5.4.6", "X520.Country"},
  298|      1|      {"2.5.4.65", "X520.Pseudonym"},
  299|      1|      {"2.5.4.7", "X520.Locality"},
  300|      1|      {"2.5.4.8", "X520.State"},
  301|      1|      {"2.5.4.9", "X520.StreetAddress"},
  302|      1|      {"2.5.8.1.1", "RSA"}};
  303|      1|}
_ZN5Botan7OID_Map16load_str2oid_mapEv:
  305|      1|std::unordered_map<std::string, OID> OID_Map::load_str2oid_map() {
  306|      1|   return std::unordered_map<std::string, OID>{
  307|       |
  308|      1|      {"AES-128/CBC", OID({2, 16, 840, 1, 101, 3, 4, 1, 2})},
  309|      1|      {"AES-128/CCM", OID({2, 16, 840, 1, 101, 3, 4, 1, 7})},
  310|      1|      {"AES-128/GCM", OID({2, 16, 840, 1, 101, 3, 4, 1, 6})},
  311|      1|      {"AES-128/OCB", OID({1, 3, 6, 1, 4, 1, 25258, 3, 2, 1})},
  312|      1|      {"AES-128/SIV", OID({1, 3, 6, 1, 4, 1, 25258, 3, 4, 1})},
  313|      1|      {"AES-192/CBC", OID({2, 16, 840, 1, 101, 3, 4, 1, 22})},
  314|      1|      {"AES-192/CCM", OID({2, 16, 840, 1, 101, 3, 4, 1, 27})},
  315|      1|      {"AES-192/GCM", OID({2, 16, 840, 1, 101, 3, 4, 1, 26})},
  316|      1|      {"AES-192/OCB", OID({1, 3, 6, 1, 4, 1, 25258, 3, 2, 2})},
  317|      1|      {"AES-192/SIV", OID({1, 3, 6, 1, 4, 1, 25258, 3, 4, 2})},
  318|      1|      {"AES-256/CBC", OID({2, 16, 840, 1, 101, 3, 4, 1, 42})},
  319|      1|      {"AES-256/CCM", OID({2, 16, 840, 1, 101, 3, 4, 1, 47})},
  320|      1|      {"AES-256/GCM", OID({2, 16, 840, 1, 101, 3, 4, 1, 46})},
  321|      1|      {"AES-256/OCB", OID({1, 3, 6, 1, 4, 1, 25258, 3, 2, 3})},
  322|      1|      {"AES-256/SIV", OID({1, 3, 6, 1, 4, 1, 25258, 3, 4, 3})},
  323|      1|      {"CAST-128/CBC", OID({1, 2, 840, 113533, 7, 66, 10})},
  324|      1|      {"Camellia-128/CBC", OID({1, 2, 392, 200011, 61, 1, 1, 1, 2})},
  325|      1|      {"Camellia-128/GCM", OID({0, 3, 4401, 5, 3, 1, 9, 6})},
  326|      1|      {"Camellia-128/OCB", OID({1, 3, 6, 1, 4, 1, 25258, 3, 2, 6})},
  327|      1|      {"Camellia-128/SIV", OID({1, 3, 6, 1, 4, 1, 25258, 3, 4, 6})},
  328|      1|      {"Camellia-192/CBC", OID({1, 2, 392, 200011, 61, 1, 1, 1, 3})},
  329|      1|      {"Camellia-192/GCM", OID({0, 3, 4401, 5, 3, 1, 9, 26})},
  330|      1|      {"Camellia-192/OCB", OID({1, 3, 6, 1, 4, 1, 25258, 3, 2, 7})},
  331|      1|      {"Camellia-192/SIV", OID({1, 3, 6, 1, 4, 1, 25258, 3, 4, 7})},
  332|      1|      {"Camellia-256/CBC", OID({1, 2, 392, 200011, 61, 1, 1, 1, 4})},
  333|      1|      {"Camellia-256/GCM", OID({0, 3, 4401, 5, 3, 1, 9, 46})},
  334|      1|      {"Camellia-256/OCB", OID({1, 3, 6, 1, 4, 1, 25258, 3, 2, 8})},
  335|      1|      {"Camellia-256/SIV", OID({1, 3, 6, 1, 4, 1, 25258, 3, 4, 8})},
  336|      1|      {"Certificate Comment", OID({2, 16, 840, 1, 113730, 1, 13})},
  337|      1|      {"ChaCha20Poly1305", OID({1, 2, 840, 113549, 1, 9, 16, 3, 18})},
  338|      1|      {"Compression.Zlib", OID({1, 2, 840, 113549, 1, 9, 16, 3, 8})},
  339|      1|      {"Curve25519", OID({1, 3, 101, 110})},
  340|      1|      {"DES/CBC", OID({1, 3, 14, 3, 2, 7})},
  341|      1|      {"DH", OID({1, 2, 840, 10046, 2, 1})},
  342|      1|      {"DSA", OID({1, 2, 840, 10040, 4, 1})},
  343|      1|      {"DSA/SHA-1", OID({1, 2, 840, 10040, 4, 3})},
  344|      1|      {"DSA/SHA-224", OID({2, 16, 840, 1, 101, 3, 4, 3, 1})},
  345|      1|      {"DSA/SHA-256", OID({2, 16, 840, 1, 101, 3, 4, 3, 2})},
  346|      1|      {"DSA/SHA-3(224)", OID({2, 16, 840, 1, 101, 3, 4, 3, 5})},
  347|      1|      {"DSA/SHA-3(256)", OID({2, 16, 840, 1, 101, 3, 4, 3, 6})},
  348|      1|      {"DSA/SHA-3(384)", OID({2, 16, 840, 1, 101, 3, 4, 3, 7})},
  349|      1|      {"DSA/SHA-3(512)", OID({2, 16, 840, 1, 101, 3, 4, 3, 8})},
  350|      1|      {"DSA/SHA-384", OID({2, 16, 840, 1, 101, 3, 4, 3, 3})},
  351|      1|      {"DSA/SHA-512", OID({2, 16, 840, 1, 101, 3, 4, 3, 4})},
  352|      1|      {"Dilithium-4x4-AES-r3", OID({1, 3, 6, 1, 4, 1, 25258, 1, 10, 1})},
  353|      1|      {"Dilithium-4x4-r3", OID({1, 3, 6, 1, 4, 1, 25258, 1, 9, 1})},
  354|      1|      {"Dilithium-6x5-AES-r3", OID({1, 3, 6, 1, 4, 1, 25258, 1, 10, 2})},
  355|      1|      {"Dilithium-6x5-r3", OID({1, 3, 6, 1, 4, 1, 25258, 1, 9, 2})},
  356|      1|      {"Dilithium-8x7-AES-r3", OID({1, 3, 6, 1, 4, 1, 25258, 1, 10, 3})},
  357|      1|      {"Dilithium-8x7-r3", OID({1, 3, 6, 1, 4, 1, 25258, 1, 9, 3})},
  358|      1|      {"ECDH", OID({1, 3, 132, 1, 12})},
  359|      1|      {"ECDSA", OID({1, 2, 840, 10045, 2, 1})},
  360|      1|      {"ECDSA/SHA-1", OID({1, 2, 840, 10045, 4, 1})},
  361|      1|      {"ECDSA/SHA-224", OID({1, 2, 840, 10045, 4, 3, 1})},
  362|      1|      {"ECDSA/SHA-256", OID({1, 2, 840, 10045, 4, 3, 2})},
  363|      1|      {"ECDSA/SHA-3(224)", OID({2, 16, 840, 1, 101, 3, 4, 3, 9})},
  364|      1|      {"ECDSA/SHA-3(256)", OID({2, 16, 840, 1, 101, 3, 4, 3, 10})},
  365|      1|      {"ECDSA/SHA-3(384)", OID({2, 16, 840, 1, 101, 3, 4, 3, 11})},
  366|      1|      {"ECDSA/SHA-3(512)", OID({2, 16, 840, 1, 101, 3, 4, 3, 12})},
  367|      1|      {"ECDSA/SHA-384", OID({1, 2, 840, 10045, 4, 3, 3})},
  368|      1|      {"ECDSA/SHA-512", OID({1, 2, 840, 10045, 4, 3, 4})},
  369|      1|      {"ECGDSA", OID({1, 3, 36, 3, 3, 2, 5, 2, 1})},
  370|      1|      {"ECGDSA/RIPEMD-160", OID({1, 3, 36, 3, 3, 2, 5, 4, 1})},
  371|      1|      {"ECGDSA/SHA-1", OID({1, 3, 36, 3, 3, 2, 5, 4, 2})},
  372|      1|      {"ECGDSA/SHA-224", OID({1, 3, 36, 3, 3, 2, 5, 4, 3})},
  373|      1|      {"ECGDSA/SHA-256", OID({1, 3, 36, 3, 3, 2, 5, 4, 4})},
  374|      1|      {"ECGDSA/SHA-384", OID({1, 3, 36, 3, 3, 2, 5, 4, 5})},
  375|      1|      {"ECGDSA/SHA-512", OID({1, 3, 36, 3, 3, 2, 5, 4, 6})},
  376|      1|      {"ECKCDSA", OID({1, 0, 14888, 3, 0, 5})},
  377|      1|      {"ECKCDSA/SHA-1", OID({1, 2, 410, 200004, 1, 100, 4, 3})},
  378|      1|      {"ECKCDSA/SHA-224", OID({1, 2, 410, 200004, 1, 100, 4, 4})},
  379|      1|      {"ECKCDSA/SHA-256", OID({1, 2, 410, 200004, 1, 100, 4, 5})},
  380|      1|      {"Ed25519", OID({1, 3, 101, 112})},
  381|      1|      {"ElGamal", OID({1, 3, 6, 1, 4, 1, 3029, 1, 2, 1})},
  382|      1|      {"FrodoKEM-1344-AES", OID({1, 3, 6, 1, 4, 1, 25258, 1, 15, 3})},
  383|      1|      {"FrodoKEM-1344-SHAKE", OID({1, 3, 6, 1, 4, 1, 25258, 1, 14, 3})},
  384|      1|      {"FrodoKEM-640-AES", OID({1, 3, 6, 1, 4, 1, 25258, 1, 15, 1})},
  385|      1|      {"FrodoKEM-640-SHAKE", OID({1, 3, 6, 1, 4, 1, 25258, 1, 14, 1})},
  386|      1|      {"FrodoKEM-976-AES", OID({1, 3, 6, 1, 4, 1, 25258, 1, 15, 2})},
  387|      1|      {"FrodoKEM-976-SHAKE", OID({1, 3, 6, 1, 4, 1, 25258, 1, 14, 2})},
  388|      1|      {"GOST-34.10", OID({1, 2, 643, 2, 2, 19})},
  389|      1|      {"GOST-34.10-2012-256", OID({1, 2, 643, 7, 1, 1, 1, 1})},
  390|      1|      {"GOST-34.10-2012-256/SHA-256", OID({1, 3, 6, 1, 4, 1, 25258, 1, 6, 1})},
  391|      1|      {"GOST-34.10-2012-256/Streebog-256", OID({1, 2, 643, 7, 1, 1, 3, 2})},
  392|      1|      {"GOST-34.10-2012-512", OID({1, 2, 643, 7, 1, 1, 1, 2})},
  393|      1|      {"GOST-34.10-2012-512/Streebog-512", OID({1, 2, 643, 7, 1, 1, 3, 3})},
  394|      1|      {"GOST-34.10/GOST-R-34.11-94", OID({1, 2, 643, 2, 2, 3})},
  395|      1|      {"GOST.INN", OID({1, 2, 643, 3, 131, 1, 1})},
  396|      1|      {"GOST.IssuerSigningTool", OID({1, 2, 643, 100, 112})},
  397|      1|      {"GOST.OGRN", OID({1, 2, 643, 100, 1})},
  398|      1|      {"GOST.SubjectSigningTool", OID({1, 2, 643, 100, 111})},
  399|      1|      {"HMAC(SHA-1)", OID({1, 2, 840, 113549, 2, 7})},
  400|      1|      {"HMAC(SHA-224)", OID({1, 2, 840, 113549, 2, 8})},
  401|      1|      {"HMAC(SHA-256)", OID({1, 2, 840, 113549, 2, 9})},
  402|      1|      {"HMAC(SHA-384)", OID({1, 2, 840, 113549, 2, 10})},
  403|      1|      {"HMAC(SHA-512)", OID({1, 2, 840, 113549, 2, 11})},
  404|      1|      {"HMAC(SHA-512-256)", OID({1, 2, 840, 113549, 2, 13})},
  405|      1|      {"KeyWrap.AES-128", OID({2, 16, 840, 1, 101, 3, 4, 1, 5})},
  406|      1|      {"KeyWrap.AES-192", OID({2, 16, 840, 1, 101, 3, 4, 1, 25})},
  407|      1|      {"KeyWrap.AES-256", OID({2, 16, 840, 1, 101, 3, 4, 1, 45})},
  408|      1|      {"KeyWrap.CAST-128", OID({1, 2, 840, 113533, 7, 66, 15})},
  409|      1|      {"KeyWrap.TripleDES", OID({1, 2, 840, 113549, 1, 9, 16, 3, 6})},
  410|      1|      {"Kyber-1024-90s-r3", OID({1, 3, 6, 1, 4, 1, 25258, 1, 11, 3})},
  411|      1|      {"Kyber-1024-r3", OID({1, 3, 6, 1, 4, 1, 25258, 1, 7, 3})},
  412|      1|      {"Kyber-512-90s-r3", OID({1, 3, 6, 1, 4, 1, 25258, 1, 11, 1})},
  413|      1|      {"Kyber-512-r3", OID({1, 3, 6, 1, 4, 1, 25258, 1, 7, 1})},
  414|      1|      {"Kyber-768-90s-r3", OID({1, 3, 6, 1, 4, 1, 25258, 1, 11, 2})},
  415|      1|      {"Kyber-768-r3", OID({1, 3, 6, 1, 4, 1, 25258, 1, 7, 2})},
  416|      1|      {"MD5", OID({1, 2, 840, 113549, 2, 5})},
  417|      1|      {"MGF1", OID({1, 2, 840, 113549, 1, 1, 8})},
  418|      1|      {"McEliece", OID({1, 3, 6, 1, 4, 1, 25258, 1, 3})},
  419|      1|      {"Microsoft SmartcardLogon", OID({1, 3, 6, 1, 4, 1, 311, 20, 2, 2})},
  420|      1|      {"Microsoft UPN", OID({1, 3, 6, 1, 4, 1, 311, 20, 2, 3})},
  421|      1|      {"OpenPGP.Curve25519", OID({1, 3, 6, 1, 4, 1, 3029, 1, 5, 1})},
  422|      1|      {"OpenPGP.Ed25519", OID({1, 3, 6, 1, 4, 1, 11591, 15, 1})},
  423|      1|      {"PBE-PKCS5v20", OID({1, 2, 840, 113549, 1, 5, 13})},
  424|      1|      {"PBES2", OID({1, 2, 840, 113549, 1, 5, 13})},
  425|      1|      {"PKCS5.PBKDF2", OID({1, 2, 840, 113549, 1, 5, 12})},
  426|      1|      {"PKCS9.ChallengePassword", OID({1, 2, 840, 113549, 1, 9, 7})},
  427|      1|      {"PKCS9.ContentType", OID({1, 2, 840, 113549, 1, 9, 3})},
  428|      1|      {"PKCS9.EmailAddress", OID({1, 2, 840, 113549, 1, 9, 1})},
  429|      1|      {"PKCS9.ExtensionRequest", OID({1, 2, 840, 113549, 1, 9, 14})},
  430|      1|      {"PKCS9.MessageDigest", OID({1, 2, 840, 113549, 1, 9, 4})},
  431|      1|      {"PKCS9.UnstructuredName", OID({1, 2, 840, 113549, 1, 9, 2})},
  432|      1|      {"PKIX.AuthorityInformationAccess", OID({1, 3, 6, 1, 5, 5, 7, 1, 1})},
  433|      1|      {"PKIX.CertificateAuthorityIssuers", OID({1, 3, 6, 1, 5, 5, 7, 48, 2})},
  434|      1|      {"PKIX.ClientAuth", OID({1, 3, 6, 1, 5, 5, 7, 3, 2})},
  435|      1|      {"PKIX.CodeSigning", OID({1, 3, 6, 1, 5, 5, 7, 3, 3})},
  436|      1|      {"PKIX.EmailProtection", OID({1, 3, 6, 1, 5, 5, 7, 3, 4})},
  437|      1|      {"PKIX.IPsecEndSystem", OID({1, 3, 6, 1, 5, 5, 7, 3, 5})},
  438|      1|      {"PKIX.IPsecTunnel", OID({1, 3, 6, 1, 5, 5, 7, 3, 6})},
  439|      1|      {"PKIX.IPsecUser", OID({1, 3, 6, 1, 5, 5, 7, 3, 7})},
  440|      1|      {"PKIX.OCSP", OID({1, 3, 6, 1, 5, 5, 7, 48, 1})},
  441|      1|      {"PKIX.OCSP.BasicResponse", OID({1, 3, 6, 1, 5, 5, 7, 48, 1, 1})},
  442|      1|      {"PKIX.OCSP.NoCheck", OID({1, 3, 6, 1, 5, 5, 7, 48, 1, 5})},
  443|      1|      {"PKIX.OCSPSigning", OID({1, 3, 6, 1, 5, 5, 7, 3, 9})},
  444|      1|      {"PKIX.ServerAuth", OID({1, 3, 6, 1, 5, 5, 7, 3, 1})},
  445|      1|      {"PKIX.TimeStamping", OID({1, 3, 6, 1, 5, 5, 7, 3, 8})},
  446|      1|      {"PKIX.XMPPAddr", OID({1, 3, 6, 1, 5, 5, 7, 8, 5})},
  447|      1|      {"RIPEMD-160", OID({1, 3, 36, 3, 2, 1})},
  448|      1|      {"RSA", OID({1, 2, 840, 113549, 1, 1, 1})},
  449|      1|      {"RSA/EMSA3(MD5)", OID({1, 2, 840, 113549, 1, 1, 4})},
  450|      1|      {"RSA/EMSA3(RIPEMD-160)", OID({1, 3, 36, 3, 3, 1, 2})},
  451|      1|      {"RSA/EMSA3(SHA-1)", OID({1, 2, 840, 113549, 1, 1, 5})},
  452|      1|      {"RSA/EMSA3(SHA-224)", OID({1, 2, 840, 113549, 1, 1, 14})},
  453|      1|      {"RSA/EMSA3(SHA-256)", OID({1, 2, 840, 113549, 1, 1, 11})},
  454|      1|      {"RSA/EMSA3(SHA-3(224))", OID({2, 16, 840, 1, 101, 3, 4, 3, 13})},
  455|      1|      {"RSA/EMSA3(SHA-3(256))", OID({2, 16, 840, 1, 101, 3, 4, 3, 14})},
  456|      1|      {"RSA/EMSA3(SHA-3(384))", OID({2, 16, 840, 1, 101, 3, 4, 3, 15})},
  457|      1|      {"RSA/EMSA3(SHA-3(512))", OID({2, 16, 840, 1, 101, 3, 4, 3, 16})},
  458|      1|      {"RSA/EMSA3(SHA-384)", OID({1, 2, 840, 113549, 1, 1, 12})},
  459|      1|      {"RSA/EMSA3(SHA-512)", OID({1, 2, 840, 113549, 1, 1, 13})},
  460|      1|      {"RSA/EMSA3(SHA-512-256)", OID({1, 2, 840, 113549, 1, 1, 16})},
  461|      1|      {"RSA/EMSA3(SM3)", OID({1, 2, 156, 10197, 1, 504})},
  462|      1|      {"RSA/EMSA4", OID({1, 2, 840, 113549, 1, 1, 10})},
  463|      1|      {"RSA/OAEP", OID({1, 2, 840, 113549, 1, 1, 7})},
  464|      1|      {"SEED/CBC", OID({1, 2, 410, 200004, 1, 4})},
  465|      1|      {"SHA-1", OID({1, 3, 14, 3, 2, 26})},
  466|      1|      {"SHA-224", OID({2, 16, 840, 1, 101, 3, 4, 2, 4})},
  467|      1|      {"SHA-256", OID({2, 16, 840, 1, 101, 3, 4, 2, 1})},
  468|      1|      {"SHA-3(224)", OID({2, 16, 840, 1, 101, 3, 4, 2, 7})},
  469|      1|      {"SHA-3(256)", OID({2, 16, 840, 1, 101, 3, 4, 2, 8})},
  470|      1|      {"SHA-3(384)", OID({2, 16, 840, 1, 101, 3, 4, 2, 9})},
  471|      1|      {"SHA-3(512)", OID({2, 16, 840, 1, 101, 3, 4, 2, 10})},
  472|      1|      {"SHA-384", OID({2, 16, 840, 1, 101, 3, 4, 2, 2})},
  473|      1|      {"SHA-512", OID({2, 16, 840, 1, 101, 3, 4, 2, 3})},
  474|      1|      {"SHA-512-256", OID({2, 16, 840, 1, 101, 3, 4, 2, 6})},
  475|      1|      {"SHAKE-128", OID({2, 16, 840, 1, 101, 3, 4, 2, 11})},
  476|      1|      {"SHAKE-256", OID({2, 16, 840, 1, 101, 3, 4, 2, 12})},
  477|      1|      {"SM2", OID({1, 2, 156, 10197, 1, 301, 1})},
  478|      1|      {"SM2_Enc", OID({1, 2, 156, 10197, 1, 301, 3})},
  479|      1|      {"SM2_Kex", OID({1, 2, 156, 10197, 1, 301, 2})},
  480|      1|      {"SM2_Sig", OID({1, 2, 156, 10197, 1, 301, 1})},
  481|      1|      {"SM2_Sig/SM3", OID({1, 2, 156, 10197, 1, 501})},
  482|      1|      {"SM3", OID({1, 2, 156, 10197, 1, 401})},
  483|      1|      {"SM4/CBC", OID({1, 2, 156, 10197, 1, 104, 2})},
  484|      1|      {"SM4/GCM", OID({1, 2, 156, 10197, 1, 104, 8})},
  485|      1|      {"SM4/OCB", OID({1, 2, 156, 10197, 1, 104, 100})},
  486|      1|      {"SM4/SIV", OID({1, 3, 6, 1, 4, 1, 25258, 3, 4, 9})},
  487|      1|      {"Scrypt", OID({1, 3, 6, 1, 4, 1, 11591, 4, 11})},
  488|      1|      {"Serpent/CBC", OID({1, 3, 6, 1, 4, 1, 25258, 3, 1})},
  489|      1|      {"Serpent/GCM", OID({1, 3, 6, 1, 4, 1, 25258, 3, 101})},
  490|      1|      {"Serpent/OCB", OID({1, 3, 6, 1, 4, 1, 25258, 3, 2, 4})},
  491|      1|      {"Serpent/SIV", OID({1, 3, 6, 1, 4, 1, 25258, 3, 4, 4})},
  492|      1|      {"SphincsPlus-haraka-128f-r3.1", OID({1, 3, 6, 1, 4, 1, 25258, 1, 12, 3, 2})},
  493|      1|      {"SphincsPlus-haraka-128s-r3.1", OID({1, 3, 6, 1, 4, 1, 25258, 1, 12, 3, 1})},
  494|      1|      {"SphincsPlus-haraka-192f-r3.1", OID({1, 3, 6, 1, 4, 1, 25258, 1, 12, 3, 4})},
  495|      1|      {"SphincsPlus-haraka-192s-r3.1", OID({1, 3, 6, 1, 4, 1, 25258, 1, 12, 3, 3})},
  496|      1|      {"SphincsPlus-haraka-256f-r3.1", OID({1, 3, 6, 1, 4, 1, 25258, 1, 12, 3, 6})},
  497|      1|      {"SphincsPlus-haraka-256s-r3.1", OID({1, 3, 6, 1, 4, 1, 25258, 1, 12, 3, 5})},
  498|      1|      {"SphincsPlus-sha2-128f-r3.1", OID({1, 3, 6, 1, 4, 1, 25258, 1, 12, 2, 2})},
  499|      1|      {"SphincsPlus-sha2-128s-r3.1", OID({1, 3, 6, 1, 4, 1, 25258, 1, 12, 2, 1})},
  500|      1|      {"SphincsPlus-sha2-192f-r3.1", OID({1, 3, 6, 1, 4, 1, 25258, 1, 12, 2, 4})},
  501|      1|      {"SphincsPlus-sha2-192s-r3.1", OID({1, 3, 6, 1, 4, 1, 25258, 1, 12, 2, 3})},
  502|      1|      {"SphincsPlus-sha2-256f-r3.1", OID({1, 3, 6, 1, 4, 1, 25258, 1, 12, 2, 6})},
  503|      1|      {"SphincsPlus-sha2-256s-r3.1", OID({1, 3, 6, 1, 4, 1, 25258, 1, 12, 2, 5})},
  504|      1|      {"SphincsPlus-shake-128f-r3.1", OID({1, 3, 6, 1, 4, 1, 25258, 1, 12, 1, 2})},
  505|      1|      {"SphincsPlus-shake-128s-r3.1", OID({1, 3, 6, 1, 4, 1, 25258, 1, 12, 1, 1})},
  506|      1|      {"SphincsPlus-shake-192f-r3.1", OID({1, 3, 6, 1, 4, 1, 25258, 1, 12, 1, 4})},
  507|      1|      {"SphincsPlus-shake-192s-r3.1", OID({1, 3, 6, 1, 4, 1, 25258, 1, 12, 1, 3})},
  508|      1|      {"SphincsPlus-shake-256f-r3.1", OID({1, 3, 6, 1, 4, 1, 25258, 1, 12, 1, 6})},
  509|      1|      {"SphincsPlus-shake-256s-r3.1", OID({1, 3, 6, 1, 4, 1, 25258, 1, 12, 1, 5})},
  510|      1|      {"Streebog-256", OID({1, 2, 643, 7, 1, 1, 2, 2})},
  511|      1|      {"Streebog-512", OID({1, 2, 643, 7, 1, 1, 2, 3})},
  512|      1|      {"Threefish-512/CBC", OID({1, 3, 6, 1, 4, 1, 25258, 3, 2})},
  513|      1|      {"TripleDES/CBC", OID({1, 2, 840, 113549, 3, 7})},
  514|      1|      {"Twofish/CBC", OID({1, 3, 6, 1, 4, 1, 25258, 3, 3})},
  515|      1|      {"Twofish/GCM", OID({1, 3, 6, 1, 4, 1, 25258, 3, 102})},
  516|      1|      {"Twofish/OCB", OID({1, 3, 6, 1, 4, 1, 25258, 3, 2, 5})},
  517|      1|      {"Twofish/SIV", OID({1, 3, 6, 1, 4, 1, 25258, 3, 4, 5})},
  518|      1|      {"X509v3.AnyPolicy", OID({2, 5, 29, 32, 0})},
  519|      1|      {"X509v3.AuthorityKeyIdentifier", OID({2, 5, 29, 35})},
  520|      1|      {"X509v3.BasicConstraints", OID({2, 5, 29, 19})},
  521|      1|      {"X509v3.CRLDistributionPoints", OID({2, 5, 29, 31})},
  522|      1|      {"X509v3.CRLIssuingDistributionPoint", OID({2, 5, 29, 28})},
  523|      1|      {"X509v3.CRLNumber", OID({2, 5, 29, 20})},
  524|      1|      {"X509v3.CertificatePolicies", OID({2, 5, 29, 32})},
  525|      1|      {"X509v3.ExtendedKeyUsage", OID({2, 5, 29, 37})},
  526|      1|      {"X509v3.HoldInstructionCode", OID({2, 5, 29, 23})},
  527|      1|      {"X509v3.InvalidityDate", OID({2, 5, 29, 24})},
  528|      1|      {"X509v3.IssuerAlternativeName", OID({2, 5, 29, 18})},
  529|      1|      {"X509v3.KeyUsage", OID({2, 5, 29, 15})},
  530|      1|      {"X509v3.NameConstraints", OID({2, 5, 29, 30})},
  531|      1|      {"X509v3.PolicyConstraints", OID({2, 5, 29, 36})},
  532|      1|      {"X509v3.PrivateKeyUsagePeriod", OID({2, 5, 29, 16})},
  533|      1|      {"X509v3.ReasonCode", OID({2, 5, 29, 21})},
  534|      1|      {"X509v3.SubjectAlternativeName", OID({2, 5, 29, 17})},
  535|      1|      {"X509v3.SubjectKeyIdentifier", OID({2, 5, 29, 14})},
  536|      1|      {"X520.CommonName", OID({2, 5, 4, 3})},
  537|      1|      {"X520.Country", OID({2, 5, 4, 6})},
  538|      1|      {"X520.DNQualifier", OID({2, 5, 4, 46})},
  539|      1|      {"X520.GenerationalQualifier", OID({2, 5, 4, 44})},
  540|      1|      {"X520.GivenName", OID({2, 5, 4, 42})},
  541|      1|      {"X520.Initials", OID({2, 5, 4, 43})},
  542|      1|      {"X520.Locality", OID({2, 5, 4, 7})},
  543|      1|      {"X520.Organization", OID({2, 5, 4, 10})},
  544|      1|      {"X520.OrganizationalUnit", OID({2, 5, 4, 11})},
  545|      1|      {"X520.Pseudonym", OID({2, 5, 4, 65})},
  546|      1|      {"X520.SerialNumber", OID({2, 5, 4, 5})},
  547|      1|      {"X520.State", OID({2, 5, 4, 8})},
  548|      1|      {"X520.StreetAddress", OID({2, 5, 4, 9})},
  549|      1|      {"X520.Surname", OID({2, 5, 4, 4})},
  550|      1|      {"X520.Title", OID({2, 5, 4, 12})},
  551|      1|      {"XMSS", OID({0, 4, 0, 127, 0, 15, 1, 1, 13, 0})},
  552|      1|      {"XMSS-draft12", OID({1, 3, 6, 1, 4, 1, 25258, 1, 8})},
  553|      1|      {"XMSS-draft6", OID({1, 3, 6, 1, 4, 1, 25258, 1, 5})},
  554|      1|      {"brainpool160r1", OID({1, 3, 36, 3, 3, 2, 8, 1, 1, 1})},
  555|      1|      {"brainpool192r1", OID({1, 3, 36, 3, 3, 2, 8, 1, 1, 3})},
  556|      1|      {"brainpool224r1", OID({1, 3, 36, 3, 3, 2, 8, 1, 1, 5})},
  557|      1|      {"brainpool256r1", OID({1, 3, 36, 3, 3, 2, 8, 1, 1, 7})},
  558|      1|      {"brainpool320r1", OID({1, 3, 36, 3, 3, 2, 8, 1, 1, 9})},
  559|      1|      {"brainpool384r1", OID({1, 3, 36, 3, 3, 2, 8, 1, 1, 11})},
  560|      1|      {"brainpool512r1", OID({1, 3, 36, 3, 3, 2, 8, 1, 1, 13})},
  561|      1|      {"eFrodoKEM-1344-AES", OID({1, 3, 6, 1, 4, 1, 25258, 1, 17, 3})},
  562|      1|      {"eFrodoKEM-1344-SHAKE", OID({1, 3, 6, 1, 4, 1, 25258, 1, 16, 3})},
  563|      1|      {"eFrodoKEM-640-AES", OID({1, 3, 6, 1, 4, 1, 25258, 1, 17, 1})},
  564|      1|      {"eFrodoKEM-640-SHAKE", OID({1, 3, 6, 1, 4, 1, 25258, 1, 16, 1})},
  565|      1|      {"eFrodoKEM-976-AES", OID({1, 3, 6, 1, 4, 1, 25258, 1, 17, 2})},
  566|      1|      {"eFrodoKEM-976-SHAKE", OID({1, 3, 6, 1, 4, 1, 25258, 1, 16, 2})},
  567|      1|      {"frp256v1", OID({1, 2, 250, 1, 223, 101, 256, 1})},
  568|      1|      {"gost_256A", OID({1, 2, 643, 7, 1, 2, 1, 1, 1})},
  569|      1|      {"gost_256B", OID({1, 2, 643, 7, 1, 2, 1, 1, 2})},
  570|      1|      {"gost_512A", OID({1, 2, 643, 7, 1, 2, 1, 2, 1})},
  571|      1|      {"gost_512B", OID({1, 2, 643, 7, 1, 2, 1, 2, 2})},
  572|      1|      {"secp160k1", OID({1, 3, 132, 0, 9})},
  573|      1|      {"secp160r1", OID({1, 3, 132, 0, 8})},
  574|      1|      {"secp160r2", OID({1, 3, 132, 0, 30})},
  575|      1|      {"secp192k1", OID({1, 3, 132, 0, 31})},
  576|      1|      {"secp192r1", OID({1, 2, 840, 10045, 3, 1, 1})},
  577|      1|      {"secp224k1", OID({1, 3, 132, 0, 32})},
  578|      1|      {"secp224r1", OID({1, 3, 132, 0, 33})},
  579|      1|      {"secp256k1", OID({1, 3, 132, 0, 10})},
  580|      1|      {"secp256r1", OID({1, 2, 840, 10045, 3, 1, 7})},
  581|      1|      {"secp384r1", OID({1, 3, 132, 0, 34})},
  582|      1|      {"secp521r1", OID({1, 3, 132, 0, 35})},
  583|      1|      {"sm2p256v1", OID({1, 2, 156, 10197, 1, 301})},
  584|      1|      {"x962_p192v2", OID({1, 2, 840, 10045, 3, 1, 2})},
  585|      1|      {"x962_p192v3", OID({1, 2, 840, 10045, 3, 1, 3})},
  586|      1|      {"x962_p239v1", OID({1, 2, 840, 10045, 3, 1, 4})},
  587|      1|      {"x962_p239v2", OID({1, 2, 840, 10045, 3, 1, 5})},
  588|      1|      {"x962_p239v3", OID({1, 2, 840, 10045, 3, 1, 6})}};
  589|      1|}

_ZN5Botan13base64_decodeEPKcmb:
  174|    122|secure_vector<uint8_t> base64_decode(const char input[], size_t input_length, bool ignore_ws) {
  175|    122|   return base_decode_to_vec<secure_vector<uint8_t>>(Base64(), input, input_length, ignore_ws);
  176|    122|}
base64.cpp:_ZN5Botan12_GLOBAL__N_16Base6417decode_max_outputEm:
   41|    244|      static inline size_t decode_max_output(size_t input_length) {
   42|    244|         return (round_up(input_length, m_encoding_bytes_out) * m_encoding_bytes_in) / m_encoding_bytes_out;
   43|    244|      }
base64.cpp:_ZN5Botan12_GLOBAL__N_16Base6417decoding_bytes_inEv:
   29|    122|      static inline size_t decoding_bytes_in() noexcept { return m_encoding_bytes_out; }
base64.cpp:_ZN5Botan12_GLOBAL__N_16Base6418decoding_bytes_outEv:
   31|    122|      static inline size_t decoding_bytes_out() noexcept { return m_encoding_bytes_in; }
base64.cpp:_ZN5Botan12_GLOBAL__N_16Base6419lookup_binary_valueEc:
  103|  18.8k|uint8_t Base64::lookup_binary_value(char input) noexcept {
  104|  18.8k|   const uint8_t c = static_cast<uint8_t>(input);
  105|       |
  106|  18.8k|   const auto is_alpha_upper = CT::Mask<uint8_t>::is_within_range(c, uint8_t('A'), uint8_t('Z'));
  107|  18.8k|   const auto is_alpha_lower = CT::Mask<uint8_t>::is_within_range(c, uint8_t('a'), uint8_t('z'));
  108|  18.8k|   const auto is_decimal = CT::Mask<uint8_t>::is_within_range(c, uint8_t('0'), uint8_t('9'));
  109|       |
  110|  18.8k|   const auto is_plus = CT::Mask<uint8_t>::is_equal(c, uint8_t('+'));
  111|  18.8k|   const auto is_slash = CT::Mask<uint8_t>::is_equal(c, uint8_t('/'));
  112|  18.8k|   const auto is_equal = CT::Mask<uint8_t>::is_equal(c, uint8_t('='));
  113|       |
  114|  18.8k|   const auto is_whitespace =
  115|  18.8k|      CT::Mask<uint8_t>::is_any_of(c, {uint8_t(' '), uint8_t('\t'), uint8_t('\n'), uint8_t('\r')});
  116|       |
  117|  18.8k|   const uint8_t c_upper = c - uint8_t('A');
  118|  18.8k|   const uint8_t c_lower = c - uint8_t('a') + 26;
  119|  18.8k|   const uint8_t c_decim = c - uint8_t('0') + 2 * 26;
  120|       |
  121|  18.8k|   uint8_t ret = 0xFF;  // default value
  122|       |
  123|  18.8k|   ret = is_alpha_upper.select(c_upper, ret);
  124|  18.8k|   ret = is_alpha_lower.select(c_lower, ret);
  125|  18.8k|   ret = is_decimal.select(c_decim, ret);
  126|  18.8k|   ret = is_plus.select(62, ret);
  127|  18.8k|   ret = is_slash.select(63, ret);
  128|  18.8k|   ret = is_equal.select(0x81, ret);
  129|  18.8k|   ret = is_whitespace.select(0x80, ret);
  130|       |
  131|  18.8k|   return ret;
  132|  18.8k|}
base64.cpp:_ZN5Botan12_GLOBAL__N_16Base6414check_bad_charEhcb:
  135|  18.5k|bool Base64::check_bad_char(uint8_t bin, char input, bool ignore_ws) {
  136|  18.5k|   if(bin <= 0x3F) {
  ------------------
  |  Branch (136:7): [True: 12.6k, False: 5.88k]
  ------------------
  137|  12.6k|      return true;
  138|  12.6k|   } else if(!(bin == 0x81 || (bin == 0x80 && ignore_ws))) {
  ------------------
  |  Branch (138:16): [True: 1.80k, False: 4.08k]
  |  Branch (138:32): [True: 4.05k, False: 26]
  |  Branch (138:47): [True: 4.05k, False: 0]
  ------------------
  139|     26|      throw Invalid_Argument(fmt("base64_decode: invalid character '{}'", format_char_for_display(input)));
  140|     26|   }
  141|  5.86k|   return false;
  142|  18.5k|}
base64.cpp:_ZN5Botan12_GLOBAL__N_16Base646decodeEPhPKh:
   51|  3.17k|      static void decode(uint8_t* out_ptr, const uint8_t decode_buf[4]) {
   52|  3.17k|         out_ptr[0] = (decode_buf[0] << 2) | (decode_buf[1] >> 4);
   53|  3.17k|         out_ptr[1] = (decode_buf[1] << 4) | (decode_buf[2] >> 2);
   54|  3.17k|         out_ptr[2] = (decode_buf[2] << 6) | decode_buf[3];
   55|  3.17k|      }
base64.cpp:_ZN5Botan12_GLOBAL__N_16Base6415bytes_to_removeEm:
   57|     96|      static inline size_t bytes_to_remove(size_t final_truncate) { return final_truncate; }
base64.cpp:_ZN5Botan12_GLOBAL__N_16Base644nameEv:
   23|     17|      static inline std::string name() noexcept { return "base64"; }

_ZN5Botan10hex_encodeEPcPKhmb:
   33|    174|void hex_encode(char output[], const uint8_t input[], size_t input_length, bool uppercase) {
   34|  4.69k|   for(size_t i = 0; i != input_length; ++i) {
  ------------------
  |  Branch (34:22): [True: 4.52k, False: 174]
  ------------------
   35|  4.52k|      const uint8_t n0 = (input[i] >> 4) & 0xF;
   36|  4.52k|      const uint8_t n1 = (input[i]) & 0xF;
   37|       |
   38|  4.52k|      output[2 * i] = hex_encode_nibble(n0, uppercase);
   39|  4.52k|      output[2 * i + 1] = hex_encode_nibble(n1, uppercase);
   40|  4.52k|   }
   41|    174|}
_ZN5Botan10hex_encodeEPKhmb:
   43|    174|std::string hex_encode(const uint8_t input[], size_t input_length, bool uppercase) {
   44|    174|   std::string output(2 * input_length, 0);
   45|       |
   46|    174|   if(input_length) {
  ------------------
  |  Branch (46:7): [True: 174, False: 0]
  ------------------
   47|    174|      hex_encode(&output.front(), input, input_length, uppercase);
   48|    174|   }
   49|       |
   50|    174|   return output;
   51|    174|}
hex.cpp:_ZN5Botan12_GLOBAL__N_117hex_encode_nibbleEhb:
   20|  9.04k|char hex_encode_nibble(uint8_t n, bool uppercase) {
   21|  9.04k|   BOTAN_DEBUG_ASSERT(n <= 15);
  ------------------
  |  |   99|  9.04k|      do {                          \
  |  |  100|  9.04k|      } while(0)
  |  |  ------------------
  |  |  |  Branch (100:15): [Folded - Ignored]
  |  |  ------------------
  ------------------
   22|       |
   23|  9.04k|   const auto in_09 = CT::Mask<uint8_t>::is_lt(n, 10);
   24|       |
   25|  9.04k|   const char c_09 = n + '0';
   26|  9.04k|   const char c_af = n + (uppercase ? 'A' : 'a') - 10;
  ------------------
  |  Branch (26:27): [True: 9.04k, False: 0]
  ------------------
   27|       |
   28|  9.04k|   return in_09.select(c_09, c_af);
   29|  9.04k|}

_ZN5Botan12HashFunction6createENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEES5_:
  107|  8.62k|std::unique_ptr<HashFunction> HashFunction::create(std::string_view algo_spec, std::string_view provider) {
  108|       |#if defined(BOTAN_HAS_COMMONCRYPTO)
  109|       |   if(provider.empty() || provider == "commoncrypto") {
  110|       |      if(auto hash = make_commoncrypto_hash(algo_spec))
  111|       |         return hash;
  112|       |
  113|       |      if(!provider.empty())
  114|       |         return nullptr;
  115|       |   }
  116|       |#endif
  117|       |
  118|  8.62k|   if(provider.empty() == false && provider != "base") {
  ------------------
  |  Branch (118:7): [True: 0, False: 8.62k]
  |  Branch (118:36): [True: 0, False: 0]
  ------------------
  119|      0|      return nullptr;  // unknown provider
  120|      0|   }
  121|       |
  122|  8.62k|#if defined(BOTAN_HAS_SHA1)
  123|  8.62k|   if(algo_spec == "SHA-1") {
  ------------------
  |  Branch (123:7): [True: 174, False: 8.45k]
  ------------------
  124|    174|      return std::make_unique<SHA_1>();
  125|    174|   }
  126|  8.45k|#endif
  127|       |
  128|  8.45k|#if defined(BOTAN_HAS_SHA2_32)
  129|  8.45k|   if(algo_spec == "SHA-224") {
  ------------------
  |  Branch (129:7): [True: 0, False: 8.45k]
  ------------------
  130|      0|      return std::make_unique<SHA_224>();
  131|      0|   }
  132|       |
  133|  8.45k|   if(algo_spec == "SHA-256") {
  ------------------
  |  Branch (133:7): [True: 8.45k, False: 0]
  ------------------
  134|  8.45k|      return std::make_unique<SHA_256>();
  135|  8.45k|   }
  136|      0|#endif
  137|       |
  138|      0|#if defined(BOTAN_HAS_SHA2_64)
  139|      0|   if(algo_spec == "SHA-384") {
  ------------------
  |  Branch (139:7): [True: 0, False: 0]
  ------------------
  140|      0|      return std::make_unique<SHA_384>();
  141|      0|   }
  142|       |
  143|      0|   if(algo_spec == "SHA-512") {
  ------------------
  |  Branch (143:7): [True: 0, False: 0]
  ------------------
  144|      0|      return std::make_unique<SHA_512>();
  145|      0|   }
  146|       |
  147|      0|   if(algo_spec == "SHA-512-256") {
  ------------------
  |  Branch (147:7): [True: 0, False: 0]
  ------------------
  148|      0|      return std::make_unique<SHA_512_256>();
  149|      0|   }
  150|      0|#endif
  151|       |
  152|      0|#if defined(BOTAN_HAS_RIPEMD_160)
  153|      0|   if(algo_spec == "RIPEMD-160") {
  ------------------
  |  Branch (153:7): [True: 0, False: 0]
  ------------------
  154|      0|      return std::make_unique<RIPEMD_160>();
  155|      0|   }
  156|      0|#endif
  157|       |
  158|      0|#if defined(BOTAN_HAS_WHIRLPOOL)
  159|      0|   if(algo_spec == "Whirlpool") {
  ------------------
  |  Branch (159:7): [True: 0, False: 0]
  ------------------
  160|      0|      return std::make_unique<Whirlpool>();
  161|      0|   }
  162|      0|#endif
  163|       |
  164|      0|#if defined(BOTAN_HAS_MD5)
  165|      0|   if(algo_spec == "MD5") {
  ------------------
  |  Branch (165:7): [True: 0, False: 0]
  ------------------
  166|      0|      return std::make_unique<MD5>();
  167|      0|   }
  168|      0|#endif
  169|       |
  170|      0|#if defined(BOTAN_HAS_MD4)
  171|      0|   if(algo_spec == "MD4") {
  ------------------
  |  Branch (171:7): [True: 0, False: 0]
  ------------------
  172|      0|      return std::make_unique<MD4>();
  173|      0|   }
  174|      0|#endif
  175|       |
  176|      0|#if defined(BOTAN_HAS_GOST_34_11)
  177|      0|   if(algo_spec == "GOST-R-34.11-94" || algo_spec == "GOST-34.11") {
  ------------------
  |  Branch (177:7): [True: 0, False: 0]
  |  Branch (177:41): [True: 0, False: 0]
  ------------------
  178|      0|      return std::make_unique<GOST_34_11>();
  179|      0|   }
  180|      0|#endif
  181|       |
  182|      0|#if defined(BOTAN_HAS_ADLER32)
  183|      0|   if(algo_spec == "Adler32") {
  ------------------
  |  Branch (183:7): [True: 0, False: 0]
  ------------------
  184|      0|      return std::make_unique<Adler32>();
  185|      0|   }
  186|      0|#endif
  187|       |
  188|      0|#if defined(BOTAN_HAS_CRC24)
  189|      0|   if(algo_spec == "CRC24") {
  ------------------
  |  Branch (189:7): [True: 0, False: 0]
  ------------------
  190|      0|      return std::make_unique<CRC24>();
  191|      0|   }
  192|      0|#endif
  193|       |
  194|      0|#if defined(BOTAN_HAS_CRC32)
  195|      0|   if(algo_spec == "CRC32") {
  ------------------
  |  Branch (195:7): [True: 0, False: 0]
  ------------------
  196|      0|      return std::make_unique<CRC32>();
  197|      0|   }
  198|      0|#endif
  199|       |
  200|      0|#if defined(BOTAN_HAS_STREEBOG)
  201|      0|   if(algo_spec == "Streebog-256") {
  ------------------
  |  Branch (201:7): [True: 0, False: 0]
  ------------------
  202|      0|      return std::make_unique<Streebog>(256);
  203|      0|   }
  204|      0|   if(algo_spec == "Streebog-512") {
  ------------------
  |  Branch (204:7): [True: 0, False: 0]
  ------------------
  205|      0|      return std::make_unique<Streebog>(512);
  206|      0|   }
  207|      0|#endif
  208|       |
  209|      0|#if defined(BOTAN_HAS_SM3)
  210|      0|   if(algo_spec == "SM3") {
  ------------------
  |  Branch (210:7): [True: 0, False: 0]
  ------------------
  211|      0|      return std::make_unique<SM3>();
  212|      0|   }
  213|      0|#endif
  214|       |
  215|      0|   const SCAN_Name req(algo_spec);
  216|       |
  217|      0|#if defined(BOTAN_HAS_SKEIN_512)
  218|      0|   if(req.algo_name() == "Skein-512") {
  ------------------
  |  Branch (218:7): [True: 0, False: 0]
  ------------------
  219|      0|      return std::make_unique<Skein_512>(req.arg_as_integer(0, 512), req.arg(1, ""));
  220|      0|   }
  221|      0|#endif
  222|       |
  223|      0|#if defined(BOTAN_HAS_BLAKE2B)
  224|      0|   if(req.algo_name() == "Blake2b" || req.algo_name() == "BLAKE2b") {
  ------------------
  |  Branch (224:7): [True: 0, False: 0]
  |  Branch (224:39): [True: 0, False: 0]
  ------------------
  225|      0|      return std::make_unique<BLAKE2b>(req.arg_as_integer(0, 512));
  226|      0|   }
  227|      0|#endif
  228|       |
  229|      0|#if defined(BOTAN_HAS_BLAKE2S)
  230|      0|   if(req.algo_name() == "Blake2s" || req.algo_name() == "BLAKE2s") {
  ------------------
  |  Branch (230:7): [True: 0, False: 0]
  |  Branch (230:39): [True: 0, False: 0]
  ------------------
  231|      0|      return std::make_unique<BLAKE2s>(req.arg_as_integer(0, 256));
  232|      0|   }
  233|      0|#endif
  234|       |
  235|      0|#if defined(BOTAN_HAS_KECCAK)
  236|      0|   if(req.algo_name() == "Keccak-1600") {
  ------------------
  |  Branch (236:7): [True: 0, False: 0]
  ------------------
  237|      0|      return std::make_unique<Keccak_1600>(req.arg_as_integer(0, 512));
  238|      0|   }
  239|      0|#endif
  240|       |
  241|      0|#if defined(BOTAN_HAS_SHA3)
  242|      0|   if(req.algo_name() == "SHA-3") {
  ------------------
  |  Branch (242:7): [True: 0, False: 0]
  ------------------
  243|      0|      return std::make_unique<SHA_3>(req.arg_as_integer(0, 512));
  244|      0|   }
  245|      0|#endif
  246|       |
  247|      0|#if defined(BOTAN_HAS_SHAKE)
  248|      0|   if(req.algo_name() == "SHAKE-128" && req.arg_count() == 1) {
  ------------------
  |  Branch (248:7): [True: 0, False: 0]
  |  Branch (248:41): [True: 0, False: 0]
  ------------------
  249|      0|      return std::make_unique<SHAKE_128>(req.arg_as_integer(0));
  250|      0|   }
  251|      0|   if(req.algo_name() == "SHAKE-256" && req.arg_count() == 1) {
  ------------------
  |  Branch (251:7): [True: 0, False: 0]
  |  Branch (251:41): [True: 0, False: 0]
  ------------------
  252|      0|      return std::make_unique<SHAKE_256>(req.arg_as_integer(0));
  253|      0|   }
  254|      0|#endif
  255|       |
  256|      0|#if defined(BOTAN_HAS_PARALLEL_HASH)
  257|      0|   if(req.algo_name() == "Parallel") {
  ------------------
  |  Branch (257:7): [True: 0, False: 0]
  ------------------
  258|      0|      std::vector<std::unique_ptr<HashFunction>> hashes;
  259|       |
  260|      0|      for(size_t i = 0; i != req.arg_count(); ++i) {
  ------------------
  |  Branch (260:25): [True: 0, False: 0]
  ------------------
  261|      0|         auto h = HashFunction::create(req.arg(i));
  262|      0|         if(!h) {
  ------------------
  |  Branch (262:13): [True: 0, False: 0]
  ------------------
  263|      0|            return nullptr;
  264|      0|         }
  265|      0|         hashes.push_back(std::move(h));
  266|      0|      }
  267|       |
  268|      0|      return std::make_unique<Parallel>(hashes);
  269|      0|   }
  270|      0|#endif
  271|       |
  272|      0|#if defined(BOTAN_HAS_TRUNCATED_HASH)
  273|      0|   if(req.algo_name() == "Truncated" && req.arg_count() == 2) {
  ------------------
  |  Branch (273:7): [True: 0, False: 0]
  |  Branch (273:41): [True: 0, False: 0]
  ------------------
  274|      0|      auto hash = HashFunction::create(req.arg(0));
  275|      0|      if(!hash) {
  ------------------
  |  Branch (275:10): [True: 0, False: 0]
  ------------------
  276|      0|         return nullptr;
  277|      0|      }
  278|       |
  279|      0|      return std::make_unique<Truncated_Hash>(std::move(hash), req.arg_as_integer(1));
  280|      0|   }
  281|      0|#endif
  282|       |
  283|      0|#if defined(BOTAN_HAS_COMB4P)
  284|      0|   if(req.algo_name() == "Comb4P" && req.arg_count() == 2) {
  ------------------
  |  Branch (284:7): [True: 0, False: 0]
  |  Branch (284:38): [True: 0, False: 0]
  ------------------
  285|      0|      auto h1 = HashFunction::create(req.arg(0));
  286|      0|      auto h2 = HashFunction::create(req.arg(1));
  287|       |
  288|      0|      if(h1 && h2) {
  ------------------
  |  Branch (288:10): [True: 0, False: 0]
  |  Branch (288:16): [True: 0, False: 0]
  ------------------
  289|      0|         return std::make_unique<Comb4P>(std::move(h1), std::move(h2));
  290|      0|      }
  291|      0|   }
  292|      0|#endif
  293|       |
  294|      0|   return nullptr;
  295|      0|}
_ZN5Botan12HashFunction15create_or_throwENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEES5_:
  298|  8.45k|std::unique_ptr<HashFunction> HashFunction::create_or_throw(std::string_view algo, std::string_view provider) {
  299|  8.45k|   if(auto hash = HashFunction::create(algo, provider)) {
  ------------------
  |  Branch (299:12): [True: 8.45k, False: 0]
  ------------------
  300|  8.45k|      return hash;
  301|  8.45k|   }
  302|      0|   throw Lookup_Error("Hash", algo, provider);
  303|  8.45k|}

_ZN5Botan5SHA_110compress_nERNSt3__16vectorIjNS_16secure_allocatorIjEEEENS1_4spanIKhLm18446744073709551615EEEm:
   63|    261|void SHA_1::compress_n(digest_type& digest, std::span<const uint8_t> input, size_t blocks) {
   64|    261|   using namespace SHA1_F;
   65|       |
   66|    261|#if defined(BOTAN_HAS_SHA1_X86_SHA_NI)
   67|    261|   if(CPUID::has_intel_sha()) {
  ------------------
  |  Branch (67:7): [True: 0, False: 261]
  ------------------
   68|      0|      return sha1_compress_x86(digest, input, blocks);
   69|      0|   }
   70|    261|#endif
   71|       |
   72|       |#if defined(BOTAN_HAS_SHA1_ARMV8)
   73|       |   if(CPUID::has_arm_sha1()) {
   74|       |      return sha1_armv8_compress_n(digest, input, blocks);
   75|       |   }
   76|       |#endif
   77|       |
   78|    261|#if defined(BOTAN_HAS_SHA1_SSE2)
   79|    261|   if(CPUID::has_sse2()) {
  ------------------
  |  Branch (79:7): [True: 261, False: 0]
  ------------------
   80|    261|      return sse2_compress_n(digest, input, blocks);
   81|    261|   }
   82|       |
   83|      0|#endif
   84|       |
   85|      0|   uint32_t A = digest[0], B = digest[1], C = digest[2], D = digest[3], E = digest[4];
   86|      0|   std::array<uint32_t, 80> W;
   87|       |
   88|      0|   BufferSlicer in(input);
   89|       |
   90|      0|   for(size_t i = 0; i != blocks; ++i) {
  ------------------
  |  Branch (90:22): [True: 0, False: 0]
  ------------------
   91|      0|      load_be(W.data(), in.take(block_bytes).data(), 16);
   92|       |
   93|      0|      for(size_t j = 16; j != 80; j += 8) {
  ------------------
  |  Branch (93:26): [True: 0, False: 0]
  ------------------
   94|      0|         W[j] = rotl<1>(W[j - 3] ^ W[j - 8] ^ W[j - 14] ^ W[j - 16]);
   95|      0|         W[j + 1] = rotl<1>(W[j - 2] ^ W[j - 7] ^ W[j - 13] ^ W[j - 15]);
   96|      0|         W[j + 2] = rotl<1>(W[j - 1] ^ W[j - 6] ^ W[j - 12] ^ W[j - 14]);
   97|      0|         W[j + 3] = rotl<1>(W[j] ^ W[j - 5] ^ W[j - 11] ^ W[j - 13]);
   98|      0|         W[j + 4] = rotl<1>(W[j + 1] ^ W[j - 4] ^ W[j - 10] ^ W[j - 12]);
   99|      0|         W[j + 5] = rotl<1>(W[j + 2] ^ W[j - 3] ^ W[j - 9] ^ W[j - 11]);
  100|      0|         W[j + 6] = rotl<1>(W[j + 3] ^ W[j - 2] ^ W[j - 8] ^ W[j - 10]);
  101|      0|         W[j + 7] = rotl<1>(W[j + 4] ^ W[j - 1] ^ W[j - 7] ^ W[j - 9]);
  102|      0|      }
  103|       |
  104|      0|      F1(A, B, C, D, E, W[0]);
  105|      0|      F1(E, A, B, C, D, W[1]);
  106|      0|      F1(D, E, A, B, C, W[2]);
  107|      0|      F1(C, D, E, A, B, W[3]);
  108|      0|      F1(B, C, D, E, A, W[4]);
  109|      0|      F1(A, B, C, D, E, W[5]);
  110|      0|      F1(E, A, B, C, D, W[6]);
  111|      0|      F1(D, E, A, B, C, W[7]);
  112|      0|      F1(C, D, E, A, B, W[8]);
  113|      0|      F1(B, C, D, E, A, W[9]);
  114|      0|      F1(A, B, C, D, E, W[10]);
  115|      0|      F1(E, A, B, C, D, W[11]);
  116|      0|      F1(D, E, A, B, C, W[12]);
  117|      0|      F1(C, D, E, A, B, W[13]);
  118|      0|      F1(B, C, D, E, A, W[14]);
  119|      0|      F1(A, B, C, D, E, W[15]);
  120|      0|      F1(E, A, B, C, D, W[16]);
  121|      0|      F1(D, E, A, B, C, W[17]);
  122|      0|      F1(C, D, E, A, B, W[18]);
  123|      0|      F1(B, C, D, E, A, W[19]);
  124|       |
  125|      0|      F2(A, B, C, D, E, W[20]);
  126|      0|      F2(E, A, B, C, D, W[21]);
  127|      0|      F2(D, E, A, B, C, W[22]);
  128|      0|      F2(C, D, E, A, B, W[23]);
  129|      0|      F2(B, C, D, E, A, W[24]);
  130|      0|      F2(A, B, C, D, E, W[25]);
  131|      0|      F2(E, A, B, C, D, W[26]);
  132|      0|      F2(D, E, A, B, C, W[27]);
  133|      0|      F2(C, D, E, A, B, W[28]);
  134|      0|      F2(B, C, D, E, A, W[29]);
  135|      0|      F2(A, B, C, D, E, W[30]);
  136|      0|      F2(E, A, B, C, D, W[31]);
  137|      0|      F2(D, E, A, B, C, W[32]);
  138|      0|      F2(C, D, E, A, B, W[33]);
  139|      0|      F2(B, C, D, E, A, W[34]);
  140|      0|      F2(A, B, C, D, E, W[35]);
  141|      0|      F2(E, A, B, C, D, W[36]);
  142|      0|      F2(D, E, A, B, C, W[37]);
  143|      0|      F2(C, D, E, A, B, W[38]);
  144|      0|      F2(B, C, D, E, A, W[39]);
  145|       |
  146|      0|      F3(A, B, C, D, E, W[40]);
  147|      0|      F3(E, A, B, C, D, W[41]);
  148|      0|      F3(D, E, A, B, C, W[42]);
  149|      0|      F3(C, D, E, A, B, W[43]);
  150|      0|      F3(B, C, D, E, A, W[44]);
  151|      0|      F3(A, B, C, D, E, W[45]);
  152|      0|      F3(E, A, B, C, D, W[46]);
  153|      0|      F3(D, E, A, B, C, W[47]);
  154|      0|      F3(C, D, E, A, B, W[48]);
  155|      0|      F3(B, C, D, E, A, W[49]);
  156|      0|      F3(A, B, C, D, E, W[50]);
  157|      0|      F3(E, A, B, C, D, W[51]);
  158|      0|      F3(D, E, A, B, C, W[52]);
  159|      0|      F3(C, D, E, A, B, W[53]);
  160|      0|      F3(B, C, D, E, A, W[54]);
  161|      0|      F3(A, B, C, D, E, W[55]);
  162|      0|      F3(E, A, B, C, D, W[56]);
  163|      0|      F3(D, E, A, B, C, W[57]);
  164|      0|      F3(C, D, E, A, B, W[58]);
  165|      0|      F3(B, C, D, E, A, W[59]);
  166|       |
  167|      0|      F4(A, B, C, D, E, W[60]);
  168|      0|      F4(E, A, B, C, D, W[61]);
  169|      0|      F4(D, E, A, B, C, W[62]);
  170|      0|      F4(C, D, E, A, B, W[63]);
  171|      0|      F4(B, C, D, E, A, W[64]);
  172|      0|      F4(A, B, C, D, E, W[65]);
  173|      0|      F4(E, A, B, C, D, W[66]);
  174|      0|      F4(D, E, A, B, C, W[67]);
  175|      0|      F4(C, D, E, A, B, W[68]);
  176|      0|      F4(B, C, D, E, A, W[69]);
  177|      0|      F4(A, B, C, D, E, W[70]);
  178|      0|      F4(E, A, B, C, D, W[71]);
  179|      0|      F4(D, E, A, B, C, W[72]);
  180|      0|      F4(C, D, E, A, B, W[73]);
  181|      0|      F4(B, C, D, E, A, W[74]);
  182|      0|      F4(A, B, C, D, E, W[75]);
  183|      0|      F4(E, A, B, C, D, W[76]);
  184|      0|      F4(D, E, A, B, C, W[77]);
  185|      0|      F4(C, D, E, A, B, W[78]);
  186|      0|      F4(B, C, D, E, A, W[79]);
  187|       |
  188|      0|      A = (digest[0] += A);
  189|      0|      B = (digest[1] += B);
  190|      0|      C = (digest[2] += C);
  191|      0|      D = (digest[3] += D);
  192|      0|      E = (digest[4] += E);
  193|      0|   }
  194|      0|}
_ZN5Botan5SHA_14initERNSt3__16vectorIjNS_16secure_allocatorIjEEEE:
  199|    348|void SHA_1::init(digest_type& digest) {
  200|    348|   digest.assign({0x67452301, 0xEFCDAB89, 0x98BADCFE, 0x10325476, 0xC3D2E1F0});
  201|    348|}
_ZN5Botan5SHA_18add_dataENSt3__14spanIKhLm18446744073709551615EEE:
  233|    174|void SHA_1::add_data(std::span<const uint8_t> input) {
  234|    174|   m_md.update(input);
  235|    174|}
_ZN5Botan5SHA_112final_resultENSt3__14spanIhLm18446744073709551615EEE:
  237|    174|void SHA_1::final_result(std::span<uint8_t> output) {
  238|    174|   m_md.final(output);
  239|    174|}

_ZN5Botan5SHA_115sse2_compress_nERNSt3__16vectorIjNS_16secure_allocatorIjEEEENS1_4spanIKhLm18446744073709551615EEEm:
  115|    261|BOTAN_FUNC_ISA("sse2") void SHA_1::sse2_compress_n(digest_type& digest, std::span<const uint8_t> input, size_t blocks) {
  116|    261|   using namespace SHA1_SSE2_F;
  117|       |
  118|    261|   const SIMD_4x32 K00_19 = SIMD_4x32::splat(0x5A827999);
  119|    261|   const SIMD_4x32 K20_39 = SIMD_4x32::splat(0x6ED9EBA1);
  120|    261|   const SIMD_4x32 K40_59 = SIMD_4x32::splat(0x8F1BBCDC);
  121|    261|   const SIMD_4x32 K60_79 = SIMD_4x32::splat(0xCA62C1D6);
  122|       |
  123|    261|   uint32_t A = digest[0], B = digest[1], C = digest[2], D = digest[3], E = digest[4];
  124|       |
  125|    261|   BufferSlicer in(input);
  126|       |
  127|    522|   for(size_t i = 0; i != blocks; ++i) {
  ------------------
  |  Branch (127:22): [True: 261, False: 261]
  ------------------
  128|    261|      uint32_t PT[4];
  129|       |
  130|    261|      const auto block = in.take(block_bytes);
  131|       |
  132|    261|      SIMD_4x32 W0 = SIMD_4x32::load_be(&block[0]);
  133|    261|      SIMD_4x32 W1 = SIMD_4x32::load_be(&block[16]);
  134|    261|      SIMD_4x32 W2 = SIMD_4x32::load_be(&block[32]);
  135|    261|      SIMD_4x32 W3 = SIMD_4x32::load_be(&block[48]);
  136|       |
  137|    261|      SIMD_4x32 P0 = W0 + K00_19;
  138|    261|      SIMD_4x32 P1 = W1 + K00_19;
  139|    261|      SIMD_4x32 P2 = W2 + K00_19;
  140|    261|      SIMD_4x32 P3 = W3 + K00_19;
  141|       |
  142|    261|      SIMD_4x32(P0).store_le(PT);
  143|    261|      F1(A, B, C, D, E, PT[0]);
  144|    261|      F1(E, A, B, C, D, PT[1]);
  145|    261|      F1(D, E, A, B, C, PT[2]);
  146|    261|      F1(C, D, E, A, B, PT[3]);
  147|    261|      P0 = prep(W0, W1, W2, W3, K00_19);
  148|       |
  149|    261|      SIMD_4x32(P1).store_le(PT);
  150|    261|      F1(B, C, D, E, A, PT[0]);
  151|    261|      F1(A, B, C, D, E, PT[1]);
  152|    261|      F1(E, A, B, C, D, PT[2]);
  153|    261|      F1(D, E, A, B, C, PT[3]);
  154|    261|      P1 = prep(W1, W2, W3, W0, K20_39);
  155|       |
  156|    261|      SIMD_4x32(P2).store_le(PT);
  157|    261|      F1(C, D, E, A, B, PT[0]);
  158|    261|      F1(B, C, D, E, A, PT[1]);
  159|    261|      F1(A, B, C, D, E, PT[2]);
  160|    261|      F1(E, A, B, C, D, PT[3]);
  161|    261|      P2 = prep(W2, W3, W0, W1, K20_39);
  162|       |
  163|    261|      SIMD_4x32(P3).store_le(PT);
  164|    261|      F1(D, E, A, B, C, PT[0]);
  165|    261|      F1(C, D, E, A, B, PT[1]);
  166|    261|      F1(B, C, D, E, A, PT[2]);
  167|    261|      F1(A, B, C, D, E, PT[3]);
  168|    261|      P3 = prep(W3, W0, W1, W2, K20_39);
  169|       |
  170|    261|      SIMD_4x32(P0).store_le(PT);
  171|    261|      F1(E, A, B, C, D, PT[0]);
  172|    261|      F1(D, E, A, B, C, PT[1]);
  173|    261|      F1(C, D, E, A, B, PT[2]);
  174|    261|      F1(B, C, D, E, A, PT[3]);
  175|    261|      P0 = prep(W0, W1, W2, W3, K20_39);
  176|       |
  177|    261|      SIMD_4x32(P1).store_le(PT);
  178|    261|      F2(A, B, C, D, E, PT[0]);
  179|    261|      F2(E, A, B, C, D, PT[1]);
  180|    261|      F2(D, E, A, B, C, PT[2]);
  181|    261|      F2(C, D, E, A, B, PT[3]);
  182|    261|      P1 = prep(W1, W2, W3, W0, K20_39);
  183|       |
  184|    261|      SIMD_4x32(P2).store_le(PT);
  185|    261|      F2(B, C, D, E, A, PT[0]);
  186|    261|      F2(A, B, C, D, E, PT[1]);
  187|    261|      F2(E, A, B, C, D, PT[2]);
  188|    261|      F2(D, E, A, B, C, PT[3]);
  189|    261|      P2 = prep(W2, W3, W0, W1, K40_59);
  190|       |
  191|    261|      SIMD_4x32(P3).store_le(PT);
  192|    261|      F2(C, D, E, A, B, PT[0]);
  193|    261|      F2(B, C, D, E, A, PT[1]);
  194|    261|      F2(A, B, C, D, E, PT[2]);
  195|    261|      F2(E, A, B, C, D, PT[3]);
  196|    261|      P3 = prep(W3, W0, W1, W2, K40_59);
  197|       |
  198|    261|      SIMD_4x32(P0).store_le(PT);
  199|    261|      F2(D, E, A, B, C, PT[0]);
  200|    261|      F2(C, D, E, A, B, PT[1]);
  201|    261|      F2(B, C, D, E, A, PT[2]);
  202|    261|      F2(A, B, C, D, E, PT[3]);
  203|    261|      P0 = prep(W0, W1, W2, W3, K40_59);
  204|       |
  205|    261|      SIMD_4x32(P1).store_le(PT);
  206|    261|      F2(E, A, B, C, D, PT[0]);
  207|    261|      F2(D, E, A, B, C, PT[1]);
  208|    261|      F2(C, D, E, A, B, PT[2]);
  209|    261|      F2(B, C, D, E, A, PT[3]);
  210|    261|      P1 = prep(W1, W2, W3, W0, K40_59);
  211|       |
  212|    261|      SIMD_4x32(P2).store_le(PT);
  213|    261|      F3(A, B, C, D, E, PT[0]);
  214|    261|      F3(E, A, B, C, D, PT[1]);
  215|    261|      F3(D, E, A, B, C, PT[2]);
  216|    261|      F3(C, D, E, A, B, PT[3]);
  217|    261|      P2 = prep(W2, W3, W0, W1, K40_59);
  218|       |
  219|    261|      SIMD_4x32(P3).store_le(PT);
  220|    261|      F3(B, C, D, E, A, PT[0]);
  221|    261|      F3(A, B, C, D, E, PT[1]);
  222|    261|      F3(E, A, B, C, D, PT[2]);
  223|    261|      F3(D, E, A, B, C, PT[3]);
  224|    261|      P3 = prep(W3, W0, W1, W2, K60_79);
  225|       |
  226|    261|      SIMD_4x32(P0).store_le(PT);
  227|    261|      F3(C, D, E, A, B, PT[0]);
  228|    261|      F3(B, C, D, E, A, PT[1]);
  229|    261|      F3(A, B, C, D, E, PT[2]);
  230|    261|      F3(E, A, B, C, D, PT[3]);
  231|    261|      P0 = prep(W0, W1, W2, W3, K60_79);
  232|       |
  233|    261|      SIMD_4x32(P1).store_le(PT);
  234|    261|      F3(D, E, A, B, C, PT[0]);
  235|    261|      F3(C, D, E, A, B, PT[1]);
  236|    261|      F3(B, C, D, E, A, PT[2]);
  237|    261|      F3(A, B, C, D, E, PT[3]);
  238|    261|      P1 = prep(W1, W2, W3, W0, K60_79);
  239|       |
  240|    261|      SIMD_4x32(P2).store_le(PT);
  241|    261|      F3(E, A, B, C, D, PT[0]);
  242|    261|      F3(D, E, A, B, C, PT[1]);
  243|    261|      F3(C, D, E, A, B, PT[2]);
  244|    261|      F3(B, C, D, E, A, PT[3]);
  245|    261|      P2 = prep(W2, W3, W0, W1, K60_79);
  246|       |
  247|    261|      SIMD_4x32(P3).store_le(PT);
  248|    261|      F4(A, B, C, D, E, PT[0]);
  249|    261|      F4(E, A, B, C, D, PT[1]);
  250|    261|      F4(D, E, A, B, C, PT[2]);
  251|    261|      F4(C, D, E, A, B, PT[3]);
  252|    261|      P3 = prep(W3, W0, W1, W2, K60_79);
  253|       |
  254|    261|      SIMD_4x32(P0).store_le(PT);
  255|    261|      F4(B, C, D, E, A, PT[0]);
  256|    261|      F4(A, B, C, D, E, PT[1]);
  257|    261|      F4(E, A, B, C, D, PT[2]);
  258|    261|      F4(D, E, A, B, C, PT[3]);
  259|       |
  260|    261|      SIMD_4x32(P1).store_le(PT);
  261|    261|      F4(C, D, E, A, B, PT[0]);
  262|    261|      F4(B, C, D, E, A, PT[1]);
  263|    261|      F4(A, B, C, D, E, PT[2]);
  264|    261|      F4(E, A, B, C, D, PT[3]);
  265|       |
  266|    261|      SIMD_4x32(P2).store_le(PT);
  267|    261|      F4(D, E, A, B, C, PT[0]);
  268|    261|      F4(C, D, E, A, B, PT[1]);
  269|    261|      F4(B, C, D, E, A, PT[2]);
  270|    261|      F4(A, B, C, D, E, PT[3]);
  271|       |
  272|    261|      SIMD_4x32(P3).store_le(PT);
  273|    261|      F4(E, A, B, C, D, PT[0]);
  274|    261|      F4(D, E, A, B, C, PT[1]);
  275|    261|      F4(C, D, E, A, B, PT[2]);
  276|    261|      F4(B, C, D, E, A, PT[3]);
  277|       |
  278|    261|      A = (digest[0] += A);
  279|    261|      B = (digest[1] += B);
  280|    261|      C = (digest[2] += C);
  281|    261|      D = (digest[3] += D);
  282|    261|      E = (digest[4] += E);
  283|    261|   }
  284|    261|}
sha1_sse2.cpp:_ZN5Botan11SHA1_SSE2_F12_GLOBAL__N_12F1EjRjjjS2_j:
   78|  5.22k|inline void F1(uint32_t A, uint32_t& B, uint32_t C, uint32_t D, uint32_t& E, uint32_t msg) {
   79|  5.22k|   E += choose(B, C, D) + msg + rotl<5>(A);
   80|  5.22k|   B = rotl<30>(B);
   81|  5.22k|}
sha1_sse2.cpp:_ZN5Botan11SHA1_SSE2_F12_GLOBAL__N_14prepERNS_9SIMD_4x32ES2_S2_S2_S2_:
   51|  4.17k|BOTAN_FORCE_INLINE SIMD_4x32 prep(SIMD_4x32& XW0, SIMD_4x32 XW1, SIMD_4x32 XW2, SIMD_4x32 XW3, SIMD_4x32 K) {
   52|  4.17k|   SIMD_4x32 T0 = XW0;
   53|       |   /* load W[t-4] 16-byte aligned, and shift */
   54|  4.17k|   SIMD_4x32 T2 = XW3.shift_elems_right<1>();
   55|       |   /* get high 64-bits of XW0 into low 64-bits */
   56|  4.17k|   SIMD_4x32 T1 = SIMD_4x32(_mm_shuffle_epi32(XW0.raw(), _MM_SHUFFLE(1, 0, 3, 2)));
   57|       |   /* load high 64-bits of T1 */
   58|  4.17k|   T1 = SIMD_4x32(_mm_unpacklo_epi64(T1.raw(), XW1.raw()));
   59|       |
   60|  4.17k|   T0 ^= T1;
   61|  4.17k|   T2 ^= XW2;
   62|  4.17k|   T0 ^= T2;
   63|       |   /* unrotated W[t]..W[t+2] in T0 ... still need W[t+3] */
   64|       |
   65|  4.17k|   T2 = T0.shift_elems_left<3>();
   66|  4.17k|   T0 = T0.rotl<1>();
   67|  4.17k|   T2 = T2.rotl<2>();
   68|       |
   69|  4.17k|   T0 ^= T2; /* T0 now has W[t+3] */
   70|       |
   71|  4.17k|   XW0 = T0;
   72|  4.17k|   return T0 + K;
   73|  4.17k|}
sha1_sse2.cpp:_ZN5Botan11SHA1_SSE2_F12_GLOBAL__N_12F2EjRjjjS2_j:
   86|  5.22k|inline void F2(uint32_t A, uint32_t& B, uint32_t C, uint32_t D, uint32_t& E, uint32_t msg) {
   87|  5.22k|   E += (B ^ C ^ D) + msg + rotl<5>(A);
   88|  5.22k|   B = rotl<30>(B);
   89|  5.22k|}
sha1_sse2.cpp:_ZN5Botan11SHA1_SSE2_F12_GLOBAL__N_12F3EjRjjjS2_j:
   94|  5.22k|inline void F3(uint32_t A, uint32_t& B, uint32_t C, uint32_t D, uint32_t& E, uint32_t msg) {
   95|  5.22k|   E += majority(B, C, D) + msg + rotl<5>(A);
   96|  5.22k|   B = rotl<30>(B);
   97|  5.22k|}
sha1_sse2.cpp:_ZN5Botan11SHA1_SSE2_F12_GLOBAL__N_12F4EjRjjjS2_j:
  102|  5.22k|inline void F4(uint32_t A, uint32_t& B, uint32_t C, uint32_t D, uint32_t& E, uint32_t msg) {
  103|  5.22k|   E += (B ^ C ^ D) + msg + rotl<5>(A);
  104|  5.22k|   B = rotl<30>(B);
  105|  5.22k|}

_ZN5Botan7SHA_25615compress_digestERNSt3__16vectorIjNS_16secure_allocatorIjEEEENS1_4spanIKhLm18446744073709551615EEEm:
   49|  54.2k|void SHA_256::compress_digest(digest_type& digest, std::span<const uint8_t> input, size_t blocks) {
   50|  54.2k|#if defined(BOTAN_HAS_SHA2_32_X86)
   51|  54.2k|   if(CPUID::has_intel_sha()) {
  ------------------
  |  Branch (51:7): [True: 0, False: 54.2k]
  ------------------
   52|      0|      return SHA_256::compress_digest_x86(digest, input, blocks);
   53|      0|   }
   54|  54.2k|#endif
   55|       |
   56|  54.2k|#if defined(BOTAN_HAS_SHA2_32_X86_BMI2)
   57|  54.2k|   if(CPUID::has_bmi2()) {
  ------------------
  |  Branch (57:7): [True: 54.2k, False: 0]
  ------------------
   58|  54.2k|      return SHA_256::compress_digest_x86_bmi2(digest, input, blocks);
   59|  54.2k|   }
   60|      0|#endif
   61|       |
   62|       |#if defined(BOTAN_HAS_SHA2_32_ARMV8)
   63|       |   if(CPUID::has_arm_sha2()) {
   64|       |      return SHA_256::compress_digest_armv8(digest, input, blocks);
   65|       |   }
   66|       |#endif
   67|       |
   68|      0|   uint32_t A = digest[0], B = digest[1], C = digest[2], D = digest[3], E = digest[4], F = digest[5], G = digest[6],
   69|      0|            H = digest[7];
   70|       |
   71|      0|   BufferSlicer in(input);
   72|       |
   73|      0|   for(size_t i = 0; i != blocks; ++i) {
  ------------------
  |  Branch (73:22): [True: 0, False: 0]
  ------------------
   74|      0|      const auto block = in.take(block_bytes);
   75|       |
   76|      0|      uint32_t W00 = load_be<uint32_t>(block.data(), 0);
   77|      0|      uint32_t W01 = load_be<uint32_t>(block.data(), 1);
   78|      0|      uint32_t W02 = load_be<uint32_t>(block.data(), 2);
   79|      0|      uint32_t W03 = load_be<uint32_t>(block.data(), 3);
   80|      0|      uint32_t W04 = load_be<uint32_t>(block.data(), 4);
   81|      0|      uint32_t W05 = load_be<uint32_t>(block.data(), 5);
   82|      0|      uint32_t W06 = load_be<uint32_t>(block.data(), 6);
   83|      0|      uint32_t W07 = load_be<uint32_t>(block.data(), 7);
   84|      0|      uint32_t W08 = load_be<uint32_t>(block.data(), 8);
   85|      0|      uint32_t W09 = load_be<uint32_t>(block.data(), 9);
   86|      0|      uint32_t W10 = load_be<uint32_t>(block.data(), 10);
   87|      0|      uint32_t W11 = load_be<uint32_t>(block.data(), 11);
   88|      0|      uint32_t W12 = load_be<uint32_t>(block.data(), 12);
   89|      0|      uint32_t W13 = load_be<uint32_t>(block.data(), 13);
   90|      0|      uint32_t W14 = load_be<uint32_t>(block.data(), 14);
   91|      0|      uint32_t W15 = load_be<uint32_t>(block.data(), 15);
   92|       |
   93|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W00, W14, W09, W01, 0x428A2F98);
   94|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W01, W15, W10, W02, 0x71374491);
   95|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W02, W00, W11, W03, 0xB5C0FBCF);
   96|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W03, W01, W12, W04, 0xE9B5DBA5);
   97|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W04, W02, W13, W05, 0x3956C25B);
   98|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W05, W03, W14, W06, 0x59F111F1);
   99|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W06, W04, W15, W07, 0x923F82A4);
  100|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W07, W05, W00, W08, 0xAB1C5ED5);
  101|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W08, W06, W01, W09, 0xD807AA98);
  102|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W09, W07, W02, W10, 0x12835B01);
  103|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W10, W08, W03, W11, 0x243185BE);
  104|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W11, W09, W04, W12, 0x550C7DC3);
  105|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W12, W10, W05, W13, 0x72BE5D74);
  106|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W13, W11, W06, W14, 0x80DEB1FE);
  107|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W14, W12, W07, W15, 0x9BDC06A7);
  108|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W15, W13, W08, W00, 0xC19BF174);
  109|       |
  110|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W00, W14, W09, W01, 0xE49B69C1);
  111|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W01, W15, W10, W02, 0xEFBE4786);
  112|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W02, W00, W11, W03, 0x0FC19DC6);
  113|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W03, W01, W12, W04, 0x240CA1CC);
  114|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W04, W02, W13, W05, 0x2DE92C6F);
  115|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W05, W03, W14, W06, 0x4A7484AA);
  116|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W06, W04, W15, W07, 0x5CB0A9DC);
  117|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W07, W05, W00, W08, 0x76F988DA);
  118|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W08, W06, W01, W09, 0x983E5152);
  119|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W09, W07, W02, W10, 0xA831C66D);
  120|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W10, W08, W03, W11, 0xB00327C8);
  121|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W11, W09, W04, W12, 0xBF597FC7);
  122|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W12, W10, W05, W13, 0xC6E00BF3);
  123|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W13, W11, W06, W14, 0xD5A79147);
  124|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W14, W12, W07, W15, 0x06CA6351);
  125|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W15, W13, W08, W00, 0x14292967);
  126|       |
  127|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W00, W14, W09, W01, 0x27B70A85);
  128|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W01, W15, W10, W02, 0x2E1B2138);
  129|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W02, W00, W11, W03, 0x4D2C6DFC);
  130|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W03, W01, W12, W04, 0x53380D13);
  131|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W04, W02, W13, W05, 0x650A7354);
  132|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W05, W03, W14, W06, 0x766A0ABB);
  133|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W06, W04, W15, W07, 0x81C2C92E);
  134|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W07, W05, W00, W08, 0x92722C85);
  135|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W08, W06, W01, W09, 0xA2BFE8A1);
  136|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W09, W07, W02, W10, 0xA81A664B);
  137|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W10, W08, W03, W11, 0xC24B8B70);
  138|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W11, W09, W04, W12, 0xC76C51A3);
  139|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W12, W10, W05, W13, 0xD192E819);
  140|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W13, W11, W06, W14, 0xD6990624);
  141|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W14, W12, W07, W15, 0xF40E3585);
  142|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W15, W13, W08, W00, 0x106AA070);
  143|       |
  144|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W00, W14, W09, W01, 0x19A4C116);
  145|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W01, W15, W10, W02, 0x1E376C08);
  146|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W02, W00, W11, W03, 0x2748774C);
  147|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W03, W01, W12, W04, 0x34B0BCB5);
  148|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W04, W02, W13, W05, 0x391C0CB3);
  149|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W05, W03, W14, W06, 0x4ED8AA4A);
  150|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W06, W04, W15, W07, 0x5B9CCA4F);
  151|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W07, W05, W00, W08, 0x682E6FF3);
  152|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W08, W06, W01, W09, 0x748F82EE);
  153|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W09, W07, W02, W10, 0x78A5636F);
  154|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W10, W08, W03, W11, 0x84C87814);
  155|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W11, W09, W04, W12, 0x8CC70208);
  156|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W12, W10, W05, W13, 0x90BEFFFA);
  157|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W13, W11, W06, W14, 0xA4506CEB);
  158|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W14, W12, W07, W15, 0xBEF9A3F7);
  159|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W15, W13, W08, W00, 0xC67178F2);
  160|       |
  161|      0|      A = (digest[0] += A);
  162|      0|      B = (digest[1] += B);
  163|      0|      C = (digest[2] += C);
  164|      0|      D = (digest[3] += D);
  165|      0|      E = (digest[4] += E);
  166|      0|      F = (digest[5] += F);
  167|      0|      G = (digest[6] += G);
  168|      0|      H = (digest[7] += H);
  169|      0|   }
  170|      0|}
_ZN5Botan7SHA_25610compress_nERNSt3__16vectorIjNS_16secure_allocatorIjEEEENS1_4spanIKhLm18446744073709551615EEEm:
  204|  54.2k|void SHA_256::compress_n(digest_type& digest, std::span<const uint8_t> input, size_t blocks) {
  205|  54.2k|   SHA_256::compress_digest(digest, input, blocks);
  206|  54.2k|}
_ZN5Botan7SHA_2564initERNSt3__16vectorIjNS_16secure_allocatorIjEEEE:
  208|  42.3k|void SHA_256::init(digest_type& digest) {
  209|  42.3k|   digest.assign({0x6A09E667, 0xBB67AE85, 0x3C6EF372, 0xA54FF53A, 0x510E527F, 0x9B05688C, 0x1F83D9AB, 0x5BE0CD19});
  210|  42.3k|}
_ZNK5Botan7SHA_25610copy_stateEv:
  216|  30.9k|std::unique_ptr<HashFunction> SHA_256::copy_state() const {
  217|  30.9k|   return std::make_unique<SHA_256>(*this);
  218|  30.9k|}
_ZN5Botan7SHA_2568add_dataENSt3__14spanIKhLm18446744073709551615EEE:
  220|  36.5k|void SHA_256::add_data(std::span<const uint8_t> input) {
  221|  36.5k|   m_md.update(input);
  222|  36.5k|}
_ZN5Botan7SHA_25612final_resultENSt3__14spanIhLm18446744073709551615EEE:
  224|  33.8k|void SHA_256::final_result(std::span<uint8_t> output) {
  225|  33.8k|   m_md.final(output);
  226|  33.8k|}

_ZN5Botan7SHA_25624compress_digest_x86_bmi2ERNSt3__16vectorIjNS_16secure_allocatorIjEEEENS1_4spanIKhLm18446744073709551615EEEm:
   24|  54.2k|void SHA_256::compress_digest_x86_bmi2(digest_type& digest, std::span<const uint8_t> input, size_t blocks) {
   25|  54.2k|   uint32_t A = digest[0], B = digest[1], C = digest[2], D = digest[3], E = digest[4], F = digest[5], G = digest[6],
   26|  54.2k|            H = digest[7];
   27|       |
   28|  54.2k|   BufferSlicer in(input);
   29|       |
   30|   110k|   for(size_t i = 0; i != blocks; ++i) {
  ------------------
  |  Branch (30:22): [True: 56.3k, False: 54.2k]
  ------------------
   31|  56.3k|      const auto block = in.take(block_bytes);
   32|       |
   33|  56.3k|      uint32_t W00 = load_be<uint32_t>(block.data(), 0);
   34|  56.3k|      uint32_t W01 = load_be<uint32_t>(block.data(), 1);
   35|  56.3k|      uint32_t W02 = load_be<uint32_t>(block.data(), 2);
   36|  56.3k|      uint32_t W03 = load_be<uint32_t>(block.data(), 3);
   37|  56.3k|      uint32_t W04 = load_be<uint32_t>(block.data(), 4);
   38|  56.3k|      uint32_t W05 = load_be<uint32_t>(block.data(), 5);
   39|  56.3k|      uint32_t W06 = load_be<uint32_t>(block.data(), 6);
   40|  56.3k|      uint32_t W07 = load_be<uint32_t>(block.data(), 7);
   41|  56.3k|      uint32_t W08 = load_be<uint32_t>(block.data(), 8);
   42|  56.3k|      uint32_t W09 = load_be<uint32_t>(block.data(), 9);
   43|  56.3k|      uint32_t W10 = load_be<uint32_t>(block.data(), 10);
   44|  56.3k|      uint32_t W11 = load_be<uint32_t>(block.data(), 11);
   45|  56.3k|      uint32_t W12 = load_be<uint32_t>(block.data(), 12);
   46|  56.3k|      uint32_t W13 = load_be<uint32_t>(block.data(), 13);
   47|  56.3k|      uint32_t W14 = load_be<uint32_t>(block.data(), 14);
   48|  56.3k|      uint32_t W15 = load_be<uint32_t>(block.data(), 15);
   49|       |
   50|  56.3k|      SHA2_32_F(A, B, C, D, E, F, G, H, W00, W14, W09, W01, 0x428A2F98);
   51|  56.3k|      SHA2_32_F(H, A, B, C, D, E, F, G, W01, W15, W10, W02, 0x71374491);
   52|  56.3k|      SHA2_32_F(G, H, A, B, C, D, E, F, W02, W00, W11, W03, 0xB5C0FBCF);
   53|  56.3k|      SHA2_32_F(F, G, H, A, B, C, D, E, W03, W01, W12, W04, 0xE9B5DBA5);
   54|  56.3k|      SHA2_32_F(E, F, G, H, A, B, C, D, W04, W02, W13, W05, 0x3956C25B);
   55|  56.3k|      SHA2_32_F(D, E, F, G, H, A, B, C, W05, W03, W14, W06, 0x59F111F1);
   56|  56.3k|      SHA2_32_F(C, D, E, F, G, H, A, B, W06, W04, W15, W07, 0x923F82A4);
   57|  56.3k|      SHA2_32_F(B, C, D, E, F, G, H, A, W07, W05, W00, W08, 0xAB1C5ED5);
   58|  56.3k|      SHA2_32_F(A, B, C, D, E, F, G, H, W08, W06, W01, W09, 0xD807AA98);
   59|  56.3k|      SHA2_32_F(H, A, B, C, D, E, F, G, W09, W07, W02, W10, 0x12835B01);
   60|  56.3k|      SHA2_32_F(G, H, A, B, C, D, E, F, W10, W08, W03, W11, 0x243185BE);
   61|  56.3k|      SHA2_32_F(F, G, H, A, B, C, D, E, W11, W09, W04, W12, 0x550C7DC3);
   62|  56.3k|      SHA2_32_F(E, F, G, H, A, B, C, D, W12, W10, W05, W13, 0x72BE5D74);
   63|  56.3k|      SHA2_32_F(D, E, F, G, H, A, B, C, W13, W11, W06, W14, 0x80DEB1FE);
   64|  56.3k|      SHA2_32_F(C, D, E, F, G, H, A, B, W14, W12, W07, W15, 0x9BDC06A7);
   65|  56.3k|      SHA2_32_F(B, C, D, E, F, G, H, A, W15, W13, W08, W00, 0xC19BF174);
   66|       |
   67|  56.3k|      SHA2_32_F(A, B, C, D, E, F, G, H, W00, W14, W09, W01, 0xE49B69C1);
   68|  56.3k|      SHA2_32_F(H, A, B, C, D, E, F, G, W01, W15, W10, W02, 0xEFBE4786);
   69|  56.3k|      SHA2_32_F(G, H, A, B, C, D, E, F, W02, W00, W11, W03, 0x0FC19DC6);
   70|  56.3k|      SHA2_32_F(F, G, H, A, B, C, D, E, W03, W01, W12, W04, 0x240CA1CC);
   71|  56.3k|      SHA2_32_F(E, F, G, H, A, B, C, D, W04, W02, W13, W05, 0x2DE92C6F);
   72|  56.3k|      SHA2_32_F(D, E, F, G, H, A, B, C, W05, W03, W14, W06, 0x4A7484AA);
   73|  56.3k|      SHA2_32_F(C, D, E, F, G, H, A, B, W06, W04, W15, W07, 0x5CB0A9DC);
   74|  56.3k|      SHA2_32_F(B, C, D, E, F, G, H, A, W07, W05, W00, W08, 0x76F988DA);
   75|  56.3k|      SHA2_32_F(A, B, C, D, E, F, G, H, W08, W06, W01, W09, 0x983E5152);
   76|  56.3k|      SHA2_32_F(H, A, B, C, D, E, F, G, W09, W07, W02, W10, 0xA831C66D);
   77|  56.3k|      SHA2_32_F(G, H, A, B, C, D, E, F, W10, W08, W03, W11, 0xB00327C8);
   78|  56.3k|      SHA2_32_F(F, G, H, A, B, C, D, E, W11, W09, W04, W12, 0xBF597FC7);
   79|  56.3k|      SHA2_32_F(E, F, G, H, A, B, C, D, W12, W10, W05, W13, 0xC6E00BF3);
   80|  56.3k|      SHA2_32_F(D, E, F, G, H, A, B, C, W13, W11, W06, W14, 0xD5A79147);
   81|  56.3k|      SHA2_32_F(C, D, E, F, G, H, A, B, W14, W12, W07, W15, 0x06CA6351);
   82|  56.3k|      SHA2_32_F(B, C, D, E, F, G, H, A, W15, W13, W08, W00, 0x14292967);
   83|       |
   84|  56.3k|      SHA2_32_F(A, B, C, D, E, F, G, H, W00, W14, W09, W01, 0x27B70A85);
   85|  56.3k|      SHA2_32_F(H, A, B, C, D, E, F, G, W01, W15, W10, W02, 0x2E1B2138);
   86|  56.3k|      SHA2_32_F(G, H, A, B, C, D, E, F, W02, W00, W11, W03, 0x4D2C6DFC);
   87|  56.3k|      SHA2_32_F(F, G, H, A, B, C, D, E, W03, W01, W12, W04, 0x53380D13);
   88|  56.3k|      SHA2_32_F(E, F, G, H, A, B, C, D, W04, W02, W13, W05, 0x650A7354);
   89|  56.3k|      SHA2_32_F(D, E, F, G, H, A, B, C, W05, W03, W14, W06, 0x766A0ABB);
   90|  56.3k|      SHA2_32_F(C, D, E, F, G, H, A, B, W06, W04, W15, W07, 0x81C2C92E);
   91|  56.3k|      SHA2_32_F(B, C, D, E, F, G, H, A, W07, W05, W00, W08, 0x92722C85);
   92|  56.3k|      SHA2_32_F(A, B, C, D, E, F, G, H, W08, W06, W01, W09, 0xA2BFE8A1);
   93|  56.3k|      SHA2_32_F(H, A, B, C, D, E, F, G, W09, W07, W02, W10, 0xA81A664B);
   94|  56.3k|      SHA2_32_F(G, H, A, B, C, D, E, F, W10, W08, W03, W11, 0xC24B8B70);
   95|  56.3k|      SHA2_32_F(F, G, H, A, B, C, D, E, W11, W09, W04, W12, 0xC76C51A3);
   96|  56.3k|      SHA2_32_F(E, F, G, H, A, B, C, D, W12, W10, W05, W13, 0xD192E819);
   97|  56.3k|      SHA2_32_F(D, E, F, G, H, A, B, C, W13, W11, W06, W14, 0xD6990624);
   98|  56.3k|      SHA2_32_F(C, D, E, F, G, H, A, B, W14, W12, W07, W15, 0xF40E3585);
   99|  56.3k|      SHA2_32_F(B, C, D, E, F, G, H, A, W15, W13, W08, W00, 0x106AA070);
  100|       |
  101|  56.3k|      SHA2_32_F(A, B, C, D, E, F, G, H, W00, W14, W09, W01, 0x19A4C116);
  102|  56.3k|      SHA2_32_F(H, A, B, C, D, E, F, G, W01, W15, W10, W02, 0x1E376C08);
  103|  56.3k|      SHA2_32_F(G, H, A, B, C, D, E, F, W02, W00, W11, W03, 0x2748774C);
  104|  56.3k|      SHA2_32_F(F, G, H, A, B, C, D, E, W03, W01, W12, W04, 0x34B0BCB5);
  105|  56.3k|      SHA2_32_F(E, F, G, H, A, B, C, D, W04, W02, W13, W05, 0x391C0CB3);
  106|  56.3k|      SHA2_32_F(D, E, F, G, H, A, B, C, W05, W03, W14, W06, 0x4ED8AA4A);
  107|  56.3k|      SHA2_32_F(C, D, E, F, G, H, A, B, W06, W04, W15, W07, 0x5B9CCA4F);
  108|  56.3k|      SHA2_32_F(B, C, D, E, F, G, H, A, W07, W05, W00, W08, 0x682E6FF3);
  109|  56.3k|      SHA2_32_F(A, B, C, D, E, F, G, H, W08, W06, W01, W09, 0x748F82EE);
  110|  56.3k|      SHA2_32_F(H, A, B, C, D, E, F, G, W09, W07, W02, W10, 0x78A5636F);
  111|  56.3k|      SHA2_32_F(G, H, A, B, C, D, E, F, W10, W08, W03, W11, 0x84C87814);
  112|  56.3k|      SHA2_32_F(F, G, H, A, B, C, D, E, W11, W09, W04, W12, 0x8CC70208);
  113|  56.3k|      SHA2_32_F(E, F, G, H, A, B, C, D, W12, W10, W05, W13, 0x90BEFFFA);
  114|  56.3k|      SHA2_32_F(D, E, F, G, H, A, B, C, W13, W11, W06, W14, 0xA4506CEB);
  115|  56.3k|      SHA2_32_F(C, D, E, F, G, H, A, B, W14, W12, W07, W15, 0xBEF9A3F7);
  116|  56.3k|      SHA2_32_F(B, C, D, E, F, G, H, A, W15, W13, W08, W00, 0xC67178F2);
  117|       |
  118|  56.3k|      A = (digest[0] += A);
  119|  56.3k|      B = (digest[1] += B);
  120|  56.3k|      C = (digest[2] += C);
  121|  56.3k|      D = (digest[3] += D);
  122|  56.3k|      E = (digest[4] += E);
  123|  56.3k|      F = (digest[5] += F);
  124|  56.3k|      G = (digest[6] += G);
  125|  56.3k|      H = (digest[7] += H);
  126|  56.3k|   }
  127|  54.2k|}

_ZN5Botan6BigIntC2EPKhm:
   91|    454|BigInt::BigInt(const uint8_t input[], size_t length) {
   92|    454|   binary_decode(input, length);
   93|    454|}
_ZNK5Botan6BigInt7byte_atEm:
  125|     52|uint8_t BigInt::byte_at(size_t n) const {
  126|     52|   return get_byte_var(sizeof(word) - (n % sizeof(word)) - 1, word_at(n / sizeof(word)));
  127|     52|}
_ZNK5Botan6BigInt4Data14calc_sig_wordsEv:
  198|    415|size_t BigInt::Data::calc_sig_words() const {
  199|    415|   const size_t sz = m_reg.size();
  200|    415|   size_t sig = sz;
  201|       |
  202|    415|   word sub = 1;
  203|       |
  204|  3.75k|   for(size_t i = 0; i != sz; ++i) {
  ------------------
  |  Branch (204:22): [True: 3.34k, False: 415]
  ------------------
  205|  3.34k|      const word w = m_reg[sz - i - 1];
  206|  3.34k|      sub &= ct_is_zero(w);
  207|  3.34k|      sig -= sub;
  208|  3.34k|   }
  209|       |
  210|       |   /*
  211|       |   * This depends on the data so is poisoned, but unpoison it here as
  212|       |   * later conditionals are made on the size.
  213|       |   */
  214|    415|   CT::unpoison(sig);
  215|       |
  216|    415|   return sig;
  217|    415|}
_ZNK5Botan6BigInt5bytesEv:
  277|    362|size_t BigInt::bytes() const {
  278|    362|   return round_up(bits(), 8) / 8;
  279|    362|}
_ZNK5Botan6BigInt13top_bits_freeEv:
  281|    368|size_t BigInt::top_bits_free() const {
  282|    368|   const size_t words = sig_words();
  283|       |
  284|    368|   const word top_word = word_at(words - 1);
  285|    368|   const size_t bits_used = high_bit(top_word);
  286|    368|   CT::unpoison(bits_used);
  287|    368|   return BOTAN_MP_WORD_BITS - bits_used;
  ------------------
  |  |   50|    368|#define BOTAN_MP_WORD_BITS 64
  ------------------
  288|    368|}
_ZNK5Botan6BigInt4bitsEv:
  290|    457|size_t BigInt::bits() const {
  291|    457|   const size_t words = sig_words();
  292|       |
  293|    457|   if(words == 0) {
  ------------------
  |  Branch (293:7): [True: 89, False: 368]
  ------------------
  294|     89|      return 0;
  295|     89|   }
  296|       |
  297|    368|   const size_t full_words = (words - 1) * BOTAN_MP_WORD_BITS;
  ------------------
  |  |   50|    368|#define BOTAN_MP_WORD_BITS 64
  ------------------
  298|    368|   const size_t top_bits = BOTAN_MP_WORD_BITS - top_bits_free();
  ------------------
  |  |   50|    368|#define BOTAN_MP_WORD_BITS 64
  ------------------
  299|       |
  300|    368|   return full_words + top_bits;
  301|    457|}
_ZNK5Botan6BigInt13binary_encodeEPh:
  375|    181|void BigInt::binary_encode(uint8_t buf[]) const {
  376|    181|   this->binary_encode(buf, bytes());
  377|    181|}
_ZNK5Botan6BigInt13binary_encodeEPhm:
  382|    181|void BigInt::binary_encode(uint8_t output[], size_t len) const {
  383|    181|   const size_t full_words = len / sizeof(word);
  384|    181|   const size_t extra_bytes = len % sizeof(word);
  385|       |
  386|    187|   for(size_t i = 0; i != full_words; ++i) {
  ------------------
  |  Branch (386:22): [True: 6, False: 181]
  ------------------
  387|      6|      const word w = word_at(i);
  388|      6|      store_be(w, output + (len - (i + 1) * sizeof(word)));
  389|      6|   }
  390|       |
  391|    181|   if(extra_bytes > 0) {
  ------------------
  |  Branch (391:7): [True: 136, False: 45]
  ------------------
  392|    136|      const word w = word_at(full_words);
  393|       |
  394|    286|      for(size_t i = 0; i != extra_bytes; ++i) {
  ------------------
  |  Branch (394:25): [True: 150, False: 136]
  ------------------
  395|    150|         output[extra_bytes - i - 1] = get_byte_var(sizeof(word) - i - 1, w);
  396|    150|      }
  397|    136|   }
  398|    181|}
_ZN5Botan6BigInt13binary_decodeEPKhm:
  403|    454|void BigInt::binary_decode(const uint8_t buf[], size_t length) {
  404|    454|   clear();
  405|       |
  406|    454|   const size_t full_words = length / sizeof(word);
  407|    454|   const size_t extra_bytes = length % sizeof(word);
  408|       |
  409|    454|   secure_vector<word> reg((round_up(full_words + (extra_bytes > 0 ? 1 : 0), 8)));
  ------------------
  |  Branch (409:52): [True: 440, False: 14]
  ------------------
  410|       |
  411|    748|   for(size_t i = 0; i != full_words; ++i) {
  ------------------
  |  Branch (411:22): [True: 294, False: 454]
  ------------------
  412|    294|      reg[i] = load_be<word>(buf + length - sizeof(word) * (i + 1), 0);
  413|    294|   }
  414|       |
  415|    454|   if(extra_bytes > 0) {
  ------------------
  |  Branch (415:7): [True: 440, False: 14]
  ------------------
  416|  1.07k|      for(size_t i = 0; i != extra_bytes; ++i) {
  ------------------
  |  Branch (416:25): [True: 632, False: 440]
  ------------------
  417|    632|         reg[full_words] = (reg[full_words] << 8) | buf[i];
  418|    632|      }
  419|    440|   }
  420|       |
  421|    454|   m_data.swap(reg);
  422|    454|}

_ZN5Botan20Curve25519_PublicKeyC1ERKNS_19AlgorithmIdentifierENSt3__14spanIKhLm18446744073709551615EEE:
   47|      3|Curve25519_PublicKey::Curve25519_PublicKey(const AlgorithmIdentifier& /*unused*/, std::span<const uint8_t> key_bits) {
   48|      3|   m_public.assign(key_bits.begin(), key_bits.end());
   49|       |
   50|      3|   size_check(m_public.size(), "public key");
   51|      3|}
curve25519.cpp:_ZN5Botan12_GLOBAL__N_110size_checkEmPKc:
   25|      3|void size_check(size_t size, const char* thing) {
   26|      3|   if(size != 32) {
  ------------------
  |  Branch (26:7): [True: 3, False: 0]
  ------------------
   27|      3|      throw Decoding_Error(fmt("Invalid size {} for Curve2551 {}", size, thing));
   28|      3|   }
   29|      3|}

_ZN5Botan17Ed25519_PublicKeyC1ERKNS_19AlgorithmIdentifierENSt3__14spanIKhLm18446744073709551615EEE:
   74|      3|Ed25519_PublicKey::Ed25519_PublicKey(const AlgorithmIdentifier& /*unused*/, std::span<const uint8_t> key_bits) {
   75|      3|   m_public.assign(key_bits.begin(), key_bits.end());
   76|       |
   77|      3|   if(m_public.size() != 32) {
  ------------------
  |  Branch (77:7): [True: 3, False: 0]
  ------------------
   78|      3|      throw Decoding_Error("Invalid size for Ed25519 public key");
   79|      3|   }
   80|      3|}

_ZN5Botan8PEM_Code6decodeERNS_10DataSourceERNSt3__112basic_stringIcNS3_11char_traitsIcEENS3_9allocatorIcEEEE:
   62|    250|secure_vector<uint8_t> decode(DataSource& source, std::string& label) {
   63|    250|   const size_t RANDOM_CHAR_LIMIT = 8;
   64|       |
   65|    250|   label.clear();
   66|       |
   67|    250|   const std::string PEM_HEADER1 = "-----BEGIN ";
   68|    250|   const std::string PEM_HEADER2 = "-----";
   69|    250|   size_t position = 0;
   70|       |
   71|  11.4k|   while(position != PEM_HEADER1.length()) {
  ------------------
  |  Branch (71:10): [True: 11.2k, False: 205]
  ------------------
   72|  11.2k|      uint8_t b;
   73|  11.2k|      if(!source.read_byte(b)) {
  ------------------
  |  Branch (73:10): [True: 44, False: 11.1k]
  ------------------
   74|     44|         throw Decoding_Error("PEM: No PEM header found");
   75|     44|      }
   76|  11.1k|      if(static_cast<char>(b) == PEM_HEADER1[position]) {
  ------------------
  |  Branch (76:10): [True: 2.75k, False: 8.41k]
  ------------------
   77|  2.75k|         ++position;
   78|  8.41k|      } else if(position >= RANDOM_CHAR_LIMIT) {
  ------------------
  |  Branch (78:17): [True: 1, False: 8.41k]
  ------------------
   79|      1|         throw Decoding_Error("PEM: Malformed PEM header");
   80|  8.41k|      } else {
   81|  8.41k|         position = 0;
   82|  8.41k|      }
   83|  11.1k|   }
   84|    205|   position = 0;
   85|  29.4k|   while(position != PEM_HEADER2.length()) {
  ------------------
  |  Branch (85:10): [True: 29.2k, False: 187]
  ------------------
   86|  29.2k|      uint8_t b;
   87|  29.2k|      if(!source.read_byte(b)) {
  ------------------
  |  Branch (87:10): [True: 16, False: 29.2k]
  ------------------
   88|     16|         throw Decoding_Error("PEM: No PEM header found");
   89|     16|      }
   90|  29.2k|      if(static_cast<char>(b) == PEM_HEADER2[position]) {
  ------------------
  |  Branch (90:10): [True: 942, False: 28.3k]
  ------------------
   91|    942|         ++position;
   92|  28.3k|      } else if(position) {
  ------------------
  |  Branch (92:17): [True: 2, False: 28.3k]
  ------------------
   93|      2|         throw Decoding_Error("PEM: Malformed PEM header");
   94|      2|      }
   95|       |
   96|  29.2k|      if(position == 0) {
  ------------------
  |  Branch (96:10): [True: 28.3k, False: 942]
  ------------------
   97|  28.3k|         label += static_cast<char>(b);
   98|  28.3k|      }
   99|  29.2k|   }
  100|       |
  101|    187|   std::vector<char> b64;
  102|       |
  103|    187|   const std::string PEM_TRAILER = fmt("-----END {}-----", label);
  104|    187|   position = 0;
  105|  41.6k|   while(position != PEM_TRAILER.length()) {
  ------------------
  |  Branch (105:10): [True: 41.5k, False: 122]
  ------------------
  106|  41.5k|      uint8_t b;
  107|  41.5k|      if(!source.read_byte(b)) {
  ------------------
  |  Branch (107:10): [True: 53, False: 41.5k]
  ------------------
  108|     53|         throw Decoding_Error("PEM: No PEM trailer found");
  109|     53|      }
  110|  41.5k|      if(static_cast<char>(b) == PEM_TRAILER[position]) {
  ------------------
  |  Branch (110:10): [True: 4.59k, False: 36.9k]
  ------------------
  111|  4.59k|         ++position;
  112|  36.9k|      } else if(position) {
  ------------------
  |  Branch (112:17): [True: 12, False: 36.9k]
  ------------------
  113|     12|         throw Decoding_Error("PEM: Malformed PEM trailer");
  114|     12|      }
  115|       |
  116|  41.5k|      if(position == 0) {
  ------------------
  |  Branch (116:10): [True: 36.9k, False: 4.59k]
  ------------------
  117|  36.9k|         b64.push_back(b);
  118|  36.9k|      }
  119|  41.5k|   }
  120|       |
  121|    122|   return base64_decode(b64.data(), b64.size());
  122|    187|}
_ZN5Botan8PEM_Code7matchesERNS_10DataSourceENSt3__117basic_string_viewIcNS3_11char_traitsIcEEEEm:
  137|  1.56k|bool matches(DataSource& source, std::string_view extra, size_t search_range) {
  138|  1.56k|   const std::string PEM_HEADER = fmt("-----BEGIN {}", extra);
  139|       |
  140|  1.56k|   secure_vector<uint8_t> search_buf(search_range);
  141|  1.56k|   const size_t got = source.peek(search_buf.data(), search_buf.size(), 0);
  142|       |
  143|  1.56k|   if(got < PEM_HEADER.length()) {
  ------------------
  |  Branch (143:7): [True: 417, False: 1.15k]
  ------------------
  144|    417|      return false;
  145|    417|   }
  146|       |
  147|  1.15k|   size_t index = 0;
  148|       |
  149|   245k|   for(size_t j = 0; j != got; ++j) {
  ------------------
  |  Branch (149:22): [True: 244k, False: 1.11k]
  ------------------
  150|   244k|      if(static_cast<char>(search_buf[j]) == PEM_HEADER[index]) {
  ------------------
  |  Branch (150:10): [True: 1.23k, False: 242k]
  ------------------
  151|  1.23k|         ++index;
  152|   242k|      } else {
  153|   242k|         index = 0;
  154|   242k|      }
  155|       |
  156|   244k|      if(index == PEM_HEADER.size()) {
  ------------------
  |  Branch (156:10): [True: 31, False: 244k]
  ------------------
  157|     31|         return true;
  158|     31|      }
  159|   244k|   }
  160|       |
  161|  1.11k|   return false;
  162|  1.15k|}

_ZN5Botan15load_public_keyERKNS_19AlgorithmIdentifierENSt3__14spanIKhLm18446744073709551615EEE:
   96|    211|                                            [[maybe_unused]] std::span<const uint8_t> key_bits) {
   97|    211|   const std::string oid_str = alg_id.oid().to_formatted_string();
   98|    211|   const std::vector<std::string> alg_info = split_on(oid_str, '/');
   99|    211|   std::string_view alg_name = alg_info[0];
  100|       |
  101|    211|#if defined(BOTAN_HAS_RSA)
  102|    211|   if(alg_name == "RSA") {
  ------------------
  |  Branch (102:7): [True: 0, False: 211]
  ------------------
  103|      0|      return std::make_unique<RSA_PublicKey>(alg_id, key_bits);
  104|      0|   }
  105|    211|#endif
  106|       |
  107|    211|#if defined(BOTAN_HAS_CURVE_25519)
  108|    211|   if(alg_name == "Curve25519") {
  ------------------
  |  Branch (108:7): [True: 3, False: 208]
  ------------------
  109|      3|      return std::make_unique<Curve25519_PublicKey>(alg_id, key_bits);
  110|      3|   }
  111|    208|#endif
  112|       |
  113|    208|#if defined(BOTAN_HAS_MCELIECE)
  114|    208|   if(alg_name == "McEliece") {
  ------------------
  |  Branch (114:7): [True: 0, False: 208]
  ------------------
  115|      0|      return std::make_unique<McEliece_PublicKey>(key_bits);
  116|      0|   }
  117|    208|#endif
  118|       |
  119|    208|#if defined(BOTAN_HAS_FRODOKEM)
  120|    208|   if(alg_name == "FrodoKEM" || alg_name.starts_with("FrodoKEM-") || alg_name.starts_with("eFrodoKEM-")) {
  ------------------
  |  Branch (120:7): [True: 0, False: 208]
  |  Branch (120:33): [True: 0, False: 208]
  |  Branch (120:70): [True: 0, False: 208]
  ------------------
  121|      0|      return std::make_unique<FrodoKEM_PublicKey>(alg_id, key_bits);
  122|      0|   }
  123|    208|#endif
  124|       |
  125|    208|#if defined(BOTAN_HAS_KYBER) || defined(BOTAN_HAS_KYBER_90S)
  126|    208|   if(alg_name == "Kyber" || alg_name.starts_with("Kyber-")) {
  ------------------
  |  Branch (126:7): [True: 0, False: 208]
  |  Branch (126:30): [True: 0, False: 208]
  ------------------
  127|      0|      return std::make_unique<Kyber_PublicKey>(alg_id, key_bits);
  128|      0|   }
  129|    208|#endif
  130|       |
  131|    208|#if defined(BOTAN_HAS_ECDSA)
  132|    208|   if(alg_name == "ECDSA") {
  ------------------
  |  Branch (132:7): [True: 0, False: 208]
  ------------------
  133|      0|      return std::make_unique<ECDSA_PublicKey>(alg_id, key_bits);
  134|      0|   }
  135|    208|#endif
  136|       |
  137|    208|#if defined(BOTAN_HAS_ECDH)
  138|    208|   if(alg_name == "ECDH") {
  ------------------
  |  Branch (138:7): [True: 0, False: 208]
  ------------------
  139|      0|      return std::make_unique<ECDH_PublicKey>(alg_id, key_bits);
  140|      0|   }
  141|    208|#endif
  142|       |
  143|    208|#if defined(BOTAN_HAS_DIFFIE_HELLMAN)
  144|    208|   if(alg_name == "DH") {
  ------------------
  |  Branch (144:7): [True: 0, False: 208]
  ------------------
  145|      0|      return std::make_unique<DH_PublicKey>(alg_id, key_bits);
  146|      0|   }
  147|    208|#endif
  148|       |
  149|    208|#if defined(BOTAN_HAS_DSA)
  150|    208|   if(alg_name == "DSA") {
  ------------------
  |  Branch (150:7): [True: 0, False: 208]
  ------------------
  151|      0|      return std::make_unique<DSA_PublicKey>(alg_id, key_bits);
  152|      0|   }
  153|    208|#endif
  154|       |
  155|    208|#if defined(BOTAN_HAS_ELGAMAL)
  156|    208|   if(alg_name == "ElGamal") {
  ------------------
  |  Branch (156:7): [True: 0, False: 208]
  ------------------
  157|      0|      return std::make_unique<ElGamal_PublicKey>(alg_id, key_bits);
  158|      0|   }
  159|    208|#endif
  160|       |
  161|    208|#if defined(BOTAN_HAS_ECGDSA)
  162|    208|   if(alg_name == "ECGDSA") {
  ------------------
  |  Branch (162:7): [True: 0, False: 208]
  ------------------
  163|      0|      return std::make_unique<ECGDSA_PublicKey>(alg_id, key_bits);
  164|      0|   }
  165|    208|#endif
  166|       |
  167|    208|#if defined(BOTAN_HAS_ECKCDSA)
  168|    208|   if(alg_name == "ECKCDSA") {
  ------------------
  |  Branch (168:7): [True: 0, False: 208]
  ------------------
  169|      0|      return std::make_unique<ECKCDSA_PublicKey>(alg_id, key_bits);
  170|      0|   }
  171|    208|#endif
  172|       |
  173|    208|#if defined(BOTAN_HAS_ED25519)
  174|    208|   if(alg_name == "Ed25519") {
  ------------------
  |  Branch (174:7): [True: 3, False: 205]
  ------------------
  175|      3|      return std::make_unique<Ed25519_PublicKey>(alg_id, key_bits);
  176|      3|   }
  177|    205|#endif
  178|       |
  179|    205|#if defined(BOTAN_HAS_GOST_34_10_2001)
  180|    205|   if(alg_name == "GOST-34.10" || alg_name == "GOST-34.10-2012-256" || alg_name == "GOST-34.10-2012-512") {
  ------------------
  |  Branch (180:7): [True: 0, False: 205]
  |  Branch (180:35): [True: 0, False: 205]
  |  Branch (180:72): [True: 0, False: 205]
  ------------------
  181|      0|      return std::make_unique<GOST_3410_PublicKey>(alg_id, key_bits);
  182|      0|   }
  183|    205|#endif
  184|       |
  185|    205|#if defined(BOTAN_HAS_SM2)
  186|    205|   if(alg_name == "SM2" || alg_name == "SM2_Sig" || alg_name == "SM2_Enc") {
  ------------------
  |  Branch (186:7): [True: 0, False: 205]
  |  Branch (186:28): [True: 0, False: 205]
  |  Branch (186:53): [True: 0, False: 205]
  ------------------
  187|      0|      return std::make_unique<SM2_PublicKey>(alg_id, key_bits);
  188|      0|   }
  189|    205|#endif
  190|       |
  191|    205|#if defined(BOTAN_HAS_XMSS_RFC8391)
  192|    205|   if(alg_name == "XMSS") {
  ------------------
  |  Branch (192:7): [True: 0, False: 205]
  ------------------
  193|      0|      return std::make_unique<XMSS_PublicKey>(key_bits);
  194|      0|   }
  195|    205|#endif
  196|       |
  197|    205|#if defined(BOTAN_HAS_DILITHIUM) || defined(BOTAN_HAS_DILITHIUM_AES)
  198|    205|   if(alg_name == "Dilithium" || alg_name.starts_with("Dilithium-")) {
  ------------------
  |  Branch (198:7): [True: 0, False: 205]
  |  Branch (198:34): [True: 0, False: 205]
  ------------------
  199|      0|      return std::make_unique<Dilithium_PublicKey>(alg_id, key_bits);
  200|      0|   }
  201|    205|#endif
  202|       |
  203|    205|#if defined(BOTAN_HAS_SPHINCS_PLUS_WITH_SHA2) || defined(BOTAN_HAS_SPHINCS_PLUS_WITH_SHAKE)
  204|    205|   if(alg_name == "SPHINCS+" || alg_name.starts_with("SphincsPlus-")) {
  ------------------
  |  Branch (204:7): [True: 0, False: 205]
  |  Branch (204:33): [True: 0, False: 205]
  ------------------
  205|      0|      return std::make_unique<SphincsPlus_PublicKey>(alg_id, key_bits);
  206|      0|   }
  207|    205|#endif
  208|       |
  209|    205|   throw Decoding_Error(fmt("Unknown or unavailable public key algorithm '{}'", alg_name));
  210|    205|}

_ZN5Botan22create_hex_fingerprintEPKhmNSt3__117basic_string_viewIcNS2_11char_traitsIcEEEE:
   30|    174|std::string create_hex_fingerprint(const uint8_t bits[], size_t bits_len, std::string_view hash_name) {
   31|    174|   auto hash_fn = HashFunction::create_or_throw(hash_name);
   32|    174|   const std::string hex_hash = hex_encode(hash_fn->process(bits, bits_len));
   33|       |
   34|    174|   std::string fprint;
   35|       |
   36|  4.69k|   for(size_t i = 0; i != hex_hash.size(); i += 2) {
  ------------------
  |  Branch (36:22): [True: 4.52k, False: 174]
  ------------------
   37|  4.52k|      if(i != 0) {
  ------------------
  |  Branch (37:10): [True: 4.35k, False: 174]
  ------------------
   38|  4.35k|         fprint.push_back(':');
   39|  4.35k|      }
   40|       |
   41|  4.52k|      fprint.push_back(hex_hash[i]);
   42|  4.52k|      fprint.push_back(hex_hash[i + 1]);
   43|  4.52k|   }
   44|       |
   45|    174|   return fprint;
   46|    174|}

_ZN5Botan4X5098load_keyERNS_10DataSourceE:
   28|    223|std::unique_ptr<Public_Key> load_key(DataSource& source) {
   29|    223|   try {
   30|    223|      AlgorithmIdentifier alg_id;
   31|    223|      std::vector<uint8_t> key_bits;
   32|       |
   33|    223|      if(ASN1::maybe_BER(source) && !PEM_Code::matches(source)) {
  ------------------
  |  Branch (33:10): [True: 223, False: 0]
  |  Branch (33:37): [True: 223, False: 0]
  ------------------
   34|    223|         BER_Decoder(source).start_sequence().decode(alg_id).decode(key_bits, ASN1_Type::BitString).end_cons();
   35|    223|      } else {
   36|      0|         DataSource_Memory ber(PEM_Code::decode_check_label(source, "PUBLIC KEY"));
   37|       |
   38|      0|         BER_Decoder(ber).start_sequence().decode(alg_id).decode(key_bits, ASN1_Type::BitString).end_cons();
   39|      0|      }
   40|       |
   41|    223|      if(key_bits.empty()) {
  ------------------
  |  Branch (41:10): [True: 5, False: 218]
  ------------------
   42|      5|         throw Decoding_Error("X.509 public key decoding");
   43|      5|      }
   44|       |
   45|    218|      return load_public_key(alg_id, key_bits);
   46|    223|   } catch(Decoding_Error& e) {
   47|    223|      throw Decoding_Error("X.509 public key decoding", e);
   48|    223|   }
   49|    223|}

_ZN5Botan3TLS18Certificate_VerifyC2ERKNSt3__16vectorIhNS2_9allocatorIhEEEE:
   45|  1.72k|Certificate_Verify::Certificate_Verify(const std::vector<uint8_t>& buf) {
   46|  1.72k|   TLS_Data_Reader reader("CertificateVerify", buf);
   47|       |
   48|  1.72k|   m_scheme = Signature_Scheme(reader.get_uint16_t());
   49|  1.72k|   m_signature = reader.get_range<uint8_t>(2, 0, 65535);
   50|  1.72k|   reader.assert_done();
   51|       |
   52|  1.72k|   if(!m_scheme.is_set()) {
  ------------------
  |  Branch (52:7): [True: 1, False: 1.72k]
  ------------------
   53|      1|      throw Decoding_Error("Counterparty did not send hash/sig IDS");
   54|      1|   }
   55|  1.72k|}
_ZN5Botan3TLS21Certificate_Verify_13C2ERKNSt3__16vectorIhNS2_9allocatorIhEEEENS0_15Connection_SideE:
  170|  1.72k|      Certificate_Verify(buf), m_side(side) {
  171|  1.72k|   if(!m_scheme.is_available()) {
  ------------------
  |  Branch (171:7): [True: 22, False: 1.70k]
  ------------------
  172|     22|      throw TLS_Exception(Alert::HandshakeFailure, "Peer sent unknown signature scheme");
  173|     22|   }
  174|       |
  175|  1.70k|   if(!m_scheme.is_compatible_with(Protocol_Version::TLS_V13)) {
  ------------------
  |  Branch (175:7): [True: 3, False: 1.70k]
  ------------------
  176|      3|      throw TLS_Exception(Alert::IllegalParameter, "Peer sent signature algorithm that is not suitable for TLS 1.3");
  177|      3|   }
  178|  1.70k|}

_ZN5Botan3TLS12Client_HelloC2EOS1_:
  169|  31.2k|Client_Hello::Client_Hello(Client_Hello&&) noexcept = default;
_ZN5Botan3TLS12Client_HelloD2Ev:
  172|  39.2k|Client_Hello::~Client_Hello() = default;
_ZN5Botan3TLS12Client_HelloC2ENSt3__110unique_ptrINS0_21Client_Hello_InternalENS2_14default_deleteIS4_EEEE:
  179|  8.00k|Client_Hello::Client_Hello(std::unique_ptr<Client_Hello_Internal> data) : m_data(std::move(data)) {
  180|  8.00k|   BOTAN_ASSERT_NONNULL(m_data);
  ------------------
  |  |   87|  8.00k|   do {                                                                                   \
  |  |   88|  8.00k|      if((ptr) == nullptr)                                                                \
  |  |  ------------------
  |  |  |  Branch (88:10): [True: 0, False: 8.00k]
  |  |  ------------------
  |  |   89|  8.00k|         Botan::assertion_failure(#ptr " is not null", "", __func__, __FILE__, __LINE__); \
  |  |   90|  8.00k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  181|  8.00k|}
_ZNK5Botan3TLS12Client_Hello13offered_suiteEt:
  261|  7.27k|bool Client_Hello::offered_suite(uint16_t ciphersuite) const {
  262|  7.27k|   return std::find(m_data->ciphersuites().cbegin(), m_data->ciphersuites().cend(), ciphersuite) !=
  263|  7.27k|          m_data->ciphersuites().cend();
  264|  7.27k|}
_ZN5Botan3TLS15Client_Hello_12C2ENSt3__110unique_ptrINS0_21Client_Hello_InternalENS2_14default_deleteIS4_EEEE:
  438|  7.27k|Client_Hello_12::Client_Hello_12(std::unique_ptr<Client_Hello_Internal> data) : Client_Hello(std::move(data)) {
  439|  7.27k|   if(offered_suite(static_cast<uint16_t>(TLS_EMPTY_RENEGOTIATION_INFO_SCSV))) {
  ------------------
  |  Branch (439:7): [True: 1.60k, False: 5.67k]
  ------------------
  440|  1.60k|      if(Renegotiation_Extension* reneg = m_data->extensions().get<Renegotiation_Extension>()) {
  ------------------
  |  Branch (440:35): [True: 67, False: 1.53k]
  ------------------
  441|     67|         if(!reneg->renegotiation_info().empty()) {
  ------------------
  |  Branch (441:13): [True: 1, False: 66]
  ------------------
  442|      1|            throw TLS_Exception(Alert::HandshakeFailure, "Client sent renegotiation SCSV and non-empty extension");
  443|      1|         }
  444|  1.53k|      } else {
  445|       |         // add fake extension
  446|  1.53k|         m_data->extensions().add(new Renegotiation_Extension());
  447|  1.53k|      }
  448|  1.60k|   }
  449|  7.27k|}
_ZN5Botan3TLS15Client_Hello_13C2ENSt3__110unique_ptrINS0_21Client_Hello_InternalENS2_14default_deleteIS4_EEEE:
  603|    721|Client_Hello_13::Client_Hello_13(std::unique_ptr<Client_Hello_Internal> data) : Client_Hello(std::move(data)) {
  604|    721|   const auto& exts = m_data->extensions();
  605|       |
  606|       |   // RFC 8446 4.1.2
  607|       |   //    TLS 1.3 ClientHellos are identified as having a legacy_version of
  608|       |   //    0x0303 and a "supported_versions" extension present with 0x0304 as the
  609|       |   //    highest version indicated therein.
  610|       |   //
  611|       |   // Note that we already checked for "supported_versions" before entering this
  612|       |   // c'tor in `Client_Hello_13::parse()`. This is just to be doubly sure.
  613|    721|   BOTAN_ASSERT_NOMSG(exts.has<Supported_Versions>());
  ------------------
  |  |   60|    721|   do {                                                                     \
  |  |   61|    721|      if(!(expr))                                                           \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 721]
  |  |  ------------------
  |  |   62|    721|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   63|    721|   } while(0)
  |  |  ------------------
  |  |  |  Branch (63:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  614|       |
  615|       |   // RFC 8446 4.2.1
  616|       |   //    Servers MAY abort the handshake upon receiving a ClientHello with
  617|       |   //    legacy_version 0x0304 or later.
  618|    721|   if(m_data->legacy_version().is_tls_13_or_later()) {
  ------------------
  |  Branch (618:7): [True: 21, False: 700]
  ------------------
  619|     21|      throw TLS_Exception(Alert::DecodeError, "TLS 1.3 Client Hello has invalid legacy_version");
  620|     21|   }
  621|       |
  622|       |   // RFC 8446 4.1.2
  623|       |   //    For every TLS 1.3 ClientHello, [the compression method] MUST contain
  624|       |   //    exactly one byte, set to zero, [...].  If a TLS 1.3 ClientHello is
  625|       |   //    received with any other value in this field, the server MUST abort the
  626|       |   //    handshake with an "illegal_parameter" alert.
  627|    700|   if(m_data->comp_methods().size() != 1 || m_data->comp_methods().front() != 0) {
  ------------------
  |  Branch (627:7): [True: 5, False: 695]
  |  Branch (627:45): [True: 11, False: 684]
  ------------------
  628|     16|      throw TLS_Exception(Alert::IllegalParameter, "Client did not offer NULL compression");
  629|     16|   }
  630|       |
  631|       |   // RFC 8446 4.2.9
  632|       |   //    A client MUST provide a "psk_key_exchange_modes" extension if it
  633|       |   //    offers a "pre_shared_key" extension. If clients offer "pre_shared_key"
  634|       |   //    without a "psk_key_exchange_modes" extension, servers MUST abort
  635|       |   //    the handshake.
  636|    684|   if(exts.has<PSK>()) {
  ------------------
  |  Branch (636:7): [True: 126, False: 558]
  ------------------
  637|    126|      if(!exts.has<PSK_Key_Exchange_Modes>()) {
  ------------------
  |  Branch (637:10): [True: 13, False: 113]
  ------------------
  638|     13|         throw TLS_Exception(Alert::MissingExtension,
  639|     13|                             "Client Hello offered a PSK without a psk_key_exchange_modes extension");
  640|     13|      }
  641|       |
  642|       |      // RFC 8446 4.2.11
  643|       |      //     The "pre_shared_key" extension MUST be the last extension in the
  644|       |      //     ClientHello [...]. Servers MUST check that it is the last extension
  645|       |      //     and otherwise fail the handshake with an "illegal_parameter" alert.
  646|    113|      if(exts.all().back()->type() != Extension_Code::PresharedKey) {
  ------------------
  |  Branch (646:10): [True: 28, False: 85]
  ------------------
  647|     28|         throw TLS_Exception(Alert::IllegalParameter, "PSK extension was not at the very end of the Client Hello");
  648|     28|      }
  649|    113|   }
  650|       |
  651|       |   // RFC 8446 9.2
  652|       |   //    [A TLS 1.3 ClientHello] message MUST meet the following requirements:
  653|       |   //
  654|       |   //     -  If not containing a "pre_shared_key" extension, it MUST contain
  655|       |   //        both a "signature_algorithms" extension and a "supported_groups"
  656|       |   //        extension.
  657|       |   //
  658|       |   //     -  If containing a "supported_groups" extension, it MUST also contain
  659|       |   //        a "key_share" extension, and vice versa.  An empty
  660|       |   //        KeyShare.client_shares vector is permitted.
  661|       |   //
  662|       |   //    Servers receiving a ClientHello which does not conform to these
  663|       |   //    requirements MUST abort the handshake with a "missing_extension"
  664|       |   //    alert.
  665|    643|   if(!exts.has<PSK>()) {
  ------------------
  |  Branch (665:7): [True: 558, False: 85]
  ------------------
  666|    558|      if(!exts.has<Supported_Groups>() || !exts.has<Signature_Algorithms>()) {
  ------------------
  |  Branch (666:10): [True: 44, False: 514]
  |  Branch (666:43): [True: 27, False: 487]
  ------------------
  667|     71|         throw TLS_Exception(
  668|     71|            Alert::MissingExtension,
  669|     71|            "Non-PSK Client Hello did not contain supported_groups and signature_algorithms extensions");
  670|     71|      }
  671|    558|   }
  672|    572|   if(exts.has<Supported_Groups>() != exts.has<Key_Share>()) {
  ------------------
  |  Branch (672:7): [True: 9, False: 563]
  ------------------
  673|      9|      throw TLS_Exception(Alert::MissingExtension,
  674|      9|                          "Client Hello must either contain both key_share and supported_groups extensions or neither");
  675|      9|   }
  676|       |
  677|    563|   if(exts.has<Key_Share>()) {
  ------------------
  |  Branch (677:7): [True: 478, False: 85]
  ------------------
  678|    478|      const auto supported_ext = exts.get<Supported_Groups>();
  679|    478|      BOTAN_ASSERT_NONNULL(supported_ext);
  ------------------
  |  |   87|    478|   do {                                                                                   \
  |  |   88|    478|      if((ptr) == nullptr)                                                                \
  |  |  ------------------
  |  |  |  Branch (88:10): [True: 0, False: 478]
  |  |  ------------------
  |  |   89|    478|         Botan::assertion_failure(#ptr " is not null", "", __func__, __FILE__, __LINE__); \
  |  |   90|    478|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  680|    478|      const auto supports = supported_ext->groups();
  681|    478|      const auto offers = exts.get<Key_Share>()->offered_groups();
  682|       |
  683|       |      // RFC 8446 4.2.8
  684|       |      //    Each KeyShareEntry value MUST correspond to a group offered in the
  685|       |      //    "supported_groups" extension and MUST appear in the same order.
  686|       |      //    [...]
  687|       |      //    Clients MUST NOT offer any KeyShareEntry values for groups not
  688|       |      //    listed in the client's "supported_groups" extension.
  689|       |      //
  690|       |      // Note: We can assume that both `offers` and `supports` are unique lists
  691|       |      //       as this is ensured in the parsing code of the extensions.
  692|    478|      auto found_in_supported_groups = [&supports, support_offset = -1](auto group) mutable {
  693|    478|         const auto i = std::find(supports.begin(), supports.end(), group);
  694|    478|         if(i == supports.end()) {
  695|    478|            return false;
  696|    478|         }
  697|       |
  698|    478|         const auto found_at = std::distance(supports.begin(), i);
  699|    478|         if(found_at <= support_offset) {
  700|    478|            return false;  // The order that groups appear in "key_share" and
  701|       |                           // "supported_groups" must be the same
  702|    478|         }
  703|       |
  704|    478|         support_offset = static_cast<decltype(support_offset)>(found_at);
  705|    478|         return true;
  706|    478|      };
  707|       |
  708|    864|      for(const auto offered : offers) {
  ------------------
  |  Branch (708:30): [True: 864, False: 441]
  ------------------
  709|       |         // RFC 8446 4.2.8
  710|       |         //    Servers MAY check for violations of these rules and abort the
  711|       |         //    handshake with an "illegal_parameter" alert if one is violated.
  712|    864|         if(!found_in_supported_groups(offered)) {
  ------------------
  |  Branch (712:13): [True: 37, False: 827]
  ------------------
  713|     37|            throw TLS_Exception(Alert::IllegalParameter,
  714|     37|                                "Offered key exchange groups do not align with claimed supported groups");
  715|     37|         }
  716|    864|      }
  717|    478|   }
  718|       |
  719|       |   // TODO: Reject oid_filters extension if found (which is the only known extension that
  720|       |   //       must not occur in the TLS 1.3 client hello.
  721|       |   // RFC 8446 4.2.5
  722|       |   //    [The oid_filters extension] MUST only be sent in the CertificateRequest message.
  723|    563|}
_ZN5Botan3TLS15Client_Hello_135parseERKNSt3__16vectorIhNS2_9allocatorIhEEEE:
  841|  8.47k|std::variant<Client_Hello_13, Client_Hello_12> Client_Hello_13::parse(const std::vector<uint8_t>& buf) {
  842|  8.47k|   auto data = std::make_unique<Client_Hello_Internal>(buf);
  843|  8.47k|   const auto version = data->version();
  844|       |
  845|  8.47k|   if(version.is_pre_tls_13()) {
  ------------------
  |  Branch (845:7): [True: 7.27k, False: 1.20k]
  ------------------
  846|  7.27k|      return Client_Hello_12(std::move(data));
  847|  7.27k|   } else {
  848|  1.20k|      return Client_Hello_13(std::move(data));
  849|  1.20k|   }
  850|  8.47k|}
_ZNK5Botan3TLS21Client_Hello_Internal14legacy_versionEv:
  138|    721|      Protocol_Version legacy_version() const { return m_legacy_version; }
_ZNK5Botan3TLS21Client_Hello_Internal12comp_methodsEv:
  146|  1.39k|      const std::vector<uint8_t>& comp_methods() const { return m_comp_methods; }
_ZNK5Botan3TLS21Client_Hello_Internal12ciphersuitesEv:
  144|  21.8k|      const std::vector<uint16_t>& ciphersuites() const { return m_suites; }
_ZN5Botan3TLS21Client_Hello_Internal10extensionsEv:
  154|  3.86k|      Extensions& extensions() { return m_extensions; }
msg_client_hello.cpp:_ZZN5Botan3TLS15Client_Hello_13C1ENSt3__110unique_ptrINS0_21Client_Hello_InternalENS2_14default_deleteIS4_EEEEEN3$_1clINS0_12Group_ParamsEEEDaT_:
  692|    864|      auto found_in_supported_groups = [&supports, support_offset = -1](auto group) mutable {
  693|    864|         const auto i = std::find(supports.begin(), supports.end(), group);
  694|    864|         if(i == supports.end()) {
  ------------------
  |  Branch (694:13): [True: 34, False: 830]
  ------------------
  695|     34|            return false;
  696|     34|         }
  697|       |
  698|    830|         const auto found_at = std::distance(supports.begin(), i);
  699|    830|         if(found_at <= support_offset) {
  ------------------
  |  Branch (699:13): [True: 3, False: 827]
  ------------------
  700|      3|            return false;  // The order that groups appear in "key_share" and
  701|       |                           // "supported_groups" must be the same
  702|      3|         }
  703|       |
  704|    827|         support_offset = static_cast<decltype(support_offset)>(found_at);
  705|    827|         return true;
  706|    830|      };
_ZNK5Botan3TLS21Client_Hello_Internal7versionEv:
  110|  8.00k|      Protocol_Version version() const {
  111|       |         // RFC 8446 4.2.1
  112|       |         //    If [the "supported_versions"] extension is not present, servers
  113|       |         //    which are compliant with this specification and which also support
  114|       |         //    TLS 1.2 MUST negotiate TLS 1.2 or prior as specified in [RFC5246],
  115|       |         //    even if ClientHello.legacy_version is 0x0304 or later.
  116|       |         //
  117|       |         // RFC 8446 4.2.1
  118|       |         //    Servers MUST be prepared to receive ClientHellos that include
  119|       |         //    [the supported_versions] extension but do not include 0x0304 in
  120|       |         //    the list of versions.
  121|       |         //
  122|       |         // RFC 8446 4.1.2
  123|       |         //    TLS 1.3 ClientHellos are identified as having a legacy_version of
  124|       |         //    0x0303 and a supported_versions extension present with 0x0304 as
  125|       |         //    the highest version indicated therein.
  126|  8.00k|         if(!extensions().has<Supported_Versions>() ||
  ------------------
  |  Branch (126:13): [True: 6.95k, False: 1.04k]
  ------------------
  127|  8.00k|            !extensions().get<Supported_Versions>()->supports(Protocol_Version::TLS_V13)) {
  ------------------
  |  Branch (127:13): [True: 326, False: 721]
  ------------------
  128|       |            // The exact legacy_version is ignored we just inspect it to
  129|       |            // distinguish TLS and DTLS.
  130|  7.27k|            return (m_legacy_version.is_datagram_protocol()) ? Protocol_Version::DTLS_V12 : Protocol_Version::TLS_V12;
  ------------------
  |  Branch (130:20): [True: 2.53k, False: 4.74k]
  ------------------
  131|  7.27k|         }
  132|       |
  133|       |         // Note: The Client_Hello_13 class will make sure that legacy_version
  134|       |         //       is exactly 0x0303 (aka ossified TLS 1.2)
  135|    721|         return Protocol_Version::TLS_V13;
  136|  8.00k|      }
_ZNK5Botan3TLS21Client_Hello_Internal10extensionsEv:
  152|  9.04k|      const Extensions& extensions() const { return m_extensions; }
_ZN5Botan3TLS21Client_Hello_InternalC2ERKNSt3__16vectorIhNS2_9allocatorIhEEEE:
   71|  8.47k|      Client_Hello_Internal(const std::vector<uint8_t>& buf) {
   72|  8.47k|         if(buf.size() < 41) {
  ------------------
  |  Branch (72:13): [True: 19, False: 8.46k]
  ------------------
   73|     19|            throw Decoding_Error("Client_Hello: Packet corrupted");
   74|     19|         }
   75|       |
   76|  8.46k|         TLS_Data_Reader reader("ClientHello", buf);
   77|       |
   78|  8.46k|         const uint8_t major_version = reader.get_byte();
   79|  8.46k|         const uint8_t minor_version = reader.get_byte();
   80|       |
   81|  8.46k|         m_legacy_version = Protocol_Version(major_version, minor_version);
   82|  8.46k|         m_random = reader.get_fixed<uint8_t>(32);
   83|  8.46k|         m_session_id = Session_ID(reader.get_range<uint8_t>(1, 0, 32));
   84|       |
   85|  8.46k|         if(m_legacy_version.is_datagram_protocol()) {
  ------------------
  |  Branch (85:13): [True: 2.69k, False: 5.76k]
  ------------------
   86|  2.69k|            auto sha256 = HashFunction::create_or_throw("SHA-256");
   87|  2.69k|            sha256->update(reader.get_data_read_so_far());
   88|       |
   89|  2.69k|            m_hello_cookie = reader.get_range<uint8_t>(1, 0, 255);
   90|       |
   91|  2.69k|            sha256->update(reader.get_remaining());
   92|  2.69k|            m_cookie_input_bits = sha256->final_stdvec();
   93|  2.69k|         }
   94|       |
   95|  8.46k|         m_suites = reader.get_range_vector<uint16_t>(2, 1, 32767);
   96|  8.46k|         m_comp_methods = reader.get_range_vector<uint8_t>(1, 1, 255);
   97|       |
   98|  8.46k|         m_extensions.deserialize(reader, Connection_Side::Client, Handshake_Type::ClientHello);
   99|  8.46k|      }

_ZN5Botan3TLS8FinishedC2ERKNSt3__16vectorIhNS2_9allocatorIhEEEE:
   53|  5.45k|Finished::Finished(const std::vector<uint8_t>& buf) : m_verification_data(buf) {}

_ZN5Botan3TLS12Server_HelloC2ENSt3__110unique_ptrINS0_21Server_Hello_InternalENS2_14default_deleteIS4_EEEE:
  168|  6.24k|Server_Hello::Server_Hello(std::unique_ptr<Server_Hello_Internal> data) : m_data(std::move(data)) {}
_ZN5Botan3TLS12Server_HelloC2EOS1_:
  170|  24.4k|Server_Hello::Server_Hello(Server_Hello&&) noexcept = default;
_ZN5Botan3TLS12Server_HelloD2Ev:
  173|  30.7k|Server_Hello::~Server_Hello() = default;
_ZNK5Botan3TLS12Server_Hello14legacy_versionEv:
  202|    632|Protocol_Version Server_Hello::legacy_version() const {
  203|    632|   return m_data->legacy_version();
  204|    632|}
_ZNK5Botan3TLS12Server_Hello18compression_methodEv:
  210|    510|uint8_t Server_Hello::compression_method() const {
  211|    510|   return m_data->comp_method();
  212|    510|}
_ZNK5Botan3TLS12Server_Hello10extensionsEv:
  226|    956|const Extensions& Server_Hello::extensions() const {
  227|    956|   return m_data->extensions();
  228|    956|}
_ZN5Botan3TLS15Server_Hello_12C2ENSt3__110unique_ptrINS0_21Server_Hello_InternalENS2_14default_deleteIS4_EEEE:
  355|  5.67k|Server_Hello_12::Server_Hello_12(std::unique_ptr<Server_Hello_Internal> data) : Server_Hello(std::move(data)) {
  356|  5.67k|   if(!m_data->version().is_pre_tls_13()) {
  ------------------
  |  Branch (356:7): [True: 0, False: 5.67k]
  ------------------
  357|      0|      throw TLS_Exception(Alert::ProtocolVersion, "Expected server hello of (D)TLS 1.2 or lower");
  358|      0|   }
  359|  5.67k|}
_ZN5Botan3TLS15Server_Hello_135parseERKNSt3__16vectorIhNS2_9allocatorIhEEEE:
  516|  6.36k|   const std::vector<uint8_t>& buf) {
  517|  6.36k|   auto data = std::make_unique<Server_Hello_Internal>(buf);
  518|  6.36k|   const auto version = data->version();
  519|       |
  520|       |   // server hello that appears to be pre-TLS 1.3, takes precedence over...
  521|  6.36k|   if(version.is_pre_tls_13()) {
  ------------------
  |  Branch (521:7): [True: 5.67k, False: 687]
  ------------------
  522|  5.67k|      return Server_Hello_12(std::move(data));
  523|  5.67k|   }
  524|       |
  525|       |   // ... the TLS 1.3 "special case" aka. Hello_Retry_Request
  526|    687|   if(version == Protocol_Version::TLS_V13) {
  ------------------
  |  Branch (526:7): [True: 571, False: 116]
  ------------------
  527|    571|      if(data->is_hello_retry_request()) {
  ------------------
  |  Branch (527:10): [True: 0, False: 571]
  ------------------
  528|      0|         return Hello_Retry_Request(std::move(data));
  529|      0|      }
  530|       |
  531|    571|      return Server_Hello_13(std::move(data));
  532|    571|   }
  533|       |
  534|    116|   throw TLS_Exception(Alert::ProtocolVersion, "unexpected server hello version: " + version.to_string());
  535|    687|}
_ZNK5Botan3TLS15Server_Hello_1316basic_validationEv:
  540|    571|void Server_Hello_13::basic_validation() const {
  541|    571|   BOTAN_ASSERT_NOMSG(m_data->version() == Protocol_Version::TLS_V13);
  ------------------
  |  |   60|    571|   do {                                                                     \
  |  |   61|    571|      if(!(expr))                                                           \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 571]
  |  |  ------------------
  |  |   62|    571|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   63|    571|   } while(0)
  |  |  ------------------
  |  |  |  Branch (63:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  542|       |
  543|       |   // Note: checks that cannot be performed without contextual information
  544|       |   //       are done in the specific TLS client implementation.
  545|       |   // Note: The Supported_Version extension makes sure internally that
  546|       |   //       exactly one entry is provided.
  547|       |
  548|       |   // Note: Hello Retry Request basic validation is equivalent with the
  549|       |   //       basic validations required for Server Hello
  550|       |   //
  551|       |   // RFC 8446 4.1.4
  552|       |   //    Upon receipt of a HelloRetryRequest, the client MUST check the
  553|       |   //    legacy_version, [...], and legacy_compression_method as specified in
  554|       |   //    Section 4.1.3 and then process the extensions, starting with determining
  555|       |   //    the version using "supported_versions".
  556|       |
  557|       |   // RFC 8446 4.1.3
  558|       |   //    In TLS 1.3, [...] the legacy_version field MUST be set to 0x0303
  559|    571|   if(legacy_version() != Protocol_Version::TLS_V12) {
  ------------------
  |  Branch (559:7): [True: 61, False: 510]
  ------------------
  560|     61|      throw TLS_Exception(Alert::ProtocolVersion,
  561|     61|                          "legacy_version '" + legacy_version().to_string() + "' is not allowed");
  562|     61|   }
  563|       |
  564|       |   // RFC 8446 4.1.3
  565|       |   //    legacy_compression_method:  A single byte which MUST have the value 0.
  566|    510|   if(compression_method() != 0x00) {
  ------------------
  |  Branch (566:7): [True: 8, False: 502]
  ------------------
  567|      8|      throw TLS_Exception(Alert::DecodeError, "compression is not supported in TLS 1.3");
  568|      8|   }
  569|       |
  570|       |   // RFC 8446 4.1.3
  571|       |   //    All TLS 1.3 ServerHello messages MUST contain the "supported_versions" extension.
  572|    502|   if(!extensions().has<Supported_Versions>()) {
  ------------------
  |  Branch (572:7): [True: 0, False: 502]
  ------------------
  573|      0|      throw TLS_Exception(Alert::MissingExtension, "server hello did not contain 'supported version' extension");
  574|      0|   }
  575|       |
  576|       |   // RFC 8446 4.2.1
  577|       |   //    A server which negotiates TLS 1.3 MUST respond by sending
  578|       |   //    a "supported_versions" extension containing the selected version
  579|       |   //    value (0x0304).
  580|    502|   if(selected_version() != Protocol_Version::TLS_V13) {
  ------------------
  |  Branch (580:7): [True: 48, False: 454]
  ------------------
  581|     48|      throw TLS_Exception(Alert::IllegalParameter, "TLS 1.3 Server Hello selected a different version");
  582|     48|   }
  583|    502|}
_ZN5Botan3TLS15Server_Hello_13C2ENSt3__110unique_ptrINS0_21Server_Hello_InternalENS2_14default_deleteIS4_EEEENS1_16Server_Hello_TagE:
  586|    571|      Server_Hello(std::move(data)) {
  587|    571|   BOTAN_ASSERT_NOMSG(!m_data->is_hello_retry_request());
  ------------------
  |  |   60|    571|   do {                                                                     \
  |  |   61|    571|      if(!(expr))                                                           \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 571]
  |  |  ------------------
  |  |   62|    571|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   63|    571|   } while(0)
  |  |  ------------------
  |  |  |  Branch (63:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  588|    571|   basic_validation();
  589|       |
  590|    571|   const auto& exts = extensions();
  591|       |
  592|       |   // RFC 8446 4.1.3
  593|       |   //    The ServerHello MUST only include extensions which are required to
  594|       |   //    establish the cryptographic context and negotiate the protocol version.
  595|       |   //    [...]
  596|       |   //    Other extensions (see Section 4.2) are sent separately in the
  597|       |   //    EncryptedExtensions message.
  598|       |   //
  599|       |   // Note that further validation dependent on the client hello is done in the
  600|       |   // TLS client implementation.
  601|    571|   const std::set<Extension_Code> allowed = {
  602|    571|      Extension_Code::KeyShare,
  603|    571|      Extension_Code::SupportedVersions,
  604|    571|      Extension_Code::PresharedKey,
  605|    571|   };
  606|       |
  607|       |   // As the ServerHello shall only contain essential extensions, we don't give
  608|       |   // any slack for extensions not implemented by Botan here.
  609|    571|   if(exts.contains_other_than(allowed)) {
  ------------------
  |  Branch (609:7): [True: 3, False: 568]
  ------------------
  610|      3|      throw TLS_Exception(Alert::UnsupportedExtension, "Server Hello contained an extension that is not allowed");
  611|      3|   }
  612|       |
  613|       |   // RFC 8446 4.1.3
  614|       |   //    Current ServerHello messages additionally contain
  615|       |   //    either the "pre_shared_key" extension or the "key_share"
  616|       |   //    extension, or both [...].
  617|    568|   if(!exts.has<Key_Share>() && !exts.has<PSK_Key_Exchange_Modes>()) {
  ------------------
  |  Branch (617:7): [True: 6, False: 562]
  |  Branch (617:33): [True: 6, False: 0]
  ------------------
  618|      6|      throw TLS_Exception(Alert::MissingExtension, "server hello must contain key exchange information");
  619|      6|   }
  620|    568|}
_ZNK5Botan3TLS15Server_Hello_1316selected_versionEv:
  777|    502|Protocol_Version Server_Hello_13::selected_version() const {
  778|    502|   const auto versions_ext = m_data->extensions().get<Supported_Versions>();
  779|    502|   BOTAN_ASSERT_NOMSG(versions_ext);
  ------------------
  |  |   60|    502|   do {                                                                     \
  |  |   61|    502|      if(!(expr))                                                           \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 502]
  |  |  ------------------
  |  |   62|    502|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   63|    502|   } while(0)
  |  |  ------------------
  |  |  |  Branch (63:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  780|    502|   const auto& versions = versions_ext->versions();
  781|    502|   BOTAN_ASSERT_NOMSG(versions.size() == 1);
  ------------------
  |  |   60|    502|   do {                                                                     \
  |  |   61|    502|      if(!(expr))                                                           \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 502]
  |  |  ------------------
  |  |   62|    502|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   63|    502|   } while(0)
  |  |  ------------------
  |  |  |  Branch (63:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  782|    502|   return versions.front();
  783|    502|}
_ZNK5Botan3TLS21Server_Hello_Internal14legacy_versionEv:
  141|    632|      Protocol_Version legacy_version() const { return m_legacy_version; }
_ZNK5Botan3TLS21Server_Hello_Internal11comp_methodEv:
  149|    510|      uint8_t comp_method() const { return m_comp_method; }
_ZN5Botan3TLS21Server_Hello_Internal10extensionsEv:
  155|  1.45k|      Extensions& extensions() { return m_extensions; }
_ZNK5Botan3TLS21Server_Hello_Internal7versionEv:
  128|  12.5k|      Protocol_Version version() const {
  129|       |         // RFC 8446 4.2.1
  130|       |         //    A server which negotiates a version of TLS prior to TLS 1.3 MUST set
  131|       |         //    ServerHello.version and MUST NOT send the "supported_versions"
  132|       |         //    extension.  A server which negotiates TLS 1.3 MUST respond by sending
  133|       |         //    a "supported_versions" extension containing the selected version
  134|       |         //    value (0x0304).
  135|       |         //
  136|       |         // Note: Here we just take a message parsing decision, further validation of
  137|       |         //       the extension's contents is done later.
  138|  12.5k|         return (extensions().has<Supported_Versions>()) ? Protocol_Version::TLS_V13 : m_legacy_version;
  ------------------
  |  Branch (138:17): [True: 1.05k, False: 11.4k]
  ------------------
  139|  12.5k|      }
_ZNK5Botan3TLS21Server_Hello_Internal10extensionsEv:
  153|  12.5k|      const Extensions& extensions() const { return m_extensions; }
_ZNK5Botan3TLS21Server_Hello_Internal22is_hello_retry_requestEv:
  151|  1.14k|      bool is_hello_retry_request() const { return m_is_hello_retry_request; }
_ZN5Botan3TLS21Server_Hello_InternalC2ERKNSt3__16vectorIhNS2_9allocatorIhEEEE:
   81|  6.36k|      Server_Hello_Internal(const std::vector<uint8_t>& buf) {
   82|  6.36k|         if(buf.size() < 38) {
  ------------------
  |  Branch (82:13): [True: 19, False: 6.34k]
  ------------------
   83|     19|            throw Decoding_Error("Server_Hello: Packet corrupted");
   84|     19|         }
   85|       |
   86|  6.34k|         TLS_Data_Reader reader("ServerHello", buf);
   87|       |
   88|  6.34k|         const uint8_t major_version = reader.get_byte();
   89|  6.34k|         const uint8_t minor_version = reader.get_byte();
   90|       |
   91|  6.34k|         m_legacy_version = Protocol_Version(major_version, minor_version);
   92|       |
   93|       |         // RFC 8446 4.1.3
   94|       |         //    Upon receiving a message with type server_hello, implementations MUST
   95|       |         //    first examine the Random value and, if it matches this value, process
   96|       |         //    it as described in Section 4.1.4 [Hello Retry Request]).
   97|  6.34k|         m_random = reader.get_fixed<uint8_t>(32);
   98|  6.34k|         m_is_hello_retry_request = random_signals_hello_retry_request(m_random);
   99|       |
  100|  6.34k|         m_session_id = Session_ID(reader.get_range<uint8_t>(1, 0, 32));
  101|  6.34k|         m_ciphersuite = reader.get_uint16_t();
  102|  6.34k|         m_comp_method = reader.get_byte();
  103|       |
  104|       |         // Note that this code path might parse a TLS 1.2 (or older) server hello message that
  105|       |         // is nevertheless marked as being a 'hello retry request' (potentially maliciously).
  106|       |         // Extension parsing will however not be affected by the associated flag.
  107|       |         // Only after parsing the extensions will the upstream code be able to decide
  108|       |         // whether we're dealing with TLS 1.3 or older.
  109|  6.34k|         m_extensions.deserialize(
  110|  6.34k|            reader,
  111|  6.34k|            Connection_Side::Server,
  112|  6.34k|            m_is_hello_retry_request ? Handshake_Type::HelloRetryRequest : Handshake_Type::ServerHello);
  ------------------
  |  Branch (112:13): [True: 0, False: 6.34k]
  ------------------
  113|  6.34k|      }
msg_server_hello.cpp:_ZN5Botan3TLS12_GLOBAL__N_134random_signals_hello_retry_requestERKNSt3__16vectorIhNS2_9allocatorIhEEEE:
   40|  6.34k|bool random_signals_hello_retry_request(const std::vector<uint8_t>& random) {
   41|  6.34k|   return CT::is_equal(random.data(), HELLO_RETRY_REQUEST_MARKER.data(), HELLO_RETRY_REQUEST_MARKER.size()).as_bool();
   42|  6.34k|}

_ZN5Botan3TLS24handshake_type_to_stringENS0_14Handshake_TypeE:
   23|      5|const char* handshake_type_to_string(Handshake_Type type) {
   24|      5|   switch(type) {
  ------------------
  |  Branch (24:11): [True: 0, False: 5]
  ------------------
   25|      0|      case Handshake_Type::HelloVerifyRequest:
  ------------------
  |  Branch (25:7): [True: 0, False: 5]
  ------------------
   26|      0|         return "hello_verify_request";
   27|       |
   28|      0|      case Handshake_Type::HelloRequest:
  ------------------
  |  Branch (28:7): [True: 0, False: 5]
  ------------------
   29|      0|         return "hello_request";
   30|       |
   31|      0|      case Handshake_Type::ClientHello:
  ------------------
  |  Branch (31:7): [True: 0, False: 5]
  ------------------
   32|      0|         return "client_hello";
   33|       |
   34|      0|      case Handshake_Type::ServerHello:
  ------------------
  |  Branch (34:7): [True: 0, False: 5]
  ------------------
   35|      0|         return "server_hello";
   36|       |
   37|      0|      case Handshake_Type::HelloRetryRequest:
  ------------------
  |  Branch (37:7): [True: 0, False: 5]
  ------------------
   38|      0|         return "hello_retry_request";
   39|       |
   40|      0|      case Handshake_Type::Certificate:
  ------------------
  |  Branch (40:7): [True: 0, False: 5]
  ------------------
   41|      0|         return "certificate";
   42|       |
   43|      0|      case Handshake_Type::CertificateUrl:
  ------------------
  |  Branch (43:7): [True: 0, False: 5]
  ------------------
   44|      0|         return "certificate_url";
   45|       |
   46|      0|      case Handshake_Type::CertificateStatus:
  ------------------
  |  Branch (46:7): [True: 0, False: 5]
  ------------------
   47|      0|         return "certificate_status";
   48|       |
   49|      0|      case Handshake_Type::ServerKeyExchange:
  ------------------
  |  Branch (49:7): [True: 0, False: 5]
  ------------------
   50|      0|         return "server_key_exchange";
   51|       |
   52|      4|      case Handshake_Type::CertificateRequest:
  ------------------
  |  Branch (52:7): [True: 4, False: 1]
  ------------------
   53|      4|         return "certificate_request";
   54|       |
   55|      0|      case Handshake_Type::ServerHelloDone:
  ------------------
  |  Branch (55:7): [True: 0, False: 5]
  ------------------
   56|      0|         return "server_hello_done";
   57|       |
   58|      0|      case Handshake_Type::CertificateVerify:
  ------------------
  |  Branch (58:7): [True: 0, False: 5]
  ------------------
   59|      0|         return "certificate_verify";
   60|       |
   61|      0|      case Handshake_Type::ClientKeyExchange:
  ------------------
  |  Branch (61:7): [True: 0, False: 5]
  ------------------
   62|      0|         return "client_key_exchange";
   63|       |
   64|      0|      case Handshake_Type::NewSessionTicket:
  ------------------
  |  Branch (64:7): [True: 0, False: 5]
  ------------------
   65|      0|         return "new_session_ticket";
   66|       |
   67|      0|      case Handshake_Type::HandshakeCCS:
  ------------------
  |  Branch (67:7): [True: 0, False: 5]
  ------------------
   68|      0|         return "change_cipher_spec";
   69|       |
   70|      0|      case Handshake_Type::Finished:
  ------------------
  |  Branch (70:7): [True: 0, False: 5]
  ------------------
   71|      0|         return "finished";
   72|       |
   73|      0|      case Handshake_Type::EndOfEarlyData:
  ------------------
  |  Branch (73:7): [True: 0, False: 5]
  ------------------
   74|      0|         return "end_of_early_data";
   75|       |
   76|      1|      case Handshake_Type::EncryptedExtensions:
  ------------------
  |  Branch (76:7): [True: 1, False: 4]
  ------------------
   77|      1|         return "encrypted_extensions";
   78|       |
   79|      0|      case Handshake_Type::KeyUpdate:
  ------------------
  |  Branch (79:7): [True: 0, False: 5]
  ------------------
   80|      0|         return "key_update";
   81|       |
   82|      0|      case Handshake_Type::None:
  ------------------
  |  Branch (82:7): [True: 0, False: 5]
  ------------------
   83|      0|         return "invalid";
   84|      5|   }
   85|       |
   86|      0|   throw TLS_Exception(Alert::UnexpectedMessage,
   87|      0|                       "Unknown TLS handshake message type " + std::to_string(static_cast<size_t>(type)));
   88|      5|}

_ZN5Botan3TLS14Certificate_1317Certificate_EntryC2ERNS0_15TLS_Data_ReaderENS0_15Connection_SideENS0_16Certificate_TypeE:
  268|  1.57k|                                                     const Certificate_Type cert_type) {
  269|  1.57k|   switch(cert_type) {
  270|  1.57k|      case Certificate_Type::X509:
  ------------------
  |  Branch (270:7): [True: 1.57k, False: 0]
  ------------------
  271|       |         // RFC 8446 4.2.2
  272|       |         //    [...] each CertificateEntry contains a DER-encoded X.509
  273|       |         //    certificate.
  274|  1.57k|         m_certificate = X509_Certificate(reader.get_tls_length_value(3));
  275|  1.57k|         m_raw_public_key = m_certificate->subject_public_key();
  276|  1.57k|         break;
  277|      0|      case Certificate_Type::RawPublicKey:
  ------------------
  |  Branch (277:7): [True: 0, False: 1.57k]
  ------------------
  278|       |         // RFC 7250 3.
  279|       |         //    This specification uses raw public keys whereby the already
  280|       |         //    available encoding used in a PKIX certificate in the form of a
  281|       |         //    SubjectPublicKeyInfo structure is reused.
  282|      0|         m_raw_public_key = X509::load_key(reader.get_tls_length_value(3));
  283|      0|         break;
  284|      0|      default:
  ------------------
  |  Branch (284:7): [True: 0, False: 1.57k]
  ------------------
  285|      0|         throw TLS_Exception(Alert::InternalError, "Unknown certificate type");
  286|  1.57k|   }
  287|       |
  288|       |   // Extensions are simply tacked at the end of the certificate entry. This
  289|       |   // is a departure from the typical "tag-length-value" in a sense that the
  290|       |   // Extensions deserializer needs the length value of the extensions.
  291|      0|   const auto extensions_length = reader.peek_uint16_t();
  292|      0|   const auto exts_buf = reader.get_fixed<uint8_t>(extensions_length + 2);
  293|      0|   TLS_Data_Reader exts_reader("extensions reader", exts_buf);
  294|      0|   m_extensions.deserialize(exts_reader, side, Handshake_Type::Certificate);
  295|       |
  296|      0|   if(cert_type == Certificate_Type::X509) {
  ------------------
  |  Branch (296:7): [True: 0, False: 0]
  ------------------
  297|       |      // RFC 8446 4.4.2
  298|       |      //    Valid extensions for server certificates at present include the
  299|       |      //    OCSP Status extension [RFC6066] and the SignedCertificateTimestamp
  300|       |      //    extension [RFC6962]; future extensions may be defined for this
  301|       |      //    message as well.
  302|       |      //
  303|       |      // RFC 8446 4.4.2.1
  304|       |      //    A server MAY request that a client present an OCSP response with its
  305|       |      //    certificate by sending an empty "status_request" extension in its
  306|       |      //    CertificateRequest message.
  307|      0|      if(m_extensions.contains_implemented_extensions_other_than({
  ------------------
  |  Branch (307:10): [True: 0, False: 0]
  ------------------
  308|      0|            Extension_Code::CertificateStatusRequest,
  309|       |            // Extension_Code::SignedCertificateTimestamp
  310|      0|         })) {
  311|      0|         throw TLS_Exception(Alert::IllegalParameter, "Certificate Entry contained an extension that is not allowed");
  312|      0|      }
  313|      0|   } else if(m_extensions.contains_implemented_extensions_other_than({})) {
  ------------------
  |  Branch (313:14): [True: 0, False: 0]
  ------------------
  314|      0|      throw TLS_Exception(
  315|      0|         Alert::IllegalParameter,
  316|      0|         "Certificate Entry holding something else than a certificate contained unexpected extensions");
  317|      0|   }
  318|      0|}
_ZN5Botan3TLS14Certificate_13C2ERKNSt3__16vectorIhNS2_9allocatorIhEEEERKNS0_6PolicyENS0_15Connection_SideENS0_16Certificate_TypeE:
  349|  1.62k|      m_side(side) {
  350|  1.62k|   TLS_Data_Reader reader("cert message reader", buf);
  351|       |
  352|  1.62k|   m_request_context = reader.get_range<uint8_t>(1, 0, 255);
  353|       |
  354|       |   // RFC 8446 4.4.2
  355|       |   //    [...] in the case of server authentication, this field SHALL be zero length.
  356|  1.62k|   if(m_side == Connection_Side::Server && !m_request_context.empty()) {
  ------------------
  |  Branch (356:7): [True: 1.62k, False: 4]
  |  Branch (356:44): [True: 4, False: 1.61k]
  ------------------
  357|      4|      throw TLS_Exception(Alert::IllegalParameter, "Server Certificate message must not contain a request context");
  358|      4|   }
  359|       |
  360|  1.62k|   const auto cert_entries_len = reader.get_uint24_t();
  361|       |
  362|  1.62k|   if(reader.remaining_bytes() != cert_entries_len) {
  ------------------
  |  Branch (362:7): [True: 36, False: 1.58k]
  ------------------
  363|     36|      throw TLS_Exception(Alert::DecodeError, "Certificate: Message malformed");
  364|     36|   }
  365|       |
  366|  1.58k|   const size_t max_size = policy.maximum_certificate_chain_size();
  367|  1.58k|   if(max_size > 0 && cert_entries_len > max_size) {
  ------------------
  |  Branch (367:7): [True: 0, False: 1.58k]
  |  Branch (367:23): [True: 0, False: 0]
  ------------------
  368|      0|      throw Decoding_Error("Certificate chain exceeds policy specified maximum size");
  369|      0|   }
  370|       |
  371|  3.16k|   while(reader.has_remaining()) {
  ------------------
  |  Branch (371:10): [True: 1.57k, False: 1.58k]
  ------------------
  372|  1.57k|      m_entries.emplace_back(reader, side, cert_type);
  373|  1.57k|   }
  374|       |
  375|       |   // RFC 8446 4.4.2
  376|       |   //    The server's certificate_list MUST always be non-empty.  A client
  377|       |   //    will send an empty certificate_list if it does not have an
  378|       |   //    appropriate certificate to send in response to the server's
  379|       |   //    authentication request.
  380|  1.58k|   if(m_entries.empty()) {
  ------------------
  |  Branch (380:7): [True: 1, False: 1.58k]
  ------------------
  381|       |      // RFC 8446 4.4.2.4
  382|       |      //    If the server supplies an empty Certificate message, the client MUST
  383|       |      //    abort the handshake with a "decode_error" alert.
  384|      1|      if(m_side == Connection_Side::Server) {
  ------------------
  |  Branch (384:10): [True: 1, False: 0]
  ------------------
  385|      1|         throw TLS_Exception(Alert::DecodeError, "No certificates sent by server");
  386|      1|      }
  387|       |
  388|      0|      return;
  389|      1|   }
  390|       |
  391|  1.58k|   BOTAN_ASSERT_NOMSG(!m_entries.empty());
  ------------------
  |  |   60|  1.58k|   do {                                                                     \
  |  |   61|  1.58k|      if(!(expr))                                                           \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 1.58k]
  |  |  ------------------
  |  |   62|  1.58k|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   63|  1.58k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (63:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  392|       |
  393|       |   // RFC 8446 4.4.2.2
  394|       |   //    The certificate type MUST be X.509v3 [RFC5280], unless explicitly
  395|       |   //    negotiated otherwise (e.g., [RFC7250]).
  396|       |   //
  397|       |   // TLS 1.0 through 1.3 all seem to require that the certificate be
  398|       |   // precisely a v3 certificate. In fact the strict wording would seem
  399|       |   // to require that every certificate in the chain be v3. But often
  400|       |   // the intermediates are outside of the control of the server.
  401|       |   // But, require that the leaf certificate be v3.
  402|  1.58k|   if(cert_type == Certificate_Type::X509 && m_entries.front().certificate().x509_version() != 3) {
  ------------------
  |  Branch (402:7): [True: 0, False: 1.58k]
  |  Branch (402:46): [True: 0, False: 0]
  ------------------
  403|      0|      throw TLS_Exception(Alert::BadCertificate, "The leaf certificate must be v3");
  404|      0|   }
  405|       |
  406|       |   // RFC 8446 4.4.2
  407|       |   //    If the RawPublicKey certificate type was negotiated, then the
  408|       |   //    certificate_list MUST contain no more than one CertificateEntry.
  409|  1.58k|   if(cert_type == Certificate_Type::RawPublicKey && m_entries.size() != 1) {
  ------------------
  |  Branch (409:7): [True: 0, False: 1.58k]
  |  Branch (409:54): [True: 0, False: 0]
  ------------------
  410|      0|      throw TLS_Exception(Alert::IllegalParameter, "Certificate message contained more than one RawPublicKey");
  411|      0|   }
  412|       |
  413|       |   // Validate the provided (certificate) public key against our policy
  414|  1.58k|   auto pubkey = public_key();
  415|  1.58k|   policy.check_peer_key_acceptable(*pubkey);
  416|       |
  417|  1.58k|   if(!policy.allowed_signature_method(pubkey->algo_name())) {
  ------------------
  |  Branch (417:7): [True: 0, False: 1.58k]
  ------------------
  418|      0|      throw TLS_Exception(Alert::HandshakeFailure, "Rejecting " + pubkey->algo_name() + " signature");
  419|      0|   }
  420|  1.58k|}

_ZNK5Botan3TLS22Certificate_Request_134typeEv:
   17|  1.62k|Handshake_Type Certificate_Request_13::type() const {
   18|  1.62k|   return TLS::Handshake_Type::CertificateRequest;
   19|  1.62k|}
_ZN5Botan3TLS22Certificate_Request_13C2ERKNSt3__16vectorIhNS2_9allocatorIhEEEENS0_15Connection_SideE:
   21|  1.63k|Certificate_Request_13::Certificate_Request_13(const std::vector<uint8_t>& buf, const Connection_Side side) {
   22|  1.63k|   TLS_Data_Reader reader("Certificate_Request_13", buf);
   23|       |
   24|       |   // RFC 8446 4.3.2
   25|       |   //    A server which is authenticating with a certificate MAY optionally
   26|       |   //    request a certificate from the client.
   27|  1.63k|   if(side != Connection_Side::Server) {
  ------------------
  |  Branch (27:7): [True: 0, False: 1.63k]
  ------------------
   28|      0|      throw TLS_Exception(Alert::UnexpectedMessage, "Received a Certificate_Request message from a client");
   29|      0|   }
   30|       |
   31|  1.63k|   m_context = reader.get_tls_length_value(1);
   32|  1.63k|   m_extensions.deserialize(reader, side, type());
   33|       |
   34|       |   // RFC 8446 4.3.2
   35|       |   //    The "signature_algorithms" extension MUST be specified, and other
   36|       |   //    extensions may optionally be included if defined for this message.
   37|       |   //    Clients MUST ignore unrecognized extensions.
   38|       |
   39|  1.63k|   if(!m_extensions.has<Signature_Algorithms>()) {
  ------------------
  |  Branch (39:7): [True: 79, False: 1.55k]
  ------------------
   40|     79|      throw TLS_Exception(Alert::MissingExtension,
   41|     79|                          "Certificate_Request message did not provide a signature_algorithms extension");
   42|     79|   }
   43|       |
   44|       |   // RFC 8446 4.2.
   45|       |   //    The table below indicates the messages where a given extension may
   46|       |   //    appear [...].  If an implementation receives an extension which it
   47|       |   //    recognizes and which is not specified for the message in which it
   48|       |   //    appears, it MUST abort the handshake with an "illegal_parameter" alert.
   49|       |   //
   50|       |   // For Certificate Request said table states:
   51|       |   //    "status_request", "signature_algorithms", "signed_certificate_timestamp",
   52|       |   //     "certificate_authorities", "oid_filters", "signature_algorithms_cert",
   53|  1.55k|   std::set<Extension_Code> allowed_extensions = {
   54|  1.55k|      Extension_Code::CertificateStatusRequest,
   55|  1.55k|      Extension_Code::SignatureAlgorithms,
   56|       |      // Extension_Code::SignedCertificateTimestamp,  // NYI
   57|  1.55k|      Extension_Code::CertificateAuthorities,
   58|       |      // Extension_Code::OidFilters,                   // NYI
   59|  1.55k|      Extension_Code::CertSignatureAlgorithms,
   60|  1.55k|   };
   61|       |
   62|  1.55k|   if(m_extensions.contains_implemented_extensions_other_than(allowed_extensions)) {
  ------------------
  |  Branch (62:7): [True: 7, False: 1.55k]
  ------------------
   63|      7|      throw TLS_Exception(Alert::IllegalParameter, "Certificate Request contained an extension that is not allowed");
   64|      7|   }
   65|  1.55k|}

_ZN5Botan3TLS20Encrypted_ExtensionsC2ERKNSt3__16vectorIhNS2_9allocatorIhEEEE:
   92|  8.66k|Encrypted_Extensions::Encrypted_Extensions(const std::vector<uint8_t>& buf) {
   93|  8.66k|   TLS_Data_Reader reader("encrypted extensions reader", buf);
   94|       |
   95|       |   // Encrypted Extensions contains a list of extensions. This list may legally
   96|       |   // be empty. However, in that case we should at least see a two-byte length
   97|       |   // field that reads 0x00 0x00.
   98|  8.66k|   if(buf.size() < 2) {
  ------------------
  |  Branch (98:7): [True: 10, False: 8.65k]
  ------------------
   99|     10|      throw TLS_Exception(Alert::DecodeError, "Server sent an empty Encrypted Extensions message");
  100|     10|   }
  101|       |
  102|  8.65k|   m_extensions.deserialize(reader, Connection_Side::Server, type());
  103|       |
  104|       |   // RFC 8446 4.2
  105|       |   //    If an implementation receives an extension which it recognizes and
  106|       |   //    which is not specified for the message in which it appears, it MUST
  107|       |   //    abort the handshake with an "illegal_parameter" alert.
  108|       |   //
  109|       |   // Note that we cannot encounter any extensions that we don't recognize here,
  110|       |   // since only extensions we previously offered are allowed in EE.
  111|  8.65k|   const auto allowed_exts = std::set<Extension_Code>{
  112|       |      // Allowed extensions listed in RFC 8446 and implemented in Botan
  113|  8.65k|      Extension_Code::ServerNameIndication,
  114|       |      // MAX_FRAGMENT_LENGTH
  115|  8.65k|      Extension_Code::SupportedGroups,
  116|  8.65k|      Extension_Code::UseSrtp,
  117|       |      // HEARTBEAT
  118|  8.65k|      Extension_Code::ApplicationLayerProtocolNegotiation,
  119|       |      // RFC 7250
  120|  8.65k|      Extension_Code::ClientCertificateType,
  121|  8.65k|      Extension_Code::ServerCertificateType,
  122|       |      // EARLY_DATA
  123|       |
  124|       |      // Allowed extensions not listed in RFC 8446 but acceptable as Botan implements them
  125|  8.65k|      Extension_Code::RecordSizeLimit,
  126|  8.65k|   };
  127|  8.65k|   if(m_extensions.contains_implemented_extensions_other_than(allowed_exts)) {
  ------------------
  |  Branch (127:7): [True: 296, False: 8.36k]
  ------------------
  128|    296|      throw TLS_Exception(Alert::IllegalParameter, "Encrypted Extensions contained an extension that is not allowed");
  129|    296|   }
  130|  8.65k|}

_ZN5Botan3TLS9Key_ShareC2ERNS0_15TLS_Data_ReaderEtNS0_14Handshake_TypeE:
  411|  2.63k|Key_Share::Key_Share(TLS_Data_Reader& reader, uint16_t extension_size, Handshake_Type message_type) {
  412|  2.63k|   if(message_type == Handshake_Type::ClientHello) {
  ------------------
  |  Branch (412:7): [True: 1.44k, False: 1.18k]
  ------------------
  413|  1.44k|      m_impl = std::make_unique<Key_Share_Impl>(Key_Share_ClientHello(reader, extension_size));
  414|  1.44k|   } else if(message_type == Handshake_Type::HelloRetryRequest)  // Connection_Side::Server
  ------------------
  |  Branch (414:14): [True: 0, False: 1.18k]
  ------------------
  415|      0|   {
  416|      0|      m_impl = std::make_unique<Key_Share_Impl>(Key_Share_HelloRetryRequest(reader, extension_size));
  417|  1.18k|   } else if(message_type == Handshake_Type::ServerHello)  // Connection_Side::Server
  ------------------
  |  Branch (417:14): [True: 1.18k, False: 5]
  ------------------
  418|  1.18k|   {
  419|  1.18k|      m_impl = std::make_unique<Key_Share_Impl>(Key_Share_ServerHello(reader, extension_size));
  420|  1.18k|   } else {
  421|      5|      throw Invalid_Argument(std::string("cannot create a Key_Share extension for message of type: ") +
  422|      5|                             handshake_type_to_string(message_type));
  423|      5|   }
  424|  2.63k|}
_ZN5Botan3TLS9Key_ShareD2Ev:
  443|  2.53k|Key_Share::~Key_Share() = default;
_ZNK5Botan3TLS9Key_Share14offered_groupsEv:
  476|    478|std::vector<Named_Group> Key_Share::offered_groups() const {
  477|    478|   return std::visit([](const auto& keyshare) { return keyshare.offered_groups(); }, m_impl->key_share);
  478|    478|}
tls_extensions_key_share.cpp:_ZN5Botan3TLS12_GLOBAL__N_121Key_Share_ClientHelloC2ERNS0_15TLS_Data_ReaderEt:
  185|  1.44k|      Key_Share_ClientHello(TLS_Data_Reader& reader, uint16_t /* extension_size */) {
  186|       |         // This construction is a crutch to make working with the incoming
  187|       |         // TLS_Data_Reader bearable. Currently, this reader spans the entire
  188|       |         // Client_Hello message. Hence, if offset or length fields are skewed
  189|       |         // or maliciously fabricated, it is possible to read further than the
  190|       |         // bounds of the current extension.
  191|       |         // Note that this aplies to many locations in the code base.
  192|       |         //
  193|       |         // TODO: Overhaul the TLS_Data_Reader to allow for cheap "sub-readers"
  194|       |         //       that enforce read bounds of sub-structures while parsing.
  195|  1.44k|         const auto client_key_share_length = reader.get_uint16_t();
  196|  1.44k|         const auto read_bytes_so_far_begin = reader.read_so_far();
  197|  1.44k|         auto remaining = [&] {
  198|  1.44k|            const auto read_so_far = reader.read_so_far() - read_bytes_so_far_begin;
  199|  1.44k|            BOTAN_STATE_CHECK(read_so_far <= client_key_share_length);
  200|  1.44k|            return client_key_share_length - read_so_far;
  201|  1.44k|         };
  202|       |
  203|  4.55k|         while(reader.has_remaining() && remaining() > 0) {
  ------------------
  |  Branch (203:16): [True: 3.13k, False: 1.42k]
  |  Branch (203:42): [True: 3.11k, False: 19]
  ------------------
  204|  3.11k|            if(remaining() < 4) {
  ------------------
  |  Branch (204:16): [True: 3, False: 3.11k]
  ------------------
  205|      3|               throw TLS_Exception(Alert::DecodeError, "Not enough data to read another KeyShareEntry");
  206|      3|            }
  207|       |
  208|  3.11k|            Key_Share_Entry new_entry(reader);
  209|       |
  210|       |            // RFC 8446 4.2.8
  211|       |            //    Clients MUST NOT offer multiple KeyShareEntry values for the same
  212|       |            //    group. [...]
  213|       |            //    Servers MAY check for violations of these rules and abort the
  214|       |            //    handshake with an "illegal_parameter" alert if one is violated.
  215|  3.11k|            if(std::find_if(m_client_shares.begin(), m_client_shares.end(), [&](const auto& entry) {
  ------------------
  |  Branch (215:16): [True: 7, False: 3.10k]
  ------------------
  216|  3.11k|                  return entry.group() == new_entry.group();
  217|  3.11k|               }) != m_client_shares.end()) {
  218|      7|               throw TLS_Exception(Alert::IllegalParameter, "Received multiple key share entries for the same group");
  219|      7|            }
  220|       |
  221|  3.10k|            m_client_shares.emplace_back(std::move(new_entry));
  222|  3.10k|         }
  223|       |
  224|  1.43k|         if((reader.read_so_far() - read_bytes_so_far_begin) != client_key_share_length) {
  ------------------
  |  Branch (224:13): [True: 11, False: 1.42k]
  ------------------
  225|     11|            throw Decoding_Error("Read bytes are not equal client KeyShare length");
  226|     11|         }
  227|  1.43k|      }
tls_extensions_key_share.cpp:_ZZN5Botan3TLS12_GLOBAL__N_121Key_Share_ClientHelloC1ERNS0_15TLS_Data_ReaderEtENKUlvE_clEv:
  197|  6.25k|         auto remaining = [&] {
  198|  6.25k|            const auto read_so_far = reader.read_so_far() - read_bytes_so_far_begin;
  199|  6.25k|            BOTAN_STATE_CHECK(read_so_far <= client_key_share_length);
  ------------------
  |  |   42|  6.25k|   do {                                                         \
  |  |   43|  6.25k|      if(!(expr))                                               \
  |  |  ------------------
  |  |  |  Branch (43:10): [True: 14, False: 6.23k]
  |  |  ------------------
  |  |   44|  6.25k|         Botan::throw_invalid_state(#expr, __func__, __FILE__); \
  |  |   45|  6.25k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (45:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  200|  6.25k|            return client_key_share_length - read_so_far;
  201|  6.25k|         };
tls_extensions_key_share.cpp:_ZN5Botan3TLS12_GLOBAL__N_115Key_Share_EntryC2ERNS0_15TLS_Data_ReaderE:
   39|  4.29k|      Key_Share_Entry(TLS_Data_Reader& reader) {
   40|       |         // TODO check that the group actually exists before casting...
   41|  4.29k|         m_group = static_cast<Named_Group>(reader.get_uint16_t());
   42|  4.29k|         m_key_exchange = reader.get_tls_length_value(2);
   43|  4.29k|      }
tls_extensions_key_share.cpp:_ZZN5Botan3TLS12_GLOBAL__N_121Key_Share_ClientHelloC1ERNS0_15TLS_Data_ReaderEtENKUlRKT_E_clINS1_15Key_Share_EntryEEEDaS7_:
  215|  10.5k|            if(std::find_if(m_client_shares.begin(), m_client_shares.end(), [&](const auto& entry) {
  216|  10.5k|                  return entry.group() == new_entry.group();
  217|  10.5k|               }) != m_client_shares.end()) {
tls_extensions_key_share.cpp:_ZNK5Botan3TLS12_GLOBAL__N_115Key_Share_Entry5groupEv:
   96|  22.0k|      Named_Group group() const { return m_group; }
tls_extensions_key_share.cpp:_ZN5Botan3TLS12_GLOBAL__N_121Key_Share_ClientHelloD2Ev:
  252|  4.06k|      ~Key_Share_ClientHello() = default;
tls_extensions_key_share.cpp:_ZN5Botan3TLS12_GLOBAL__N_121Key_Share_ServerHelloC2ERNS0_15TLS_Data_ReaderEt:
  145|  1.18k|      Key_Share_ServerHello(TLS_Data_Reader& reader, uint16_t) : m_server_share(reader) {}
tls_extensions_key_share.cpp:_ZN5Botan3TLS12_GLOBAL__N_121Key_Share_ServerHelloD2Ev:
  153|  3.54k|      ~Key_Share_ServerHello() = default;
tls_extensions_key_share.cpp:_ZZNK5Botan3TLS9Key_Share14offered_groupsEvENK3$_4clINS0_12_GLOBAL__N_121Key_Share_ClientHelloEEEDaRKT_:
  477|    478|   return std::visit([](const auto& keyshare) { return keyshare.offered_groups(); }, m_impl->key_share);
tls_extensions_key_share.cpp:_ZNK5Botan3TLS12_GLOBAL__N_121Key_Share_ClientHello14offered_groupsEv:
  274|    478|      std::vector<Named_Group> offered_groups() const {
  275|    478|         std::vector<Named_Group> offered_groups;
  276|    478|         offered_groups.reserve(m_client_shares.size());
  277|    921|         for(const auto& share : m_client_shares) {
  ------------------
  |  Branch (277:32): [True: 921, False: 478]
  ------------------
  278|    921|            offered_groups.push_back(share.group());
  279|    921|         }
  280|    478|         return offered_groups;
  281|    478|      }
tls_extensions_key_share.cpp:_ZN5Botan3TLS12_GLOBAL__N_121Key_Share_ClientHelloC2EOS2_:
  257|  2.71k|      Key_Share_ClientHello(Key_Share_ClientHello&&) = default;
tls_extensions_key_share.cpp:_ZN5Botan3TLS9Key_Share14Key_Share_ImplC2ENSt3__17variantIJNS0_12_GLOBAL__N_121Key_Share_ClientHelloENS5_21Key_Share_ServerHelloENS5_27Key_Share_HelloRetryRequestEEEE:
  405|  2.53k|      Key_Share_Impl(Key_Share_Type ks) : key_share(std::move(ks)) {}
tls_extensions_key_share.cpp:_ZN5Botan3TLS12_GLOBAL__N_121Key_Share_ServerHelloC2EOS2_:
  158|  2.36k|      Key_Share_ServerHello(Key_Share_ServerHello&&) = default;

_ZN5Botan3TLS3PSKC2ERNS0_15TLS_Data_ReaderEtNS0_14Handshake_TypeE:
  141|    888|PSK::PSK(TLS_Data_Reader& reader, uint16_t extension_size, Handshake_Type message_type) {
  142|    888|   if(message_type == Handshake_Type::ServerHello) {
  ------------------
  |  Branch (142:7): [True: 438, False: 450]
  ------------------
  143|    438|      if(extension_size != 2) {
  ------------------
  |  Branch (143:10): [True: 10, False: 428]
  ------------------
  144|     10|         throw TLS_Exception(Alert::DecodeError, "Server provided a malformed PSK extension");
  145|     10|      }
  146|       |
  147|    428|      const uint16_t selected_id = reader.get_uint16_t();
  148|    428|      m_impl = std::make_unique<PSK_Internal>(Server_PSK(selected_id));
  149|    450|   } else if(message_type == Handshake_Type::ClientHello) {
  ------------------
  |  Branch (149:14): [True: 444, False: 6]
  ------------------
  150|    444|      const auto identities_length = reader.get_uint16_t();
  151|    444|      const auto identities_offset = reader.read_so_far();
  152|       |
  153|    444|      std::vector<PskIdentity> psk_identities;
  154|  3.93k|      while(reader.has_remaining() && (reader.read_so_far() - identities_offset) < identities_length) {
  ------------------
  |  Branch (154:13): [True: 3.87k, False: 57]
  |  Branch (154:39): [True: 3.49k, False: 387]
  ------------------
  155|  3.49k|         auto identity = reader.get_tls_length_value(2);
  156|  3.49k|         const auto obfuscated_ticket_age = reader.get_uint32_t();
  157|  3.49k|         psk_identities.emplace_back(std::move(identity), obfuscated_ticket_age);
  158|  3.49k|      }
  159|       |
  160|    444|      if(psk_identities.empty()) {
  ------------------
  |  Branch (160:10): [True: 2, False: 442]
  ------------------
  161|      2|         throw TLS_Exception(Alert::DecodeError, "Empty PSK list");
  162|      2|      }
  163|       |
  164|    442|      if(reader.read_so_far() - identities_offset != identities_length) {
  ------------------
  |  Branch (164:10): [True: 37, False: 405]
  ------------------
  165|     37|         throw TLS_Exception(Alert::DecodeError, "Inconsistent PSK identity list");
  166|     37|      }
  167|       |
  168|    405|      const auto binders_length = reader.get_uint16_t();
  169|    405|      const auto binders_offset = reader.read_so_far();
  170|       |
  171|    405|      if(binders_length == 0) {
  ------------------
  |  Branch (171:10): [True: 1, False: 404]
  ------------------
  172|      1|         throw TLS_Exception(Alert::DecodeError, "Empty PSK binders list");
  173|      1|      }
  174|       |
  175|    404|      std::vector<Client_PSK> psks;
  176|  2.01k|      for(auto& psk_identity : psk_identities) {
  ------------------
  |  Branch (176:30): [True: 2.01k, False: 390]
  ------------------
  177|  2.01k|         if(!reader.has_remaining() || reader.read_so_far() - binders_offset >= binders_length) {
  ------------------
  |  Branch (177:13): [True: 3, False: 2.00k]
  |  Branch (177:40): [True: 11, False: 1.99k]
  ------------------
  178|     14|            throw TLS_Exception(Alert::IllegalParameter, "Not enough PSK binders");
  179|     14|         }
  180|       |
  181|  1.99k|         psks.emplace_back(std::move(psk_identity), reader.get_tls_length_value(1));
  182|  1.99k|      }
  183|       |
  184|    390|      if(reader.read_so_far() - binders_offset != binders_length) {
  ------------------
  |  Branch (184:10): [True: 40, False: 350]
  ------------------
  185|     40|         throw TLS_Exception(Alert::IllegalParameter, "Too many PSK binders");
  186|     40|      }
  187|       |
  188|    350|      m_impl = std::make_unique<PSK_Internal>(std::move(psks));
  189|    350|   } else {
  190|      6|      throw TLS_Exception(Alert::DecodeError, "Found a PSK extension in an unexpected handshake message");
  191|      6|   }
  192|    888|}
_ZN5Botan3TLS3PSKD2Ev:
  214|    733|PSK::~PSK() = default;
tls_extensions_psk.cpp:_ZN5Botan3TLS12_GLOBAL__N_110Server_PSKC2Et:
  108|    428|      Server_PSK(uint16_t id) : m_selected_identity(id), m_session_to_resume_or_psk(std::monostate()) {}
tls_extensions_psk.cpp:_ZN5Botan3TLS3PSK12PSK_InternalC2ENS0_12_GLOBAL__N_110Server_PSKE:
  133|    428|      PSK_Internal(Server_PSK srv_psk) : psk(std::move(srv_psk)) {}
tls_extensions_psk.cpp:_ZN5Botan3TLS12_GLOBAL__N_110Client_PSKC2ENS0_11PskIdentityENSt3__16vectorIhNS4_9allocatorIhEEEE:
   55|  1.99k|            m_identity(std::move(id)), m_binder(std::move(bndr)), m_is_resumption(false) {}
tls_extensions_psk.cpp:_ZN5Botan3TLS3PSK12PSK_InternalC2ENSt3__16vectorINS0_12_GLOBAL__N_110Client_PSKENS3_9allocatorIS6_EEEE:
  135|    305|      PSK_Internal(std::vector<Client_PSK> clt_psks) : psk(std::move(clt_psks)) {}

_ZN5Botan3TLS15Handshake_Layer9copy_dataENSt3__14spanIKhLm18446744073709551615EEE:
   19|  7.09k|void Handshake_Layer::copy_data(std::span<const uint8_t> data_from_peer) {
   20|  7.09k|   m_read_buffer.insert(m_read_buffer.end(), data_from_peer.begin(), data_from_peer.end());
   21|  7.09k|}
_ZN5Botan3TLS15Handshake_Layer12next_messageERKNS0_6PolicyERNS0_21Transcript_Hash_StateE:
  120|  35.4k|                                                                  Transcript_Hash_State& transcript_hash) {
  121|  35.4k|   TLS::TLS_Data_Reader reader("handshake message", m_read_buffer);
  122|       |
  123|  35.4k|   auto msg = parse_message<Handshake_Message_13>(reader, policy, m_peer, m_certificate_type);
  124|  35.4k|   if(msg.has_value()) {
  ------------------
  |  Branch (124:7): [True: 29.9k, False: 5.51k]
  ------------------
  125|  29.9k|      BOTAN_ASSERT_NOMSG(m_read_buffer.size() >= reader.read_so_far());
  ------------------
  |  |   60|  29.9k|   do {                                                                     \
  |  |   61|  29.9k|      if(!(expr))                                                           \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 29.9k]
  |  |  ------------------
  |  |   62|  29.9k|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   63|  29.9k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (63:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  126|  29.9k|      transcript_hash.update(std::span{m_read_buffer.data(), reader.read_so_far()});
  127|  29.9k|      m_read_buffer.erase(m_read_buffer.cbegin(), m_read_buffer.cbegin() + reader.read_so_far());
  128|  29.9k|   }
  129|       |
  130|  35.4k|   return msg;
  131|  35.4k|}
_ZN5Botan3TLS15Handshake_Layer27next_post_handshake_messageERKNS0_6PolicyE:
  133|  1.51k|std::optional<Post_Handshake_Message_13> Handshake_Layer::next_post_handshake_message(const Policy& policy) {
  134|  1.51k|   TLS::TLS_Data_Reader reader("post handshake message", m_read_buffer);
  135|       |
  136|  1.51k|   auto msg = parse_message<Post_Handshake_Message_13>(reader, policy, m_peer, m_certificate_type);
  137|  1.51k|   if(msg.has_value()) {
  ------------------
  |  Branch (137:7): [True: 0, False: 1.51k]
  ------------------
  138|      0|      m_read_buffer.erase(m_read_buffer.cbegin(), m_read_buffer.cbegin() + reader.read_so_far());
  139|      0|   }
  140|       |
  141|  1.51k|   return msg;
  142|  1.51k|}
tls_handshake_layer_13.cpp:_ZN5Botan3TLS12_GLOBAL__N_113parse_messageINSt3__17variantIJNS0_15Client_Hello_13ENS0_15Client_Hello_12ENS0_15Server_Hello_13ENS0_15Server_Hello_12ENS0_19Hello_Retry_RequestENS0_20Encrypted_ExtensionsENS0_14Certificate_13ENS0_22Certificate_Request_13ENS0_21Certificate_Verify_13ENS0_11Finished_13EEEEEENS3_8optionalIT_EERNS0_15TLS_Data_ReaderERKNS0_6PolicyENS0_15Connection_SideENS0_16Certificate_TypeE:
   61|  35.4k|                                      const Certificate_Type cert_type) {
   62|       |   // read the message header
   63|  35.4k|   if(reader.remaining_bytes() < HEADER_LENGTH) {
  ------------------
  |  Branch (63:7): [True: 1.44k, False: 34.0k]
  ------------------
   64|  1.44k|      return std::nullopt;
   65|  1.44k|   }
   66|       |
   67|  34.0k|   Handshake_Type type = handshake_type_from_byte<Msg_Type>(reader.get_byte());
   68|       |
   69|       |   // make sure we have received the full message
   70|  34.0k|   const size_t msg_len = reader.get_uint24_t();
   71|  34.0k|   if(reader.remaining_bytes() < msg_len) {
  ------------------
  |  Branch (71:7): [True: 68, False: 33.9k]
  ------------------
   72|     68|      return std::nullopt;
   73|     68|   }
   74|       |
   75|       |   // create the message
   76|  33.9k|   const auto msg = reader.get_fixed<uint8_t>(msg_len);
   77|  33.9k|   if constexpr(std::is_same_v<Msg_Type, Handshake_Message_13>) {
  ------------------
  |  Branch (77:17): [Folded - Ignored]
  ------------------
   78|  33.9k|      switch(type) {
   79|       |         // Client Hello and Server Hello messages are ambiguous. Both may come
   80|       |         // from non-TLS 1.3 peers. Hence, their parsing is somewhat different.
   81|  8.47k|         case Handshake_Type::ClientHello:
  ------------------
  |  Branch (81:10): [True: 8.47k, False: 25.4k]
  ------------------
   82|       |            // ... might be TLS 1.2 Client Hello or TLS 1.3 Client Hello
   83|  8.47k|            return generalize_to<Handshake_Message_13>(Client_Hello_13::parse(msg));
   84|  6.36k|         case Handshake_Type::ServerHello:
  ------------------
  |  Branch (84:10): [True: 6.36k, False: 27.5k]
  ------------------
   85|       |            // ... might be TLS 1.2 Server Hello or TLS 1.3 Server Hello or
   86|       |            // a TLS 1.3 Hello Retry Request disguising as a Server Hello
   87|  6.36k|            return generalize_to<Handshake_Message_13>(Server_Hello_13::parse(msg));
   88|       |         // case Handshake_Type::EndOfEarlyData:
   89|       |         //    return End_Of_Early_Data(msg);
   90|  8.66k|         case Handshake_Type::EncryptedExtensions:
  ------------------
  |  Branch (90:10): [True: 8.66k, False: 25.2k]
  ------------------
   91|  8.66k|            return Encrypted_Extensions(msg);
   92|  1.62k|         case Handshake_Type::Certificate:
  ------------------
  |  Branch (92:10): [True: 1.62k, False: 32.3k]
  ------------------
   93|  1.62k|            return Certificate_13(msg, policy, peer_side, cert_type);
   94|  1.63k|         case Handshake_Type::CertificateRequest:
  ------------------
  |  Branch (94:10): [True: 1.63k, False: 32.3k]
  ------------------
   95|  1.63k|            return Certificate_Request_13(msg, peer_side);
   96|  1.72k|         case Handshake_Type::CertificateVerify:
  ------------------
  |  Branch (96:10): [True: 1.72k, False: 32.2k]
  ------------------
   97|  1.72k|            return Certificate_Verify_13(msg, peer_side);
   98|  5.45k|         case Handshake_Type::Finished:
  ------------------
  |  Branch (98:10): [True: 5.45k, False: 28.5k]
  ------------------
   99|  5.45k|            return Finished_13(msg);
  100|      0|         default:
  ------------------
  |  Branch (100:10): [True: 0, False: 33.9k]
  ------------------
  101|      0|            BOTAN_ASSERT(false, "cannot be reached");  // make sure to update handshake_type_from_byte
  ------------------
  |  |   51|      0|   do {                                                                                 \
  |  |   52|      0|      if(!(expr))                                                                       \
  |  |  ------------------
  |  |  |  Branch (52:10): [Folded - Ignored]
  |  |  ------------------
  |  |   53|      0|         Botan::assertion_failure(#expr, assertion_made, __func__, __FILE__, __LINE__); \
  |  |   54|      0|   } while(0)
  |  |  ------------------
  |  |  |  Branch (54:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  102|  33.9k|      }
  103|  33.9k|   } else {
  104|  33.9k|      BOTAN_UNUSED(peer_side);
  105|       |
  106|  33.9k|      switch(type) {
  107|  33.9k|         case Handshake_Type::NewSessionTicket:
  108|  33.9k|            return New_Session_Ticket_13(msg, peer_side);
  109|  33.9k|         case Handshake_Type::KeyUpdate:
  110|  33.9k|            return Key_Update(msg);
  111|  33.9k|         default:
  112|  33.9k|            BOTAN_ASSERT(false, "cannot be reached");  // make sure to update handshake_type_from_byte
  113|  33.9k|      }
  114|  33.9k|   }
  115|  33.9k|}
tls_handshake_layer_13.cpp:_ZN5Botan3TLS12_GLOBAL__N_124handshake_type_from_byteINSt3__17variantIJNS0_15Client_Hello_13ENS0_15Client_Hello_12ENS0_15Server_Hello_13ENS0_15Server_Hello_12ENS0_19Hello_Retry_RequestENS0_20Encrypted_ExtensionsENS0_14Certificate_13ENS0_22Certificate_Request_13ENS0_21Certificate_Verify_13ENS0_11Finished_13EEEEEENS0_14Handshake_TypeEh:
   28|  34.0k|Handshake_Type handshake_type_from_byte(uint8_t byte_value) {
   29|  34.0k|   const auto type = static_cast<Handshake_Type>(byte_value);
   30|       |
   31|  34.0k|   if constexpr(std::is_same_v<Msg_Type, Handshake_Message_13>) {
  ------------------
  |  Branch (31:17): [Folded - Ignored]
  ------------------
   32|  34.0k|      switch(type) {
   33|  8.50k|         case Handshake_Type::ClientHello:
  ------------------
  |  Branch (33:10): [True: 8.50k, False: 25.5k]
  ------------------
   34|  14.8k|         case Handshake_Type::ServerHello:
  ------------------
  |  Branch (34:10): [True: 6.38k, False: 27.6k]
  ------------------
   35|       |         // case Handshake_Type::EndOfEarlyData:  // NYI: needs PSK/resumption support -- won't be offered in Client Hello for now
   36|  23.5k|         case Handshake_Type::EncryptedExtensions:
  ------------------
  |  Branch (36:10): [True: 8.67k, False: 25.3k]
  ------------------
   37|  25.1k|         case Handshake_Type::Certificate:
  ------------------
  |  Branch (37:10): [True: 1.63k, False: 32.4k]
  ------------------
   38|  26.8k|         case Handshake_Type::CertificateRequest:
  ------------------
  |  Branch (38:10): [True: 1.63k, False: 32.4k]
  ------------------
   39|  28.5k|         case Handshake_Type::CertificateVerify:
  ------------------
  |  Branch (39:10): [True: 1.73k, False: 32.3k]
  ------------------
   40|  34.0k|         case Handshake_Type::Finished:
  ------------------
  |  Branch (40:10): [True: 5.46k, False: 28.5k]
  ------------------
   41|  34.0k|            return type;
   42|     21|         default:
  ------------------
  |  Branch (42:10): [True: 21, False: 34.0k]
  ------------------
   43|     21|            throw TLS_Exception(AlertType::UnexpectedMessage, "Unknown handshake message received");
   44|  34.0k|      }
   45|  34.0k|   } else {
   46|  34.0k|      switch(type) {
   47|  34.0k|         case Handshake_Type::NewSessionTicket:
   48|  34.0k|         case Handshake_Type::KeyUpdate:
   49|       |            // case Handshake_Type::CertificateRequest:  // NYI: post-handshake client auth (RFC 8446 4.6.2) -- won't be offered in Client Hello for now
   50|  34.0k|            return type;
   51|  34.0k|         default:
   52|  34.0k|            throw TLS_Exception(AlertType::UnexpectedMessage, "Unknown post-handshake message received");
   53|  34.0k|      }
   54|  34.0k|   }
   55|  34.0k|}
tls_handshake_layer_13.cpp:_ZN5Botan3TLS12_GLOBAL__N_113parse_messageINSt3__17variantIJNS0_21New_Session_Ticket_13ENS0_10Key_UpdateEEEEEENS3_8optionalIT_EERNS0_15TLS_Data_ReaderERKNS0_6PolicyENS0_15Connection_SideENS0_16Certificate_TypeE:
   61|  1.51k|                                      const Certificate_Type cert_type) {
   62|       |   // read the message header
   63|  1.51k|   if(reader.remaining_bytes() < HEADER_LENGTH) {
  ------------------
  |  Branch (63:7): [True: 3, False: 1.51k]
  ------------------
   64|      3|      return std::nullopt;
   65|      3|   }
   66|       |
   67|  1.51k|   Handshake_Type type = handshake_type_from_byte<Msg_Type>(reader.get_byte());
   68|       |
   69|       |   // make sure we have received the full message
   70|  1.51k|   const size_t msg_len = reader.get_uint24_t();
   71|  1.51k|   if(reader.remaining_bytes() < msg_len) {
  ------------------
  |  Branch (71:7): [True: 0, False: 1.51k]
  ------------------
   72|      0|      return std::nullopt;
   73|      0|   }
   74|       |
   75|       |   // create the message
   76|  1.51k|   const auto msg = reader.get_fixed<uint8_t>(msg_len);
   77|  1.51k|   if constexpr(std::is_same_v<Msg_Type, Handshake_Message_13>) {
  ------------------
  |  Branch (77:17): [Folded - Ignored]
  ------------------
   78|  1.51k|      switch(type) {
   79|       |         // Client Hello and Server Hello messages are ambiguous. Both may come
   80|       |         // from non-TLS 1.3 peers. Hence, their parsing is somewhat different.
   81|  1.51k|         case Handshake_Type::ClientHello:
   82|       |            // ... might be TLS 1.2 Client Hello or TLS 1.3 Client Hello
   83|  1.51k|            return generalize_to<Handshake_Message_13>(Client_Hello_13::parse(msg));
   84|  1.51k|         case Handshake_Type::ServerHello:
   85|       |            // ... might be TLS 1.2 Server Hello or TLS 1.3 Server Hello or
   86|       |            // a TLS 1.3 Hello Retry Request disguising as a Server Hello
   87|  1.51k|            return generalize_to<Handshake_Message_13>(Server_Hello_13::parse(msg));
   88|       |         // case Handshake_Type::EndOfEarlyData:
   89|       |         //    return End_Of_Early_Data(msg);
   90|  1.51k|         case Handshake_Type::EncryptedExtensions:
   91|  1.51k|            return Encrypted_Extensions(msg);
   92|  1.51k|         case Handshake_Type::Certificate:
   93|  1.51k|            return Certificate_13(msg, policy, peer_side, cert_type);
   94|  1.51k|         case Handshake_Type::CertificateRequest:
   95|  1.51k|            return Certificate_Request_13(msg, peer_side);
   96|  1.51k|         case Handshake_Type::CertificateVerify:
   97|  1.51k|            return Certificate_Verify_13(msg, peer_side);
   98|  1.51k|         case Handshake_Type::Finished:
   99|  1.51k|            return Finished_13(msg);
  100|  1.51k|         default:
  101|  1.51k|            BOTAN_ASSERT(false, "cannot be reached");  // make sure to update handshake_type_from_byte
  102|  1.51k|      }
  103|  1.51k|   } else {
  104|  1.51k|      BOTAN_UNUSED(peer_side);
  ------------------
  |  |  118|  1.51k|#define BOTAN_UNUSED Botan::ignore_params
  ------------------
  105|       |
  106|  1.51k|      switch(type) {
  107|      0|         case Handshake_Type::NewSessionTicket:
  ------------------
  |  Branch (107:10): [True: 0, False: 1.51k]
  ------------------
  108|      0|            return New_Session_Ticket_13(msg, peer_side);
  109|      0|         case Handshake_Type::KeyUpdate:
  ------------------
  |  Branch (109:10): [True: 0, False: 1.51k]
  ------------------
  110|      0|            return Key_Update(msg);
  111|      0|         default:
  ------------------
  |  Branch (111:10): [True: 0, False: 1.51k]
  ------------------
  112|      0|            BOTAN_ASSERT(false, "cannot be reached");  // make sure to update handshake_type_from_byte
  ------------------
  |  |   51|      0|   do {                                                                                 \
  |  |   52|      0|      if(!(expr))                                                                       \
  |  |  ------------------
  |  |  |  Branch (52:10): [Folded - Ignored]
  |  |  ------------------
  |  |   53|      0|         Botan::assertion_failure(#expr, assertion_made, __func__, __FILE__, __LINE__); \
  |  |   54|      0|   } while(0)
  |  |  ------------------
  |  |  |  Branch (54:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  113|  1.51k|      }
  114|  1.51k|   }
  115|  1.51k|}
tls_handshake_layer_13.cpp:_ZN5Botan3TLS12_GLOBAL__N_124handshake_type_from_byteINSt3__17variantIJNS0_21New_Session_Ticket_13ENS0_10Key_UpdateEEEEEENS0_14Handshake_TypeEh:
   28|  1.51k|Handshake_Type handshake_type_from_byte(uint8_t byte_value) {
   29|  1.51k|   const auto type = static_cast<Handshake_Type>(byte_value);
   30|       |
   31|  1.51k|   if constexpr(std::is_same_v<Msg_Type, Handshake_Message_13>) {
  ------------------
  |  Branch (31:17): [Folded - Ignored]
  ------------------
   32|  1.51k|      switch(type) {
   33|  1.51k|         case Handshake_Type::ClientHello:
   34|  1.51k|         case Handshake_Type::ServerHello:
   35|       |         // case Handshake_Type::EndOfEarlyData:  // NYI: needs PSK/resumption support -- won't be offered in Client Hello for now
   36|  1.51k|         case Handshake_Type::EncryptedExtensions:
   37|  1.51k|         case Handshake_Type::Certificate:
   38|  1.51k|         case Handshake_Type::CertificateRequest:
   39|  1.51k|         case Handshake_Type::CertificateVerify:
   40|  1.51k|         case Handshake_Type::Finished:
   41|  1.51k|            return type;
   42|  1.51k|         default:
   43|  1.51k|            throw TLS_Exception(AlertType::UnexpectedMessage, "Unknown handshake message received");
   44|  1.51k|      }
   45|  1.51k|   } else {
   46|  1.51k|      switch(type) {
   47|      0|         case Handshake_Type::NewSessionTicket:
  ------------------
  |  Branch (47:10): [True: 0, False: 1.51k]
  ------------------
   48|      0|         case Handshake_Type::KeyUpdate:
  ------------------
  |  Branch (48:10): [True: 0, False: 1.51k]
  ------------------
   49|       |            // case Handshake_Type::CertificateRequest:  // NYI: post-handshake client auth (RFC 8446 4.6.2) -- won't be offered in Client Hello for now
   50|      0|            return type;
   51|  1.51k|         default:
  ------------------
  |  Branch (51:10): [True: 1.51k, False: 0]
  ------------------
   52|  1.51k|            throw TLS_Exception(AlertType::UnexpectedMessage, "Unknown post-handshake message received");
   53|  1.51k|      }
   54|  1.51k|   }
   55|  1.51k|}

_ZN5Botan3TLS21Transcript_Hash_StateC2ENSt3__117basic_string_viewIcNS2_11char_traitsIcEEEE:
   19|  5.58k|Transcript_Hash_State::Transcript_Hash_State(std::string_view algo_spec) {
   20|  5.58k|   set_algorithm(algo_spec);
   21|  5.58k|}
_ZN5Botan3TLS21Transcript_Hash_State6updateENSt3__14spanIKhLm18446744073709551615EEE:
  147|  29.9k|void Transcript_Hash_State::update(std::span<const uint8_t> serialized_message_s) {
  148|  29.9k|   auto serialized_message = serialized_message_s.data();
  149|  29.9k|   auto serialized_message_length = serialized_message_s.size();
  150|  29.9k|   if(m_hash != nullptr) {
  ------------------
  |  Branch (150:7): [True: 29.9k, False: 0]
  ------------------
  151|  29.9k|      auto truncation_mark = serialized_message_length;
  152|       |
  153|       |      // Check whether we should generate a truncated hash for supporting PSK
  154|       |      // binder calculation or verification. See RFC 8446 4.2.11.2.
  155|  29.9k|      if(serialized_message_length > 0 && *serialized_message == static_cast<uint8_t>(Handshake_Type::ClientHello)) {
  ------------------
  |  Branch (155:10): [True: 29.9k, False: 0]
  |  Branch (155:43): [True: 7.80k, False: 22.1k]
  ------------------
  156|  7.80k|         truncation_mark = find_client_hello_truncation_mark(serialized_message_s);
  157|  7.80k|      }
  158|       |
  159|  29.9k|      if(truncation_mark < serialized_message_length) {
  ------------------
  |  Branch (159:10): [True: 1.02k, False: 28.9k]
  ------------------
  160|  1.02k|         m_hash->update(serialized_message, truncation_mark);
  161|  1.02k|         m_truncated = read_hash_state(m_hash);
  162|  1.02k|         m_hash->update(serialized_message + truncation_mark, serialized_message_length - truncation_mark);
  163|  28.9k|      } else {
  164|  28.9k|         m_truncated.clear();
  165|  28.9k|         m_hash->update(serialized_message, serialized_message_length);
  166|  28.9k|      }
  167|       |
  168|  29.9k|      m_previous = std::exchange(m_current, read_hash_state(m_hash));
  169|  29.9k|   } else {
  170|      0|      m_unprocessed_transcript.push_back(
  171|      0|         std::vector(serialized_message, serialized_message + serialized_message_length));
  172|      0|   }
  173|  29.9k|}
_ZN5Botan3TLS21Transcript_Hash_State13set_algorithmENSt3__117basic_string_viewIcNS2_11char_traitsIcEEEE:
  190|  5.58k|void Transcript_Hash_State::set_algorithm(std::string_view algo_spec) {
  191|  5.58k|   BOTAN_STATE_CHECK(m_hash == nullptr || m_hash->name() == algo_spec);
  ------------------
  |  |   42|  5.58k|   do {                                                         \
  |  |   43|  5.58k|      if(!(expr))                                               \
  |  |  ------------------
  |  |  |  Branch (43:10): [True: 0, False: 5.58k]
  |  |  |  Branch (43:12): [True: 5.58k, False: 0]
  |  |  |  Branch (43:12): [True: 0, False: 0]
  |  |  ------------------
  |  |   44|  5.58k|         Botan::throw_invalid_state(#expr, __func__, __FILE__); \
  |  |   45|  5.58k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (45:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  192|  5.58k|   if(m_hash != nullptr) {
  ------------------
  |  Branch (192:7): [True: 0, False: 5.58k]
  ------------------
  193|      0|      return;
  194|      0|   }
  195|       |
  196|  5.58k|   m_hash = HashFunction::create_or_throw(algo_spec);
  197|  5.58k|   for(const auto& msg : m_unprocessed_transcript) {
  ------------------
  |  Branch (197:24): [True: 0, False: 5.58k]
  ------------------
  198|      0|      update(msg);
  199|      0|   }
  200|  5.58k|   m_unprocessed_transcript.clear();
  201|  5.58k|}
tls_transcript_hash_13.cpp:_ZN5Botan3TLS12_GLOBAL__N_133find_client_hello_truncation_markENSt3__14spanIKhLm18446744073709551615EEE:
   76|  7.80k|size_t find_client_hello_truncation_mark(std::span<const uint8_t> client_hello) {
   77|  7.80k|   TLS_Data_Reader reader("Client Hello Truncation", client_hello);
   78|       |
   79|       |   // handshake message type
   80|  7.80k|   BOTAN_ASSERT_NOMSG(reader.get_byte() == static_cast<uint8_t>(Handshake_Type::ClientHello));
  ------------------
  |  |   60|  7.80k|   do {                                                                     \
  |  |   61|  7.80k|      if(!(expr))                                                           \
  |  |  ------------------
  |  |  |  Branch (61:10): [True: 0, False: 7.80k]
  |  |  ------------------
  |  |   62|  7.80k|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   63|  7.80k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (63:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
   81|       |
   82|       |   // message length
   83|  7.80k|   reader.discard_next(3);
   84|       |
   85|       |   // legacy version
   86|  7.80k|   reader.discard_next(2);
   87|       |
   88|       |   // random
   89|  7.80k|   reader.discard_next(32);
   90|       |
   91|       |   // session ID
   92|  7.80k|   const auto session_id_length = reader.get_byte();
   93|  7.80k|   reader.discard_next(session_id_length);
   94|       |
   95|       |   // TODO: DTLS contains a hello_cookie in this location
   96|       |   //       Currently we don't support DTLS 1.3
   97|       |
   98|       |   // cipher suites
   99|  7.80k|   const auto ciphersuites_length = reader.get_uint16_t();
  100|  7.80k|   reader.discard_next(ciphersuites_length);
  101|       |
  102|       |   // compression methods
  103|  7.80k|   const auto compression_methods_length = reader.get_byte();
  104|  7.80k|   reader.discard_next(compression_methods_length);
  105|       |
  106|       |   // extensions
  107|  7.80k|   const auto extensions_length = reader.get_uint16_t();
  108|  7.80k|   const auto extensions_offset = reader.read_so_far();
  109|  20.3k|   while(reader.has_remaining() && reader.read_so_far() - extensions_offset < extensions_length) {
  ------------------
  |  Branch (109:10): [True: 13.5k, False: 6.76k]
  |  Branch (109:36): [True: 13.4k, False: 53]
  ------------------
  110|  13.4k|      const auto ext_type = static_cast<Extension_Code>(reader.get_uint16_t());
  111|  13.4k|      const auto ext_length = reader.get_uint16_t();
  112|       |
  113|       |      // skip over all extensions, finding the PSK extension to be truncated
  114|  13.4k|      if(ext_type != Extension_Code::PresharedKey) {
  ------------------
  |  Branch (114:10): [True: 12.4k, False: 985]
  ------------------
  115|  12.4k|         reader.discard_next(ext_length);
  116|  12.4k|         continue;
  117|  12.4k|      }
  118|       |
  119|       |      // PSK identities list
  120|    985|      const auto identities_length = reader.get_uint16_t();
  121|    985|      reader.discard_next(identities_length);
  122|       |
  123|       |      // check that only the binders are left in the buffer...
  124|    985|      const auto binders_length = reader.peek_uint16_t();
  125|    985|      if(binders_length != reader.remaining_bytes() - 2 /* binders_length */) {
  ------------------
  |  Branch (125:10): [True: 2, False: 983]
  ------------------
  126|      2|         throw TLS_Exception(Alert::IllegalParameter,
  127|      2|                             "Failed to truncate Client Hello that doesn't end on the PSK binders list");
  128|      2|      }
  129|       |
  130|       |      // the reader now points to the truncation point
  131|    983|      break;
  132|    985|   }
  133|       |
  134|       |   // if no PSK extension was found, this will point to the end of the buffer
  135|  7.80k|   return reader.read_so_far();
  136|  7.80k|}
tls_transcript_hash_13.cpp:_ZN5Botan3TLS12_GLOBAL__N_115read_hash_stateERNSt3__110unique_ptrINS_12HashFunctionENS2_14default_deleteIS4_EEEE:
  138|  30.9k|std::vector<uint8_t> read_hash_state(std::unique_ptr<HashFunction>& hash) {
  139|       |   // Botan does not support finalizing a HashFunction without resetting
  140|       |   // the internal state of the hash. Hence we first copy the internal
  141|       |   // state and then finalize the transient HashFunction.
  142|  30.9k|   return hash->copy_state()->final_stdvec();
  143|  30.9k|}

_ZN5Botan3TLS10Extensions3addENSt3__110unique_ptrINS0_9ExtensionENS2_14default_deleteIS4_EEEE:
  110|  52.4k|void Extensions::add(std::unique_ptr<Extension> extn) {
  111|  52.4k|   if(has(extn->type())) {
  ------------------
  |  Branch (111:7): [True: 0, False: 52.4k]
  ------------------
  112|      0|      throw Invalid_Argument("cannot add the same extension twice: " +
  113|      0|                             std::to_string(static_cast<uint16_t>(extn->type())));
  114|      0|   }
  115|       |
  116|  52.4k|   m_extensions.emplace_back(extn.release());
  117|  52.4k|}
_ZN5Botan3TLS10Extensions11deserializeERNS0_15TLS_Data_ReaderENS0_15Connection_SideENS0_14Handshake_TypeE:
  119|  24.9k|void Extensions::deserialize(TLS_Data_Reader& reader, const Connection_Side from, const Handshake_Type message_type) {
  120|  24.9k|   if(reader.has_remaining()) {
  ------------------
  |  Branch (120:7): [True: 20.7k, False: 4.22k]
  ------------------
  121|  20.7k|      const uint16_t all_extn_size = reader.get_uint16_t();
  122|       |
  123|  20.7k|      if(reader.remaining_bytes() != all_extn_size) {
  ------------------
  |  Branch (123:10): [True: 60, False: 20.7k]
  ------------------
  124|     60|         throw Decoding_Error("Bad extension size");
  125|     60|      }
  126|       |
  127|  72.9k|      while(reader.has_remaining()) {
  ------------------
  |  Branch (127:13): [True: 52.2k, False: 20.7k]
  ------------------
  128|  52.2k|         const uint16_t extension_code = reader.get_uint16_t();
  129|  52.2k|         const uint16_t extension_size = reader.get_uint16_t();
  130|       |
  131|  52.2k|         const auto type = static_cast<Extension_Code>(extension_code);
  132|       |
  133|  52.2k|         if(this->has(type)) {
  ------------------
  |  Branch (133:13): [True: 8, False: 52.2k]
  ------------------
  134|      8|            throw TLS_Exception(TLS::Alert::DecodeError, "Peer sent duplicated extensions");
  135|      8|         }
  136|       |
  137|       |         // TODO offer a function on reader that returns a byte range as a reference
  138|       |         // to avoid this copy of the extension data
  139|  52.2k|         const std::vector<uint8_t> extn_data = reader.get_fixed<uint8_t>(extension_size);
  140|  52.2k|         TLS_Data_Reader extn_reader("Extension", extn_data);
  141|  52.2k|         this->add(make_extension(extn_reader, type, from, message_type));
  142|  52.2k|         extn_reader.assert_done();
  143|  52.2k|      }
  144|  20.7k|   }
  145|  24.9k|}
_ZNK5Botan3TLS10Extensions19contains_other_thanERKNSt3__13setINS0_14Extension_CodeENS2_4lessIS4_EENS2_9allocatorIS4_EEEEb:
  148|  9.68k|                                     const bool allow_unknown_extensions) const {
  149|  9.68k|   const auto found = extension_types();
  150|       |
  151|  9.68k|   std::vector<Extension_Code> diff;
  152|  9.68k|   std::set_difference(
  153|  9.68k|      found.cbegin(), found.end(), allowed_extensions.cbegin(), allowed_extensions.cend(), std::back_inserter(diff));
  154|       |
  155|  9.68k|   if(allow_unknown_extensions) {
  ------------------
  |  Branch (155:7): [True: 9.23k, False: 454]
  ------------------
  156|       |      // Go through the found unexpected extensions whether any of those
  157|       |      // is known to this TLS implementation.
  158|  9.23k|      const auto itr = std::find_if(diff.cbegin(), diff.cend(), [this](const auto ext_type) {
  159|  9.23k|         const auto ext = get(ext_type);
  160|  9.23k|         return ext && ext->is_implemented();
  161|  9.23k|      });
  162|       |
  163|       |      // ... if yes, `contains_other_than` is true
  164|  9.23k|      return itr != diff.cend();
  165|  9.23k|   }
  166|       |
  167|    454|   return !diff.empty();
  168|  9.68k|}
_ZNK5Botan3TLS10Extensions15extension_typesEv:
  217|  9.68k|std::set<Extension_Code> Extensions::extension_types() const {
  218|  9.68k|   std::set<Extension_Code> offers;
  219|  9.68k|   std::transform(
  220|  9.68k|      m_extensions.cbegin(), m_extensions.cend(), std::inserter(offers, offers.begin()), [](const auto& ext) {
  221|  9.68k|         return ext->type();
  222|  9.68k|      });
  223|  9.68k|   return offers;
  224|  9.68k|}
_ZN5Botan3TLS17Unknown_ExtensionC2ENS0_14Extension_CodeERNS0_15TLS_Data_ReaderEt:
  227|  28.2k|      m_type(type), m_value(reader.get_fixed<uint8_t>(extension_size)) {}
_ZN5Botan3TLS21Server_Name_IndicatorC2ERNS0_15TLS_Data_ReaderEt:
  233|  3.00k|Server_Name_Indicator::Server_Name_Indicator(TLS_Data_Reader& reader, uint16_t extension_size) {
  234|       |   /*
  235|       |   * This is used by the server to confirm that it knew the name
  236|       |   */
  237|  3.00k|   if(extension_size == 0) {
  ------------------
  |  Branch (237:7): [True: 2.05k, False: 950]
  ------------------
  238|  2.05k|      return;
  239|  2.05k|   }
  240|       |
  241|    950|   uint16_t name_bytes = reader.get_uint16_t();
  242|       |
  243|    950|   if(name_bytes + 2 != extension_size) {
  ------------------
  |  Branch (243:7): [True: 25, False: 925]
  ------------------
  244|     25|      throw Decoding_Error("Bad encoding of SNI extension");
  245|     25|   }
  246|       |
  247|  2.03k|   while(name_bytes) {
  ------------------
  |  Branch (247:10): [True: 1.10k, False: 925]
  ------------------
  248|  1.10k|      uint8_t name_type = reader.get_byte();
  249|  1.10k|      name_bytes--;
  250|       |
  251|  1.10k|      if(name_type == 0)  // DNS
  ------------------
  |  Branch (251:10): [True: 828, False: 280]
  ------------------
  252|    828|      {
  253|    828|         m_sni_host_name = reader.get_string(2, 1, 65535);
  254|    828|         name_bytes -= static_cast<uint16_t>(2 + m_sni_host_name.size());
  255|    828|      } else  // some other unknown name type
  256|    280|      {
  257|    280|         reader.discard_next(name_bytes);
  258|    280|         name_bytes = 0;
  259|    280|      }
  260|  1.10k|   }
  261|    925|}
_ZN5Botan3TLS23Renegotiation_ExtensionC2ERNS0_15TLS_Data_ReaderEt:
  289|    339|      m_reneg_data(reader.get_range<uint8_t>(1, 0, 255)) {
  290|    339|   if(m_reneg_data.size() + 1 != extension_size) {
  ------------------
  |  Branch (290:7): [True: 13, False: 326]
  ------------------
  291|     13|      throw Decoding_Error("Bad encoding for secure renegotiation extn");
  292|     13|   }
  293|    339|}
_ZN5Botan3TLS39Application_Layer_Protocol_NotificationC2ERNS0_15TLS_Data_ReaderEtNS0_15Connection_SideE:
  303|  1.89k|                                                                                 Connection_Side from) {
  304|  1.89k|   if(extension_size == 0) {
  ------------------
  |  Branch (304:7): [True: 1.33k, False: 556]
  ------------------
  305|  1.33k|      return;  // empty extension
  306|  1.33k|   }
  307|       |
  308|    556|   const uint16_t name_bytes = reader.get_uint16_t();
  309|       |
  310|    556|   size_t bytes_remaining = extension_size - 2;
  311|       |
  312|    556|   if(name_bytes != bytes_remaining) {
  ------------------
  |  Branch (312:7): [True: 32, False: 524]
  ------------------
  313|     32|      throw Decoding_Error("Bad encoding of ALPN extension, bad length field");
  314|     32|   }
  315|       |
  316|  5.01k|   while(bytes_remaining) {
  ------------------
  |  Branch (316:10): [True: 4.50k, False: 510]
  ------------------
  317|  4.50k|      const std::string p = reader.get_string(1, 0, 255);
  318|       |
  319|  4.50k|      if(bytes_remaining < p.size() + 1) {
  ------------------
  |  Branch (319:10): [True: 0, False: 4.50k]
  ------------------
  320|      0|         throw Decoding_Error("Bad encoding of ALPN, length field too long");
  321|      0|      }
  322|       |
  323|  4.50k|      if(p.empty()) {
  ------------------
  |  Branch (323:10): [True: 14, False: 4.49k]
  ------------------
  324|     14|         throw Decoding_Error("Empty ALPN protocol not allowed");
  325|     14|      }
  326|       |
  327|  4.49k|      bytes_remaining -= (p.size() + 1);
  328|       |
  329|  4.49k|      m_protocols.push_back(p);
  330|  4.49k|   }
  331|       |
  332|       |   // RFC 7301 3.1
  333|       |   //    The "extension_data" field of the [...] extension is structured the
  334|       |   //    same as described above for the client "extension_data", except that
  335|       |   //    the "ProtocolNameList" MUST contain exactly one "ProtocolName".
  336|    510|   if(from == Connection_Side::Server && m_protocols.size() != 1) {
  ------------------
  |  Branch (336:7): [True: 246, False: 264]
  |  Branch (336:42): [True: 30, False: 216]
  ------------------
  337|     30|      throw TLS_Exception(
  338|     30|         Alert::DecodeError,
  339|     30|         "Server sent " + std::to_string(m_protocols.size()) + " protocols in ALPN extension response");
  340|     30|   }
  341|    510|}
_ZN5Botan3TLS21Certificate_Type_BaseC2ERNS0_15TLS_Data_ReaderEtNS0_15Connection_SideE:
  423|  1.22k|      m_from(from) {
  424|  1.22k|   if(extension_size == 0) {
  ------------------
  |  Branch (424:7): [True: 4, False: 1.22k]
  ------------------
  425|      4|      throw Decoding_Error("Certificate type extension cannot be empty");
  426|      4|   }
  427|       |
  428|  1.22k|   if(from == Connection_Side::Client) {
  ------------------
  |  Branch (428:7): [True: 547, False: 676]
  ------------------
  429|    547|      const auto type_bytes = reader.get_tls_length_value(1);
  430|    547|      if(static_cast<size_t>(extension_size) != type_bytes.size() + 1) {
  ------------------
  |  Branch (430:10): [True: 12, False: 535]
  ------------------
  431|     12|         throw Decoding_Error("certificate type extension had inconsistent length");
  432|     12|      }
  433|    535|      std::transform(
  434|    535|         type_bytes.begin(), type_bytes.end(), std::back_inserter(m_certificate_types), [](const auto type_byte) {
  435|    535|            return static_cast<Certificate_Type>(type_byte);
  436|    535|         });
  437|    676|   } else {
  438|       |      // RFC 7250 4.2
  439|       |      //    Note that only a single value is permitted in the
  440|       |      //    server_certificate_type extension when carried in the server hello.
  441|    676|      if(extension_size != 1) {
  ------------------
  |  Branch (441:10): [True: 11, False: 665]
  ------------------
  442|     11|         throw Decoding_Error("Server's certificate type extension must be of length 1");
  443|     11|      }
  444|    665|      const auto type_byte = reader.get_byte();
  445|    665|      m_certificate_types.push_back(static_cast<Certificate_Type>(type_byte));
  446|    665|   }
  447|  1.22k|}
_ZNK5Botan3TLS16Supported_Groups6groupsEv:
  488|    478|const std::vector<Group_Params>& Supported_Groups::groups() const {
  489|    478|   return m_groups;
  490|    478|}
_ZN5Botan3TLS16Supported_GroupsC2ERNS0_15TLS_Data_ReaderEt:
  530|  1.20k|Supported_Groups::Supported_Groups(TLS_Data_Reader& reader, uint16_t extension_size) {
  531|  1.20k|   const uint16_t len = reader.get_uint16_t();
  532|       |
  533|  1.20k|   if(len + 2 != extension_size) {
  ------------------
  |  Branch (533:7): [True: 20, False: 1.18k]
  ------------------
  534|     20|      throw Decoding_Error("Inconsistent length field in supported groups list");
  535|     20|   }
  536|       |
  537|  1.18k|   if(len % 2 == 1) {
  ------------------
  |  Branch (537:7): [True: 1, False: 1.18k]
  ------------------
  538|      1|      throw Decoding_Error("Supported groups list of strange size");
  539|      1|   }
  540|       |
  541|  1.18k|   const size_t elems = len / 2;
  542|       |
  543|  5.50k|   for(size_t i = 0; i != elems; ++i) {
  ------------------
  |  Branch (543:22): [True: 4.32k, False: 1.18k]
  ------------------
  544|  4.32k|      const auto group = static_cast<Group_Params>(reader.get_uint16_t());
  545|       |      // Note: RFC 8446 does not explicitly enforce that groups must be unique.
  546|  4.32k|      if(!value_exists(m_groups, group)) {
  ------------------
  |  Branch (546:10): [True: 3.27k, False: 1.04k]
  ------------------
  547|  3.27k|         m_groups.push_back(group);
  548|  3.27k|      }
  549|  4.32k|   }
  550|  1.18k|}
_ZN5Botan3TLS23Supported_Point_FormatsC2ERNS0_15TLS_Data_ReaderEt:
  561|    723|Supported_Point_Formats::Supported_Point_Formats(TLS_Data_Reader& reader, uint16_t extension_size) {
  562|    723|   uint8_t len = reader.get_byte();
  563|       |
  564|    723|   if(len + 1 != extension_size) {
  ------------------
  |  Branch (564:7): [True: 10, False: 713]
  ------------------
  565|     10|      throw Decoding_Error("Inconsistent length field in supported point formats list");
  566|     10|   }
  567|       |
  568|    713|   bool includes_uncompressed = false;
  569|  1.16k|   for(size_t i = 0; i != len; ++i) {
  ------------------
  |  Branch (569:22): [True: 1.14k, False: 14]
  ------------------
  570|  1.14k|      uint8_t format = reader.get_byte();
  571|       |
  572|  1.14k|      if(static_cast<ECPointFormat>(format) == UNCOMPRESSED) {
  ------------------
  |  Branch (572:10): [True: 288, False: 858]
  ------------------
  573|    288|         m_prefers_compressed = false;
  574|    288|         reader.discard_next(len - i - 1);
  575|    288|         return;
  576|    858|      } else if(static_cast<ECPointFormat>(format) == ANSIX962_COMPRESSED_PRIME) {
  ------------------
  |  Branch (576:17): [True: 411, False: 447]
  ------------------
  577|    411|         m_prefers_compressed = true;
  578|    411|         std::vector<uint8_t> remaining_formats = reader.get_fixed<uint8_t>(len - i - 1);
  579|    411|         includes_uncompressed =
  580|    411|            std::any_of(std::begin(remaining_formats), std::end(remaining_formats), [](uint8_t remaining_format) {
  581|    411|               return static_cast<ECPointFormat>(remaining_format) == UNCOMPRESSED;
  582|    411|            });
  583|    411|         break;
  584|    411|      }
  585|       |
  586|       |      // ignore ANSIX962_COMPRESSED_CHAR2, we don't support these curves
  587|  1.14k|   }
  588|       |
  589|       |   // RFC 4492 5.1.:
  590|       |   //   If the Supported Point Formats Extension is indeed sent, it MUST contain the value 0 (uncompressed)
  591|       |   //   as one of the items in the list of point formats.
  592|       |   // Note:
  593|       |   //   RFC 8422 5.1.2. explicitly requires this check,
  594|       |   //   but only if the Supported Groups extension was sent.
  595|    425|   if(!includes_uncompressed) {
  ------------------
  |  Branch (595:7): [True: 33, False: 392]
  ------------------
  596|     33|      throw TLS_Exception(Alert::IllegalParameter,
  597|     33|                          "Supported Point Formats Extension must contain the uncompressed point format");
  598|     33|   }
  599|    425|}
_ZN5Botan3TLS20Signature_AlgorithmsC2ERNS0_15TLS_Data_ReaderEt:
  645|  1.98k|      m_schemes(parse_signature_algorithms(reader, extension_size)) {}
_ZN5Botan3TLS25Signature_Algorithms_CertC2ERNS0_15TLS_Data_ReaderEt:
  652|    323|      m_schemes(parse_signature_algorithms(reader, extension_size)) {}
_ZN5Botan3TLS24Session_Ticket_ExtensionC2ERNS0_15TLS_Data_ReaderEt:
  655|    584|      m_ticket(Session_Ticket(reader.get_elem<uint8_t, std::vector<uint8_t>>(extension_size))) {}
_ZN5Botan3TLS24SRTP_Protection_ProfilesC2ERNS0_15TLS_Data_ReaderEt:
  658|    468|      m_pp(reader.get_range<uint16_t>(2, 0, 65535)) {
  659|    468|   const std::vector<uint8_t> mki = reader.get_range<uint8_t>(1, 0, 255);
  660|       |
  661|    468|   if(m_pp.size() * 2 + mki.size() + 3 != extension_size) {
  ------------------
  |  Branch (661:7): [True: 12, False: 456]
  ------------------
  662|     12|      throw Decoding_Error("Bad encoding for SRTP protection extension");
  663|     12|   }
  664|       |
  665|    456|   if(!mki.empty()) {
  ------------------
  |  Branch (665:7): [True: 2, False: 454]
  ------------------
  666|      2|      throw Decoding_Error("Unhandled non-empty MKI for SRTP protection extension");
  667|      2|   }
  668|    456|}
_ZN5Botan3TLS22Extended_Master_SecretC2ERNS0_15TLS_Data_ReaderEt:
  687|    529|Extended_Master_Secret::Extended_Master_Secret(TLS_Data_Reader& /*unused*/, uint16_t extension_size) {
  688|    529|   if(extension_size != 0) {
  ------------------
  |  Branch (688:7): [True: 4, False: 525]
  ------------------
  689|      4|      throw Decoding_Error("Invalid extended_master_secret extension");
  690|      4|   }
  691|    529|}
_ZN5Botan3TLS16Encrypt_then_MACC2ERNS0_15TLS_Data_ReaderEt:
  697|    387|Encrypt_then_MAC::Encrypt_then_MAC(TLS_Data_Reader& /*unused*/, uint16_t extension_size) {
  698|    387|   if(extension_size != 0) {
  ------------------
  |  Branch (698:7): [True: 3, False: 384]
  ------------------
  699|      3|      throw Decoding_Error("Invalid encrypt_then_mac extension");
  700|      3|   }
  701|    387|}
_ZN5Botan3TLS18Supported_VersionsC2ERNS0_15TLS_Data_ReaderEtNS0_15Connection_SideE:
  750|  1.61k|Supported_Versions::Supported_Versions(TLS_Data_Reader& reader, uint16_t extension_size, Connection_Side from) {
  751|  1.61k|   if(from == Connection_Side::Server) {
  ------------------
  |  Branch (751:7): [True: 545, False: 1.07k]
  ------------------
  752|    545|      if(extension_size != 2) {
  ------------------
  |  Branch (752:10): [True: 2, False: 543]
  ------------------
  753|      2|         throw Decoding_Error("Server sent invalid supported_versions extension");
  754|      2|      }
  755|    543|      m_versions.push_back(Protocol_Version(reader.get_uint16_t()));
  756|  1.07k|   } else {
  757|  1.07k|      auto versions = reader.get_range<uint16_t>(1, 1, 127);
  758|       |
  759|  4.98k|      for(auto v : versions) {
  ------------------
  |  Branch (759:18): [True: 4.98k, False: 1.07k]
  ------------------
  760|  4.98k|         m_versions.push_back(Protocol_Version(v));
  761|  4.98k|      }
  762|       |
  763|  1.07k|      if(extension_size != 1 + 2 * versions.size()) {
  ------------------
  |  Branch (763:10): [True: 16, False: 1.05k]
  ------------------
  764|     16|         throw Decoding_Error("Client sent invalid supported_versions extension");
  765|     16|      }
  766|  1.07k|   }
  767|  1.61k|}
_ZNK5Botan3TLS18Supported_Versions8supportsENS0_16Protocol_VersionE:
  769|  1.04k|bool Supported_Versions::supports(Protocol_Version version) const {
  770|  2.59k|   for(auto v : m_versions) {
  ------------------
  |  Branch (770:15): [True: 2.59k, False: 326]
  ------------------
  771|  2.59k|      if(version == v) {
  ------------------
  |  Branch (771:10): [True: 721, False: 1.87k]
  ------------------
  772|    721|         return true;
  773|    721|      }
  774|  2.59k|   }
  775|    326|   return false;
  776|  1.04k|}
_ZN5Botan3TLS17Record_Size_LimitC2ERNS0_15TLS_Data_ReaderEtNS0_15Connection_SideE:
  784|    639|Record_Size_Limit::Record_Size_Limit(TLS_Data_Reader& reader, uint16_t extension_size, Connection_Side from) {
  785|    639|   if(extension_size != 2) {
  ------------------
  |  Branch (785:7): [True: 6, False: 633]
  ------------------
  786|      6|      throw TLS_Exception(Alert::DecodeError, "invalid record_size_limit extension");
  787|      6|   }
  788|       |
  789|    633|   m_limit = reader.get_uint16_t();
  790|       |
  791|       |   // RFC 8449 4.
  792|       |   //    This value is the length of the plaintext of a protected record.
  793|       |   //    The value includes the content type and padding added in TLS 1.3 (that
  794|       |   //    is, the complete length of TLSInnerPlaintext).
  795|       |   //
  796|       |   //    A server MUST NOT enforce this restriction; a client might advertise
  797|       |   //    a higher limit that is enabled by an extension or version the server
  798|       |   //    does not understand. A client MAY abort the handshake with an
  799|       |   //    "illegal_parameter" alert.
  800|       |   //
  801|       |   // Note: We are currently supporting this extension in TLS 1.3 only, hence
  802|       |   //       we check for the TLS 1.3 limit. The TLS 1.2 limit would not include
  803|       |   //       the "content type byte" and hence be one byte less!
  804|    633|   if(m_limit > MAX_PLAINTEXT_SIZE + 1 /* encrypted content type byte */ && from == Connection_Side::Server) {
  ------------------
  |  Branch (804:7): [True: 211, False: 422]
  |  Branch (804:77): [True: 4, False: 207]
  ------------------
  805|      4|      throw TLS_Exception(Alert::IllegalParameter,
  806|      4|                          "Server requested a record size limit larger than the protocol's maximum");
  807|      4|   }
  808|       |
  809|       |   // RFC 8449 4.
  810|       |   //    Endpoints MUST NOT send a "record_size_limit" extension with a value
  811|       |   //    smaller than 64.  An endpoint MUST treat receipt of a smaller value
  812|       |   //    as a fatal error and generate an "illegal_parameter" alert.
  813|    629|   if(m_limit < 64) {
  ------------------
  |  Branch (813:7): [True: 7, False: 622]
  ------------------
  814|      7|      throw TLS_Exception(Alert::IllegalParameter, "Received a record size limit smaller than 64 bytes");
  815|      7|   }
  816|    629|}
_ZN5Botan3TLS6CookieC2ERNS0_15TLS_Data_ReaderEt:
  830|    662|Cookie::Cookie(TLS_Data_Reader& reader, uint16_t extension_size) {
  831|    662|   if(extension_size == 0) {
  ------------------
  |  Branch (831:7): [True: 333, False: 329]
  ------------------
  832|    333|      return;
  833|    333|   }
  834|       |
  835|    329|   const uint16_t len = reader.get_uint16_t();
  836|       |
  837|    329|   if(len == 0) {
  ------------------
  |  Branch (837:7): [True: 1, False: 328]
  ------------------
  838|       |      // Based on RFC 8446 4.2.2, len of the Cookie buffer must be at least 1
  839|      1|      throw Decoding_Error("Cookie length must be at least 1 byte");
  840|      1|   }
  841|       |
  842|    328|   if(len > reader.remaining_bytes()) {
  ------------------
  |  Branch (842:7): [True: 17, False: 311]
  ------------------
  843|     17|      throw Decoding_Error("Not enough bytes in the buffer to decode Cookie");
  844|     17|   }
  845|       |
  846|  4.42k|   for(size_t i = 0; i < len; ++i) {
  ------------------
  |  Branch (846:22): [True: 4.10k, False: 311]
  ------------------
  847|  4.10k|      m_cookie.push_back(reader.get_byte());
  848|  4.10k|   }
  849|    311|}
_ZN5Botan3TLS22PSK_Key_Exchange_ModesC2ERNS0_15TLS_Data_ReaderEt:
  878|    684|PSK_Key_Exchange_Modes::PSK_Key_Exchange_Modes(TLS_Data_Reader& reader, uint16_t extension_size) {
  879|    684|   if(extension_size < 2) {
  ------------------
  |  Branch (879:7): [True: 2, False: 682]
  ------------------
  880|      2|      throw Decoding_Error("Empty psk_key_exchange_modes extension is illegal");
  881|      2|   }
  882|       |
  883|    682|   const auto mode_count = reader.get_byte();
  884|  3.62k|   for(uint16_t i = 0; i < mode_count; ++i) {
  ------------------
  |  Branch (884:24): [True: 2.93k, False: 682]
  ------------------
  885|  2.93k|      const auto mode = static_cast<PSK_Key_Exchange_Mode>(reader.get_byte());
  886|  2.93k|      if(mode == PSK_Key_Exchange_Mode::PSK_KE || mode == PSK_Key_Exchange_Mode::PSK_DHE_KE) {
  ------------------
  |  Branch (886:10): [True: 1.65k, False: 1.28k]
  |  Branch (886:51): [True: 437, False: 843]
  ------------------
  887|  2.05k|         m_modes.push_back(mode);
  888|  2.05k|      }
  889|  2.93k|   }
  890|    682|}
_ZN5Botan3TLS23Certificate_AuthoritiesC2ERNS0_15TLS_Data_ReaderEt:
  908|  1.40k|Certificate_Authorities::Certificate_Authorities(TLS_Data_Reader& reader, uint16_t extension_size) {
  909|  1.40k|   if(extension_size < 2) {
  ------------------
  |  Branch (909:7): [True: 2, False: 1.39k]
  ------------------
  910|      2|      throw Decoding_Error("Empty certificate_authorities extension is illegal");
  911|      2|   }
  912|       |
  913|  1.39k|   const uint16_t purported_size = reader.get_uint16_t();
  914|       |
  915|  1.39k|   if(reader.remaining_bytes() != purported_size) {
  ------------------
  |  Branch (915:7): [True: 4, False: 1.39k]
  ------------------
  916|      4|      throw Decoding_Error("Inconsistent length in certificate_authorities extension");
  917|      4|   }
  918|       |
  919|  5.39k|   while(reader.has_remaining()) {
  ------------------
  |  Branch (919:10): [True: 4.00k, False: 1.39k]
  ------------------
  920|  4.00k|      std::vector<uint8_t> name_bits = reader.get_tls_length_value(2);
  921|       |
  922|  4.00k|      BER_Decoder decoder(name_bits.data(), name_bits.size());
  923|  4.00k|      m_distinguished_names.emplace_back();
  924|  4.00k|      decoder.decode(m_distinguished_names.back());
  925|  4.00k|   }
  926|  1.39k|}
_ZN5Botan3TLS19EarlyDataIndicationC2ERNS0_15TLS_Data_ReaderEtNS0_14Handshake_TypeE:
  945|    671|                                         Handshake_Type message_type) {
  946|    671|   if(message_type == Handshake_Type::NewSessionTicket) {
  ------------------
  |  Branch (946:7): [True: 0, False: 671]
  ------------------
  947|      0|      if(extension_size != 4) {
  ------------------
  |  Branch (947:10): [True: 0, False: 0]
  ------------------
  948|      0|         throw TLS_Exception(Alert::DecodeError,
  949|      0|                             "Received an early_data extension in a NewSessionTicket message "
  950|      0|                             "without maximum early data size indication");
  951|      0|      }
  952|       |
  953|      0|      m_max_early_data_size = reader.get_uint32_t();
  954|    671|   } else if(extension_size != 0) {
  ------------------
  |  Branch (954:14): [True: 12, False: 659]
  ------------------
  955|     12|      throw TLS_Exception(Alert::DecodeError,
  956|     12|                          "Received an early_data extension containing an unexpected data "
  957|     12|                          "size indication");
  958|     12|   }
  959|    671|}
tls_extensions.cpp:_ZN5Botan3TLS12_GLOBAL__N_114make_extensionERNS0_15TLS_Data_ReaderENS0_14Extension_CodeENS0_15Connection_SideENS0_14Handshake_TypeE:
   31|  52.0k|                                          const Handshake_Type message_type) {
   32|       |   // This cast is safe because we read exactly a 16 bit length field for
   33|       |   // the extension in Extensions::deserialize
   34|  52.0k|   const uint16_t size = static_cast<uint16_t>(reader.remaining_bytes());
   35|  52.0k|   switch(code) {
  ------------------
  |  Branch (35:11): [True: 28.2k, False: 23.8k]
  ------------------
   36|  3.00k|      case Extension_Code::ServerNameIndication:
  ------------------
  |  Branch (36:7): [True: 3.00k, False: 49.0k]
  ------------------
   37|  3.00k|         return std::make_unique<Server_Name_Indicator>(reader, size);
   38|       |
   39|  1.20k|      case Extension_Code::SupportedGroups:
  ------------------
  |  Branch (39:7): [True: 1.20k, False: 50.8k]
  ------------------
   40|  1.20k|         return std::make_unique<Supported_Groups>(reader, size);
   41|       |
   42|  1.93k|      case Extension_Code::CertificateStatusRequest:
  ------------------
  |  Branch (42:7): [True: 1.93k, False: 50.1k]
  ------------------
   43|  1.93k|         return std::make_unique<Certificate_Status_Request>(reader, size, message_type, from);
   44|       |
   45|    723|      case Extension_Code::EcPointFormats:
  ------------------
  |  Branch (45:7): [True: 723, False: 51.3k]
  ------------------
   46|    723|         return std::make_unique<Supported_Point_Formats>(reader, size);
   47|       |
   48|    339|      case Extension_Code::SafeRenegotiation:
  ------------------
  |  Branch (48:7): [True: 339, False: 51.7k]
  ------------------
   49|    339|         return std::make_unique<Renegotiation_Extension>(reader, size);
   50|       |
   51|  1.98k|      case Extension_Code::SignatureAlgorithms:
  ------------------
  |  Branch (51:7): [True: 1.98k, False: 50.1k]
  ------------------
   52|  1.98k|         return std::make_unique<Signature_Algorithms>(reader, size);
   53|       |
   54|    323|      case Extension_Code::CertSignatureAlgorithms:
  ------------------
  |  Branch (54:7): [True: 323, False: 51.7k]
  ------------------
   55|    323|         return std::make_unique<Signature_Algorithms_Cert>(reader, size);
   56|       |
   57|    468|      case Extension_Code::UseSrtp:
  ------------------
  |  Branch (57:7): [True: 468, False: 51.6k]
  ------------------
   58|    468|         return std::make_unique<SRTP_Protection_Profiles>(reader, size);
   59|       |
   60|  1.89k|      case Extension_Code::ApplicationLayerProtocolNegotiation:
  ------------------
  |  Branch (60:7): [True: 1.89k, False: 50.1k]
  ------------------
   61|  1.89k|         return std::make_unique<Application_Layer_Protocol_Notification>(reader, size, from);
   62|       |
   63|    636|      case Extension_Code::ClientCertificateType:
  ------------------
  |  Branch (63:7): [True: 636, False: 51.4k]
  ------------------
   64|    636|         return std::make_unique<Client_Certificate_Type>(reader, size, from);
   65|       |
   66|    591|      case Extension_Code::ServerCertificateType:
  ------------------
  |  Branch (66:7): [True: 591, False: 51.5k]
  ------------------
   67|    591|         return std::make_unique<Server_Certificate_Type>(reader, size, from);
   68|       |
   69|    529|      case Extension_Code::ExtendedMasterSecret:
  ------------------
  |  Branch (69:7): [True: 529, False: 51.5k]
  ------------------
   70|    529|         return std::make_unique<Extended_Master_Secret>(reader, size);
   71|       |
   72|    639|      case Extension_Code::RecordSizeLimit:
  ------------------
  |  Branch (72:7): [True: 639, False: 51.4k]
  ------------------
   73|    639|         return std::make_unique<Record_Size_Limit>(reader, size, from);
   74|       |
   75|    387|      case Extension_Code::EncryptThenMac:
  ------------------
  |  Branch (75:7): [True: 387, False: 51.7k]
  ------------------
   76|    387|         return std::make_unique<Encrypt_then_MAC>(reader, size);
   77|       |
   78|    584|      case Extension_Code::SessionTicket:
  ------------------
  |  Branch (78:7): [True: 584, False: 51.5k]
  ------------------
   79|    584|         return std::make_unique<Session_Ticket_Extension>(reader, size);
   80|       |
   81|  1.61k|      case Extension_Code::SupportedVersions:
  ------------------
  |  Branch (81:7): [True: 1.61k, False: 50.4k]
  ------------------
   82|  1.61k|         return std::make_unique<Supported_Versions>(reader, size, from);
   83|       |
   84|      0|#if defined(BOTAN_HAS_TLS_13)
   85|    888|      case Extension_Code::PresharedKey:
  ------------------
  |  Branch (85:7): [True: 888, False: 51.2k]
  ------------------
   86|    888|         return std::make_unique<PSK>(reader, size, message_type);
   87|       |
   88|    671|      case Extension_Code::EarlyData:
  ------------------
  |  Branch (88:7): [True: 671, False: 51.4k]
  ------------------
   89|    671|         return std::make_unique<EarlyDataIndication>(reader, size, message_type);
   90|       |
   91|    662|      case Extension_Code::Cookie:
  ------------------
  |  Branch (91:7): [True: 662, False: 51.4k]
  ------------------
   92|    662|         return std::make_unique<Cookie>(reader, size);
   93|       |
   94|    684|      case Extension_Code::PskKeyExchangeModes:
  ------------------
  |  Branch (94:7): [True: 684, False: 51.4k]
  ------------------
   95|    684|         return std::make_unique<PSK_Key_Exchange_Modes>(reader, size);
   96|       |
   97|  1.40k|      case Extension_Code::CertificateAuthorities:
  ------------------
  |  Branch (97:7): [True: 1.40k, False: 50.6k]
  ------------------
   98|  1.40k|         return std::make_unique<Certificate_Authorities>(reader, size);
   99|       |
  100|  2.63k|      case Extension_Code::KeyShare:
  ------------------
  |  Branch (100:7): [True: 2.63k, False: 49.4k]
  ------------------
  101|  2.63k|         return std::make_unique<Key_Share>(reader, size, message_type);
  102|  52.0k|#endif
  103|  52.0k|   }
  104|       |
  105|  28.2k|   return std::make_unique<Unknown_Extension>(static_cast<Extension_Code>(code), reader, size);
  106|  52.0k|}
tls_extensions.cpp:_ZZNK5Botan3TLS10Extensions19contains_other_thanERKNSt3__13setINS0_14Extension_CodeENS2_4lessIS4_EENS2_9allocatorIS4_EEEEbENK3$_0clIS4_EEDaT_:
  158|  22.5k|      const auto itr = std::find_if(diff.cbegin(), diff.cend(), [this](const auto ext_type) {
  159|  22.5k|         const auto ext = get(ext_type);
  160|  22.5k|         return ext && ext->is_implemented();
  ------------------
  |  Branch (160:17): [True: 22.5k, False: 0]
  |  Branch (160:24): [True: 303, False: 22.2k]
  ------------------
  161|  22.5k|      });
tls_extensions.cpp:_ZZNK5Botan3TLS10Extensions15extension_typesEvENK3$_2clINSt3__110unique_ptrINS0_9ExtensionENS4_14default_deleteIS6_EEEEEEDaRKT_:
  220|  31.7k|      m_extensions.cbegin(), m_extensions.cend(), std::inserter(offers, offers.begin()), [](const auto& ext) {
  221|  31.7k|         return ext->type();
  222|  31.7k|      });
tls_extensions.cpp:_ZZN5Botan3TLS21Certificate_Type_BaseC1ERNS0_15TLS_Data_ReaderEtNS0_15Connection_SideEENK3$_3clIhEEDaT_:
  434|  1.96k|         type_bytes.begin(), type_bytes.end(), std::back_inserter(m_certificate_types), [](const auto type_byte) {
  435|  1.96k|            return static_cast<Certificate_Type>(type_byte);
  436|  1.96k|         });
tls_extensions.cpp:_ZZN5Botan3TLS23Supported_Point_FormatsC1ERNS0_15TLS_Data_ReaderEtENK3$_5clEh:
  580|    802|            std::any_of(std::begin(remaining_formats), std::end(remaining_formats), [](uint8_t remaining_format) {
  581|    802|               return static_cast<ECPointFormat>(remaining_format) == UNCOMPRESSED;
  582|    802|            });
tls_extensions.cpp:_ZN5Botan3TLS12_GLOBAL__N_126parse_signature_algorithmsERNS0_15TLS_Data_ReaderEt:
  621|  2.31k|std::vector<Signature_Scheme> parse_signature_algorithms(TLS_Data_Reader& reader, uint16_t extension_size) {
  622|  2.31k|   uint16_t len = reader.get_uint16_t();
  623|       |
  624|  2.31k|   if(len + 2 != extension_size || len % 2 == 1 || len == 0) {
  ------------------
  |  Branch (624:7): [True: 30, False: 2.28k]
  |  Branch (624:36): [True: 1, False: 2.28k]
  |  Branch (624:52): [True: 1, False: 2.27k]
  ------------------
  625|     28|      throw Decoding_Error("Bad encoding on signature algorithms extension");
  626|     28|   }
  627|       |
  628|  2.28k|   std::vector<Signature_Scheme> schemes;
  629|  2.28k|   schemes.reserve(len / 2);
  630|  5.83k|   while(len) {
  ------------------
  |  Branch (630:10): [True: 3.55k, False: 2.28k]
  ------------------
  631|  3.55k|      schemes.emplace_back(reader.get_uint16_t());
  632|  3.55k|      len -= 2;
  633|  3.55k|   }
  634|       |
  635|  2.28k|   return schemes;
  636|  2.31k|}

_ZN5Botan3TLS26Certificate_Status_RequestC2ERNS0_15TLS_Data_ReaderEtNS0_14Handshake_TypeENS0_15Connection_SideE:
   89|  1.93k|                                                       Connection_Side from) {
   90|       |   // This parser needs to take TLS 1.2 and TLS 1.3 into account. The
   91|       |   // extension's content and structure is dependent on the context it
   92|       |   // was sent in (i.e. the enclosing handshake message). Below is a list
   93|       |   // of handshake messages this can appear in.
   94|       |   //
   95|       |   // TLS 1.2
   96|       |   //  * Client Hello
   97|       |   //  * Server Hello
   98|       |   //
   99|       |   // TLS 1.3
  100|       |   //  * Client Hello
  101|       |   //  * Certificate Request
  102|       |   //  * Certificate (Entry)
  103|       |
  104|       |   // RFC 6066 8.
  105|       |   //    In order to indicate their desire to receive certificate status
  106|       |   //    information, clients MAY include an extension of type "status_request"
  107|       |   //    in the (extended) client hello.
  108|  1.93k|   if(message_type == Handshake_Type::ClientHello) {
  ------------------
  |  Branch (108:7): [True: 1.41k, False: 520]
  ------------------
  109|  1.41k|      m_impl = std::make_unique<Certificate_Status_Request_Internal>(
  110|  1.41k|         RFC6066_Certificate_Status_Request(reader, extension_size));
  111|  1.41k|   }
  112|       |
  113|       |   // RFC 6066 8.
  114|       |   //    If a server returns a "CertificateStatus" message, then the server MUST
  115|       |   //    have included an extension of type "status_request" with empty
  116|       |   //    "extension_data" in the extended server hello.
  117|       |   //
  118|       |   // RFC 8446 4.4.2.1
  119|       |   //    A server MAY request that a client present an OCSP response with its
  120|       |   //    certificate by sending an empty "status_request" extension in its
  121|       |   //    CertificateRequest message.
  122|    520|   else if(message_type == Handshake_Type::ServerHello || message_type == Handshake_Type::CertificateRequest) {
  ------------------
  |  Branch (122:12): [True: 213, False: 307]
  |  Branch (122:59): [True: 306, False: 1]
  ------------------
  123|    519|      m_impl = std::make_unique<Certificate_Status_Request_Internal>(
  124|    519|         RFC6066_Empty_Certificate_Status_Request(extension_size));
  125|    519|   }
  126|       |
  127|       |   // RFC 8446 4.4.2.1
  128|       |   //    In TLS 1.3, the server's OCSP information is carried in an extension
  129|       |   //    in the CertificateEntry [in a Certificate handshake message] [...].
  130|       |   //    Specifically, the body of the "status_request" extension from the
  131|       |   //    server MUST be a CertificateStatus structure as defined in [RFC6066]
  132|       |   //    [...].
  133|       |   //
  134|       |   // RFC 8446 4.4.2.1
  135|       |   //    If the client opts to send an OCSP response, the body of its
  136|       |   //    "status_request" extension MUST be a CertificateStatus structure as
  137|       |   //    defined in [RFC6066].
  138|      1|   else if(message_type == Handshake_Type::Certificate) {
  ------------------
  |  Branch (138:12): [True: 0, False: 1]
  ------------------
  139|      0|      m_impl = std::make_unique<Certificate_Status_Request_Internal>(
  140|      0|         Certificate_Status(reader.get_fixed<uint8_t>(extension_size), from));
  141|      0|   }
  142|       |
  143|       |   // all other contexts are not allowed for this extension
  144|      1|   else {
  145|      1|      throw TLS_Exception(Alert::UnsupportedExtension,
  146|      1|                          "Server sent a Certificate_Status_Request extension in an unsupported context");
  147|      1|   }
  148|  1.93k|}
_ZN5Botan3TLS26Certificate_Status_RequestD2Ev:
  161|  1.91k|Certificate_Status_Request::~Certificate_Status_Request() = default;
tls_extensions_cert_status_req.cpp:_ZN5Botan3TLS12_GLOBAL__N_134RFC6066_Certificate_Status_RequestC2ERNS0_15TLS_Data_ReaderEt:
   38|  1.41k|      RFC6066_Certificate_Status_Request(TLS_Data_Reader& reader, uint16_t extension_size) {
   39|  1.41k|         if(extension_size == 0) {
  ------------------
  |  Branch (39:13): [True: 1, False: 1.41k]
  ------------------
   40|      1|            throw Decoding_Error("Received an unexpectedly empty Certificate_Status_Request");
   41|      1|         }
   42|       |
   43|  1.41k|         const uint8_t type = reader.get_byte();
   44|  1.41k|         if(type == 1 /* ocsp */) {
  ------------------
  |  Branch (44:13): [True: 708, False: 704]
  ------------------
   45|    708|            const size_t len_resp_id_list = reader.get_uint16_t();
   46|    708|            ocsp_names = reader.get_fixed<uint8_t>(len_resp_id_list);
   47|    708|            const size_t len_requ_ext = reader.get_uint16_t();
   48|    708|            extension_bytes = reader.get_fixed<uint8_t>(len_requ_ext);
   49|    708|         } else {
   50|       |            // RFC 6066 does not specify anything but 'ocsp' and we
   51|       |            // don't support anything else either.
   52|    704|            reader.discard_next(extension_size - 1);
   53|    704|         }
   54|  1.41k|      }
tls_extensions_cert_status_req.cpp:_ZN5Botan3TLS12_GLOBAL__N_140RFC6066_Empty_Certificate_Status_RequestC2Et:
   24|    519|      RFC6066_Empty_Certificate_Status_Request(uint16_t extension_size) {
   25|    519|         if(extension_size != 0) {
  ------------------
  |  Branch (25:13): [True: 9, False: 510]
  ------------------
   26|      9|            throw Decoding_Error("Received an unexpectedly non-empty Certificate_Status_Request");
   27|      9|         }
   28|    519|      }
tls_extensions_cert_status_req.cpp:_ZN5Botan3TLS35Certificate_Status_Request_InternalC2ENSt3__17variantIJNS0_12_GLOBAL__N_140RFC6066_Empty_Certificate_Status_RequestENS4_34RFC6066_Certificate_Status_RequestENS0_18Certificate_StatusEEEE:
   81|  1.91k|      Certificate_Status_Request_Internal(Contents c) : content(std::move(c)) {}

_ZNK5Botan3TLS6Policy30maximum_certificate_chain_sizeEv:
  402|  1.58k|size_t Policy::maximum_certificate_chain_size() const {
  403|  1.58k|   return 0;
  404|  1.58k|}

_ZN5Botan3TLS16Signature_Scheme21all_available_schemesEv:
   21|  1.69k|const std::vector<Signature_Scheme>& Signature_Scheme::all_available_schemes() {
   22|       |   /*
   23|       |   * This is ordered in some approximate order of preference
   24|       |   */
   25|  1.69k|   static const std::vector<Signature_Scheme> all_schemes = {
   26|       |
   27|       |      // EdDSA 25519 is currently not supported as a signature scheme for certificates
   28|       |      // certificate authentication.
   29|       |      // See: https://github.com/randombit/botan/pull/2958#discussion_r851294715
   30|       |      //
   31|       |      // #if defined(BOTAN_HAS_ED25519)
   32|       |      //       EDDSA_25519,
   33|       |      // #endif
   34|       |
   35|  1.69k|      RSA_PSS_SHA384,
   36|  1.69k|      RSA_PSS_SHA256,
   37|  1.69k|      RSA_PSS_SHA512,
   38|       |
   39|  1.69k|      RSA_PKCS1_SHA384,
   40|  1.69k|      RSA_PKCS1_SHA512,
   41|  1.69k|      RSA_PKCS1_SHA256,
   42|       |
   43|  1.69k|      ECDSA_SHA384,
   44|  1.69k|      ECDSA_SHA512,
   45|  1.69k|      ECDSA_SHA256,
   46|  1.69k|   };
   47|       |
   48|  1.69k|   return all_schemes;
   49|  1.69k|}
_ZN5Botan3TLS16Signature_SchemeC2Ev:
   51|  1.72k|Signature_Scheme::Signature_Scheme() : m_code(NONE) {}
_ZN5Botan3TLS16Signature_SchemeC2Et:
   53|  5.27k|Signature_Scheme::Signature_Scheme(uint16_t wire_code) : Signature_Scheme(Signature_Scheme::Code(wire_code)) {}
_ZN5Botan3TLS16Signature_SchemeC2ENS1_4CodeE:
   55|  5.28k|Signature_Scheme::Signature_Scheme(Signature_Scheme::Code wire_code) : m_code(wire_code) {}
_ZNK5Botan3TLS16Signature_Scheme12is_availableEv:
   57|  1.69k|bool Signature_Scheme::is_available() const noexcept {
   58|  1.69k|   return value_exists(Signature_Scheme::all_available_schemes(), *this);
   59|  1.69k|}
_ZNK5Botan3TLS16Signature_Scheme6is_setEv:
   61|  1.69k|bool Signature_Scheme::is_set() const noexcept {
   62|  1.69k|   return m_code != NONE;
   63|  1.69k|}
_ZNK5Botan3TLS16Signature_Scheme18hash_function_nameEv:
  102|  1.66k|std::string Signature_Scheme::hash_function_name() const noexcept {
  103|  1.66k|   switch(m_code) {
  104|      0|      case RSA_PKCS1_SHA1:
  ------------------
  |  Branch (104:7): [True: 0, False: 1.66k]
  ------------------
  105|      0|      case ECDSA_SHA1:
  ------------------
  |  Branch (105:7): [True: 0, False: 1.66k]
  ------------------
  106|      0|         return "SHA-1";
  107|       |
  108|    351|      case ECDSA_SHA256:
  ------------------
  |  Branch (108:7): [True: 351, False: 1.31k]
  ------------------
  109|    352|      case RSA_PKCS1_SHA256:
  ------------------
  |  Branch (109:7): [True: 1, False: 1.66k]
  ------------------
  110|    620|      case RSA_PSS_SHA256:
  ------------------
  |  Branch (110:7): [True: 268, False: 1.40k]
  ------------------
  111|    620|         return "SHA-256";
  112|       |
  113|    250|      case ECDSA_SHA384:
  ------------------
  |  Branch (113:7): [True: 250, False: 1.41k]
  ------------------
  114|    251|      case RSA_PKCS1_SHA384:
  ------------------
  |  Branch (114:7): [True: 1, False: 1.66k]
  ------------------
  115|    476|      case RSA_PSS_SHA384:
  ------------------
  |  Branch (115:7): [True: 225, False: 1.44k]
  ------------------
  116|    476|         return "SHA-384";
  117|       |
  118|    232|      case ECDSA_SHA512:
  ------------------
  |  Branch (118:7): [True: 232, False: 1.43k]
  ------------------
  119|    233|      case RSA_PKCS1_SHA512:
  ------------------
  |  Branch (119:7): [True: 1, False: 1.66k]
  ------------------
  120|    572|      case RSA_PSS_SHA512:
  ------------------
  |  Branch (120:7): [True: 339, False: 1.32k]
  ------------------
  121|    572|         return "SHA-512";
  122|       |
  123|      0|      case EDDSA_25519:
  ------------------
  |  Branch (123:7): [True: 0, False: 1.66k]
  ------------------
  124|      0|      case EDDSA_448:
  ------------------
  |  Branch (124:7): [True: 0, False: 1.66k]
  ------------------
  125|      0|         return "Pure";
  126|       |
  127|      0|      default:
  ------------------
  |  Branch (127:7): [True: 0, False: 1.66k]
  ------------------
  128|      0|         return "Unknown hash function";
  129|  1.66k|   }
  130|  1.66k|}
_ZNK5Botan3TLS16Signature_Scheme18is_compatible_withERKNS0_16Protocol_VersionE:
  281|  1.66k|bool Signature_Scheme::is_compatible_with(const Protocol_Version& protocol_version) const noexcept {
  282|       |   // RFC 8446 4.4.3:
  283|       |   //   The SHA-1 algorithm MUST NOT be used in any signatures of
  284|       |   //   CertificateVerify messages.
  285|       |   //
  286|       |   // Note that Botan enforces that for TLS 1.2 as well.
  287|  1.66k|   if(hash_function_name() == "SHA-1") {
  ------------------
  |  Branch (287:7): [True: 0, False: 1.66k]
  ------------------
  288|      0|      return false;
  289|      0|   }
  290|       |
  291|       |   // RFC 8446 4.4.3:
  292|       |   //   RSA signatures MUST use an RSASSA-PSS algorithm, regardless of whether
  293|       |   //   RSASSA-PKCS1-v1_5 algorithms appear in "signature_algorithms".
  294|       |   //
  295|       |   // Note that this is enforced for TLS 1.3 and above only.
  296|  1.66k|   if(!protocol_version.is_pre_tls_13() && (m_code == RSA_PKCS1_SHA1 || m_code == RSA_PKCS1_SHA256 ||
  ------------------
  |  Branch (296:7): [True: 1.66k, False: 0]
  |  Branch (296:45): [True: 0, False: 1.66k]
  |  Branch (296:73): [True: 1, False: 1.66k]
  ------------------
  297|  1.66k|                                            m_code == RSA_PKCS1_SHA384 || m_code == RSA_PKCS1_SHA512)) {
  ------------------
  |  Branch (297:45): [True: 1, False: 1.66k]
  |  Branch (297:75): [True: 1, False: 1.66k]
  ------------------
  298|      3|      return false;
  299|      3|   }
  300|       |
  301|  1.66k|   return true;
  302|  1.66k|}

_ZNK5Botan3TLS16Protocol_Version9to_stringEv:
   16|    118|std::string Protocol_Version::to_string() const {
   17|    118|   const uint8_t maj = major_version();
   18|    118|   const uint8_t min = minor_version();
   19|       |
   20|    118|   if(maj == 3 && min == 0) {
  ------------------
  |  Branch (20:7): [True: 56, False: 62]
  |  Branch (20:19): [True: 1, False: 55]
  ------------------
   21|      1|      return "SSL v3";
   22|      1|   }
   23|       |
   24|    117|   if(maj == 3 && min >= 1) {  // TLS v1.x
  ------------------
  |  Branch (24:7): [True: 55, False: 62]
  |  Branch (24:19): [True: 55, False: 0]
  ------------------
   25|     55|      return "TLS v1." + std::to_string(min - 1);
   26|     55|   }
   27|       |
   28|     62|   if(maj == 254) {  // DTLS 1.x
  ------------------
  |  Branch (28:7): [True: 12, False: 50]
  ------------------
   29|     12|      return "DTLS v1." + std::to_string(255 - min);
   30|     12|   }
   31|       |
   32|       |   // Some very new or very old protocol (or bogus data)
   33|     50|   return "Unknown " + std::to_string(maj) + "." + std::to_string(min);
   34|     62|}
_ZNK5Botan3TLS16Protocol_Version20is_datagram_protocolEv:
   36|  82.8k|bool Protocol_Version::is_datagram_protocol() const {
   37|  82.8k|   return major_version() > 250;
   38|  82.8k|}
_ZNK5Botan3TLS16Protocol_Version13is_pre_tls_13Ev:
   40|  21.6k|bool Protocol_Version::is_pre_tls_13() const {
   41|  21.6k|   return (!is_datagram_protocol() && *this <= Protocol_Version::TLS_V12) ||
  ------------------
  |  Branch (41:12): [True: 15.4k, False: 6.23k]
  |  Branch (41:39): [True: 12.4k, False: 2.99k]
  ------------------
   42|  21.6k|          (is_datagram_protocol() && *this <= Protocol_Version::DTLS_V12);
  ------------------
  |  Branch (42:12): [True: 6.23k, False: 2.99k]
  |  Branch (42:38): [True: 6.21k, False: 20]
  ------------------
   43|  21.6k|}
_ZNK5Botan3TLS16Protocol_Version18is_tls_13_or_laterEv:
   45|    721|bool Protocol_Version::is_tls_13_or_later() const {
   46|    721|   return (!is_datagram_protocol() && *this >= Protocol_Version::TLS_V13) ||
  ------------------
  |  Branch (46:12): [True: 646, False: 75]
  |  Branch (46:39): [True: 12, False: 634]
  ------------------
   47|    721|          (is_datagram_protocol() && *this >= Protocol_Version::DTLS_V13);
  ------------------
  |  Branch (47:12): [True: 75, False: 634]
  |  Branch (47:38): [True: 9, False: 66]
  ------------------
   48|    721|}
_ZNK5Botan3TLS16Protocol_VersiongtERKS1_:
   50|  11.6k|bool Protocol_Version::operator>(const Protocol_Version& other) const {
   51|  11.6k|   if(this->is_datagram_protocol() != other.is_datagram_protocol()) {
  ------------------
  |  Branch (51:7): [True: 0, False: 11.6k]
  ------------------
   52|      0|      throw TLS_Exception(Alert::ProtocolVersion, "Version comparing " + to_string() + " with " + other.to_string());
   53|      0|   }
   54|       |
   55|  11.6k|   if(this->is_datagram_protocol()) {
  ------------------
  |  Branch (55:7): [True: 2.97k, False: 8.64k]
  ------------------
   56|  2.97k|      return m_version < other.m_version;  // goes backwards
   57|  2.97k|   }
   58|       |
   59|  8.64k|   return m_version > other.m_version;
   60|  11.6k|}

_ZN5Botan15allocate_memoryEmm:
   20|   114k|BOTAN_MALLOC_FN void* allocate_memory(size_t elems, size_t elem_size) {
   21|   114k|   if(elems == 0 || elem_size == 0) {
  ------------------
  |  Branch (21:7): [True: 0, False: 114k]
  |  Branch (21:21): [True: 0, False: 114k]
  ------------------
   22|      0|      return nullptr;
   23|      0|   }
   24|       |
   25|       |   // Some calloc implementations do not check for overflow (?!?)
   26|       |
   27|   114k|   if(!BOTAN_CHECKED_MUL(elems, elem_size).has_value()) {
  ------------------
  |  |   74|   114k|#define BOTAN_CHECKED_MUL(x, y) checked_mul(x, y)
  ------------------
  |  Branch (27:7): [True: 0, False: 114k]
  ------------------
   28|      0|      throw std::bad_alloc();
   29|      0|   }
   30|       |
   31|       |#if defined(BOTAN_HAS_LOCKING_ALLOCATOR)
   32|       |   if(void* p = mlock_allocator::instance().allocate(elems, elem_size)) {
   33|       |      return p;
   34|       |   }
   35|       |#endif
   36|       |
   37|       |#if defined(BOTAN_TARGET_OS_HAS_ALLOC_CONCEAL)
   38|       |   void* ptr = ::calloc_conceal(elems, elem_size);
   39|       |#else
   40|   114k|   void* ptr = std::calloc(elems, elem_size);  // NOLINT(*-no-malloc)
   41|   114k|#endif
   42|   114k|   if(!ptr) {
  ------------------
  |  Branch (42:7): [True: 0, False: 114k]
  ------------------
   43|      0|      [[unlikely]] throw std::bad_alloc();
   44|      0|   }
   45|   114k|   return ptr;
   46|   114k|}
_ZN5Botan17deallocate_memoryEPvmm:
   48|   114k|void deallocate_memory(void* p, size_t elems, size_t elem_size) {
   49|   114k|   if(p == nullptr) {
  ------------------
  |  Branch (49:7): [True: 0, False: 114k]
  ------------------
   50|      0|      [[unlikely]] return;
   51|      0|   }
   52|       |
   53|   114k|   secure_scrub_memory(p, elems * elem_size);
   54|       |
   55|       |#if defined(BOTAN_HAS_LOCKING_ALLOCATOR)
   56|       |   if(mlock_allocator::instance().deallocate(p, elems, elem_size)) {
   57|       |      return;
   58|       |   }
   59|       |#endif
   60|       |
   61|   114k|   std::free(p);  // NOLINT(*-no-malloc)
   62|   114k|}

_ZN5Botan22throw_invalid_argumentEPKcS1_S1_:
   21|     58|void throw_invalid_argument(const char* message, const char* func, const char* file) {
   22|     58|   throw Invalid_Argument(fmt("{} in {}:{}", message, func, file));
   23|     58|}
_ZN5Botan19throw_invalid_stateEPKcS1_S1_:
   25|     14|void throw_invalid_state(const char* expr, const char* func, const char* file) {
   26|     14|   throw Invalid_State(fmt("Invalid state: expr {} was false in {}:{}", expr, func, file));
   27|     14|}

_ZN5Botan12ucs2_to_utf8EPKhm:
   54|    332|std::string ucs2_to_utf8(const uint8_t ucs2[], size_t len) {
   55|    332|   if(len % 2 != 0) {
  ------------------
  |  Branch (55:7): [True: 2, False: 330]
  ------------------
   56|      2|      throw Decoding_Error("Invalid length for UCS-2 string");
   57|      2|   }
   58|       |
   59|    330|   const size_t chars = len / 2;
   60|       |
   61|    330|   std::string s;
   62|  2.00k|   for(size_t i = 0; i != chars; ++i) {
  ------------------
  |  Branch (62:22): [True: 1.67k, False: 330]
  ------------------
   63|  1.67k|      const uint32_t c = load_be<uint16_t>(ucs2, i);
   64|  1.67k|      append_utf8_for(s, c);
   65|  1.67k|   }
   66|       |
   67|    330|   return s;
   68|    332|}
_ZN5Botan12ucs4_to_utf8EPKhm:
   70|    688|std::string ucs4_to_utf8(const uint8_t ucs4[], size_t len) {
   71|    688|   if(len % 4 != 0) {
  ------------------
  |  Branch (71:7): [True: 3, False: 685]
  ------------------
   72|      3|      throw Decoding_Error("Invalid length for UCS-4 string");
   73|      3|   }
   74|       |
   75|    685|   const size_t chars = len / 4;
   76|       |
   77|    685|   std::string s;
   78|  1.02k|   for(size_t i = 0; i != chars; ++i) {
  ------------------
  |  Branch (78:22): [True: 344, False: 685]
  ------------------
   79|    344|      const uint32_t c = load_be<uint32_t>(ucs4, i);
   80|    344|      append_utf8_for(s, c);
   81|    344|   }
   82|       |
   83|    685|   return s;
   84|    688|}
_ZN5Botan14latin1_to_utf8EPKhm:
   89|  1.28k|std::string latin1_to_utf8(const uint8_t chars[], size_t len) {
   90|  1.28k|   std::string s;
   91|  11.0k|   for(size_t i = 0; i != len; ++i) {
  ------------------
  |  Branch (91:22): [True: 9.80k, False: 1.28k]
  ------------------
   92|  9.80k|      const uint32_t c = static_cast<uint8_t>(chars[i]);
   93|  9.80k|      append_utf8_for(s, c);
   94|  9.80k|   }
   95|  1.28k|   return s;
   96|  1.28k|}
_ZN5Botan23format_char_for_displayEc:
   98|     26|std::string format_char_for_display(char c) {
   99|     26|   std::ostringstream oss;
  100|       |
  101|     26|   oss << "'";
  102|       |
  103|     26|   if(c == '\t') {
  ------------------
  |  Branch (103:7): [True: 0, False: 26]
  ------------------
  104|      0|      oss << "\\t";
  105|     26|   } else if(c == '\n') {
  ------------------
  |  Branch (105:14): [True: 0, False: 26]
  ------------------
  106|      0|      oss << "\\n";
  107|     26|   } else if(c == '\r') {
  ------------------
  |  Branch (107:14): [True: 0, False: 26]
  ------------------
  108|      0|      oss << "\\r";
  109|     26|   } else if(static_cast<unsigned char>(c) >= 128) {
  ------------------
  |  Branch (109:14): [True: 13, False: 13]
  ------------------
  110|     13|      unsigned char z = static_cast<unsigned char>(c);
  111|     13|      oss << "\\x" << std::hex << std::uppercase << static_cast<int>(z);
  112|     13|   } else {
  113|     13|      oss << c;
  114|     13|   }
  115|       |
  116|     26|   oss << "'";
  117|       |
  118|     26|   return oss.str();
  119|     26|}
charset.cpp:_ZN5Botan12_GLOBAL__N_115append_utf8_forERNSt3__112basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEEj:
   18|  11.8k|void append_utf8_for(std::string& s, uint32_t c) {
   19|  11.8k|   if(c >= 0xD800 && c < 0xE000) {
  ------------------
  |  Branch (19:7): [True: 687, False: 11.1k]
  |  Branch (19:22): [True: 17, False: 670]
  ------------------
   20|     17|      throw Decoding_Error("Invalid Unicode character");
   21|     17|   }
   22|       |
   23|  11.8k|   if(c <= 0x7F) {
  ------------------
  |  Branch (23:7): [True: 7.50k, False: 4.29k]
  ------------------
   24|  7.50k|      const uint8_t b0 = static_cast<uint8_t>(c);
   25|  7.50k|      s.push_back(static_cast<char>(b0));
   26|  7.50k|   } else if(c <= 0x7FF) {
  ------------------
  |  Branch (26:14): [True: 2.76k, False: 1.53k]
  ------------------
   27|  2.76k|      const uint8_t b0 = 0xC0 | static_cast<uint8_t>(c >> 6);
   28|  2.76k|      const uint8_t b1 = 0x80 | static_cast<uint8_t>(c & 0x3F);
   29|  2.76k|      s.push_back(static_cast<char>(b0));
   30|  2.76k|      s.push_back(static_cast<char>(b1));
   31|  2.76k|   } else if(c <= 0xFFFF) {
  ------------------
  |  Branch (31:14): [True: 1.27k, False: 256]
  ------------------
   32|  1.27k|      const uint8_t b0 = 0xE0 | static_cast<uint8_t>(c >> 12);
   33|  1.27k|      const uint8_t b1 = 0x80 | static_cast<uint8_t>((c >> 6) & 0x3F);
   34|  1.27k|      const uint8_t b2 = 0x80 | static_cast<uint8_t>(c & 0x3F);
   35|  1.27k|      s.push_back(static_cast<char>(b0));
   36|  1.27k|      s.push_back(static_cast<char>(b1));
   37|  1.27k|      s.push_back(static_cast<char>(b2));
   38|  1.27k|   } else if(c <= 0x10FFFF) {
  ------------------
  |  Branch (38:14): [True: 201, False: 55]
  ------------------
   39|    201|      const uint8_t b0 = 0xF0 | static_cast<uint8_t>(c >> 18);
   40|    201|      const uint8_t b1 = 0x80 | static_cast<uint8_t>((c >> 12) & 0x3F);
   41|    201|      const uint8_t b2 = 0x80 | static_cast<uint8_t>((c >> 6) & 0x3F);
   42|    201|      const uint8_t b3 = 0x80 | static_cast<uint8_t>(c & 0x3F);
   43|    201|      s.push_back(static_cast<char>(b0));
   44|    201|      s.push_back(static_cast<char>(b1));
   45|    201|      s.push_back(static_cast<char>(b2));
   46|    201|      s.push_back(static_cast<char>(b3));
   47|    201|   } else {
   48|     55|      throw Decoding_Error("Invalid Unicode character");
   49|     55|   }
   50|  11.8k|}

_ZN5Botan5CPUID10CPUID_DataC2Ev:
  122|      1|CPUID::CPUID_Data::CPUID_Data() {
  123|      1|   m_processor_features = 0;
  124|       |
  125|      1|#if defined(BOTAN_TARGET_CPU_IS_PPC_FAMILY) || defined(BOTAN_TARGET_CPU_IS_ARM_FAMILY) || \
  126|      1|   defined(BOTAN_TARGET_CPU_IS_X86_FAMILY)
  127|       |
  128|      1|   m_processor_features = detect_cpu_features();
  129|       |
  130|      1|#endif
  131|       |
  132|      1|   m_processor_features |= CPUID::CPUID_INITIALIZED_BIT;
  133|       |
  134|      1|   if(runtime_check_if_big_endian()) {
  ------------------
  |  Branch (134:7): [True: 0, False: 1]
  ------------------
  135|      0|      m_processor_features |= CPUID::CPUID_IS_BIG_ENDIAN_BIT;
  136|      0|   }
  137|       |
  138|      1|   std::string clear_cpuid_env;
  139|      1|   if(OS::read_env_variable(clear_cpuid_env, "BOTAN_CLEAR_CPUID")) {
  ------------------
  |  Branch (139:7): [True: 0, False: 1]
  ------------------
  140|      0|      for(const auto& cpuid : split_on(clear_cpuid_env, ',')) {
  ------------------
  |  Branch (140:29): [True: 0, False: 0]
  ------------------
  141|      0|         for(auto& bit : CPUID::bit_from_string(cpuid)) {
  ------------------
  |  Branch (141:24): [True: 0, False: 0]
  ------------------
  142|      0|            const uint32_t cleared = ~static_cast<uint32_t>(bit);
  143|      0|            m_processor_features &= cleared;
  144|      0|         }
  145|      0|      }
  146|      0|   }
  147|      1|}
cpuid.cpp:_ZN5Botan12_GLOBAL__N_127runtime_check_if_big_endianEv:
   95|      1|bool runtime_check_if_big_endian() {
   96|       |   // Check runtime endian
   97|      1|   const uint32_t endian32 = 0x01234567;
   98|      1|   const uint8_t* e8 = reinterpret_cast<const uint8_t*>(&endian32);
   99|       |
  100|      1|   bool is_big_endian = false;
  101|       |
  102|      1|   if(e8[0] == 0x01 && e8[1] == 0x23 && e8[2] == 0x45 && e8[3] == 0x67) {
  ------------------
  |  Branch (102:7): [True: 0, False: 1]
  |  Branch (102:24): [True: 0, False: 0]
  |  Branch (102:41): [True: 0, False: 0]
  |  Branch (102:58): [True: 0, False: 0]
  ------------------
  103|      0|      is_big_endian = true;
  104|      1|   } else if(e8[0] == 0x67 && e8[1] == 0x45 && e8[2] == 0x23 && e8[3] == 0x01) {
  ------------------
  |  Branch (104:14): [True: 1, False: 0]
  |  Branch (104:31): [True: 1, False: 0]
  |  Branch (104:48): [True: 1, False: 0]
  |  Branch (104:65): [True: 1, False: 0]
  ------------------
  105|      1|      is_big_endian = false;
  106|      1|   } else {
  107|      0|      throw Internal_Error("Unexpected endian at runtime, neither big nor little");
  108|      0|   }
  109|       |
  110|       |   // If we were compiled with a known endian, verify it matches at runtime
  111|      1|#if defined(BOTAN_TARGET_CPU_IS_LITTLE_ENDIAN)
  112|      1|   BOTAN_ASSERT(!is_big_endian, "Build and runtime endian match");
  ------------------
  |  |   51|      1|   do {                                                                                 \
  |  |   52|      1|      if(!(expr))                                                                       \
  |  |  ------------------
  |  |  |  Branch (52:10): [True: 0, False: 1]
  |  |  ------------------
  |  |   53|      1|         Botan::assertion_failure(#expr, assertion_made, __func__, __FILE__, __LINE__); \
  |  |   54|      1|   } while(0)
  |  |  ------------------
  |  |  |  Branch (54:12): [Folded - Ignored]
  |  |  ------------------
  ------------------
  113|       |#elif defined(BOTAN_TARGET_CPU_IS_BIG_ENDIAN)
  114|       |   BOTAN_ASSERT(is_big_endian, "Build and runtime endian match");
  115|       |#endif
  116|       |
  117|      1|   return is_big_endian;
  118|      1|}

_ZN5Botan5CPUID10CPUID_Data19detect_cpu_featuresEv:
   71|      1|uint32_t CPUID::CPUID_Data::detect_cpu_features() {
   72|      1|   uint32_t features_detected = 0;
   73|      1|   uint32_t cpuid[4] = {0};
   74|      1|   bool has_os_ymm_support = false;
   75|      1|   bool has_os_zmm_support = false;
   76|       |
   77|       |   // CPUID 0: vendor identification, max sublevel
   78|      1|   invoke_cpuid(0, cpuid);
   79|       |
   80|      1|   const uint32_t max_supported_sublevel = cpuid[0];
   81|       |
   82|      1|   if(max_supported_sublevel >= 1) {
  ------------------
  |  Branch (82:7): [True: 1, False: 0]
  ------------------
   83|       |      // CPUID 1: feature bits
   84|      1|      invoke_cpuid(1, cpuid);
   85|      1|      const uint64_t flags0 = (static_cast<uint64_t>(cpuid[2]) << 32) | cpuid[3];
   86|       |
   87|      1|      enum x86_CPUID_1_bits : uint64_t {
   88|      1|         RDTSC = (1ULL << 4),
   89|      1|         SSE2 = (1ULL << 26),
   90|      1|         CLMUL = (1ULL << 33),
   91|      1|         SSSE3 = (1ULL << 41),
   92|      1|         AESNI = (1ULL << 57),
   93|      1|         OSXSAVE = (1ULL << 59),
   94|      1|         AVX = (1ULL << 60),
   95|      1|         RDRAND = (1ULL << 62)
   96|      1|      };
   97|       |
   98|      1|      if(flags0 & x86_CPUID_1_bits::RDTSC) {
  ------------------
  |  Branch (98:10): [True: 1, False: 0]
  ------------------
   99|      1|         features_detected |= CPUID::CPUID_RDTSC_BIT;
  100|      1|      }
  101|      1|      if(flags0 & x86_CPUID_1_bits::SSE2) {
  ------------------
  |  Branch (101:10): [True: 1, False: 0]
  ------------------
  102|      1|         features_detected |= CPUID::CPUID_SSE2_BIT;
  103|      1|      }
  104|      1|      if(flags0 & x86_CPUID_1_bits::CLMUL) {
  ------------------
  |  Branch (104:10): [True: 1, False: 0]
  ------------------
  105|      1|         features_detected |= CPUID::CPUID_CLMUL_BIT;
  106|      1|      }
  107|      1|      if(flags0 & x86_CPUID_1_bits::SSSE3) {
  ------------------
  |  Branch (107:10): [True: 1, False: 0]
  ------------------
  108|      1|         features_detected |= CPUID::CPUID_SSSE3_BIT;
  109|      1|      }
  110|      1|      if(flags0 & x86_CPUID_1_bits::AESNI) {
  ------------------
  |  Branch (110:10): [True: 1, False: 0]
  ------------------
  111|      1|         features_detected |= CPUID::CPUID_AESNI_BIT;
  112|      1|      }
  113|      1|      if(flags0 & x86_CPUID_1_bits::RDRAND) {
  ------------------
  |  Branch (113:10): [True: 1, False: 0]
  ------------------
  114|      1|         features_detected |= CPUID::CPUID_RDRAND_BIT;
  115|      1|      }
  116|       |
  117|      1|      if((flags0 & x86_CPUID_1_bits::AVX) && (flags0 & x86_CPUID_1_bits::OSXSAVE)) {
  ------------------
  |  Branch (117:10): [True: 1, False: 0]
  |  Branch (117:46): [True: 1, False: 0]
  ------------------
  118|      1|         const uint64_t xcr_flags = xgetbv();
  119|      1|         if((xcr_flags & 0x6) == 0x6) {
  ------------------
  |  Branch (119:13): [True: 1, False: 0]
  ------------------
  120|      1|            has_os_ymm_support = true;
  121|      1|            has_os_zmm_support = (xcr_flags & 0xE0) == 0xE0;
  122|      1|         }
  123|      1|      }
  124|      1|   }
  125|       |
  126|      1|   if(max_supported_sublevel >= 7) {
  ------------------
  |  Branch (126:7): [True: 1, False: 0]
  ------------------
  127|      1|      clear_mem(cpuid, 4);
  128|      1|      invoke_cpuid_sublevel(7, 0, cpuid);
  129|       |
  130|      1|      enum x86_CPUID_7_bits : uint64_t {
  131|      1|         BMI1 = (1ULL << 3),
  132|      1|         AVX2 = (1ULL << 5),
  133|      1|         BMI2 = (1ULL << 8),
  134|      1|         AVX512_F = (1ULL << 16),
  135|      1|         AVX512_DQ = (1ULL << 17),
  136|      1|         RDSEED = (1ULL << 18),
  137|      1|         ADX = (1ULL << 19),
  138|      1|         AVX512_IFMA = (1ULL << 21),
  139|      1|         SHA = (1ULL << 29),
  140|      1|         AVX512_BW = (1ULL << 30),
  141|      1|         AVX512_VL = (1ULL << 31),
  142|      1|         AVX512_VBMI = (1ULL << 33),
  143|      1|         AVX512_VBMI2 = (1ULL << 38),
  144|      1|         AVX512_VAES = (1ULL << 41),
  145|      1|         AVX512_VCLMUL = (1ULL << 42),
  146|      1|         AVX512_VBITALG = (1ULL << 44),
  147|      1|      };
  148|       |
  149|      1|      const uint64_t flags7 = (static_cast<uint64_t>(cpuid[2]) << 32) | cpuid[1];
  150|       |
  151|      1|      if((flags7 & x86_CPUID_7_bits::AVX2) && has_os_ymm_support) {
  ------------------
  |  Branch (151:10): [True: 1, False: 0]
  |  Branch (151:47): [True: 1, False: 0]
  ------------------
  152|      1|         features_detected |= CPUID::CPUID_AVX2_BIT;
  153|      1|      }
  154|      1|      if(flags7 & x86_CPUID_7_bits::RDSEED) {
  ------------------
  |  Branch (154:10): [True: 1, False: 0]
  ------------------
  155|      1|         features_detected |= CPUID::CPUID_RDSEED_BIT;
  156|      1|      }
  157|      1|      if(flags7 & x86_CPUID_7_bits::ADX) {
  ------------------
  |  Branch (157:10): [True: 1, False: 0]
  ------------------
  158|      1|         features_detected |= CPUID::CPUID_ADX_BIT;
  159|      1|      }
  160|      1|      if(flags7 & x86_CPUID_7_bits::SHA) {
  ------------------
  |  Branch (160:10): [True: 0, False: 1]
  ------------------
  161|      0|         features_detected |= CPUID::CPUID_SHA_BIT;
  162|      0|      }
  163|       |
  164|       |      /*
  165|       |      We only set the BMI bit if both BMI1 and BMI2 are supported, since
  166|       |      typically we want to use both extensions in the same code.
  167|       |      */
  168|      1|      if((flags7 & x86_CPUID_7_bits::BMI1) && (flags7 & x86_CPUID_7_bits::BMI2)) {
  ------------------
  |  Branch (168:10): [True: 1, False: 0]
  |  Branch (168:47): [True: 1, False: 0]
  ------------------
  169|      1|         features_detected |= CPUID::CPUID_BMI_BIT;
  170|      1|      }
  171|       |
  172|      1|      if((flags7 & x86_CPUID_7_bits::AVX512_F) && has_os_zmm_support) {
  ------------------
  |  Branch (172:10): [True: 0, False: 1]
  |  Branch (172:51): [True: 0, False: 0]
  ------------------
  173|      0|         const uint64_t AVX512_PROFILE_FLAGS = x86_CPUID_7_bits::AVX512_F | x86_CPUID_7_bits::AVX512_DQ |
  174|      0|                                               x86_CPUID_7_bits::AVX512_IFMA | x86_CPUID_7_bits::AVX512_BW |
  175|      0|                                               x86_CPUID_7_bits::AVX512_VL | x86_CPUID_7_bits::AVX512_VBMI |
  176|      0|                                               x86_CPUID_7_bits::AVX512_VBMI2 | x86_CPUID_7_bits::AVX512_VBITALG;
  177|       |
  178|       |         /*
  179|       |         We only enable AVX512 support if all of the above flags are available
  180|       |
  181|       |         This is more than we strictly need for most uses, however it also has
  182|       |         the effect of preventing execution of AVX512 codepaths on cores that
  183|       |         have serious downclocking problems when AVX512 code executes,
  184|       |         especially Intel Skylake.
  185|       |
  186|       |         VBMI2/VBITALG are the key flags here as they restrict us to Intel Ice
  187|       |         Lake/Rocket Lake, or AMD Zen4, all of which do not have penalties for
  188|       |         executing AVX512.
  189|       |
  190|       |         There is nothing stopping some future processor from supporting the
  191|       |         above flags and having AVX512 penalties, but maybe you should not have
  192|       |         bought such a processor.
  193|       |         */
  194|      0|         if((flags7 & AVX512_PROFILE_FLAGS) == AVX512_PROFILE_FLAGS) {
  ------------------
  |  Branch (194:13): [True: 0, False: 0]
  ------------------
  195|      0|            features_detected |= CPUID::CPUID_AVX512_BIT;
  196|       |
  197|      0|            if(flags7 & x86_CPUID_7_bits::AVX512_VAES) {
  ------------------
  |  Branch (197:16): [True: 0, False: 0]
  ------------------
  198|      0|               features_detected |= CPUID::CPUID_AVX512_AES_BIT;
  199|      0|            }
  200|      0|            if(flags7 & x86_CPUID_7_bits::AVX512_VCLMUL) {
  ------------------
  |  Branch (200:16): [True: 0, False: 0]
  ------------------
  201|      0|               features_detected |= CPUID::CPUID_AVX512_CLMUL_BIT;
  202|      0|            }
  203|      0|         }
  204|      0|      }
  205|      1|   }
  206|       |
  207|       |   /*
  208|       |   * If we don't have access to CPUID, we can still safely assume that
  209|       |   * any x86-64 processor has SSE2 and RDTSC
  210|       |   */
  211|      1|   #if defined(BOTAN_TARGET_ARCH_IS_X86_64)
  212|      1|   if(features_detected == 0) {
  ------------------
  |  Branch (212:7): [True: 0, False: 1]
  ------------------
  213|      0|      features_detected |= CPUID::CPUID_SSE2_BIT;
  214|      0|      features_detected |= CPUID::CPUID_RDTSC_BIT;
  215|      0|   }
  216|      1|   #endif
  217|       |
  218|      1|   return features_detected;
  219|      1|}
cpuid_x86.cpp:_ZN5Botan12_GLOBAL__N_112invoke_cpuidEjPj:
   33|      2|void invoke_cpuid(uint32_t type, uint32_t out[4]) {
   34|       |   #if defined(BOTAN_BUILD_COMPILER_IS_MSVC) || defined(BOTAN_BUILD_COMPILER_IS_INTEL)
   35|       |   __cpuid((int*)out, type);
   36|       |
   37|       |   #elif defined(BOTAN_BUILD_COMPILER_IS_GCC) || defined(BOTAN_BUILD_COMPILER_IS_CLANG)
   38|      2|   __get_cpuid(type, out, out + 1, out + 2, out + 3);
   39|       |
   40|       |   #elif defined(BOTAN_USE_GCC_INLINE_ASM)
   41|       |   asm("cpuid\n\t" : "=a"(out[0]), "=b"(out[1]), "=c"(out[2]), "=d"(out[3]) : "0"(type));
   42|       |
   43|       |   #else
   44|       |      #warning "No way of calling x86 cpuid instruction for this compiler"
   45|       |   clear_mem(out, 4);
   46|       |   #endif
   47|      2|}
cpuid_x86.cpp:_ZN5Botan12_GLOBAL__N_16xgetbvEv:
   49|      1|BOTAN_FUNC_ISA("xsave") uint64_t xgetbv() {
   50|      1|   return _xgetbv(0);
   51|      1|}
cpuid_x86.cpp:_ZN5Botan12_GLOBAL__N_121invoke_cpuid_sublevelEjjPj:
   53|      1|void invoke_cpuid_sublevel(uint32_t type, uint32_t level, uint32_t out[4]) {
   54|       |   #if defined(BOTAN_BUILD_COMPILER_IS_MSVC)
   55|       |   __cpuidex((int*)out, type, level);
   56|       |
   57|       |   #elif defined(BOTAN_BUILD_COMPILER_IS_GCC) || defined(BOTAN_BUILD_COMPILER_IS_CLANG)
   58|      1|   __cpuid_count(type, level, out[0], out[1], out[2], out[3]);
   59|       |
   60|       |   #elif defined(BOTAN_USE_GCC_INLINE_ASM)
   61|       |   asm("cpuid\n\t" : "=a"(out[0]), "=b"(out[1]), "=c"(out[2]), "=d"(out[3]) : "0"(type), "2"(level));
   62|       |
   63|       |   #else
   64|       |      #warning "No way of calling x86 cpuid instruction for this compiler"
   65|       |   clear_mem(out, 4);
   66|       |   #endif
   67|      1|}

_ZN5Botan10DataSource9read_byteERh:
   26|   397k|size_t DataSource::read_byte(uint8_t& out) {
   27|   397k|   return read(&out, 1);
   28|   397k|}
_ZNK5Botan10DataSource9peek_byteERh:
   33|  1.78k|size_t DataSource::peek_byte(uint8_t& out) const {
   34|  1.78k|   return peek(&out, 1, 0);
   35|  1.78k|}
_ZN5Botan10DataSource12discard_nextEm:
   40|  33.8k|size_t DataSource::discard_next(size_t n) {
   41|  33.8k|   uint8_t buf[64] = {0};
   42|  33.8k|   size_t discarded = 0;
   43|       |
   44|  80.4k|   while(n) {
  ------------------
  |  Branch (44:10): [True: 46.7k, False: 33.7k]
  ------------------
   45|  46.7k|      const size_t got = this->read(buf, std::min(n, sizeof(buf)));
   46|  46.7k|      discarded += got;
   47|  46.7k|      n -= got;
   48|       |
   49|  46.7k|      if(got == 0) {
  ------------------
  |  Branch (49:10): [True: 130, False: 46.5k]
  ------------------
   50|    130|         break;
   51|    130|      }
   52|  46.7k|   }
   53|       |
   54|  33.8k|   return discarded;
   55|  33.8k|}
_ZN5Botan17DataSource_Memory4readEPhm:
   60|   248k|size_t DataSource_Memory::read(uint8_t out[], size_t length) {
   61|   248k|   const size_t got = std::min<size_t>(m_source.size() - m_offset, length);
   62|   248k|   copy_mem(out, m_source.data() + m_offset, got);
   63|   248k|   m_offset += got;
   64|   248k|   return got;
   65|   248k|}
_ZN5Botan17DataSource_Memory15check_availableEm:
   67|  11.5k|bool DataSource_Memory::check_available(size_t n) {
   68|  11.5k|   return (n <= (m_source.size() - m_offset));
   69|  11.5k|}
_ZNK5Botan17DataSource_Memory4peekEPhmm:
   74|  25.3k|size_t DataSource_Memory::peek(uint8_t out[], size_t length, size_t peek_offset) const {
   75|  25.3k|   const size_t bytes_left = m_source.size() - m_offset;
   76|  25.3k|   if(peek_offset >= bytes_left) {
  ------------------
  |  Branch (76:7): [True: 12.1k, False: 13.1k]
  ------------------
   77|  12.1k|      return 0;
   78|  12.1k|   }
   79|       |
   80|  13.1k|   const size_t got = std::min(bytes_left - peek_offset, length);
   81|  13.1k|   copy_mem(out, &m_source[m_offset + peek_offset], got);
   82|  13.1k|   return got;
   83|  25.3k|}
_ZNK5Botan17DataSource_Memory11end_of_dataEv:
   88|  6.34k|bool DataSource_Memory::end_of_data() const {
   89|  6.34k|   return (m_offset == m_source.size());
   90|  6.34k|}

_ZN5Botan9ExceptionC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
   71|  5.66k|Exception::Exception(std::string_view msg) : m_msg(msg) {}
_ZN5Botan9ExceptionC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEERKSt9exception:
   73|  1.59k|Exception::Exception(std::string_view msg, const std::exception& e) : m_msg(fmt("{} failed with {}", msg, e.what())) {}
_ZN5Botan9ExceptionC2EPKcNSt3__117basic_string_viewIcNS3_11char_traitsIcEEEE:
   75|     50|Exception::Exception(const char* prefix, std::string_view msg) : m_msg(fmt("{} {}", prefix, msg)) {}
_ZN5Botan16Invalid_ArgumentC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
   77|    143|Invalid_Argument::Invalid_Argument(std::string_view msg) : Exception(msg) {}
_ZN5Botan14Encoding_ErrorC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
  123|     49|Encoding_Error::Encoding_Error(std::string_view name) : Exception("Encoding error:", name) {}
_ZN5Botan14Decoding_ErrorC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
  125|  2.91k|Decoding_Error::Decoding_Error(std::string_view name) : Exception(name) {}
_ZN5Botan14Decoding_ErrorC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEERKSt9exception:
  130|  1.59k|Decoding_Error::Decoding_Error(std::string_view msg, const std::exception& e) : Exception(msg, e) {}
_ZN5Botan15Stream_IO_ErrorC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
  135|      1|Stream_IO_Error::Stream_IO_Error(std::string_view err) : Exception("I/O error:", err) {}

_ZN5Botan19secure_scrub_memoryEPvm:
   87|   153k|void secure_scrub_memory(void* ptr, size_t n) {
   88|       |#if defined(BOTAN_TARGET_OS_HAS_RTLSECUREZEROMEMORY)
   89|       |   ::RtlSecureZeroMemory(ptr, n);
   90|       |
   91|       |#elif defined(BOTAN_TARGET_OS_HAS_EXPLICIT_BZERO)
   92|   153k|   ::explicit_bzero(ptr, n);
   93|       |
   94|       |#elif defined(BOTAN_TARGET_OS_HAS_EXPLICIT_MEMSET)
   95|       |   (void)::explicit_memset(ptr, 0, n);
   96|       |
   97|       |#elif defined(BOTAN_USE_VOLATILE_MEMSET_FOR_ZERO) && (BOTAN_USE_VOLATILE_MEMSET_FOR_ZERO == 1)
   98|       |   /*
   99|       |   Call memset through a static volatile pointer, which the compiler
  100|       |   should not elide. This construct should be safe in conforming
  101|       |   compilers, but who knows. I did confirm that on x86-64 GCC 6.1 and
  102|       |   Clang 3.8 both create code that saves the memset address in the
  103|       |   data segment and unconditionally loads and jumps to that address.
  104|       |   */
  105|       |   static void* (*const volatile memset_ptr)(void*, int, size_t) = std::memset;
  106|       |   (memset_ptr)(ptr, 0, n);
  107|       |#else
  108|       |
  109|       |   volatile uint8_t* p = reinterpret_cast<volatile uint8_t*>(ptr);
  110|       |
  111|       |   for(size_t i = 0; i != n; ++i)
  112|       |      p[i] = 0;
  113|       |#endif
  114|   153k|}
_ZN5Botan2OS10get_auxvalEm:
  128|      1|unsigned long OS::get_auxval(unsigned long id) {
  129|      1|#if defined(BOTAN_TARGET_OS_HAS_GETAUXVAL)
  130|      1|   return ::getauxval(id);
  131|       |#elif defined(BOTAN_TARGET_OS_IS_ANDROID) && defined(BOTAN_TARGET_ARCH_IS_ARM32)
  132|       |
  133|       |   if(id == 0)
  134|       |      return 0;
  135|       |
  136|       |   char** p = environ;
  137|       |
  138|       |   while(*p++ != nullptr)
  139|       |      ;
  140|       |
  141|       |   Elf32_auxv_t* e = reinterpret_cast<Elf32_auxv_t*>(p);
  142|       |
  143|       |   while(e != nullptr) {
  144|       |      if(e->a_type == id)
  145|       |         return e->a_un.a_val;
  146|       |      e++;
  147|       |   }
  148|       |
  149|       |   return 0;
  150|       |#elif defined(BOTAN_TARGET_OS_HAS_ELF_AUX_INFO)
  151|       |   unsigned long auxinfo = 0;
  152|       |   ::elf_aux_info(static_cast<int>(id), &auxinfo, sizeof(auxinfo));
  153|       |   return auxinfo;
  154|       |#elif defined(BOTAN_TARGET_OS_HAS_AUXINFO)
  155|       |   for(const AuxInfo* auxinfo = static_cast<AuxInfo*>(::_dlauxinfo()); auxinfo != AT_NULL; ++auxinfo) {
  156|       |      if(id == auxinfo->a_type)
  157|       |         return auxinfo->a_v;
  158|       |   }
  159|       |
  160|       |   return 0;
  161|       |#else
  162|       |   BOTAN_UNUSED(id);
  163|       |   return 0;
  164|       |#endif
  165|      1|}
_ZN5Botan2OS27running_in_privileged_stateEv:
  167|      1|bool OS::running_in_privileged_state() {
  168|      1|#if defined(AT_SECURE)
  169|      1|   return OS::get_auxval(AT_SECURE) != 0;
  170|       |#elif defined(BOTAN_TARGET_OS_HAS_POSIX1)
  171|       |   return (::getuid() != ::geteuid()) || (::getgid() != ::getegid());
  172|       |#else
  173|       |   return false;
  174|       |#endif
  175|      1|}
_ZN5Botan2OS17read_env_variableERNSt3__112basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEENS1_17basic_string_viewIcS4_EE:
  409|      1|bool OS::read_env_variable(std::string& value_out, std::string_view name_view) {
  410|      1|   value_out = "";
  411|       |
  412|      1|   if(running_in_privileged_state()) {
  ------------------
  |  Branch (412:7): [True: 0, False: 1]
  ------------------
  413|      0|      return false;
  414|      0|   }
  415|       |
  416|       |#if defined(BOTAN_TARGET_OS_HAS_WIN32) && defined(BOTAN_BUILD_COMPILER_IS_MSVC)
  417|       |   const std::string name(name_view);
  418|       |   char val[128] = {0};
  419|       |   size_t req_size = 0;
  420|       |   if(getenv_s(&req_size, val, sizeof(val), name.c_str()) == 0) {
  421|       |      // Microsoft's implementation always writes a terminating \0,
  422|       |      // and includes it in the reported length of the environment variable
  423|       |      // if a value exists.
  424|       |      if(req_size > 0 && val[req_size - 1] == '\0') {
  425|       |         value_out = std::string(val);
  426|       |      } else {
  427|       |         value_out = std::string(val, req_size);
  428|       |      }
  429|       |      return true;
  430|       |   }
  431|       |#else
  432|      1|   const std::string name(name_view);
  433|      1|   if(const char* val = std::getenv(name.c_str())) {
  ------------------
  |  Branch (433:19): [True: 0, False: 1]
  ------------------
  434|      0|      value_out = val;
  435|      0|      return true;
  436|      0|   }
  437|      1|#endif
  438|       |
  439|      1|   return false;
  440|      1|}

_ZN5Botan9to_u32bitENSt3__117basic_string_viewIcNS0_11char_traitsIcEEEE:
   32|  9.61k|uint32_t to_u32bit(std::string_view str_view) {
   33|  9.61k|   const std::string str(str_view);
   34|       |
   35|       |   // std::stoul is not strict enough. Ensure that str is digit only [0-9]*
   36|  16.2k|   for(const char chr : str) {
  ------------------
  |  Branch (36:23): [True: 16.2k, False: 9.61k]
  ------------------
   37|  16.2k|      if(chr < '0' || chr > '9') {
  ------------------
  |  Branch (37:10): [True: 6, False: 16.2k]
  |  Branch (37:23): [True: 3, False: 16.2k]
  ------------------
   38|      9|         throw Invalid_Argument("to_u32bit invalid decimal string '" + str + "'");
   39|      9|      }
   40|  16.2k|   }
   41|       |
   42|  9.61k|   const unsigned long int x = std::stoul(str);
   43|       |
   44|  9.61k|   if constexpr(sizeof(unsigned long int) > 4) {
  ------------------
  |  Branch (44:17): [Folded - Ignored]
  ------------------
   45|       |      // x might be uint64
   46|  9.61k|      if(x > std::numeric_limits<uint32_t>::max()) {
  ------------------
  |  Branch (46:10): [True: 0, False: 9.61k]
  ------------------
   47|      0|         throw Invalid_Argument("Integer value of " + str + " exceeds 32 bit range");
   48|      0|      }
   49|  9.61k|   }
   50|       |
   51|  9.61k|   return static_cast<uint32_t>(x);
   52|  9.61k|}
_ZN5Botan8split_onENSt3__117basic_string_viewIcNS0_11char_traitsIcEEEEc:
  111|    211|std::vector<std::string> split_on(std::string_view str, char delim) {
  112|    211|   std::vector<std::string> elems;
  113|    211|   if(str.empty()) {
  ------------------
  |  Branch (113:7): [True: 0, False: 211]
  ------------------
  114|      0|      return elems;
  115|      0|   }
  116|       |
  117|    211|   std::string substr;
  118|  2.70k|   for(auto i = str.begin(); i != str.end(); ++i) {
  ------------------
  |  Branch (118:30): [True: 2.49k, False: 211]
  ------------------
  119|  2.49k|      if(*i == delim) {
  ------------------
  |  Branch (119:10): [True: 0, False: 2.49k]
  ------------------
  120|      0|         if(!substr.empty()) {
  ------------------
  |  Branch (120:13): [True: 0, False: 0]
  ------------------
  121|      0|            elems.push_back(substr);
  122|      0|         }
  123|      0|         substr.clear();
  124|  2.49k|      } else {
  125|  2.49k|         substr += *i;
  126|  2.49k|      }
  127|  2.49k|   }
  128|       |
  129|    211|   if(substr.empty()) {
  ------------------
  |  Branch (129:7): [True: 0, False: 211]
  ------------------
  130|      0|      throw Invalid_Argument(fmt("Unable to split string '{}", str));
  131|      0|   }
  132|    211|   elems.push_back(substr);
  133|       |
  134|    211|   return elems;
  135|    211|}

_ZN5Botan15AlternativeNameC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEES5_S5_S5_:
   27|  1.18k|                                 std::string_view ip) {
   28|  1.18k|   add_attribute("RFC822", email_addr);
   29|  1.18k|   add_attribute("DNS", dns);
   30|  1.18k|   add_attribute("URI", uri);
   31|  1.18k|   add_attribute("IP", ip);
   32|  1.18k|}
_ZN5Botan15AlternativeName13add_attributeENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEES5_:
   37|  4.74k|void AlternativeName::add_attribute(std::string_view type, std::string_view value) {
   38|  4.74k|   if(type.empty() || value.empty()) {
  ------------------
  |  Branch (38:7): [True: 0, False: 4.74k]
  |  Branch (38:23): [True: 4.74k, False: 0]
  ------------------
   39|  4.74k|      return;
   40|  4.74k|   }
   41|       |
   42|      0|   auto range = m_alt_info.equal_range(type);
   43|      0|   for(auto j = range.first; j != range.second; ++j) {
  ------------------
  |  Branch (43:30): [True: 0, False: 0]
  ------------------
   44|      0|      if(j->second == value) {
  ------------------
  |  Branch (44:10): [True: 0, False: 0]
  ------------------
   45|      0|         return;
   46|      0|      }
   47|      0|   }
   48|       |
   49|      0|   m_alt_info.emplace(type, value);
   50|      0|}

_ZN5Botan7X509_DN13add_attributeERKNS_3OIDERKNS_11ASN1_StringE:
  100|  4.17k|void X509_DN::add_attribute(const OID& oid, const ASN1_String& str) {
  101|  4.17k|   if(str.empty()) {
  ------------------
  |  Branch (101:7): [True: 2.57k, False: 1.60k]
  ------------------
  102|  2.57k|      return;
  103|  2.57k|   }
  104|       |
  105|  1.60k|   m_rdn.push_back(std::make_pair(oid, str));
  106|  1.60k|   m_dn_bits.clear();
  107|  1.60k|}
_ZNK5Botan7X509_DN14get_attributesEv:
  112|    272|std::multimap<OID, std::string> X509_DN::get_attributes() const {
  113|    272|   std::multimap<OID, std::string> retval;
  114|       |
  115|    272|   for(auto& i : m_rdn) {
  ------------------
  |  Branch (115:16): [True: 0, False: 272]
  ------------------
  116|      0|      multimap_insert(retval, i.first, i.second.value());
  117|      0|   }
  118|    272|   return retval;
  119|    272|}
_ZN5BotaneqERKNS_7X509_DNES2_:
  220|    136|bool operator==(const X509_DN& dn1, const X509_DN& dn2) {
  221|    136|   auto attr1 = dn1.get_attributes();
  222|    136|   auto attr2 = dn2.get_attributes();
  223|       |
  224|    136|   if(attr1.size() != attr2.size()) {
  ------------------
  |  Branch (224:7): [True: 0, False: 136]
  ------------------
  225|      0|      return false;
  226|      0|   }
  227|       |
  228|    136|   auto p1 = attr1.begin();
  229|    136|   auto p2 = attr2.begin();
  230|       |
  231|    136|   while(true) {
  ------------------
  |  Branch (231:10): [Folded - Ignored]
  ------------------
  232|    136|      if(p1 == attr1.end() && p2 == attr2.end()) {
  ------------------
  |  Branch (232:10): [True: 136, False: 0]
  |  Branch (232:10): [True: 136, False: 0]
  |  Branch (232:31): [True: 136, False: 0]
  ------------------
  233|    136|         break;
  234|    136|      }
  235|      0|      if(p1 == attr1.end()) {
  ------------------
  |  Branch (235:10): [True: 0, False: 0]
  ------------------
  236|      0|         return false;
  237|      0|      }
  238|      0|      if(p2 == attr2.end()) {
  ------------------
  |  Branch (238:10): [True: 0, False: 0]
  ------------------
  239|      0|         return false;
  240|      0|      }
  241|      0|      if(p1->first != p2->first) {
  ------------------
  |  Branch (241:10): [True: 0, False: 0]
  ------------------
  242|      0|         return false;
  243|      0|      }
  244|      0|      if(!x500_name_cmp(p1->second, p2->second)) {
  ------------------
  |  Branch (244:10): [True: 0, False: 0]
  ------------------
  245|      0|         return false;
  246|      0|      }
  247|      0|      ++p1;
  248|      0|      ++p2;
  249|      0|   }
  250|    136|   return true;
  251|    136|}
_ZN5Botan7X509_DN11decode_fromERNS_11BER_DecoderE:
  347|  4.51k|void X509_DN::decode_from(BER_Decoder& source) {
  348|  4.51k|   std::vector<uint8_t> bits;
  349|       |
  350|  4.51k|   source.start_sequence().raw_bytes(bits).end_cons();
  351|       |
  352|  4.51k|   BER_Decoder sequence(bits);
  353|       |
  354|  4.51k|   m_rdn.clear();
  355|       |
  356|  6.50k|   while(sequence.more_items()) {
  ------------------
  |  Branch (356:10): [True: 1.99k, False: 4.51k]
  ------------------
  357|  1.99k|      BER_Decoder rdn = sequence.start_set();
  358|       |
  359|  6.45k|      while(rdn.more_items()) {
  ------------------
  |  Branch (359:13): [True: 4.45k, False: 1.99k]
  ------------------
  360|  4.45k|         OID oid;
  361|  4.45k|         ASN1_String str;
  362|       |
  363|  4.45k|         rdn.start_sequence()
  364|  4.45k|            .decode(oid)
  365|  4.45k|            .decode(str)  // TODO support Any
  366|  4.45k|            .end_cons();
  367|       |
  368|  4.45k|         add_attribute(oid, str);
  369|  4.45k|      }
  370|  1.99k|   }
  371|       |
  372|       |   // Have to assign last as add_attribute zaps m_dn_bits
  373|  4.51k|   m_dn_bits = bits;
  374|  4.51k|}

_ZNK5Botan10Extensions20get_extension_objectERKNS_3OIDE:
  190|  1.49k|const Certificate_Extension* Extensions::get_extension_object(const OID& oid) const {
  191|  1.49k|   auto extn = m_extension_info.find(oid);
  192|  1.49k|   if(extn == m_extension_info.end()) {
  ------------------
  |  Branch (192:7): [True: 1.49k, False: 0]
  ------------------
  193|  1.49k|      return nullptr;
  194|  1.49k|   }
  195|       |
  196|      0|   return &extn->second.obj();
  197|  1.49k|}
_ZN5Botan10Extensions11decode_fromERNS_11BER_DecoderE:
  247|      4|void Extensions::decode_from(BER_Decoder& from_source) {
  248|      4|   m_extension_oids.clear();
  249|      4|   m_extension_info.clear();
  250|       |
  251|      4|   BER_Decoder sequence = from_source.start_sequence();
  252|       |
  253|      5|   while(sequence.more_items()) {
  ------------------
  |  Branch (253:10): [True: 1, False: 4]
  ------------------
  254|      1|      OID oid;
  255|      1|      bool critical;
  256|      1|      std::vector<uint8_t> bits;
  257|       |
  258|      1|      sequence.start_sequence()
  259|      1|         .decode(oid)
  260|      1|         .decode_optional(critical, ASN1_Type::Boolean, ASN1_Class::Universal, false)
  261|      1|         .decode(bits, ASN1_Type::OctetString)
  262|      1|         .end_cons();
  263|       |
  264|      1|      auto obj = create_extn_obj(oid, critical, bits);
  265|      1|      Extensions_Info info(critical, bits, std::move(obj));
  266|       |
  267|      1|      m_extension_oids.push_back(oid);
  268|      1|      m_extension_info.emplace(oid, info);
  269|      1|   }
  270|      4|   sequence.verify_end();
  271|      4|}

_ZN5Botan11X509_Object9load_dataERNS_10DataSourceE:
   24|  1.56k|void X509_Object::load_data(DataSource& in) {
   25|  1.56k|   try {
   26|  1.56k|      if(ASN1::maybe_BER(in) && !PEM_Code::matches(in)) {
  ------------------
  |  Branch (26:10): [True: 1.34k, False: 220]
  |  Branch (26:33): [True: 1.31k, False: 31]
  ------------------
   27|  1.31k|         BER_Decoder dec(in);
   28|  1.31k|         decode_from(dec);
   29|  1.31k|      } else {
   30|    251|         std::string got_label;
   31|    251|         DataSource_Memory ber(PEM_Code::decode(in, got_label));
   32|       |
   33|    251|         if(got_label != PEM_label()) {
  ------------------
  |  Branch (33:13): [True: 78, False: 173]
  ------------------
   34|     78|            bool is_alternate = false;
   35|     78|            for(std::string_view alt_label : alternate_PEM_labels()) {
  ------------------
  |  Branch (35:44): [True: 78, False: 77]
  ------------------
   36|     78|               if(got_label == alt_label) {
  ------------------
  |  Branch (36:19): [True: 1, False: 77]
  ------------------
   37|      1|                  is_alternate = true;
   38|      1|                  break;
   39|      1|               }
   40|     78|            }
   41|       |
   42|     78|            if(!is_alternate) {
  ------------------
  |  Branch (42:16): [True: 77, False: 1]
  ------------------
   43|     77|               throw Decoding_Error("Unexpected PEM label for " + PEM_label() + " of " + got_label);
   44|     77|            }
   45|     78|         }
   46|       |
   47|    174|         BER_Decoder dec(ber);
   48|    174|         decode_from(dec);
   49|    174|      }
   50|  1.56k|   } catch(Decoding_Error& e) {
   51|  1.28k|      throw Decoding_Error(PEM_label() + " decoding", e);
   52|  1.28k|   }
   53|  1.56k|}
_ZNK5Botan11X509_Object11encode_intoERNS_11DER_EncoderE:
   55|    136|void X509_Object::encode_into(DER_Encoder& to) const {
   56|    136|   to.start_sequence()
   57|    136|      .start_sequence()
   58|    136|      .raw_bytes(signed_body())
   59|    136|      .end_cons()
   60|    136|      .encode(signature_algorithm())
   61|    136|      .encode(signature(), ASN1_Type::BitString)
   62|    136|      .end_cons();
   63|    136|}
_ZN5Botan11X509_Object11decode_fromERNS_11BER_DecoderE:
   68|  1.31k|void X509_Object::decode_from(BER_Decoder& from) {
   69|  1.31k|   from.start_sequence()
   70|  1.31k|      .start_sequence()
   71|  1.31k|      .raw_bytes(m_tbs_bits)
   72|  1.31k|      .end_cons()
   73|  1.31k|      .decode(m_sig_algo)
   74|  1.31k|      .decode(m_sig, ASN1_Type::BitString)
   75|  1.31k|      .end_cons();
   76|       |
   77|  1.31k|   force_decode();
   78|  1.31k|}

_ZNK5Botan16X509_Certificate9PEM_labelEv:
   70|  1.44k|std::string X509_Certificate::PEM_label() const {
   71|  1.44k|   return "CERTIFICATE";
   72|  1.44k|}
_ZNK5Botan16X509_Certificate20alternate_PEM_labelsEv:
   74|     78|std::vector<std::string> X509_Certificate::alternate_PEM_labels() const {
   75|     78|   return {"X509 CERTIFICATE"};
   76|     78|}
_ZN5Botan16X509_CertificateC2ERKNSt3__16vectorIhNS1_9allocatorIhEEEE:
   82|  1.56k|X509_Certificate::X509_Certificate(const std::vector<uint8_t>& vec) {
   83|  1.56k|   DataSource_Memory src(vec.data(), vec.size());
   84|  1.56k|   load_data(src);
   85|  1.56k|}
_ZN5Botan16X509_Certificate12force_decodeEv:
  282|    593|void X509_Certificate::force_decode() {
  283|    593|   m_data.reset();
  284|    593|   m_data = parse_x509_cert_body(*this);
  285|    593|}
_ZNK5Botan16X509_Certificate4dataEv:
  287|     87|const X509_Certificate_Data& X509_Certificate::data() const {
  288|     87|   if(m_data == nullptr) {
  ------------------
  |  Branch (288:7): [True: 0, False: 87]
  ------------------
  289|      0|      throw Invalid_State("X509_Certificate uninitialized");
  290|      0|   }
  291|     87|   return *m_data;
  292|     87|}
_ZNK5Botan16X509_Certificate23subject_public_key_infoEv:
  326|     87|const std::vector<uint8_t>& X509_Certificate::subject_public_key_info() const {
  327|     87|   return data().m_subject_public_key_bits_seq;
  328|     87|}
_ZNK5Botan16X509_Certificate18subject_public_keyEv:
  546|     87|std::unique_ptr<Public_Key> X509_Certificate::subject_public_key() const {
  547|     87|   try {
  548|     87|      return std::unique_ptr<Public_Key>(X509::load_key(subject_public_key_info()));
  549|     87|   } catch(std::exception& e) {
  550|     87|      throw Decoding_Error("X509_Certificate::subject_public_key", e);
  551|     87|   }
  552|     87|}
x509cert.cpp:_ZN5Botan12_GLOBAL__N_120parse_x509_cert_bodyERKNS_11X509_ObjectE:
  101|    593|std::unique_ptr<X509_Certificate_Data> parse_x509_cert_body(const X509_Object& obj) {
  102|    593|   auto data = std::make_unique<X509_Certificate_Data>();
  103|       |
  104|    593|   BigInt serial_bn;
  105|    593|   BER_Object public_key;
  106|    593|   BER_Object v3_exts_data;
  107|       |
  108|    593|   BER_Decoder(obj.signed_body())
  109|    593|      .decode_optional(data->m_version, ASN1_Type(0), ASN1_Class::Constructed | ASN1_Class::ContextSpecific)
  110|    593|      .decode(serial_bn)
  111|    593|      .decode(data->m_sig_algo_inner)
  112|    593|      .decode(data->m_issuer_dn)
  113|    593|      .start_sequence()
  114|    593|      .decode(data->m_not_before)
  115|    593|      .decode(data->m_not_after)
  116|    593|      .end_cons()
  117|    593|      .decode(data->m_subject_dn)
  118|    593|      .get_next(public_key)
  119|    593|      .decode_optional_string(data->m_v2_issuer_key_id, ASN1_Type::BitString, 1)
  120|    593|      .decode_optional_string(data->m_v2_subject_key_id, ASN1_Type::BitString, 2)
  121|    593|      .get_next(v3_exts_data)
  122|    593|      .verify_end("TBSCertificate has extra data after extensions block");
  123|       |
  124|    593|   if(data->m_version > 2) {
  ------------------
  |  Branch (124:7): [True: 0, False: 593]
  ------------------
  125|      0|      throw Decoding_Error("Unknown X.509 cert version " + std::to_string(data->m_version));
  126|      0|   }
  127|    593|   if(obj.signature_algorithm() != data->m_sig_algo_inner) {
  ------------------
  |  Branch (127:7): [True: 28, False: 565]
  ------------------
  128|     28|      throw Decoding_Error("X.509 Certificate had differing algorithm identifers in inner and outer ID fields");
  129|     28|   }
  130|       |
  131|    565|   public_key.assert_is_a(ASN1_Type::Sequence, ASN1_Class::Constructed, "X.509 certificate public key");
  132|       |
  133|       |   // crude method to save the serial's sign; will get lost during decoding, otherwise
  134|    565|   data->m_serial_negative = serial_bn.is_negative();
  135|       |
  136|       |   // for general sanity convert wire version (0 based) to standards version (v1 .. v3)
  137|    565|   data->m_version += 1;
  138|       |
  139|    565|   data->m_serial = BigInt::encode(serial_bn);
  140|    565|   data->m_subject_dn_bits = ASN1::put_in_sequence(data->m_subject_dn.get_bits());
  141|    565|   data->m_issuer_dn_bits = ASN1::put_in_sequence(data->m_issuer_dn.get_bits());
  142|       |
  143|    565|   data->m_subject_public_key_bits.assign(public_key.bits(), public_key.bits() + public_key.length());
  144|       |
  145|    565|   data->m_subject_public_key_bits_seq = ASN1::put_in_sequence(data->m_subject_public_key_bits);
  146|       |
  147|    565|   BER_Decoder(data->m_subject_public_key_bits)
  148|    565|      .decode(data->m_subject_public_key_algid)
  149|    565|      .decode(data->m_subject_public_key_bitstring, ASN1_Type::BitString);
  150|       |
  151|    565|   if(v3_exts_data.is_a(3, ASN1_Class::Constructed | ASN1_Class::ContextSpecific)) {
  ------------------
  |  Branch (151:7): [True: 4, False: 561]
  ------------------
  152|       |      // Path validation will reject a v1/v2 cert with v3 extensions
  153|      4|      BER_Decoder(v3_exts_data).decode(data->m_v3_extensions).verify_end();
  154|    561|   } else if(v3_exts_data.is_set()) {
  ------------------
  |  Branch (154:14): [True: 31, False: 530]
  ------------------
  155|     31|      throw BER_Bad_Tag("Unknown tag in X.509 cert", v3_exts_data.tagging());
  156|     31|   }
  157|       |
  158|       |   // Now cache some fields from the extensions
  159|    534|   if(auto ext = data->m_v3_extensions.get_extension_object_as<Cert_Extension::Key_Usage>()) {
  ------------------
  |  Branch (159:12): [True: 0, False: 534]
  ------------------
  160|      0|      data->m_key_constraints = ext->get_constraints();
  161|       |      /*
  162|       |      RFC 5280: When the keyUsage extension appears in a certificate,
  163|       |      at least one of the bits MUST be set to 1.
  164|       |      */
  165|      0|      if(data->m_key_constraints.empty()) {
  ------------------
  |  Branch (165:10): [True: 0, False: 0]
  ------------------
  166|      0|         throw Decoding_Error("Certificate has invalid encoding for KeyUsage");
  167|      0|      }
  168|      0|   }
  169|       |
  170|    534|   if(auto ext = data->m_v3_extensions.get_extension_object_as<Cert_Extension::Subject_Key_ID>()) {
  ------------------
  |  Branch (170:12): [True: 0, False: 534]
  ------------------
  171|      0|      data->m_subject_key_id = ext->get_key_id();
  172|      0|   }
  173|       |
  174|    534|   if(auto ext = data->m_v3_extensions.get_extension_object_as<Cert_Extension::Authority_Key_ID>()) {
  ------------------
  |  Branch (174:12): [True: 0, False: 534]
  ------------------
  175|      0|      data->m_authority_key_id = ext->get_key_id();
  176|      0|   }
  177|       |
  178|    534|   if(auto ext = data->m_v3_extensions.get_extension_object_as<Cert_Extension::Name_Constraints>()) {
  ------------------
  |  Branch (178:12): [True: 0, False: 534]
  ------------------
  179|      0|      data->m_name_constraints = ext->get_name_constraints();
  180|      0|   }
  181|       |
  182|    534|   if(auto ext = data->m_v3_extensions.get_extension_object_as<Cert_Extension::Basic_Constraints>()) {
  ------------------
  |  Branch (182:12): [True: 0, False: 534]
  ------------------
  183|      0|      if(ext->get_is_ca() == true) {
  ------------------
  |  Branch (183:10): [True: 0, False: 0]
  ------------------
  184|       |         /*
  185|       |         * RFC 5280 section 4.2.1.3 requires that CAs include KeyUsage in all
  186|       |         * intermediate CA certificates they issue. Currently we accept it being
  187|       |         * missing, as do most other implementations. But it may be worth
  188|       |         * removing this entirely, or alternately adding a warning level
  189|       |         * validation failure for it.
  190|       |         */
  191|      0|         if(data->m_key_constraints.empty() || data->m_key_constraints.includes(Key_Constraints::KeyCertSign)) {
  ------------------
  |  Branch (191:13): [True: 0, False: 0]
  |  Branch (191:48): [True: 0, False: 0]
  ------------------
  192|      0|            data->m_is_ca_certificate = true;
  193|      0|            data->m_path_len_constraint = ext->get_path_limit();
  194|      0|         }
  195|      0|      }
  196|      0|   }
  197|       |
  198|    534|   if(auto ext = data->m_v3_extensions.get_extension_object_as<Cert_Extension::Issuer_Alternative_Name>()) {
  ------------------
  |  Branch (198:12): [True: 0, False: 534]
  ------------------
  199|      0|      data->m_issuer_alt_name = ext->get_alt_name();
  200|      0|   }
  201|       |
  202|    534|   if(auto ext = data->m_v3_extensions.get_extension_object_as<Cert_Extension::Subject_Alternative_Name>()) {
  ------------------
  |  Branch (202:12): [True: 0, False: 534]
  ------------------
  203|      0|      data->m_subject_alt_name = ext->get_alt_name();
  204|      0|   }
  205|       |
  206|    534|   if(auto ext = data->m_v3_extensions.get_extension_object_as<Cert_Extension::Extended_Key_Usage>()) {
  ------------------
  |  Branch (206:12): [True: 0, False: 534]
  ------------------
  207|      0|      data->m_extended_key_usage = ext->object_identifiers();
  208|      0|   }
  209|       |
  210|    534|   if(auto ext = data->m_v3_extensions.get_extension_object_as<Cert_Extension::Certificate_Policies>()) {
  ------------------
  |  Branch (210:12): [True: 0, False: 534]
  ------------------
  211|      0|      data->m_cert_policies = ext->get_policy_oids();
  212|      0|   }
  213|       |
  214|    534|   if(auto ext = data->m_v3_extensions.get_extension_object_as<Cert_Extension::Authority_Information_Access>()) {
  ------------------
  |  Branch (214:12): [True: 0, False: 534]
  ------------------
  215|      0|      data->m_ocsp_responder = ext->ocsp_responder();
  216|      0|      data->m_ca_issuers = ext->ca_issuers();
  217|      0|   }
  218|       |
  219|    534|   if(auto ext = data->m_v3_extensions.get_extension_object_as<Cert_Extension::CRL_Distribution_Points>()) {
  ------------------
  |  Branch (219:12): [True: 0, False: 534]
  ------------------
  220|      0|      data->m_crl_distribution_points = ext->crl_distribution_urls();
  221|      0|   }
  222|       |
  223|       |   // Check for self-signed vs self-issued certificates
  224|    534|   if(data->m_subject_dn == data->m_issuer_dn) {
  ------------------
  |  Branch (224:7): [True: 136, False: 398]
  ------------------
  225|    136|      if(data->m_subject_key_id.empty() == false && data->m_authority_key_id.empty() == false) {
  ------------------
  |  Branch (225:10): [True: 0, False: 136]
  |  Branch (225:53): [True: 0, False: 0]
  ------------------
  226|      0|         data->m_self_signed = (data->m_subject_key_id == data->m_authority_key_id);
  227|    136|      } else {
  228|       |         /*
  229|       |         If a parse error or unknown algorithm is encountered, default
  230|       |         to assuming it is self signed. We have no way of being certain but
  231|       |         that is usually the default case (self-issued is rare in practice).
  232|       |         */
  233|    136|         data->m_self_signed = true;
  234|       |
  235|    136|         try {
  236|    136|            auto pub_key = X509::load_key(data->m_subject_public_key_bits_seq);
  237|       |
  238|    136|            const auto sig_status = obj.verify_signature(*pub_key);
  239|       |
  240|    136|            if(sig_status.first == Certificate_Status_Code::OK ||
  ------------------
  |  Branch (240:16): [True: 136, False: 0]
  ------------------
  241|    136|               sig_status.first == Certificate_Status_Code::SIGNATURE_ALGO_UNKNOWN) {
  ------------------
  |  Branch (241:16): [True: 0, False: 0]
  ------------------
  242|      0|               data->m_self_signed = true;
  243|    136|            } else {
  244|    136|               data->m_self_signed = false;
  245|    136|            }
  246|    136|         } catch(...) {
  247|       |            // ignore errors here to allow parsing to continue
  248|    136|         }
  249|    136|      }
  250|    136|   }
  251|       |
  252|    534|   const std::vector<uint8_t> full_encoding = obj.BER_encode();
  253|       |
  254|    534|   auto sha1 = HashFunction::create("SHA-1");
  255|    534|   if(sha1) {
  ------------------
  |  Branch (255:7): [True: 87, False: 447]
  ------------------
  256|     87|      sha1->update(data->m_subject_public_key_bitstring);
  257|     87|      data->m_subject_public_key_bitstring_sha1 = sha1->final_stdvec();
  258|       |      // otherwise left as empty, and we will throw if subject_public_key_bitstring_sha1 is called
  259|       |
  260|     87|      data->m_fingerprint_sha1 = create_hex_fingerprint(full_encoding, "SHA-1");
  261|     87|   }
  262|       |
  263|    534|   auto sha256 = HashFunction::create("SHA-256");
  264|    534|   if(sha256) {
  ------------------
  |  Branch (264:7): [True: 87, False: 447]
  ------------------
  265|     87|      sha256->update(data->m_issuer_dn_bits);
  266|     87|      data->m_issuer_dn_bits_sha256 = sha256->final_stdvec();
  267|       |
  268|     87|      sha256->update(data->m_subject_dn_bits);
  269|     87|      data->m_subject_dn_bits_sha256 = sha256->final_stdvec();
  270|       |
  271|     87|      data->m_fingerprint_sha256 = create_hex_fingerprint(full_encoding, "SHA-256");
  272|     87|   }
  273|       |
  274|    534|   return data;
  275|    534|}

