_ZN5Botan17ct_expand_top_bitITkNSt3__117unsigned_integralEmEET_S2_:
   28|  19.9k|BOTAN_FORCE_INLINE constexpr T ct_expand_top_bit(T a) {
   29|  19.9k|   const T top = CT::value_barrier<T>(a >> (sizeof(T) * 8 - 1));
   30|  19.9k|   return static_cast<T>(0) - top;
   31|  19.9k|}
_ZN5Botan10ct_is_zeroITkNSt3__117unsigned_integralEmEET_S2_:
   37|  19.9k|BOTAN_FORCE_INLINE constexpr T ct_is_zero(T x) {
   38|  19.9k|   return ct_expand_top_bit<T>(~x & (x - 1));
   39|  19.9k|}
_ZN5Botan8high_bitITkNSt3__117unsigned_integralEmEEmT_:
   73|    167|BOTAN_FORCE_INLINE constexpr size_t high_bit(T n) {
   74|    167|   size_t hb = 0;
   75|       |
   76|  1.16k|   for(size_t s = 8 * sizeof(T) / 2; s > 0; s /= 2) {
  ------------------
  |  Branch (76:38): [True: 1.00k, False: 167]
  ------------------
   77|       |      // Equivalent to: ((n >> s) == 0) ? 0 : s;
   78|  1.00k|      const size_t z = s - ct_if_is_zero_ret<T>(n >> s, s);
   79|  1.00k|      hb += z;
   80|  1.00k|      n >>= z;
   81|  1.00k|   }
   82|       |
   83|    167|   hb += n;
   84|       |
   85|    167|   return hb;
   86|    167|}
_ZN5Botan17ct_if_is_zero_retITkNSt3__117unsigned_integralEmEEmT_m:
   45|  1.00k|BOTAN_FORCE_INLINE constexpr size_t ct_if_is_zero_ret(T x, size_t s) {
   46|       |   /*
   47|       |   Similar to `return ct_is_zero(x) & s` but has to account for possibility that
   48|       |   sizeof(T) is smaller than sizeof(size_t) which would lead to incomplete masking
   49|       |   */
   50|  1.00k|   const T a = ~x & (x - 1);
   51|  1.00k|   const size_t a_top = static_cast<size_t>(CT::value_barrier<T>(a >> (sizeof(T) * 8 - 1)));
   52|  1.00k|   const size_t mask = static_cast<size_t>(0) - a_top;
   53|  1.00k|   return mask & s;
   54|  1.00k|}
_ZN5Botan8high_bitITkNSt3__117unsigned_integralEjEEmT_:
   73|     75|BOTAN_FORCE_INLINE constexpr size_t high_bit(T n) {
   74|     75|   size_t hb = 0;
   75|       |
   76|    450|   for(size_t s = 8 * sizeof(T) / 2; s > 0; s /= 2) {
  ------------------
  |  Branch (76:38): [True: 375, False: 75]
  ------------------
   77|       |      // Equivalent to: ((n >> s) == 0) ? 0 : s;
   78|    375|      const size_t z = s - ct_if_is_zero_ret<T>(n >> s, s);
   79|    375|      hb += z;
   80|    375|      n >>= z;
   81|    375|   }
   82|       |
   83|     75|   hb += n;
   84|       |
   85|     75|   return hb;
   86|     75|}
_ZN5Botan17ct_if_is_zero_retITkNSt3__117unsigned_integralEjEEmT_m:
   45|    375|BOTAN_FORCE_INLINE constexpr size_t ct_if_is_zero_ret(T x, size_t s) {
   46|       |   /*
   47|       |   Similar to `return ct_is_zero(x) & s` but has to account for possibility that
   48|       |   sizeof(T) is smaller than sizeof(size_t) which would lead to incomplete masking
   49|       |   */
   50|    375|   const T a = ~x & (x - 1);
   51|    375|   const size_t a_top = static_cast<size_t>(CT::value_barrier<T>(a >> (sizeof(T) * 8 - 1)));
   52|    375|   const size_t mask = static_cast<size_t>(0) - a_top;
   53|    375|   return mask & s;
   54|    375|}

_ZN5Botan13reverse_bytesITkNSt3__117unsigned_integralEmQooooooeqstT_Li1EeqstS2_Li2EeqstS2_Li4EeqstS2_Li8EEES2_S2_:
   27|  9.40k|inline constexpr T reverse_bytes(T x) {
   28|       |   if constexpr(sizeof(T) == 1) {
   29|       |      return x;
   30|       |   } else if constexpr(sizeof(T) == 2) {
   31|       |#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap16)
   32|       |      return static_cast<T>(__builtin_bswap16(x));
   33|       |#else
   34|       |      return static_cast<T>((x << 8) | (x >> 8));
   35|       |#endif
   36|       |   } else if constexpr(sizeof(T) == 4) {
   37|       |#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap32)
   38|       |      return static_cast<T>(__builtin_bswap32(x));
   39|       |#else
   40|       |      // MSVC at least recognizes this as a bswap
   41|       |      return static_cast<T>(((x & 0x000000FF) << 24) | ((x & 0x0000FF00) << 8) | ((x & 0x00FF0000) >> 8) |
   42|       |                            ((x & 0xFF000000) >> 24));
   43|       |#endif
   44|  9.40k|   } else if constexpr(sizeof(T) == 8) {
   45|  9.40k|#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap64)
   46|  9.40k|      return static_cast<T>(__builtin_bswap64(x));
   47|       |#else
   48|       |      uint32_t hi = static_cast<uint32_t>(x >> 32);
   49|       |      uint32_t lo = static_cast<uint32_t>(x);
   50|       |
   51|       |      hi = reverse_bytes(hi);
   52|       |      lo = reverse_bytes(lo);
   53|       |
   54|       |      return (static_cast<T>(lo) << 32) | hi;
   55|       |#endif
   56|  9.40k|   }
   57|  9.40k|}
_ZN5Botan13reverse_bytesITkNSt3__117unsigned_integralEtQooooooeqstT_Li1EeqstS2_Li2EeqstS2_Li4EeqstS2_Li8EEES2_S2_:
   27|     74|inline constexpr T reverse_bytes(T x) {
   28|       |   if constexpr(sizeof(T) == 1) {
   29|       |      return x;
   30|     74|   } else if constexpr(sizeof(T) == 2) {
   31|     74|#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap16)
   32|     74|      return static_cast<T>(__builtin_bswap16(x));
   33|       |#else
   34|       |      return static_cast<T>((x << 8) | (x >> 8));
   35|       |#endif
   36|       |   } else if constexpr(sizeof(T) == 4) {
   37|       |#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap32)
   38|       |      return static_cast<T>(__builtin_bswap32(x));
   39|       |#else
   40|       |      // MSVC at least recognizes this as a bswap
   41|       |      return static_cast<T>(((x & 0x000000FF) << 24) | ((x & 0x0000FF00) << 8) | ((x & 0x00FF0000) >> 8) |
   42|       |                            ((x & 0xFF000000) >> 24));
   43|       |#endif
   44|       |   } else if constexpr(sizeof(T) == 8) {
   45|       |#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap64)
   46|       |      return static_cast<T>(__builtin_bswap64(x));
   47|       |#else
   48|       |      uint32_t hi = static_cast<uint32_t>(x >> 32);
   49|       |      uint32_t lo = static_cast<uint32_t>(x);
   50|       |
   51|       |      hi = reverse_bytes(hi);
   52|       |      lo = reverse_bytes(lo);
   53|       |
   54|       |      return (static_cast<T>(lo) << 32) | hi;
   55|       |#endif
   56|       |   }
   57|     74|}
_ZN5Botan13reverse_bytesITkNSt3__117unsigned_integralEjQooooooeqstT_Li1EeqstS2_Li2EeqstS2_Li4EeqstS2_Li8EEES2_S2_:
   27|     81|inline constexpr T reverse_bytes(T x) {
   28|       |   if constexpr(sizeof(T) == 1) {
   29|       |      return x;
   30|       |   } else if constexpr(sizeof(T) == 2) {
   31|       |#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap16)
   32|       |      return static_cast<T>(__builtin_bswap16(x));
   33|       |#else
   34|       |      return static_cast<T>((x << 8) | (x >> 8));
   35|       |#endif
   36|     81|   } else if constexpr(sizeof(T) == 4) {
   37|     81|#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap32)
   38|     81|      return static_cast<T>(__builtin_bswap32(x));
   39|       |#else
   40|       |      // MSVC at least recognizes this as a bswap
   41|       |      return static_cast<T>(((x & 0x000000FF) << 24) | ((x & 0x0000FF00) << 8) | ((x & 0x00FF0000) >> 8) |
   42|       |                            ((x & 0xFF000000) >> 24));
   43|       |#endif
   44|       |   } else if constexpr(sizeof(T) == 8) {
   45|       |#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap64)
   46|       |      return static_cast<T>(__builtin_bswap64(x));
   47|       |#else
   48|       |      uint32_t hi = static_cast<uint32_t>(x >> 32);
   49|       |      uint32_t lo = static_cast<uint32_t>(x);
   50|       |
   51|       |      hi = reverse_bytes(hi);
   52|       |      lo = reverse_bytes(lo);
   53|       |
   54|       |      return (static_cast<T>(lo) << 32) | hi;
   55|       |#endif
   56|       |   }
   57|     81|}

_ZN5Botan12BufferSlicerC2ENSt3__14spanIKhLm18446744073709551615EEE:
   25|  2.55k|      explicit BufferSlicer(std::span<const uint8_t> buffer) : m_remaining(buffer) {}
_ZNK5Botan12BufferSlicer5emptyEv:
   68|  33.5k|      bool empty() const { return m_remaining.empty(); }
_ZN5Botan12BufferSlicer9take_byteEv:
   57|  16.5k|      uint8_t take_byte() { return take(1)[0]; }
_ZN5Botan12BufferSlicer4takeEm:
   37|  16.5k|      std::span<const uint8_t> take(const size_t count) {
   38|  16.5k|         BOTAN_STATE_CHECK(remaining() >= count);
  ------------------
  |  |   51|  16.5k|   do {                                                         \
  |  |   52|  16.5k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */             \
  |  |   53|  16.5k|      if(!(expr)) {                                             \
  |  |  ------------------
  |  |  |  Branch (53:10): [True: 0, False: 16.5k]
  |  |  ------------------
  |  |   54|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */    \
  |  |   55|      0|         Botan::throw_invalid_state(#expr, __func__, __FILE__); \
  |  |   56|      0|      }                                                         \
  |  |   57|  16.5k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (57:12): [Folded, False: 16.5k]
  |  |  ------------------
  ------------------
   39|  16.5k|         auto result = m_remaining.first(count);
   40|  16.5k|         m_remaining = m_remaining.subspan(count);
   41|  16.5k|         return result;
   42|  16.5k|      }
_ZNK5Botan12BufferSlicer9remainingEv:
   66|  16.5k|      size_t remaining() const { return m_remaining.size(); }

_ZN5Botan2CT8unpoisonITkNSt3__18integralEmEEvRKT_:
  112|  1.73k|constexpr void unpoison(const T& p) {
  113|  1.73k|   unpoison(&p, 1);
  114|  1.73k|}
_ZN5Botan2CT8unpoisonImEEvPKT_m:
   67|  3.38k|constexpr inline void unpoison(const T* p, size_t n) {
   68|       |#if defined(BOTAN_HAS_VALGRIND)
   69|       |   if(!std::is_constant_evaluated()) {
   70|       |      VALGRIND_MAKE_MEM_DEFINED(p, n * sizeof(T));
   71|       |   }
   72|       |#endif
   73|       |
   74|  3.38k|   BOTAN_UNUSED(p, n);
  ------------------
  |  |  144|  3.38k|#define BOTAN_UNUSED Botan::ignore_params
  ------------------
   75|  3.38k|}

_ZN5Botan3fmtIJPKcS2_S2_EEENSt3__112basic_stringIcNS3_11char_traitsIcEENS3_9allocatorIcEEEENS3_17basic_string_viewIcS6_EEDpRKT_:
   53|     19|std::string fmt(std::string_view format, const T&... args) {
   54|     19|   std::ostringstream oss;
   55|     19|   oss.imbue(std::locale::classic());
   56|     19|   fmt_detail::do_fmt(oss, format, args...);
   57|     19|   return oss.str();
   58|     19|}
_ZN5Botan10fmt_detail6do_fmtIPKcJS3_S3_EEEvRNSt3__119basic_ostringstreamIcNS4_11char_traitsIcEENS4_9allocatorIcEEEENS4_17basic_string_viewIcS7_EERKT_DpRKT0_:
   25|     19|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|     19|   size_t i = 0;
   27|       |
   28|     19|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 19, False: 0]
  ------------------
   29|     19|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 19, False: 0]
  |  Branch (29:30): [True: 19, False: 0]
  |  Branch (29:59): [True: 19, False: 0]
  ------------------
   30|     19|         oss << val;
   31|     19|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|     19|      } else {
   33|      0|         oss << format[i];
   34|      0|      }
   35|       |
   36|      0|      i += 1;
   37|      0|   }
   38|     19|}
_ZN5Botan10fmt_detail6do_fmtIPKcJS3_EEEvRNSt3__119basic_ostringstreamIcNS4_11char_traitsIcEENS4_9allocatorIcEEEENS4_17basic_string_viewIcS7_EERKT_DpRKT0_:
   25|     19|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|     19|   size_t i = 0;
   27|       |
   28|     95|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 95, False: 0]
  ------------------
   29|     95|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 19, False: 76]
  |  Branch (29:30): [True: 19, False: 0]
  |  Branch (29:59): [True: 19, False: 0]
  ------------------
   30|     19|         oss << val;
   31|     19|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|     76|      } else {
   33|     76|         oss << format[i];
   34|     76|      }
   35|       |
   36|     76|      i += 1;
   37|     76|   }
   38|     19|}
_ZN5Botan10fmt_detail6do_fmtIPKcJEEEvRNSt3__119basic_ostringstreamIcNS4_11char_traitsIcEENS4_9allocatorIcEEEENS4_17basic_string_viewIcS7_EERKT_DpRKT0_:
   25|     82|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|     82|   size_t i = 0;
   27|       |
   28|  1.83k|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 1.83k, False: 0]
  ------------------
   29|  1.83k|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 82, False: 1.75k]
  |  Branch (29:30): [True: 82, False: 0]
  |  Branch (29:59): [True: 82, False: 0]
  ------------------
   30|     82|         oss << val;
   31|     82|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|  1.75k|      } else {
   33|  1.75k|         oss << format[i];
   34|  1.75k|      }
   35|       |
   36|  1.75k|      i += 1;
   37|  1.75k|   }
   38|     82|}
_ZN5Botan10fmt_detail6do_fmtERNSt3__119basic_ostringstreamIcNS1_11char_traitsIcEENS1_9allocatorIcEEEENS1_17basic_string_viewIcS4_EE:
   20|  1.68k|inline void do_fmt(std::ostringstream& oss, std::string_view format) {
   21|  1.68k|   oss << format;
   22|  1.68k|}
_ZN5Botan10fmt_detail6do_fmtINSt3__117basic_string_viewIcNS2_11char_traitsIcEEEEJEEEvRNS2_19basic_ostringstreamIcS5_NS2_9allocatorIcEEEES6_RKT_DpRKT0_:
   25|  1.10k|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|  1.10k|   size_t i = 0;
   27|       |
   28|  6.81k|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 6.81k, False: 0]
  ------------------
   29|  6.81k|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 1.10k, False: 5.71k]
  |  Branch (29:30): [True: 1.10k, False: 0]
  |  Branch (29:59): [True: 1.10k, False: 0]
  ------------------
   30|  1.10k|         oss << val;
   31|  1.10k|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|  5.71k|      } else {
   33|  5.71k|         oss << format[i];
   34|  5.71k|      }
   35|       |
   36|  5.71k|      i += 1;
   37|  5.71k|   }
   38|  1.10k|}
_ZN5Botan3fmtIJNSt3__117basic_string_viewIcNS1_11char_traitsIcEEEEEEENS1_12basic_stringIcS4_NS1_9allocatorIcEEEES5_DpRKT_:
   53|  1.10k|std::string fmt(std::string_view format, const T&... args) {
   54|  1.10k|   std::ostringstream oss;
   55|  1.10k|   oss.imbue(std::locale::classic());
   56|  1.10k|   fmt_detail::do_fmt(oss, format, args...);
   57|  1.10k|   return oss.str();
   58|  1.10k|}
_ZN5Botan3fmtIJPKcEEENSt3__112basic_stringIcNS3_11char_traitsIcEENS3_9allocatorIcEEEENS3_17basic_string_viewIcS6_EEDpRKT_:
   53|     63|std::string fmt(std::string_view format, const T&... args) {
   54|     63|   std::ostringstream oss;
   55|     63|   oss.imbue(std::locale::classic());
   56|     63|   fmt_detail::do_fmt(oss, format, args...);
   57|     63|   return oss.str();
   58|     63|}
_ZN5Botan3fmtIJNSt3__112basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEEEEES7_NS1_17basic_string_viewIcS4_EEDpRKT_:
   53|     46|std::string fmt(std::string_view format, const T&... args) {
   54|     46|   std::ostringstream oss;
   55|     46|   oss.imbue(std::locale::classic());
   56|     46|   fmt_detail::do_fmt(oss, format, args...);
   57|     46|   return oss.str();
   58|     46|}
_ZN5Botan10fmt_detail6do_fmtINSt3__112basic_stringIcNS2_11char_traitsIcEENS2_9allocatorIcEEEEJEEEvRNS2_19basic_ostringstreamIcS5_S7_EENS2_17basic_string_viewIcS5_EERKT_DpRKT0_:
   25|     46|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|     46|   size_t i = 0;
   27|       |
   28|  1.01k|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 1.01k, False: 0]
  ------------------
   29|  1.01k|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 46, False: 966]
  |  Branch (29:30): [True: 46, False: 0]
  |  Branch (29:59): [True: 46, False: 0]
  ------------------
   30|     46|         oss << val;
   31|     46|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|    966|      } else {
   33|    966|         oss << format[i];
   34|    966|      }
   35|       |
   36|    966|      i += 1;
   37|    966|   }
   38|     46|}
_ZN5Botan3fmtIJjEEENSt3__112basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEENS1_17basic_string_viewIcS4_EEDpRKT_:
   53|     19|std::string fmt(std::string_view format, const T&... args) {
   54|     19|   std::ostringstream oss;
   55|     19|   oss.imbue(std::locale::classic());
   56|     19|   fmt_detail::do_fmt(oss, format, args...);
   57|     19|   return oss.str();
   58|     19|}
_ZN5Botan10fmt_detail6do_fmtIjJEEEvRNSt3__119basic_ostringstreamIcNS2_11char_traitsIcEENS2_9allocatorIcEEEENS2_17basic_string_viewIcS5_EERKT_DpRKT0_:
   25|    444|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|    444|   size_t i = 0;
   27|       |
   28|  1.48k|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 1.48k, False: 0]
  ------------------
   29|  1.48k|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 444, False: 1.04k]
  |  Branch (29:30): [True: 444, False: 0]
  |  Branch (29:59): [True: 444, False: 0]
  ------------------
   30|    444|         oss << val;
   31|    444|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|  1.04k|      } else {
   33|  1.04k|         oss << format[i];
   34|  1.04k|      }
   35|       |
   36|  1.04k|      i += 1;
   37|  1.04k|   }
   38|    444|}
_ZN5Botan3fmtIJNSt3__117basic_string_viewIcNS1_11char_traitsIcEEEEjEEENS1_12basic_stringIcS4_NS1_9allocatorIcEEEES5_DpRKT_:
   53|     55|std::string fmt(std::string_view format, const T&... args) {
   54|     55|   std::ostringstream oss;
   55|     55|   oss.imbue(std::locale::classic());
   56|     55|   fmt_detail::do_fmt(oss, format, args...);
   57|     55|   return oss.str();
   58|     55|}
_ZN5Botan10fmt_detail6do_fmtINSt3__117basic_string_viewIcNS2_11char_traitsIcEEEEJjEEEvRNS2_19basic_ostringstreamIcS5_NS2_9allocatorIcEEEES6_RKT_DpRKT0_:
   25|     55|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|     55|   size_t i = 0;
   27|       |
   28|     55|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 55, False: 0]
  ------------------
   29|     55|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 55, False: 0]
  |  Branch (29:30): [True: 55, False: 0]
  |  Branch (29:59): [True: 55, False: 0]
  ------------------
   30|     55|         oss << val;
   31|     55|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|     55|      } else {
   33|      0|         oss << format[i];
   34|      0|      }
   35|       |
   36|      0|      i += 1;
   37|      0|   }
   38|     55|}
_ZN5Botan3fmtIJjjEEENSt3__112basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEENS1_17basic_string_viewIcS4_EEDpRKT_:
   53|    370|std::string fmt(std::string_view format, const T&... args) {
   54|    370|   std::ostringstream oss;
   55|    370|   oss.imbue(std::locale::classic());
   56|    370|   fmt_detail::do_fmt(oss, format, args...);
   57|    370|   return oss.str();
   58|    370|}
_ZN5Botan10fmt_detail6do_fmtIjJjEEEvRNSt3__119basic_ostringstreamIcNS2_11char_traitsIcEENS2_9allocatorIcEEEENS2_17basic_string_viewIcS5_EERKT_DpRKT0_:
   25|    370|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|    370|   size_t i = 0;
   27|       |
   28|  10.3k|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 10.3k, False: 0]
  ------------------
   29|  10.3k|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 370, False: 9.94k]
  |  Branch (29:30): [True: 370, False: 0]
  |  Branch (29:59): [True: 370, False: 0]
  ------------------
   30|    370|         oss << val;
   31|    370|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|  9.94k|      } else {
   33|  9.94k|         oss << format[i];
   34|  9.94k|      }
   35|       |
   36|  9.94k|      i += 1;
   37|  9.94k|   }
   38|    370|}
_ZN5Botan3fmtIJtttEEENSt3__112basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEENS1_17basic_string_viewIcS4_EEDpRKT_:
   53|      3|std::string fmt(std::string_view format, const T&... args) {
   54|      3|   std::ostringstream oss;
   55|      3|   oss.imbue(std::locale::classic());
   56|      3|   fmt_detail::do_fmt(oss, format, args...);
   57|      3|   return oss.str();
   58|      3|}
_ZN5Botan10fmt_detail6do_fmtItJttEEEvRNSt3__119basic_ostringstreamIcNS2_11char_traitsIcEENS2_9allocatorIcEEEENS2_17basic_string_viewIcS5_EERKT_DpRKT0_:
   25|      3|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|      3|   size_t i = 0;
   27|       |
   28|     48|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 48, False: 0]
  ------------------
   29|     48|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 3, False: 45]
  |  Branch (29:30): [True: 3, False: 0]
  |  Branch (29:59): [True: 3, False: 0]
  ------------------
   30|      3|         oss << val;
   31|      3|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|     45|      } else {
   33|     45|         oss << format[i];
   34|     45|      }
   35|       |
   36|     45|      i += 1;
   37|     45|   }
   38|      3|}
_ZN5Botan10fmt_detail6do_fmtItJtEEEvRNSt3__119basic_ostringstreamIcNS2_11char_traitsIcEENS2_9allocatorIcEEEENS2_17basic_string_viewIcS5_EERKT_DpRKT0_:
   25|      3|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|      3|   size_t i = 0;
   27|       |
   28|     57|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 57, False: 0]
  ------------------
   29|     57|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 3, False: 54]
  |  Branch (29:30): [True: 3, False: 0]
  |  Branch (29:59): [True: 3, False: 0]
  ------------------
   30|      3|         oss << val;
   31|      3|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|     54|      } else {
   33|     54|         oss << format[i];
   34|     54|      }
   35|       |
   36|     54|      i += 1;
   37|     54|   }
   38|      3|}
_ZN5Botan10fmt_detail6do_fmtItJEEEvRNSt3__119basic_ostringstreamIcNS2_11char_traitsIcEENS2_9allocatorIcEEEENS2_17basic_string_viewIcS5_EERKT_DpRKT0_:
   25|      3|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|      3|   size_t i = 0;
   27|       |
   28|     15|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 15, False: 0]
  ------------------
   29|     15|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 3, False: 12]
  |  Branch (29:30): [True: 3, False: 0]
  |  Branch (29:59): [True: 3, False: 0]
  ------------------
   30|      3|         oss << val;
   31|      3|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|     12|      } else {
   33|     12|         oss << format[i];
   34|     12|      }
   35|       |
   36|     12|      i += 1;
   37|     12|   }
   38|      3|}

_ZN5Botan11checked_mulITkNSt3__117unsigned_integralEmEENS1_8optionalIT_EES3_S3_:
   46|  6.66k|constexpr inline std::optional<T> checked_mul(T a, T b) {
   47|       |   // Multiplication by 1U is a hack to work around C's insane
   48|       |   // integer promotion rules.
   49|       |   // https://stackoverflow.com/questions/24795651
   50|  6.66k|   const T r = (1U * a) * b;
   51|       |   // If a == 0 then the multiply certainly did not overflow
   52|       |   // Otherwise r / a == b unless overflow occurred
   53|  6.66k|   if(a != 0 && r / a != b) {
  ------------------
  |  Branch (53:7): [True: 6.66k, False: 0]
  |  Branch (53:17): [True: 0, False: 6.66k]
  ------------------
   54|      0|      return {};
   55|      0|   }
   56|  6.66k|   return r;
   57|  6.66k|}
_ZN5Botan11checked_addITkNSt3__117unsigned_integralEjEENS1_8optionalIT_EES3_S3_:
   19|    203|constexpr inline std::optional<T> checked_add(T a, T b) {
   20|    203|   const T r = a + b;
   21|    203|   if(r < a || r < b) {
  ------------------
  |  Branch (21:7): [True: 0, False: 203]
  |  Branch (21:16): [True: 0, False: 203]
  ------------------
   22|      0|      return {};
   23|      0|   }
   24|    203|   return r;
   25|    203|}
_ZN5Botan11checked_addITkNSt3__117unsigned_integralEmTpTkNS1_17unsigned_integralEJmmEQ10all_same_vIT_DpT0_EEENS1_8optionalIS2_EES2_S2_S4_:
   37|    646|constexpr inline std::optional<T> checked_add(T a, T b, Ts... rest) {
   38|    646|   if(auto r = checked_add(a, b)) {
  ------------------
  |  Branch (38:12): [True: 646, False: 0]
  ------------------
   39|    646|      return checked_add(r.value(), rest...);
   40|    646|   } else {
   41|      0|      return {};
   42|      0|   }
   43|    646|}
_ZN5Botan11checked_addITkNSt3__117unsigned_integralEmEENS1_8optionalIT_EES3_S3_:
   19|  1.93k|constexpr inline std::optional<T> checked_add(T a, T b) {
   20|  1.93k|   const T r = a + b;
   21|  1.93k|   if(r < a || r < b) {
  ------------------
  |  Branch (21:7): [True: 0, False: 1.93k]
  |  Branch (21:16): [True: 0, False: 1.93k]
  ------------------
   22|      0|      return {};
   23|      0|   }
   24|  1.93k|   return r;
   25|  1.93k|}
_ZN5Botan11checked_addITkNSt3__117unsigned_integralEmTpTkNS1_17unsigned_integralEJmEQ10all_same_vIT_DpT0_EEENS1_8optionalIS2_EES2_S2_S4_:
   37|    646|constexpr inline std::optional<T> checked_add(T a, T b, Ts... rest) {
   38|    646|   if(auto r = checked_add(a, b)) {
  ------------------
  |  Branch (38:12): [True: 646, False: 0]
  ------------------
   39|    646|      return checked_add(r.value(), rest...);
   40|    646|   } else {
   41|      0|      return {};
   42|      0|   }
   43|    646|}

_ZN5Botan12get_byte_varImEEhmT_:
   69|  5.52k|inline constexpr uint8_t get_byte_var(size_t byte_num, T input) {
   70|  5.52k|   return static_cast<uint8_t>(input >> (((~byte_num) & (sizeof(T) - 1)) << 3));
   71|  5.52k|}
_ZN5Botan7load_beImJNSt3__14spanIKhLm8EEEEEEDaDpOT0_:
  504|  7.84k|inline constexpr auto load_be(ParamTs&&... params) {
  505|  7.84k|   return detail::load_any<std::endian::big, OutT>(std::forward<ParamTs>(params)...);
  506|  7.84k|}
_ZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEmTkNS_6ranges16contiguous_rangeIhEENS2_4spanIKhLm8EEEQnt15custom_loadableINS0_19wrapped_type_helperIu14__remove_cvrefIT0_EE4typeEEEESA_OT1_:
  278|  7.84k|inline constexpr WrappedOutT load_any(InR&& in_range) {
  279|  7.84k|   using OutT = detail::wrapped_type<WrappedOutT>;
  280|  7.84k|   ranges::assert_exact_byte_length<sizeof(OutT)>(in_range);
  281|       |
  282|  7.84k|   return detail::wrap_strong_type_or_enum<WrappedOutT>([&]() -> OutT {
  283|       |      // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  284|       |      // internally to copy ranges on a byte-by-byte basis, which is not allowed
  285|       |      // in a `constexpr` context.
  286|  7.84k|      if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  287|  7.84k|         return fallback_load_any<endianness, OutT>(std::forward<InR>(in_range));
  288|  7.84k|      } else {
  289|  7.84k|         const std::span in{in_range};
  290|  7.84k|         if constexpr(sizeof(OutT) == 1) {
  291|  7.84k|            return static_cast<OutT>(in[0]);
  292|  7.84k|         } else if constexpr(endianness == std::endian::native) {
  293|  7.84k|            return typecast_copy<OutT>(in);
  294|  7.84k|         } else {
  295|  7.84k|            static_assert(opposite(endianness) == std::endian::native);
  296|  7.84k|            return reverse_bytes(typecast_copy<OutT>(in));
  297|  7.84k|         }
  298|  7.84k|      }
  299|  7.84k|   }());
  300|  7.84k|}
_ZN5Botan6detail24wrap_strong_type_or_enumITkNS0_20unsigned_integralishEmTkNSt3__117unsigned_integralEmEEDaT0_:
  200|  9.40k|constexpr auto wrap_strong_type_or_enum(T t) {
  201|       |   if constexpr(std::is_enum_v<OutT>) {
  202|       |      return static_cast<OutT>(t);
  203|  9.40k|   } else {
  204|  9.40k|      return Botan::wrap_strong_type<OutT>(t);
  205|  9.40k|   }
  206|  9.40k|}
_ZZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEmTkNS_6ranges16contiguous_rangeIhEENS2_4spanIKhLm8EEEQnt15custom_loadableINS0_19wrapped_type_helperIu14__remove_cvrefIT0_EE4typeEEEESA_OT1_ENKUlvE_clEv:
  282|  7.84k|   return detail::wrap_strong_type_or_enum<WrappedOutT>([&]() -> OutT {
  283|       |      // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  284|       |      // internally to copy ranges on a byte-by-byte basis, which is not allowed
  285|       |      // in a `constexpr` context.
  286|  7.84k|      if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  ------------------
  |  Branch (286:10): [Folded, False: 7.84k]
  ------------------
  287|      0|         return fallback_load_any<endianness, OutT>(std::forward<InR>(in_range));
  288|  7.84k|      } else {
  289|  7.84k|         const std::span in{in_range};
  290|       |         if constexpr(sizeof(OutT) == 1) {
  291|       |            return static_cast<OutT>(in[0]);
  292|       |         } else if constexpr(endianness == std::endian::native) {
  293|       |            return typecast_copy<OutT>(in);
  294|  7.84k|         } else {
  295|  7.84k|            static_assert(opposite(endianness) == std::endian::native);
  296|  7.84k|            return reverse_bytes(typecast_copy<OutT>(in));
  297|  7.84k|         }
  298|  7.84k|      }
  299|  7.84k|   }());
_ZN5Botan7load_beImJRNSt3__15arrayIhLm8EEEEEEDaDpOT0_:
  504|  1.55k|inline constexpr auto load_be(ParamTs&&... params) {
  505|  1.55k|   return detail::load_any<std::endian::big, OutT>(std::forward<ParamTs>(params)...);
  506|  1.55k|}
_ZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEmTkNS_6ranges16contiguous_rangeIhEERNS2_5arrayIhLm8EEEQnt15custom_loadableINS0_19wrapped_type_helperIu14__remove_cvrefIT0_EE4typeEEEESA_OT1_:
  278|  1.55k|inline constexpr WrappedOutT load_any(InR&& in_range) {
  279|  1.55k|   using OutT = detail::wrapped_type<WrappedOutT>;
  280|  1.55k|   ranges::assert_exact_byte_length<sizeof(OutT)>(in_range);
  281|       |
  282|  1.55k|   return detail::wrap_strong_type_or_enum<WrappedOutT>([&]() -> OutT {
  283|       |      // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  284|       |      // internally to copy ranges on a byte-by-byte basis, which is not allowed
  285|       |      // in a `constexpr` context.
  286|  1.55k|      if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  287|  1.55k|         return fallback_load_any<endianness, OutT>(std::forward<InR>(in_range));
  288|  1.55k|      } else {
  289|  1.55k|         const std::span in{in_range};
  290|  1.55k|         if constexpr(sizeof(OutT) == 1) {
  291|  1.55k|            return static_cast<OutT>(in[0]);
  292|  1.55k|         } else if constexpr(endianness == std::endian::native) {
  293|  1.55k|            return typecast_copy<OutT>(in);
  294|  1.55k|         } else {
  295|  1.55k|            static_assert(opposite(endianness) == std::endian::native);
  296|  1.55k|            return reverse_bytes(typecast_copy<OutT>(in));
  297|  1.55k|         }
  298|  1.55k|      }
  299|  1.55k|   }());
  300|  1.55k|}
_ZZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEmTkNS_6ranges16contiguous_rangeIhEERNS2_5arrayIhLm8EEEQnt15custom_loadableINS0_19wrapped_type_helperIu14__remove_cvrefIT0_EE4typeEEEESA_OT1_ENKUlvE_clEv:
  282|  1.55k|   return detail::wrap_strong_type_or_enum<WrappedOutT>([&]() -> OutT {
  283|       |      // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  284|       |      // internally to copy ranges on a byte-by-byte basis, which is not allowed
  285|       |      // in a `constexpr` context.
  286|  1.55k|      if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  ------------------
  |  Branch (286:10): [Folded, False: 1.55k]
  ------------------
  287|      0|         return fallback_load_any<endianness, OutT>(std::forward<InR>(in_range));
  288|  1.55k|      } else {
  289|  1.55k|         const std::span in{in_range};
  290|       |         if constexpr(sizeof(OutT) == 1) {
  291|       |            return static_cast<OutT>(in[0]);
  292|       |         } else if constexpr(endianness == std::endian::native) {
  293|       |            return typecast_copy<OutT>(in);
  294|  1.55k|         } else {
  295|  1.55k|            static_assert(opposite(endianness) == std::endian::native);
  296|  1.55k|            return reverse_bytes(typecast_copy<OutT>(in));
  297|  1.55k|         }
  298|  1.55k|      }
  299|  1.55k|   }());
_ZN5Botan8get_byteILm0EmEEhT0_QltT_stS1_:
   81|    207|{
   82|    207|   const size_t shift = ((~B) & (sizeof(T) - 1)) << 3;
   83|    207|   return static_cast<uint8_t>((input >> shift) & 0xFF);
   84|    207|}
_ZN5Botan8store_leINS_6detail10AutoDetectEJmEEEDaDpOT0_:
  736|    609|inline constexpr auto store_le(ParamTs&&... params) {
  737|    609|   return detail::store_any<std::endian::little, ModifierT>(std::forward<ParamTs>(params)...);
  738|    609|}
_ZN5Botan6detail9store_anyILNSt3__16endianE57005ENS0_10AutoDetectETpTkNS0_20unsigned_integralishEJmEQ10all_same_vIDpT1_EEEDaS6_:
  696|    609|inline constexpr auto store_any(Ts... ins) {
  697|    609|   return store_any<endianness, OutR>(std::array{ins...});
  698|    609|}
_ZN5Botan6detail9store_anyILNSt3__16endianE57005ENS0_10AutoDetectETkNS_6ranges14spanable_rangeENS2_5arrayImLm1EEEQoooosr3stdE7same_asIS4_T0_Eaasr6rangesE25statically_spanable_rangeIS8_Esr3stdE21default_initializableIS8_Esr8conceptsE21resizable_byte_bufferIS8_EEEDaOT1_:
  663|    609|inline constexpr auto store_any(InR&& in_range) {
  664|    609|   auto out = []([[maybe_unused]] const auto& in) {
  665|    609|      if constexpr(std::same_as<AutoDetect, OutR>) {
  666|    609|         if constexpr(ranges::statically_spanable_range<InR>) {
  667|    609|            constexpr size_t bytes = decltype(std::span{in})::extent * sizeof(std::ranges::range_value_t<InR>);
  668|    609|            return std::array<uint8_t, bytes>();
  669|    609|         } else {
  670|    609|            static_assert(
  671|    609|               !std::same_as<AutoDetect, OutR>,
  672|    609|               "cannot infer a suitable result container type from the given parameters at compile time, please specify it explicitly");
  673|    609|         }
  674|    609|      } else if constexpr(concepts::resizable_byte_buffer<OutR>) {
  675|    609|         return OutR(std::span{in}.size_bytes());
  676|    609|      } else {
  677|    609|         return OutR{};
  678|    609|      }
  679|    609|   }(in_range);
  680|       |
  681|    609|   store_any<endianness, std::ranges::range_value_t<InR>>(out, std::forward<InR>(in_range));
  682|    609|   return out;
  683|    609|}
_ZZN5Botan6detail9store_anyILNSt3__16endianE57005ENS0_10AutoDetectETkNS_6ranges14spanable_rangeENS2_5arrayImLm1EEEQoooosr3stdE7same_asIS4_T0_Eaasr6rangesE25statically_spanable_rangeIS8_Esr3stdE21default_initializableIS8_Esr8conceptsE21resizable_byte_bufferIS8_EEEDaOT1_ENKUlRKT_E_clIS7_EEDaSD_:
  664|    609|   auto out = []([[maybe_unused]] const auto& in) {
  665|    609|      if constexpr(std::same_as<AutoDetect, OutR>) {
  666|    609|         if constexpr(ranges::statically_spanable_range<InR>) {
  667|    609|            constexpr size_t bytes = decltype(std::span{in})::extent * sizeof(std::ranges::range_value_t<InR>);
  668|    609|            return std::array<uint8_t, bytes>();
  669|       |         } else {
  670|       |            static_assert(
  671|       |               !std::same_as<AutoDetect, OutR>,
  672|       |               "cannot infer a suitable result container type from the given parameters at compile time, please specify it explicitly");
  673|       |         }
  674|       |      } else if constexpr(concepts::resizable_byte_buffer<OutR>) {
  675|       |         return OutR(std::span{in}.size_bytes());
  676|       |      } else {
  677|       |         return OutR{};
  678|       |      }
  679|    609|   }(in_range);
_ZN5Botan6detail9store_anyILNSt3__16endianE57005EmTkNS_6ranges23contiguous_output_rangeIhEERNS2_5arrayIhLm8EEETkNS4_14spanable_rangeENS6_ImLm1EEEQoosr3stdE7same_asINS0_10AutoDetectET0_Esr3stdE7same_asISB_NS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT2_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISJ_EESK_E4type10value_typeEEEEvOT1_RKSG_:
  603|    609|inline constexpr void store_any(OutR&& out /* NOLINT(*-std-forward) */, const InR& in) {
  604|    609|   ranges::assert_equal_byte_lengths(out, in);
  605|    609|   using element_type = std::ranges::range_value_t<InR>;
  606|       |
  607|    609|   auto store_elementwise = [&] {
  608|    609|      constexpr size_t bytes_per_element = sizeof(element_type);
  609|    609|      std::span<uint8_t> out_s(out);
  610|    609|      for(auto in_elem : in) {
  611|    609|         store_any<endianness, element_type>(out_s.template first<bytes_per_element>(), in_elem);
  612|    609|         out_s = out_s.subspan(bytes_per_element);
  613|    609|      }
  614|    609|   };
  615|       |
  616|       |   // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  617|       |   // internally to copy ranges on a byte-by-byte basis, which is not allowed
  618|       |   // in a `constexpr` context.
  619|    609|   if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  ------------------
  |  Branch (619:7): [Folded, False: 609]
  ------------------
  620|      0|      store_elementwise();
  621|    609|   } else {
  622|    609|      if constexpr(endianness == std::endian::native && !custom_storable<element_type>) {
  623|    609|         typecast_copy(out, in);
  624|       |      } else {
  625|       |         store_elementwise();
  626|       |      }
  627|    609|   }
  628|    609|}
_ZN5Botan6detail24wrap_strong_type_or_enumITkNS0_20unsigned_integralishEjTkNSt3__117unsigned_integralEjEEDaT0_:
  200|     81|constexpr auto wrap_strong_type_or_enum(T t) {
  201|       |   if constexpr(std::is_enum_v<OutT>) {
  202|       |      return static_cast<OutT>(t);
  203|     81|   } else {
  204|     81|      return Botan::wrap_strong_type<OutT>(t);
  205|     81|   }
  206|     81|}
_ZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEjTkNS_6ranges16contiguous_rangeIhEENS2_4spanIKhLm4EEEQnt15custom_loadableINS0_19wrapped_type_helperIu14__remove_cvrefIT0_EE4typeEEEESA_OT1_:
  278|     81|inline constexpr WrappedOutT load_any(InR&& in_range) {
  279|     81|   using OutT = detail::wrapped_type<WrappedOutT>;
  280|     81|   ranges::assert_exact_byte_length<sizeof(OutT)>(in_range);
  281|       |
  282|     81|   return detail::wrap_strong_type_or_enum<WrappedOutT>([&]() -> OutT {
  283|       |      // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  284|       |      // internally to copy ranges on a byte-by-byte basis, which is not allowed
  285|       |      // in a `constexpr` context.
  286|     81|      if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  287|     81|         return fallback_load_any<endianness, OutT>(std::forward<InR>(in_range));
  288|     81|      } else {
  289|     81|         const std::span in{in_range};
  290|     81|         if constexpr(sizeof(OutT) == 1) {
  291|     81|            return static_cast<OutT>(in[0]);
  292|     81|         } else if constexpr(endianness == std::endian::native) {
  293|     81|            return typecast_copy<OutT>(in);
  294|     81|         } else {
  295|     81|            static_assert(opposite(endianness) == std::endian::native);
  296|     81|            return reverse_bytes(typecast_copy<OutT>(in));
  297|     81|         }
  298|     81|      }
  299|     81|   }());
  300|     81|}
_ZZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEjTkNS_6ranges16contiguous_rangeIhEENS2_4spanIKhLm4EEEQnt15custom_loadableINS0_19wrapped_type_helperIu14__remove_cvrefIT0_EE4typeEEEESA_OT1_ENKUlvE_clEv:
  282|     81|   return detail::wrap_strong_type_or_enum<WrappedOutT>([&]() -> OutT {
  283|       |      // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  284|       |      // internally to copy ranges on a byte-by-byte basis, which is not allowed
  285|       |      // in a `constexpr` context.
  286|     81|      if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  ------------------
  |  Branch (286:10): [Folded, False: 81]
  ------------------
  287|      0|         return fallback_load_any<endianness, OutT>(std::forward<InR>(in_range));
  288|     81|      } else {
  289|     81|         const std::span in{in_range};
  290|       |         if constexpr(sizeof(OutT) == 1) {
  291|       |            return static_cast<OutT>(in[0]);
  292|       |         } else if constexpr(endianness == std::endian::native) {
  293|       |            return typecast_copy<OutT>(in);
  294|     81|         } else {
  295|     81|            static_assert(opposite(endianness) == std::endian::native);
  296|     81|            return reverse_bytes(typecast_copy<OutT>(in));
  297|     81|         }
  298|     81|      }
  299|     81|   }());
_ZN5Botan7load_beItJPKhRmEEEDaDpOT0_:
  504|     74|inline constexpr auto load_be(ParamTs&&... params) {
  505|     74|   return detail::load_any<std::endian::big, OutT>(std::forward<ParamTs>(params)...);
  506|     74|}
_ZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEtEET0_PKhm:
  454|     74|inline constexpr OutT load_any(const uint8_t in[], size_t off) {
  455|       |   // asserts that *in points to enough bytes to read at offset off
  456|     74|   constexpr size_t out_size = sizeof(OutT);
  457|     74|   return load_any<endianness, OutT>(std::span<const uint8_t, out_size>(in + off * out_size, out_size));
  458|     74|}
_ZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEtTkNS_6ranges16contiguous_rangeIhEENS2_4spanIKhLm2EEEQnt15custom_loadableINS0_19wrapped_type_helperIu14__remove_cvrefIT0_EE4typeEEEESA_OT1_:
  278|     74|inline constexpr WrappedOutT load_any(InR&& in_range) {
  279|     74|   using OutT = detail::wrapped_type<WrappedOutT>;
  280|     74|   ranges::assert_exact_byte_length<sizeof(OutT)>(in_range);
  281|       |
  282|     74|   return detail::wrap_strong_type_or_enum<WrappedOutT>([&]() -> OutT {
  283|       |      // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  284|       |      // internally to copy ranges on a byte-by-byte basis, which is not allowed
  285|       |      // in a `constexpr` context.
  286|     74|      if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  287|     74|         return fallback_load_any<endianness, OutT>(std::forward<InR>(in_range));
  288|     74|      } else {
  289|     74|         const std::span in{in_range};
  290|     74|         if constexpr(sizeof(OutT) == 1) {
  291|     74|            return static_cast<OutT>(in[0]);
  292|     74|         } else if constexpr(endianness == std::endian::native) {
  293|     74|            return typecast_copy<OutT>(in);
  294|     74|         } else {
  295|     74|            static_assert(opposite(endianness) == std::endian::native);
  296|     74|            return reverse_bytes(typecast_copy<OutT>(in));
  297|     74|         }
  298|     74|      }
  299|     74|   }());
  300|     74|}
_ZN5Botan6detail24wrap_strong_type_or_enumITkNS0_20unsigned_integralishEtTkNSt3__117unsigned_integralEtEEDaT0_:
  200|     74|constexpr auto wrap_strong_type_or_enum(T t) {
  201|       |   if constexpr(std::is_enum_v<OutT>) {
  202|       |      return static_cast<OutT>(t);
  203|     74|   } else {
  204|     74|      return Botan::wrap_strong_type<OutT>(t);
  205|     74|   }
  206|     74|}
_ZZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEtTkNS_6ranges16contiguous_rangeIhEENS2_4spanIKhLm2EEEQnt15custom_loadableINS0_19wrapped_type_helperIu14__remove_cvrefIT0_EE4typeEEEESA_OT1_ENKUlvE_clEv:
  282|     74|   return detail::wrap_strong_type_or_enum<WrappedOutT>([&]() -> OutT {
  283|       |      // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  284|       |      // internally to copy ranges on a byte-by-byte basis, which is not allowed
  285|       |      // in a `constexpr` context.
  286|     74|      if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  ------------------
  |  Branch (286:10): [Folded, False: 74]
  ------------------
  287|      0|         return fallback_load_any<endianness, OutT>(std::forward<InR>(in_range));
  288|     74|      } else {
  289|     74|         const std::span in{in_range};
  290|       |         if constexpr(sizeof(OutT) == 1) {
  291|       |            return static_cast<OutT>(in[0]);
  292|       |         } else if constexpr(endianness == std::endian::native) {
  293|       |            return typecast_copy<OutT>(in);
  294|     74|         } else {
  295|     74|            static_assert(opposite(endianness) == std::endian::native);
  296|     74|            return reverse_bytes(typecast_copy<OutT>(in));
  297|     74|         }
  298|     74|      }
  299|     74|   }());
_ZN5Botan7load_beIjJPKhRmEEEDaDpOT0_:
  504|     81|inline constexpr auto load_be(ParamTs&&... params) {
  505|     81|   return detail::load_any<std::endian::big, OutT>(std::forward<ParamTs>(params)...);
  506|     81|}
_ZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEjEET0_PKhm:
  454|     81|inline constexpr OutT load_any(const uint8_t in[], size_t off) {
  455|       |   // asserts that *in points to enough bytes to read at offset off
  456|     81|   constexpr size_t out_size = sizeof(OutT);
  457|     81|   return load_any<endianness, OutT>(std::span<const uint8_t, out_size>(in + off * out_size, out_size));
  458|     81|}

_ZN5Botan15bytes_to_stringENSt3__14spanIKhLm18446744073709551615EEE:
   76|    195|inline std::string bytes_to_string(std::span<const uint8_t> bytes) {
   77|    195|   return std::string(reinterpret_cast<const char*>(bytes.data()), bytes.size());
   78|    195|}

_ZN5Botan8round_upEmm:
   26|  1.56k|constexpr inline size_t round_up(size_t n, size_t align_to) {
   27|       |   // Arguably returning n in this case would also be sensible
   28|  1.56k|   BOTAN_ARG_CHECK(align_to != 0, "align_to must not be 0");
  ------------------
  |  |   35|  1.56k|   do {                                                          \
  |  |   36|  1.56k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  1.56k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 1.56k]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|  1.56k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 1.56k]
  |  |  ------------------
  ------------------
   29|       |
   30|  1.56k|   if(n % align_to > 0) {
  ------------------
  |  Branch (30:7): [True: 1.54k, False: 25]
  ------------------
   31|  1.54k|      const size_t adj = align_to - (n % align_to);
   32|  1.54k|      BOTAN_ARG_CHECK(n + adj >= n, "Integer overflow during rounding");
  ------------------
  |  |   35|  1.54k|   do {                                                          \
  |  |   36|  1.54k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  1.54k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 1.54k]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|  1.54k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 1.54k]
  |  |  ------------------
  ------------------
   33|  1.54k|      n += adj;
   34|  1.54k|   }
   35|  1.56k|   return n;
   36|  1.56k|}

_ZN5Botan2CT13value_barrierITkNSt3__117unsigned_integralEmQntsr3stdE7same_asIbT_EEES3_S3_:
   43|  21.1k|constexpr inline T value_barrier(T x) {
   44|  21.1k|   if(std::is_constant_evaluated()) {
  ------------------
  |  Branch (44:7): [Folded, False: 21.1k]
  ------------------
   45|      0|      return x;
   46|  21.1k|   } else {
   47|  21.1k|#if defined(BOTAN_CT_VALUE_BARRIER_USE_ASM)
   48|       |      /*
   49|       |      * We may want a "stronger" statement such as
   50|       |      *     asm volatile("" : "+r,m"(x) : : "memory);
   51|       |      * (see https://theunixzoo.co.uk/blog/2021-10-14-preventing-optimisations.html)
   52|       |      * however the current approach seems sufficient with current compilers,
   53|       |      * and is minimally damaging with regards to degrading code generation.
   54|       |      */
   55|  21.1k|      asm("" : "+r"(x) : /* no input */);  // NOLINT(*-no-assembler)
   56|  21.1k|      return x;
   57|       |#elif defined(BOTAN_CT_VALUE_BARRIER_USE_VOLATILE)
   58|       |      volatile T vx = x;
   59|       |      return vx;
   60|       |#else
   61|       |      return x;
   62|       |#endif
   63|  21.1k|   }
   64|  21.1k|}
_ZN5Botan2CT13value_barrierITkNSt3__117unsigned_integralEjQntsr3stdE7same_asIbT_EEES3_S3_:
   43|    375|constexpr inline T value_barrier(T x) {
   44|    375|   if(std::is_constant_evaluated()) {
  ------------------
  |  Branch (44:7): [Folded, False: 375]
  ------------------
   45|      0|      return x;
   46|    375|   } else {
   47|    375|#if defined(BOTAN_CT_VALUE_BARRIER_USE_ASM)
   48|       |      /*
   49|       |      * We may want a "stronger" statement such as
   50|       |      *     asm volatile("" : "+r,m"(x) : : "memory);
   51|       |      * (see https://theunixzoo.co.uk/blog/2021-10-14-preventing-optimisations.html)
   52|       |      * however the current approach seems sufficient with current compilers,
   53|       |      * and is minimally damaging with regards to degrading code generation.
   54|       |      */
   55|    375|      asm("" : "+r"(x) : /* no input */);  // NOLINT(*-no-assembler)
   56|    375|      return x;
   57|       |#elif defined(BOTAN_CT_VALUE_BARRIER_USE_VOLATILE)
   58|       |      volatile T vx = x;
   59|       |      return vx;
   60|       |#else
   61|       |      return x;
   62|       |#endif
   63|    375|   }
   64|    375|}

_ZN5Botan11ASN1_ObjectD2Ev:
  122|  15.2k|      virtual ~ASN1_Object() = default;
_ZNK5Botan14ASN1_BitString5bytesEv:
  136|  1.63k|      std::span<const uint8_t> bytes() const { return std::span{m_bytes}; }
_ZNK5Botan14ASN1_BitString11unused_bitsEv:
  138|    819|      size_t unused_bits() const { return m_unused_bits; }
_ZNK5Botan10BER_Object6is_setEv:
  162|  43.2k|      bool is_set() const { return m_type_tag != ASN1_Type::NoObject; }
_ZNK5Botan10BER_Object7taggingEv:
  164|  18.7k|      uint32_t tagging() const { return type_tag() | class_tag(); }
_ZNK5Botan10BER_Object8type_tagEv:
  166|  18.7k|      ASN1_Type type_tag() const { return m_type_tag; }
_ZNK5Botan10BER_Object9class_tagEv:
  168|  21.3k|      ASN1_Class class_tag() const { return m_class_tag; }
_ZNK5Botan10BER_Object4typeEv:
  170|  1.41k|      ASN1_Type type() const { return m_type_tag; }
_ZNK5Botan10BER_Object9get_classEv:
  172|  1.11k|      ASN1_Class get_class() const { return m_class_tag; }
_ZNK5Botan10BER_Object4bitsEv:
  174|  68.2k|      const uint8_t* bits() const { return m_value.data(); }
_ZNK5Botan10BER_Object6lengthEv:
  176|   188k|      size_t length() const { return m_value.size(); }
_ZNK5Botan10BER_Object4dataEv:
  178|  4.82k|      std::span<const uint8_t> data() const { return std::span{m_value}; }
_ZN5Botan10BER_Object12mutable_bitsEm:
  195|  16.0k|      uint8_t* mutable_bits(size_t length) {
  196|  16.0k|         m_value.resize(length);
  197|  16.0k|         return m_value.data();
  198|  16.0k|      }
_ZNK5Botan3OIDeqERKS0_:
  333|  1.18k|      bool operator==(const OID& other) const { return m_id == other.m_id; }
_ZNK5Botan11ASN1_String5valueEv:
  397|    203|      const std::string& value() const { return m_utf8_str; }
_ZNK5Botan19AlgorithmIdentifier20parameters_are_emptyEv:
  451|    954|      bool parameters_are_empty() const { return m_parameters.empty(); }
_ZNK5Botan19AlgorithmIdentifier28parameters_are_null_or_emptyEv:
  453|    954|      bool parameters_are_null_or_empty() const { return parameters_are_empty() || parameters_are_null(); }
  ------------------
  |  Branch (453:58): [True: 799, False: 155]
  |  Branch (453:84): [True: 4, False: 151]
  ------------------
_ZN5BotanorENS_10ASN1_ClassES0_:
   78|  11.6k|inline ASN1_Class operator|(ASN1_Class x, ASN1_Class y) {
   79|  11.6k|   return static_cast<ASN1_Class>(static_cast<uint32_t>(x) | static_cast<uint32_t>(y));
   80|  11.6k|}
_ZN5BotanorENS_9ASN1_TypeENS_10ASN1_ClassE:
   82|  18.7k|inline uint32_t operator|(ASN1_Type x, ASN1_Class y) {
   83|  18.7k|   return static_cast<uint32_t>(x) | static_cast<uint32_t>(y);
   84|  18.7k|}
_ZN5BotanorENS_10ASN1_ClassENS_9ASN1_TypeE:
   86|  2.61k|inline uint32_t operator|(ASN1_Class x, ASN1_Type y) {
   87|  2.61k|   return static_cast<uint32_t>(x) | static_cast<uint32_t>(y);
   88|  2.61k|}
_ZN5BotanneERKNS_3OIDES2_:
  374|  1.18k|inline bool operator!=(const OID& a, const OID& b) {
  375|  1.18k|   return !(a == b);
  376|  1.18k|}
_ZN5Botan11ASN1_ObjectC2Ev:
  117|  13.9k|      ASN1_Object() = default;
_ZN5Botan19AlgorithmIdentifierC2Ev:
  431|  2.13k|      AlgorithmIdentifier() = default;
_ZN5Botan3OIDC2Ev:
  246|  3.80k|      explicit OID() = default;
_ZN5Botan11ASN1_ObjectaSEOS0_:
  121|     10|      ASN1_Object& operator=(ASN1_Object&&) = default;
_ZN5Botan10BER_ObjectC2Ev:
  154|  32.1k|      BER_Object() = default;
_ZN5Botan10BER_ObjectaSEOS0_:
  159|  3.39k|      BER_Object& operator=(BER_Object&& other) = default;
_ZN5Botan11ASN1_ObjectC2ERKS0_:
  118|    607|      ASN1_Object(const ASN1_Object&) = default;
_ZN5Botan11ASN1_ObjectC2EOS0_:
  120|    622|      ASN1_Object(ASN1_Object&&) = default;
_ZN5Botan11ASN1_ObjectaSERKS0_:
  119|    373|      ASN1_Object& operator=(const ASN1_Object&) = default;
_ZN5Botan14ASN1_BitStringC2Ev:
  130|    841|      ASN1_BitString() = default;
_ZN5Botan10BER_ObjectC2EOS0_:
  157|  9.52k|      BER_Object(BER_Object&& other) = default;
_ZN5Botan10BER_ObjectaSERKS0_:
  158|    795|      BER_Object& operator=(const BER_Object& other) = default;

_ZNK5Botan9ASN1_Time7taggingEv:
   36|      2|      ASN1_Type tagging() const { return m_tag; }
_ZN5Botan9ASN1_TimeC2Ev:
   42|  2.12k|      ASN1_Time() = default;

_ZN5Botan13ignore_paramsIJPKmmEEEvDpRKT_:
  142|  3.38k|constexpr void ignore_params([[maybe_unused]] const T&... args) {}
_ZN5Botan13ignore_paramsIJjEEEvDpRKT_:
  142|    137|constexpr void ignore_params([[maybe_unused]] const T&... args) {}

_ZN5Botan11BER_Decoder14start_sequenceEv:
  238|  7.29k|      BER_Decoder start_sequence() { return start_cons(ASN1_Type::Sequence, ASN1_Class::Universal); }
_ZN5Botan11BER_Decoder6decodeERNS_6BigIntE:
  308|      1|      BER_Decoder& decode(BigInt& out) { return decode(out, ASN1_Type::Integer, ASN1_Class::Universal); }
_ZN5Botan11BER_Decoder6Limits3DEREv:
   41|  3.84k|            static Limits DER() { return Limits(false, 0, false, DefaultMaxObjectSize, false); }
_ZN5Botan11BER_Decoder6LimitsC2EbmbNSt3__18optionalImEEb:
  120|  3.84k|                  m_allow_ber(allow_ber),
  121|  3.84k|                  m_max_nested_indef(max_nested_indef),
  122|  3.84k|                  m_allow_standalone_eoc(allow_standalone_eoc),
  123|  3.84k|                  m_max_object_size(max_object_size),
  124|  3.84k|                  m_reject_default_value_encoding(reject_default_value_encoding) {}
_ZN5Botan11BER_DecoderC2ERKNS_10BER_ObjectENS0_6LimitsE:
  154|    605|            BER_Decoder(obj.data(), limits) {}
_ZN5Botan11BER_Decoder22start_context_specificEj:
  242|  1.29k|      BER_Decoder start_context_specific(uint32_t tag) {
  243|  1.29k|         return start_cons(ASN1_Type(tag), ASN1_Class::ContextSpecific);
  244|  1.29k|      }
_ZN5Botan11BER_Decoder21get_next_octet_stringEv:
  310|    962|      std::vector<uint8_t> get_next_octet_string() {
  311|    962|         std::vector<uint8_t> out_vec;
  312|    962|         decode(out_vec, ASN1_Type::OctetString);
  313|    962|         return out_vec;
  314|    962|      }
_ZN5Botan11BER_Decoder6decodeINSt3__19allocatorIhEEEERS0_RNS2_6vectorIhT_EENS_9ASN1_TypeE:
  320|    969|      BER_Decoder& decode(std::vector<uint8_t, Alloc>& out, ASN1_Type real_type) {
  321|    969|         return decode(out, real_type, real_type, ASN1_Class::Universal);
  322|    969|      }
_ZN5Botan11BER_Decoder16decode_and_checkINS_3OIDEEERS0_RKT_NSt3__117basic_string_viewIcNS7_11char_traitsIcEEEE:
  481|  1.27k|      BER_Decoder& decode_and_check(const T& expected, std::string_view error_msg) {
  482|  1.27k|         T actual;
  483|  1.27k|         decode(actual);
  484|       |
  485|  1.27k|         if(actual != expected) {
  ------------------
  |  Branch (485:13): [True: 218, False: 1.05k]
  ------------------
  486|    218|            throw Decoding_Error(error_msg);
  487|    218|         }
  488|       |
  489|  1.05k|         return (*this);
  490|  1.27k|      }
_ZN5Botan11BER_Decoder9raw_bytesINSt3__19allocatorIhEEEERS0_RNS2_6vectorIhT_EE:
  281|  2.48k|      BER_Decoder& raw_bytes(std::vector<uint8_t, Alloc>& out) {
  282|  2.48k|         out.clear();
  283|  24.5k|         for(;;) {
  284|  24.5k|            if(auto next = this->read_next_byte()) {
  ------------------
  |  Branch (284:21): [True: 22.0k, False: 2.48k]
  ------------------
  285|  22.0k|               out.push_back(*next);
  286|  22.0k|            } else {
  287|  2.48k|               break;
  288|  2.48k|            }
  289|  24.5k|         }
  290|  2.48k|         return (*this);
  291|  2.48k|      }
_ZN5Botan11BER_Decoder30decode_octet_aligned_bitstringINSt3__19allocatorIhEEEERS0_RNS2_6vectorIhT_EENS_9ASN1_TypeENS_10ASN1_ClassE:
  347|    841|                                                  ASN1_Class class_tag = ASN1_Class::Universal) {
  348|    841|         ASN1_BitString bits;
  349|    841|         decode_bitstring(bits, type_tag, class_tag);
  350|       |
  351|    841|         if(bits.unused_bits() != 0) {
  ------------------
  |  Branch (351:13): [True: 4, False: 837]
  ------------------
  352|      4|            throw Decoding_Error("Expected octet-aligned BIT STRING");
  353|      4|         }
  354|       |
  355|    837|         out.assign(bits.bytes().begin(), bits.bytes().end());
  356|    837|         return (*this);
  357|    841|      }
_ZN5Botan11BER_Decoder15decode_optionalImEERS0_RT_NS_9ASN1_TypeENS_10ASN1_ClassERKS3_:
  387|    744|      BER_Decoder& decode_optional(T& out, ASN1_Type type_tag, ASN1_Class class_tag, const T& default_value = T()) {
  388|    744|         std::optional<T> optval;
  389|    744|         this->decode_optional(optval, type_tag, class_tag);
  390|    744|         out = optval ? *optval : default_value;
  ------------------
  |  Branch (390:16): [True: 5, False: 739]
  ------------------
  391|    744|         return (*this);
  392|    744|      }
_ZN5Botan11BER_Decoder15decode_optionalImEERS0_RNSt3__18optionalIT_EENS_9ASN1_TypeENS_10ASN1_ClassE:
  578|    744|BER_Decoder& BER_Decoder::decode_optional(std::optional<T>& optval, ASN1_Type type_tag, ASN1_Class class_tag) {
  579|    744|   BER_Object obj = get_next_object();
  580|       |
  581|    744|   if(obj.is_a(type_tag, class_tag)) {
  ------------------
  |  Branch (581:7): [True: 8, False: 736]
  ------------------
  582|      8|      T out{};
  583|      8|      if(class_tag == ASN1_Class::ExplicitContextSpecific) {
  ------------------
  |  Branch (583:10): [True: 8, False: 0]
  ------------------
  584|      8|         BER_Decoder(obj, m_limits).decode(out).verify_end();
  585|      8|      } else {
  586|      0|         this->push_back(std::move(obj));
  587|      0|         this->decode(out, type_tag, class_tag);
  588|      0|      }
  589|      8|      optval = std::move(out);
  590|    736|   } else {
  591|    736|      this->push_back(std::move(obj));
  592|    736|      optval = std::nullopt;
  593|    736|   }
  594|       |
  595|    744|   return (*this);
  596|    744|}
_ZN5Botan11BER_Decoder6decodeERm:
  303|      8|      BER_Decoder& decode(size_t& out) { return decode(out, ASN1_Type::Integer, ASN1_Class::Universal); }
_ZN5Botan11BER_Decoder15decode_optionalINS_7X509_DNEEERS0_RT_NS_9ASN1_TypeENS_10ASN1_ClassERKS4_:
  387|    740|      BER_Decoder& decode_optional(T& out, ASN1_Type type_tag, ASN1_Class class_tag, const T& default_value = T()) {
  388|    740|         std::optional<T> optval;
  389|    740|         this->decode_optional(optval, type_tag, class_tag);
  390|    740|         out = optval ? *optval : default_value;
  ------------------
  |  Branch (390:16): [True: 206, False: 534]
  ------------------
  391|    740|         return (*this);
  392|    740|      }
_ZN5Botan11BER_Decoder15decode_optionalINS_7X509_DNEEERS0_RNSt3__18optionalIT_EENS_9ASN1_TypeENS_10ASN1_ClassE:
  578|    740|BER_Decoder& BER_Decoder::decode_optional(std::optional<T>& optval, ASN1_Type type_tag, ASN1_Class class_tag) {
  579|    740|   BER_Object obj = get_next_object();
  580|       |
  581|    740|   if(obj.is_a(type_tag, class_tag)) {
  ------------------
  |  Branch (581:7): [True: 572, False: 168]
  ------------------
  582|    572|      T out{};
  583|    572|      if(class_tag == ASN1_Class::ExplicitContextSpecific) {
  ------------------
  |  Branch (583:10): [True: 572, False: 0]
  ------------------
  584|    572|         BER_Decoder(obj, m_limits).decode(out).verify_end();
  585|    572|      } else {
  586|      0|         this->push_back(std::move(obj));
  587|      0|         this->decode(out, type_tag, class_tag);
  588|      0|      }
  589|    572|      optval = std::move(out);
  590|    572|   } else {
  591|    168|      this->push_back(std::move(obj));
  592|    168|      optval = std::nullopt;
  593|    168|   }
  594|       |
  595|    740|   return (*this);
  596|    740|}
_ZN5Botan11BER_Decoder22decode_optional_stringINSt3__19allocatorIhEEEERS0_RNS2_6vectorIhT_EENS_9ASN1_TypeEjNS_10ASN1_ClassE:
  499|    373|                                          ASN1_Class class_tag = ASN1_Class::ContextSpecific) {
  500|    373|         BER_Object obj = get_next_object();
  501|       |
  502|    373|         const ASN1_Type type_tag = static_cast<ASN1_Type>(expected_tag);
  503|       |
  504|    373|         if(obj.is_a(type_tag, class_tag)) {
  ------------------
  |  Branch (504:13): [True: 7, False: 366]
  ------------------
  505|      7|            if(class_tag == ASN1_Class::ExplicitContextSpecific) {
  ------------------
  |  Branch (505:16): [True: 7, False: 0]
  ------------------
  506|      7|               BER_Decoder(obj, m_limits).decode(out, real_type).verify_end();
  507|      7|            } else {
  508|      0|               push_back(std::move(obj));
  509|      0|               decode(out, real_type, type_tag, class_tag);
  510|      0|            }
  511|    366|         } else {
  512|    366|            out.clear();
  513|    366|            push_back(std::move(obj));
  514|    366|         }
  515|       |
  516|    373|         return (*this);
  517|    373|      }
_ZN5Botan11BER_Decoder11decode_listINS_4OCSP14SingleResponseEEERS0_RNSt3__16vectorIT_NS5_9allocatorIS7_EEEENS_9ASN1_TypeENS_10ASN1_ClassE:
  625|     10|BER_Decoder& BER_Decoder::decode_list(std::vector<T>& vec, ASN1_Type type_tag, ASN1_Class class_tag) {
  626|     10|   BER_Decoder list = start_cons(type_tag, class_tag);
  627|       |
  628|     12|   while(list.more_items()) {
  ------------------
  |  Branch (628:10): [True: 2, False: 10]
  ------------------
  629|      2|      T value;
  630|      2|      list.decode(value);
  631|      2|      vec.push_back(std::move(value));
  632|      2|   }
  633|       |
  634|     10|   list.end_cons();
  635|       |
  636|     10|   return (*this);
  637|     10|}
_ZNK5Botan11BER_Decoder6Limits18allow_ber_encodingEv:
   52|  43.8k|            bool allow_ber_encoding() const { return m_allow_ber; }
_ZNK5Botan11BER_Decoder6Limits20require_der_encodingEv:
   54|  27.4k|            bool require_der_encoding() const { return !allow_ber_encoding(); }
_ZNK5Botan11BER_Decoder6Limits15max_object_sizeEv:
   70|  16.2k|            std::optional<size_t> max_object_size() const { return m_max_object_size; }
_ZNK5Botan11BER_Decoder6limitsEv:
  176|  9.02k|      Limits limits() const { return m_limits; }
_ZN5Botan11BER_Decoder9start_setEv:
  240|    568|      BER_Decoder start_set() { return start_cons(ASN1_Type::Set, ASN1_Class::Universal); }

_ZN5Botan6BigIntD2Ev:
  185|  1.65k|      ~BigInt() { _const_time_unpoison(); }
_ZN5Botan6BigInt5clearEv:
  415|  1.56k|      void clear() {
  416|  1.56k|         m_data.set_to_zero();
  417|  1.56k|         m_signedness = Positive;
  418|  1.56k|      }
_ZNK5Botan6BigInt6signumEv:
  467|  1.56k|      int signum() const {
  468|  1.56k|         if(sig_words() == 0) {
  ------------------
  |  Branch (468:13): [True: 1.29k, False: 270]
  ------------------
  469|  1.29k|            return 0;
  470|  1.29k|         }
  471|    270|         return (sign() == Negative) ? -1 : 1;
  ------------------
  |  Branch (471:17): [True: 103, False: 167]
  ------------------
  472|  1.56k|      }
_ZNK5Botan6BigInt7is_zeroEv:
  484|    103|      bool is_zero() const { return sig_words() == 0; }
_ZNK5Botan6BigInt7word_atEm:
  574|  5.68k|      word word_at(size_t n) const { return m_data.get_word_at(n); }
_ZNK5Botan6BigInt4signEv:
  604|    373|      Sign sign() const { return (m_signedness); }
_ZNK5Botan6BigInt12reverse_signEv:
  609|    103|      Sign reverse_sign() const {
  610|    103|         if(sign() == Positive) {
  ------------------
  |  Branch (610:13): [True: 103, False: 0]
  ------------------
  611|    103|            return Negative;
  612|    103|         }
  613|      0|         return Positive;
  614|    103|      }
_ZN5Botan6BigInt9flip_signEv:
  619|    103|      BOTAN_DEPRECATED("Deprecated no replacement") void flip_sign() { set_sign(reverse_sign()); }
_ZN5Botan6BigInt8set_signENS0_4SignE:
  625|    103|      void set_sign(Sign sign) {
  626|    103|         if(sign == Negative && is_zero()) {
  ------------------
  |  Branch (626:13): [True: 103, False: 0]
  |  Branch (626:33): [True: 0, False: 103]
  ------------------
  627|      0|            sign = Positive;
  628|      0|         }
  629|       |
  630|    103|         m_signedness = sign;
  631|    103|      }
_ZNK5Botan6BigInt9sig_wordsEv:
  648|  3.30k|      size_t sig_words() const { return m_data.sig_words(); }
_ZN5Botan6BigInt18_assign_from_bytesENSt3__14spanIKhLm18446744073709551615EEE:
  983|  1.56k|      void _assign_from_bytes(std::span<const uint8_t> bytes) { assign_from_bytes(bytes); }
_ZNK5Botan6BigInt4Data10const_dataEv:
 1027|  1.65k|            const word* const_data() const { return m_reg.data(); }
_ZNK5Botan6BigInt4Data11get_word_atEm:
 1038|  5.68k|            word get_word_at(size_t n) const {
 1039|  5.68k|               if(n < m_reg.size()) {
  ------------------
  |  Branch (1039:19): [True: 5.68k, False: 0]
  ------------------
 1040|  5.68k|                  return m_reg[n];
 1041|  5.68k|               }
 1042|      0|               return 0;
 1043|  5.68k|            }
_ZNK5Botan6BigInt4Data4sizeEv:
 1075|  1.65k|            size_t size() const { return m_reg.size(); }
_ZN5Botan6BigInt4Data4swapERNSt3__16vectorImNS_16secure_allocatorImEEEE:
 1095|  1.56k|            void swap(secure_vector<word>& reg) noexcept {
 1096|  1.56k|               m_reg.swap(reg);
 1097|  1.56k|               invalidate_sig_words();
 1098|  1.56k|            }
_ZNK5Botan6BigInt4Data20invalidate_sig_wordsEv:
 1100|  1.56k|            void invalidate_sig_words() const noexcept { m_sig_words = sig_words_npos; }
_ZNK5Botan6BigInt4Data9sig_wordsEv:
 1102|  3.30k|            size_t sig_words() const {
 1103|  3.30k|               if(m_sig_words == sig_words_npos) {
  ------------------
  |  Branch (1103:19): [True: 1.56k, False: 1.73k]
  ------------------
 1104|  1.56k|                  m_sig_words = calc_sig_words();
 1105|  1.56k|               }
 1106|  3.30k|               return m_sig_words;
 1107|  3.30k|            }
_ZN5Botan6BigIntC2Ev:
   45|  1.65k|      BigInt() = default;

_ZN5Botan10DataSourceC2Ev:
  100|  14.4k|      DataSource() = default;
_ZN5Botan10DataSourceD2Ev:
  101|  13.4k|      virtual ~DataSource() = default;
_ZN5Botan17DataSource_MemoryC2ENSt3__14spanIKhLm18446744073709551615EEE:
  141|  4.99k|      explicit DataSource_Memory(std::span<const uint8_t> in) : m_offset(0) {
  142|       |         // Guard against forming a range from a null pointer (eg an empty span)
  143|  4.99k|         if(!in.empty()) {
  ------------------
  |  Branch (143:13): [True: 4.98k, False: 9]
  ------------------
  144|  4.98k|            m_source.assign(in.begin(), in.end());
  145|  4.98k|         }
  146|  4.99k|      }

_ZN5Botan11DER_Encoder10add_objectENS_9ASN1_TypeENS_10ASN1_ClassENSt3__14spanIKhLm18446744073709551615EEE:
  218|    203|      DER_Encoder& add_object(ASN1_Type type_tag, ASN1_Class class_tag, std::span<const uint8_t> rep) {
  219|    203|         return add_object(type_tag, class_tag, rep.data(), rep.size());
  220|    203|      }
_ZN5Botan11DER_Encoder10add_objectENS_9ASN1_TypeENS_10ASN1_ClassERKNSt3__16vectorIhNS3_9allocatorIhEEEE:
  222|    203|      DER_Encoder& add_object(ASN1_Type type_tag, ASN1_Class class_tag, const std::vector<uint8_t>& rep) {
  223|    203|         return add_object(type_tag, class_tag, std::span{rep});
  224|    203|      }

_ZNK5Botan9Exception4whatEv:
   94|     61|      const char* what() const noexcept override { return m_msg.c_str(); }

_ZN5Botan9clear_memImEEvPT_m:
  118|  1.56k|inline constexpr void clear_mem(T* ptr, size_t n) {
  119|  1.56k|   clear_bytes(ptr, sizeof(T) * n);
  120|  1.56k|}
_ZN5Botan11clear_bytesEPvm:
  101|  1.56k|inline constexpr void clear_bytes(void* ptr, size_t bytes) {
  102|  1.56k|   if(bytes > 0) {
  ------------------
  |  Branch (102:7): [True: 0, False: 1.56k]
  ------------------
  103|      0|      std::memset(ptr, 0, bytes);
  104|      0|   }
  105|  1.56k|}
_ZN5Botan13typecast_copyImTkNS_6ranges16contiguous_rangeENSt3__14spanIKhLm8EEEQaaaasr3stdE26is_default_constructible_vIT_Esr3stdE23is_trivially_copyable_vIS6_Esr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISE_EESF_E4type10value_typeEEEES6_RKSB_:
  210|  7.84k|inline constexpr ToT typecast_copy(const FromR& src) {
  211|  7.84k|   ToT dst;  // NOLINT(*-member-init)
  212|  7.84k|   typecast_copy(dst, src);
  213|  7.84k|   return dst;
  214|  7.84k|}
_ZN5Botan13typecast_copyImTkNS_6ranges16contiguous_rangeENSt3__14spanIKhLm8EEEQaaaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISD_EESE_E4type10value_typeEEsr3stdE23is_trivially_copyable_vIT_Entsr3std6rangesE5rangeISK_EEEvRSK_RKSA_:
  188|  7.84k|inline constexpr void typecast_copy(ToT& out, const FromR& in) {
  189|  7.84k|   typecast_copy(std::span<ToT, 1>(&out, 1), in);
  190|  7.84k|}
_ZN5Botan13typecast_copyITkNS_6ranges23contiguous_output_rangeENSt3__14spanImLm1EEETkNS1_16contiguous_rangeENS3_IKhLm8EEEQaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISE_EESF_E4type10value_typeEEsr3stdE23is_trivially_copyable_vINS7_IXsr21__is_primary_templateINS8_Iu14__remove_cvrefIDTclL_ZNSA_5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENSG_ISO_EESP_E4type10value_typeEEEEvOSL_RKSB_:
  176|  7.84k|inline constexpr void typecast_copy(ToR&& out /* NOLINT(*-std-forward) */, const FromR& in) {
  177|  7.84k|   ranges::assert_equal_byte_lengths(out, in);
  178|  7.84k|   std::memcpy(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  179|  7.84k|}
_ZN5Botan8copy_memITkNS_6ranges23contiguous_output_rangeENSt3__14spanIhLm18446744073709551615EEETkNS1_16contiguous_rangeENS3_IKhLm18446744073709551615EEEQaasr3stdE9is_same_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISE_EESF_E4type10value_typeENS7_IXsr21__is_primary_templateINS8_Iu14__remove_cvrefIDTclL_ZNSA_5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENSG_ISO_EESP_E4type10value_typeEEsr3stdE23is_trivially_copyable_vIST_EEEvOSB_RKSL_:
  160|  1.55k|inline constexpr void copy_mem(OutR&& out /* NOLINT(*-std-forward) */, const InR& in) {
  161|  1.55k|   ranges::assert_equal_byte_lengths(out, in);
  162|  1.55k|   if(std::is_constant_evaluated()) {
  ------------------
  |  Branch (162:7): [Folded, False: 1.55k]
  ------------------
  163|      0|      std::copy(std::ranges::begin(in), std::ranges::end(in), std::ranges::begin(out));
  164|  1.55k|   } else if(ranges::size_bytes(out) > 0) {
  ------------------
  |  Branch (164:14): [True: 1.55k, False: 0]
  ------------------
  165|  1.55k|      std::memmove(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  166|  1.55k|   }
  167|  1.55k|}
_ZN5Botan13typecast_copyImTkNS_6ranges16contiguous_rangeENSt3__14spanIhLm8EEEQaaaasr3stdE26is_default_constructible_vIT_Esr3stdE23is_trivially_copyable_vIS5_Esr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISD_EESE_E4type10value_typeEEEES5_RKSA_:
  210|  1.55k|inline constexpr ToT typecast_copy(const FromR& src) {
  211|  1.55k|   ToT dst;  // NOLINT(*-member-init)
  212|  1.55k|   typecast_copy(dst, src);
  213|  1.55k|   return dst;
  214|  1.55k|}
_ZN5Botan13typecast_copyImTkNS_6ranges16contiguous_rangeENSt3__14spanIhLm8EEEQaaaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISC_EESD_E4type10value_typeEEsr3stdE23is_trivially_copyable_vIT_Entsr3std6rangesE5rangeISJ_EEEvRSJ_RKS9_:
  188|  1.55k|inline constexpr void typecast_copy(ToT& out, const FromR& in) {
  189|  1.55k|   typecast_copy(std::span<ToT, 1>(&out, 1), in);
  190|  1.55k|}
_ZN5Botan13typecast_copyITkNS_6ranges23contiguous_output_rangeENSt3__14spanImLm1EEETkNS1_16contiguous_rangeENS3_IhLm8EEEQaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISD_EESE_E4type10value_typeEEsr3stdE23is_trivially_copyable_vINS6_IXsr21__is_primary_templateINS7_Iu14__remove_cvrefIDTclL_ZNS9_5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENSF_ISN_EESO_E4type10value_typeEEEEvOSK_RKSA_:
  176|  1.55k|inline constexpr void typecast_copy(ToR&& out /* NOLINT(*-std-forward) */, const FromR& in) {
  177|  1.55k|   ranges::assert_equal_byte_lengths(out, in);
  178|  1.55k|   std::memcpy(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  179|  1.55k|}
_ZN5Botan13typecast_copyITkNS_6ranges23contiguous_output_rangeERNSt3__15arrayIhLm8EEETkNS1_16contiguous_rangeENS3_ImLm1EEEQaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISE_EESF_E4type10value_typeEEsr3stdE23is_trivially_copyable_vINS7_IXsr21__is_primary_templateINS8_Iu14__remove_cvrefIDTclL_ZNSA_5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENSG_ISO_EESP_E4type10value_typeEEEEvOSL_RKSB_:
  176|    609|inline constexpr void typecast_copy(ToR&& out /* NOLINT(*-std-forward) */, const FromR& in) {
  177|    609|   ranges::assert_equal_byte_lengths(out, in);
  178|    609|   std::memcpy(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  179|    609|}
_ZN5Botan19secure_scrub_memoryITkNS_6ranges23contiguous_output_rangeERNSt3__16vectorIhNS2_9allocatorIhEEEEEEvOT_:
   59|  41.6k|void secure_scrub_memory(ranges::contiguous_output_range auto&& data) {
   60|  41.6k|   secure_scrub_memory(std::ranges::data(data), ranges::size_bytes(data));
   61|  41.6k|}
_ZN5Botan8copy_memIhQsr3stdE12is_trivial_vIu7__decayIT_EEEEvPS1_PKS1_m:
  144|  80.1k|inline constexpr void copy_mem(T* out, const T* in, size_t n) {
  145|  80.1k|   BOTAN_ASSERT_IMPLICATION(n > 0, in != nullptr && out != nullptr, "If n > 0 then args are not null");
  ------------------
  |  |  103|  80.1k|   do {                                                                                          \
  |  |  104|  80.1k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                                              \
  |  |  105|   151k|      if((expr1) && !(expr2)) {                                                                  \
  |  |  ------------------
  |  |  |  Branch (105:10): [True: 75.7k, False: 4.41k]
  |  |  |  Branch (105:23): [True: 75.7k, False: 0]
  |  |  |  Branch (105:23): [True: 75.7k, False: 0]
  |  |  ------------------
  |  |  106|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                                     \
  |  |  107|      0|         Botan::assertion_failure(#expr1 " implies " #expr2, msg, __func__, __FILE__, __LINE__); \
  |  |  108|      0|      }                                                                                          \
  |  |  109|  80.1k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (109:12): [Folded, False: 80.1k]
  |  |  ------------------
  ------------------
  146|       |
  147|  80.1k|   if(in != nullptr && out != nullptr && n > 0) {
  ------------------
  |  Branch (147:7): [True: 79.9k, False: 166]
  |  Branch (147:24): [True: 79.3k, False: 612]
  |  Branch (147:42): [True: 75.7k, False: 3.63k]
  ------------------
  148|  75.7k|      std::memmove(out, in, sizeof(T) * n);
  149|  75.7k|   }
  150|  80.1k|}
_ZN5Botan13typecast_copyITkNS_6ranges23contiguous_output_rangeENSt3__14spanIjLm1EEETkNS1_16contiguous_rangeENS3_IKhLm4EEEQaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISE_EESF_E4type10value_typeEEsr3stdE23is_trivially_copyable_vINS7_IXsr21__is_primary_templateINS8_Iu14__remove_cvrefIDTclL_ZNSA_5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENSG_ISO_EESP_E4type10value_typeEEEEvOSL_RKSB_:
  176|     81|inline constexpr void typecast_copy(ToR&& out /* NOLINT(*-std-forward) */, const FromR& in) {
  177|     81|   ranges::assert_equal_byte_lengths(out, in);
  178|     81|   std::memcpy(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  179|     81|}
_ZN5Botan13typecast_copyIjTkNS_6ranges16contiguous_rangeENSt3__14spanIKhLm4EEEQaaaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISD_EESE_E4type10value_typeEEsr3stdE23is_trivially_copyable_vIT_Entsr3std6rangesE5rangeISK_EEEvRSK_RKSA_:
  188|     81|inline constexpr void typecast_copy(ToT& out, const FromR& in) {
  189|     81|   typecast_copy(std::span<ToT, 1>(&out, 1), in);
  190|     81|}
_ZN5Botan13typecast_copyIjTkNS_6ranges16contiguous_rangeENSt3__14spanIKhLm4EEEQaaaasr3stdE26is_default_constructible_vIT_Esr3stdE23is_trivially_copyable_vIS6_Esr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISE_EESF_E4type10value_typeEEEES6_RKSB_:
  210|     81|inline constexpr ToT typecast_copy(const FromR& src) {
  211|     81|   ToT dst;  // NOLINT(*-member-init)
  212|     81|   typecast_copy(dst, src);
  213|     81|   return dst;
  214|     81|}
_ZN5Botan13typecast_copyItTkNS_6ranges16contiguous_rangeENSt3__14spanIKhLm2EEEQaaaasr3stdE26is_default_constructible_vIT_Esr3stdE23is_trivially_copyable_vIS6_Esr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISE_EESF_E4type10value_typeEEEES6_RKSB_:
  210|     74|inline constexpr ToT typecast_copy(const FromR& src) {
  211|     74|   ToT dst;  // NOLINT(*-member-init)
  212|     74|   typecast_copy(dst, src);
  213|     74|   return dst;
  214|     74|}
_ZN5Botan13typecast_copyItTkNS_6ranges16contiguous_rangeENSt3__14spanIKhLm2EEEQaaaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISD_EESE_E4type10value_typeEEsr3stdE23is_trivially_copyable_vIT_Entsr3std6rangesE5rangeISK_EEEvRSK_RKSA_:
  188|     74|inline constexpr void typecast_copy(ToT& out, const FromR& in) {
  189|     74|   typecast_copy(std::span<ToT, 1>(&out, 1), in);
  190|     74|}
_ZN5Botan13typecast_copyITkNS_6ranges23contiguous_output_rangeENSt3__14spanItLm1EEETkNS1_16contiguous_rangeENS3_IKhLm2EEEQaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISE_EESF_E4type10value_typeEEsr3stdE23is_trivially_copyable_vINS7_IXsr21__is_primary_templateINS8_Iu14__remove_cvrefIDTclL_ZNSA_5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENSG_ISO_EESP_E4type10value_typeEEEEvOSL_RKSB_:
  176|     74|inline constexpr void typecast_copy(ToR&& out /* NOLINT(*-std-forward) */, const FromR& in) {
  177|     74|   ranges::assert_equal_byte_lengths(out, in);
  178|     74|   std::memcpy(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  179|     74|}

_ZN5Botan4OCSP6CertIDC2Ev:
   30|      2|      CertID() = default;

_ZN5Botan15Key_ConstraintsC2Ev:
  166|      1|      Key_Constraints() : m_value(0) {}

_ZN5Botan10ExtensionsC2Ev:
  905|    746|      Extensions() = default;
_ZN5Botan10ExtensionsD2Ev:
  913|    746|      ~Extensions() override = default;
_ZN5Botan7X509_DNC2Ev:
   49|  3.43k|      X509_DN() = default;
_ZN5Botan15NameConstraintsC2Ev:
  641|      1|      NameConstraints() = default;
_ZN5Botan15AlternativeNameC2Ev:
  228|      2|      AlternativeName() = default;

_ZN5Botan6ranges24assert_exact_byte_lengthILm8ETkNS0_14spanable_rangeENSt3__14spanIhLm8EEEEEvRKT0_:
   77|  1.55k|inline constexpr void assert_exact_byte_length(const R& r) {
   78|  1.55k|   const std::span s{r};
   79|  1.55k|   if constexpr(statically_spanable_range<R>) {
   80|  1.55k|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   81|       |   } else {
   82|       |      if(s.size_bytes() != expected) {
   83|       |         memory_region_size_violation();
   84|       |      }
   85|       |   }
   86|  1.55k|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm8ETkNS0_14spanable_rangeENSt3__14spanIKhLm8EEEEEvRKT0_:
   77|  15.6k|inline constexpr void assert_exact_byte_length(const R& r) {
   78|  15.6k|   const std::span s{r};
   79|  15.6k|   if constexpr(statically_spanable_range<R>) {
   80|  15.6k|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   81|       |   } else {
   82|       |      if(s.size_bytes() != expected) {
   83|       |         memory_region_size_violation();
   84|       |      }
   85|       |   }
   86|  15.6k|}
_ZN5Botan6ranges25assert_equal_byte_lengthsITkNS0_14spanable_rangeENSt3__14spanImLm1EEETpTkNS0_14spanable_rangeEJNS3_IKhLm8EEEEEEvRKT_DpRKT0_QgtsZT0_Li0E:
  100|  7.84k|{
  101|  7.84k|   const std::span s0{r0};
  102|       |
  103|  7.84k|   if constexpr(statically_spanable_range<R0>) {
  104|  7.84k|      constexpr size_t expected_size = s0.size_bytes();
  105|  7.84k|      (assert_exact_byte_length<expected_size>(rs), ...);
  106|       |   } else {
  107|       |      const size_t expected_size = s0.size_bytes();
  108|       |      const bool correct_size =
  109|       |         ((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...);
  110|       |
  111|       |      if(!correct_size) {
  112|       |         memory_region_size_violation();
  113|       |      }
  114|       |   }
  115|  7.84k|}
_ZN5Botan6ranges10size_bytesITkNS0_14spanable_rangeENSt3__14spanImLm1EEEEEmRKT_:
   59|  9.40k|inline constexpr size_t size_bytes(const spanable_range auto& r) {
   60|  9.40k|   return std::span{r}.size_bytes();
   61|  9.40k|}
_ZN5Botan6ranges25assert_equal_byte_lengthsITkNS0_14spanable_rangeENSt3__14spanIhLm18446744073709551615EEETpTkNS0_14spanable_rangeEJNS3_IKhLm18446744073709551615EEEEEEvRKT_DpRKT0_QgtsZT0_Li0E:
  100|  1.55k|{
  101|  1.55k|   const std::span s0{r0};
  102|       |
  103|       |   if constexpr(statically_spanable_range<R0>) {
  104|       |      constexpr size_t expected_size = s0.size_bytes();
  105|       |      (assert_exact_byte_length<expected_size>(rs), ...);
  106|  1.55k|   } else {
  107|  1.55k|      const size_t expected_size = s0.size_bytes();
  108|  1.55k|      const bool correct_size =
  109|  1.55k|         ((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...);
  110|       |
  111|  1.55k|      if(!correct_size) {
  ------------------
  |  Branch (111:10): [True: 0, False: 1.55k]
  ------------------
  112|      0|         memory_region_size_violation();
  113|      0|      }
  114|  1.55k|   }
  115|  1.55k|}
_ZN5Botan6ranges10size_bytesITkNS0_14spanable_rangeENSt3__14spanIhLm18446744073709551615EEEEEmRKT_:
   59|  3.11k|inline constexpr size_t size_bytes(const spanable_range auto& r) {
   60|  3.11k|   return std::span{r}.size_bytes();
   61|  3.11k|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm8ETkNS0_14spanable_rangeENSt3__15arrayIhLm8EEEEEvRKT0_:
   77|  1.55k|inline constexpr void assert_exact_byte_length(const R& r) {
   78|  1.55k|   const std::span s{r};
   79|  1.55k|   if constexpr(statically_spanable_range<R>) {
   80|  1.55k|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   81|       |   } else {
   82|       |      if(s.size_bytes() != expected) {
   83|       |         memory_region_size_violation();
   84|       |      }
   85|       |   }
   86|  1.55k|}
_ZN5Botan6ranges25assert_equal_byte_lengthsITkNS0_14spanable_rangeENSt3__14spanImLm1EEETpTkNS0_14spanable_rangeEJNS3_IhLm8EEEEEEvRKT_DpRKT0_QgtsZT0_Li0E:
  100|  1.55k|{
  101|  1.55k|   const std::span s0{r0};
  102|       |
  103|  1.55k|   if constexpr(statically_spanable_range<R0>) {
  104|  1.55k|      constexpr size_t expected_size = s0.size_bytes();
  105|  1.55k|      (assert_exact_byte_length<expected_size>(rs), ...);
  106|       |   } else {
  107|       |      const size_t expected_size = s0.size_bytes();
  108|       |      const bool correct_size =
  109|       |         ((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...);
  110|       |
  111|       |      if(!correct_size) {
  112|       |         memory_region_size_violation();
  113|       |      }
  114|       |   }
  115|  1.55k|}
_ZN5Botan6ranges25assert_equal_byte_lengthsITkNS0_14spanable_rangeENSt3__15arrayIhLm8EEETpTkNS0_14spanable_rangeEJNS3_ImLm1EEEEEEvRKT_DpRKT0_QgtsZT0_Li0E:
  100|  1.21k|{
  101|  1.21k|   const std::span s0{r0};
  102|       |
  103|  1.21k|   if constexpr(statically_spanable_range<R0>) {
  104|  1.21k|      constexpr size_t expected_size = s0.size_bytes();
  105|  1.21k|      (assert_exact_byte_length<expected_size>(rs), ...);
  106|       |   } else {
  107|       |      const size_t expected_size = s0.size_bytes();
  108|       |      const bool correct_size =
  109|       |         ((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...);
  110|       |
  111|       |      if(!correct_size) {
  112|       |         memory_region_size_violation();
  113|       |      }
  114|       |   }
  115|  1.21k|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm8ETkNS0_14spanable_rangeENSt3__15arrayImLm1EEEEEvRKT0_:
   77|  1.21k|inline constexpr void assert_exact_byte_length(const R& r) {
   78|  1.21k|   const std::span s{r};
   79|  1.21k|   if constexpr(statically_spanable_range<R>) {
   80|  1.21k|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   81|       |   } else {
   82|       |      if(s.size_bytes() != expected) {
   83|       |         memory_region_size_violation();
   84|       |      }
   85|       |   }
   86|  1.21k|}
_ZN5Botan6ranges10size_bytesITkNS0_14spanable_rangeENSt3__15arrayIhLm8EEEEEmRKT_:
   59|    609|inline constexpr size_t size_bytes(const spanable_range auto& r) {
   60|    609|   return std::span{r}.size_bytes();
   61|    609|}
_ZN5Botan6ranges10size_bytesITkNS0_14spanable_rangeENSt3__16vectorIhNS2_9allocatorIhEEEEEEmRKT_:
   59|  41.6k|inline constexpr size_t size_bytes(const spanable_range auto& r) {
   60|  41.6k|   return std::span{r}.size_bytes();
   61|  41.6k|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm4ETkNS0_14spanable_rangeENSt3__14spanIKhLm4EEEEEvRKT0_:
   77|    162|inline constexpr void assert_exact_byte_length(const R& r) {
   78|    162|   const std::span s{r};
   79|    162|   if constexpr(statically_spanable_range<R>) {
   80|    162|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   81|       |   } else {
   82|       |      if(s.size_bytes() != expected) {
   83|       |         memory_region_size_violation();
   84|       |      }
   85|       |   }
   86|    162|}
_ZN5Botan6ranges25assert_equal_byte_lengthsITkNS0_14spanable_rangeENSt3__14spanIjLm1EEETpTkNS0_14spanable_rangeEJNS3_IKhLm4EEEEEEvRKT_DpRKT0_QgtsZT0_Li0E:
  100|     81|{
  101|     81|   const std::span s0{r0};
  102|       |
  103|     81|   if constexpr(statically_spanable_range<R0>) {
  104|     81|      constexpr size_t expected_size = s0.size_bytes();
  105|     81|      (assert_exact_byte_length<expected_size>(rs), ...);
  106|       |   } else {
  107|       |      const size_t expected_size = s0.size_bytes();
  108|       |      const bool correct_size =
  109|       |         ((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...);
  110|       |
  111|       |      if(!correct_size) {
  112|       |         memory_region_size_violation();
  113|       |      }
  114|       |   }
  115|     81|}
_ZN5Botan6ranges10size_bytesITkNS0_14spanable_rangeENSt3__14spanIjLm1EEEEEmRKT_:
   59|     81|inline constexpr size_t size_bytes(const spanable_range auto& r) {
   60|     81|   return std::span{r}.size_bytes();
   61|     81|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm2ETkNS0_14spanable_rangeENSt3__14spanIKhLm2EEEEEvRKT0_:
   77|    148|inline constexpr void assert_exact_byte_length(const R& r) {
   78|    148|   const std::span s{r};
   79|    148|   if constexpr(statically_spanable_range<R>) {
   80|    148|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   81|       |   } else {
   82|       |      if(s.size_bytes() != expected) {
   83|       |         memory_region_size_violation();
   84|       |      }
   85|       |   }
   86|    148|}
_ZN5Botan6ranges25assert_equal_byte_lengthsITkNS0_14spanable_rangeENSt3__14spanItLm1EEETpTkNS0_14spanable_rangeEJNS3_IKhLm2EEEEEEvRKT_DpRKT0_QgtsZT0_Li0E:
  100|     74|{
  101|     74|   const std::span s0{r0};
  102|       |
  103|     74|   if constexpr(statically_spanable_range<R0>) {
  104|     74|      constexpr size_t expected_size = s0.size_bytes();
  105|     74|      (assert_exact_byte_length<expected_size>(rs), ...);
  106|       |   } else {
  107|       |      const size_t expected_size = s0.size_bytes();
  108|       |      const bool correct_size =
  109|       |         ((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...);
  110|       |
  111|       |      if(!correct_size) {
  112|       |         memory_region_size_violation();
  113|       |      }
  114|       |   }
  115|     74|}
_ZN5Botan6ranges10size_bytesITkNS0_14spanable_rangeENSt3__14spanItLm1EEEEEmRKT_:
   59|     74|inline constexpr size_t size_bytes(const spanable_range auto& r) {
   60|     74|   return std::span{r}.size_bytes();
   61|     74|}

_ZN5Botan16secure_allocatorImE10deallocateEPmm:
   54|  1.56k|      void deallocate(T* p, std::size_t n) { deallocate_memory(p, n, sizeof(T)); }
_ZN5Botan16secure_allocatorIhE10deallocateEPhm:
   54|  5.09k|      void deallocate(T* p, std::size_t n) { deallocate_memory(p, n, sizeof(T)); }
_ZN5Botan16secure_allocatorIhE8allocateEm:
   52|  5.09k|      T* allocate(std::size_t n) { return static_cast<T*>(allocate_memory(n, sizeof(T))); }
_ZN5Botan16secure_allocatorImE8allocateEm:
   52|  1.56k|      T* allocate(std::size_t n) { return static_cast<T*>(allocate_memory(n, sizeof(T))); }

_ZN5Botan16wrap_strong_typeImRmQoosr3stdE18constructible_fromIT_T0_Eaasr8conceptsE11strong_typeIS2_Esr3stdE18constructible_fromINS2_12wrapped_typeES3_EEEDcOS3_:
  268|  9.40k|[[nodiscard]] constexpr decltype(auto) wrap_strong_type(ParamT&& t) {
  269|  9.40k|   if constexpr(std::same_as<std::remove_cvref_t<ParamT>, T>) {
  270|       |      // Noop, if the parameter type already is the desired return type.
  271|  9.40k|      return std::forward<ParamT>(t);
  272|       |   } else if constexpr(std::constructible_from<T, ParamT>) {
  273|       |      // Implicit conversion from the parameter type to the return type.
  274|       |      return T{std::forward<ParamT>(t)};
  275|       |   } else {
  276|       |      // Explicitly calling the wrapped type's constructor to support
  277|       |      // implicit conversions on types that mark their constructors as explicit.
  278|       |      static_assert(concepts::strong_type<T> && std::constructible_from<typename T::wrapped_type, ParamT>);
  279|       |      return T{typename T::wrapped_type{std::forward<ParamT>(t)}};
  280|       |   }
  281|  9.40k|}
_ZN5Botan16wrap_strong_typeIjRjQoosr3stdE18constructible_fromIT_T0_Eaasr8conceptsE11strong_typeIS2_Esr3stdE18constructible_fromINS2_12wrapped_typeES3_EEEDcOS3_:
  268|     81|[[nodiscard]] constexpr decltype(auto) wrap_strong_type(ParamT&& t) {
  269|     81|   if constexpr(std::same_as<std::remove_cvref_t<ParamT>, T>) {
  270|       |      // Noop, if the parameter type already is the desired return type.
  271|     81|      return std::forward<ParamT>(t);
  272|       |   } else if constexpr(std::constructible_from<T, ParamT>) {
  273|       |      // Implicit conversion from the parameter type to the return type.
  274|       |      return T{std::forward<ParamT>(t)};
  275|       |   } else {
  276|       |      // Explicitly calling the wrapped type's constructor to support
  277|       |      // implicit conversions on types that mark their constructors as explicit.
  278|       |      static_assert(concepts::strong_type<T> && std::constructible_from<typename T::wrapped_type, ParamT>);
  279|       |      return T{typename T::wrapped_type{std::forward<ParamT>(t)}};
  280|       |   }
  281|     81|}
_ZN5Botan16wrap_strong_typeItRtQoosr3stdE18constructible_fromIT_T0_Eaasr8conceptsE11strong_typeIS2_Esr3stdE18constructible_fromINS2_12wrapped_typeES3_EEEDcOS3_:
  268|     74|[[nodiscard]] constexpr decltype(auto) wrap_strong_type(ParamT&& t) {
  269|     74|   if constexpr(std::same_as<std::remove_cvref_t<ParamT>, T>) {
  270|       |      // Noop, if the parameter type already is the desired return type.
  271|     74|      return std::forward<ParamT>(t);
  272|       |   } else if constexpr(std::constructible_from<T, ParamT>) {
  273|       |      // Implicit conversion from the parameter type to the return type.
  274|       |      return T{std::forward<ParamT>(t)};
  275|       |   } else {
  276|       |      // Explicitly calling the wrapped type's constructor to support
  277|       |      // implicit conversions on types that mark their constructors as explicit.
  278|       |      static_assert(concepts::strong_type<T> && std::constructible_from<typename T::wrapped_type, ParamT>);
  279|       |      return T{typename T::wrapped_type{std::forward<ParamT>(t)}};
  280|       |   }
  281|     74|}

_ZN5Botan11X509_ObjectC2Ev:
  120|     14|      X509_Object() = default;

_ZN5Botan16X509_CertificateC2Ev:
  546|     14|      X509_Certificate() = default;

LLVMFuzzerInitialize:
   28|      2|extern "C" int LLVMFuzzerInitialize(int* /*argc*/, char*** /*argv*/) {
   29|       |   /*
   30|       |   * This disables the mlock pool, as overwrites within the pool are
   31|       |   * opaque to ASan or other instrumentation.
   32|       |   */
   33|      2|   ::setenv("BOTAN_MLOCK_POOL_SIZE", "0", 1);
   34|      2|   return 0;
   35|      2|}
LLVMFuzzerTestOneInput:
   39|  2.12k|extern "C" int LLVMFuzzerTestOneInput(const uint8_t in[], size_t len) {
   40|  2.12k|   if(len <= max_fuzzer_input_size) {
  ------------------
  |  Branch (40:7): [True: 2.11k, False: 9]
  ------------------
   41|  2.11k|      try {
   42|  2.11k|         fuzz(std::span<const uint8_t>(in, len));
   43|  2.11k|      } catch(const std::exception& e) {
   44|      0|         std::cerr << "Uncaught exception from fuzzer driver " << e.what() << "\n";
   45|      0|         abort();
   46|      0|      } catch(...) {
   47|      0|         std::cerr << "Uncaught exception from fuzzer driver (unknown type)\n";
   48|      0|         abort();
   49|      0|      }
   50|  2.11k|   }
   51|  2.12k|   return 0;
   52|  2.12k|}

_Z4fuzzNSt3__14spanIKhLm18446744073709551615EEE:
   11|  2.11k|void fuzz(std::span<const uint8_t> in) {
   12|  2.11k|   try {
   13|  2.11k|      const Botan::OCSP::Response response(in.data(), in.size());
   14|  2.11k|   } catch(const Botan::Exception& e) {}
   15|  2.11k|}

_ZNK5Botan19AlgorithmIdentifier19parameters_are_nullEv:
   50|    155|bool AlgorithmIdentifier::parameters_are_null() const {
   51|    155|   return (m_parameters.size() == 2 && (m_parameters[0] == 0x05) && (m_parameters[1] == 0x00));
  ------------------
  |  Branch (51:12): [True: 44, False: 111]
  |  Branch (51:40): [True: 12, False: 32]
  |  Branch (51:69): [True: 4, False: 8]
  ------------------
   52|    155|}
_ZN5Botan19AlgorithmIdentifier11decode_fromERNS_11BER_DecoderE:
   83|    964|void AlgorithmIdentifier::decode_from(BER_Decoder& codec) {
   84|    964|   codec.start_sequence().decode(m_oid).raw_bytes(m_parameters).end_cons();
   85|       |
   86|       |   /*
   87|       |   * The parameters field is OPTIONAL ANY but in practice it is one of
   88|       |   * - empty
   89|       |   * - NULL
   90|       |   * - SEQUENCE
   91|       |   * - OBJECT IDENTIFIER (namedCurve)
   92|       |   * - OCTET STRING (CBC IV in PBES2)
   93|       |   *
   94|       |   * So require it be exactly one of these values. In particular this ensures that
   95|       |   * there is not any additional trailing data (eg after the SEQUENCE encoding)
   96|       |   * that might be otherwise skipped over by a reader.
   97|       |   */
   98|       |
   99|    964|   const bool acceptable_parameters = [&]() {
  100|    964|      if(this->parameters_are_null_or_empty()) {
  101|    964|         return true;
  102|    964|      }
  103|    964|      if(ASN1::is_der_sequence_header(m_parameters)) {
  104|    964|         return true;
  105|    964|      }
  106|    964|      if(ASN1::is_single_der_object(m_parameters, ASN1_Type::ObjectId, ASN1_Class::Universal)) {
  107|    964|         return true;
  108|    964|      }
  109|    964|      if(ASN1::is_single_der_object(m_parameters, ASN1_Type::OctetString, ASN1_Class::Universal)) {
  110|    964|         return true;
  111|    964|      }
  112|    964|      return false;
  113|    964|   }();
  114|       |
  115|    964|   if(!acceptable_parameters) {
  ------------------
  |  Branch (115:7): [True: 113, False: 851]
  ------------------
  116|    113|      throw Decoding_Error("AlgorithmIdentifier parameters were not NULL, a SEQUENCE, an OID, or an OCTET STRING");
  117|    113|   }
  118|    964|}
alg_id.cpp:_ZZN5Botan19AlgorithmIdentifier11decode_fromERNS_11BER_DecoderEENK3$_0clEv:
   99|    954|   const bool acceptable_parameters = [&]() {
  100|    954|      if(this->parameters_are_null_or_empty()) {
  ------------------
  |  Branch (100:10): [True: 803, False: 151]
  ------------------
  101|    803|         return true;
  102|    803|      }
  103|    151|      if(ASN1::is_der_sequence_header(m_parameters)) {
  ------------------
  |  Branch (103:10): [True: 7, False: 144]
  ------------------
  104|      7|         return true;
  105|      7|      }
  106|    144|      if(ASN1::is_single_der_object(m_parameters, ASN1_Type::ObjectId, ASN1_Class::Universal)) {
  ------------------
  |  Branch (106:10): [True: 25, False: 119]
  ------------------
  107|     25|         return true;
  108|     25|      }
  109|    119|      if(ASN1::is_single_der_object(m_parameters, ASN1_Type::OctetString, ASN1_Class::Universal)) {
  ------------------
  |  Branch (109:10): [True: 6, False: 113]
  ------------------
  110|      6|         return true;
  111|      6|      }
  112|    113|      return false;
  113|    119|   }();

_ZNK5Botan11ASN1_Object10BER_encodeEv:
   21|    203|std::vector<uint8_t> ASN1_Object::BER_encode() const {
   22|    203|   std::vector<uint8_t> output;
   23|    203|   DER_Encoder der(output);
   24|    203|   this->encode_into(der);
   25|    203|   return output;
   26|    203|}
_ZN5Botan14ASN1_BitStringC2ENSt3__16vectorIhNS1_9allocatorIhEEEEm:
   29|    819|      m_bytes(std::move(bytes)), m_unused_bits(unused_bits) {
   30|    819|   if(m_unused_bits >= 8) {
  ------------------
  |  Branch (30:7): [True: 0, False: 819]
  ------------------
   31|      0|      throw Invalid_Argument("ASN1_BitString: Invalid unused bit count");
   32|      0|   }
   33|       |
   34|    819|   if(m_bytes.empty() && m_unused_bits != 0) {
  ------------------
  |  Branch (34:7): [True: 781, False: 38]
  |  Branch (34:26): [True: 0, False: 781]
  ------------------
   35|      0|      throw Invalid_Argument("ASN1_BitString: Empty BIT STRING cannot have unused bits");
   36|      0|   }
   37|       |
   38|    819|   if(m_unused_bits > 0 && (m_bytes.back() & ((1U << m_unused_bits) - 1)) != 0) {
  ------------------
  |  Branch (38:7): [True: 4, False: 815]
  |  Branch (38:28): [True: 0, False: 4]
  ------------------
   39|      0|      throw Invalid_Argument("ASN1_BitString: Unused bits must be zero");
   40|      0|   }
   41|    819|}
_ZN5Botan10BER_ObjectD2Ev:
   58|  41.6k|BER_Object::~BER_Object() {
   59|  41.6k|   secure_scrub_memory(m_value);
   60|  41.6k|}
_ZNK5Botan10BER_Object11assert_is_aENS_9ASN1_TypeENS_10ASN1_ClassENSt3__117basic_string_viewIcNS3_11char_traitsIcEEEE:
   65|  12.2k|void BER_Object::assert_is_a(ASN1_Type expected_type_tag, ASN1_Class expected_class_tag, std::string_view descr) const {
   66|  12.2k|   if(!this->is_a(expected_type_tag, expected_class_tag)) {
  ------------------
  |  Branch (66:7): [True: 253, False: 12.0k]
  ------------------
   67|    253|      std::stringstream msg;
   68|       |
   69|    253|      msg << "Tag mismatch when decoding " << descr << " got ";
   70|       |
   71|    253|      if(m_class_tag == ASN1_Class::NoObject && m_type_tag == ASN1_Type::NoObject) {
  ------------------
  |  Branch (71:10): [True: 22, False: 231]
  |  Branch (71:49): [True: 22, False: 0]
  ------------------
   72|     22|         msg << "EOF";
   73|    231|      } else {
   74|    231|         if(m_class_tag == ASN1_Class::Universal || m_class_tag == ASN1_Class::Constructed) {
  ------------------
  |  Branch (74:13): [True: 72, False: 159]
  |  Branch (74:53): [True: 92, False: 67]
  ------------------
   75|    164|            msg << asn1_tag_to_string(m_type_tag);
   76|    164|         } else {
   77|     67|            msg << std::to_string(static_cast<uint32_t>(m_type_tag));
   78|     67|         }
   79|       |
   80|    231|         msg << "/" << asn1_class_to_string(m_class_tag);
   81|    231|      }
   82|       |
   83|    253|      msg << " expected ";
   84|       |
   85|    253|      if(expected_class_tag == ASN1_Class::Universal || expected_class_tag == ASN1_Class::Constructed) {
  ------------------
  |  Branch (85:10): [True: 23, False: 230]
  |  Branch (85:57): [True: 224, False: 6]
  ------------------
   86|    247|         msg << asn1_tag_to_string(expected_type_tag);
   87|    247|      } else {
   88|      6|         msg << std::to_string(static_cast<uint32_t>(expected_type_tag));
   89|      6|      }
   90|       |
   91|    253|      msg << "/" << asn1_class_to_string(expected_class_tag);
   92|       |
   93|    253|      throw BER_Decoding_Error(msg.str());
   94|    253|   }
   95|  12.2k|}
_ZNK5Botan10BER_Object4is_aENS_9ASN1_TypeENS_10ASN1_ClassE:
   97|  14.9k|bool BER_Object::is_a(ASN1_Type expected_type_tag, ASN1_Class expected_class_tag) const {
   98|  14.9k|   return (m_type_tag == expected_type_tag && m_class_tag == expected_class_tag);
  ------------------
  |  Branch (98:12): [True: 12.6k, False: 2.30k]
  |  Branch (98:47): [True: 12.6k, False: 15]
  ------------------
   99|  14.9k|}
_ZN5Botan10BER_Object11set_taggingENS_9ASN1_TypeENS_10ASN1_ClassE:
  105|  17.5k|void BER_Object::set_tagging(ASN1_Type type_tag, ASN1_Class class_tag) {
  106|  17.5k|   m_type_tag = type_tag;
  107|  17.5k|   m_class_tag = class_tag;
  108|  17.5k|}
_ZN5Botan20asn1_class_to_stringENS_10ASN1_ClassE:
  110|    484|std::string asn1_class_to_string(ASN1_Class type) {
  111|    484|   switch(type) {
  112|     95|      case ASN1_Class::Universal:
  ------------------
  |  Branch (112:7): [True: 95, False: 389]
  ------------------
  113|     95|         return "UNIVERSAL";
  114|    316|      case ASN1_Class::Constructed:
  ------------------
  |  Branch (114:7): [True: 316, False: 168]
  ------------------
  115|    316|         return "CONSTRUCTED";
  116|      7|      case ASN1_Class::ContextSpecific:
  ------------------
  |  Branch (116:7): [True: 7, False: 477]
  ------------------
  117|      7|         return "CONTEXT_SPECIFIC";
  118|      7|      case ASN1_Class::Application:
  ------------------
  |  Branch (118:7): [True: 7, False: 477]
  ------------------
  119|      7|         return "APPLICATION";
  120|     13|      case ASN1_Class::Private:
  ------------------
  |  Branch (120:7): [True: 13, False: 471]
  ------------------
  121|     13|         return "PRIVATE";
  122|      0|      case ASN1_Class::NoObject:
  ------------------
  |  Branch (122:7): [True: 0, False: 484]
  ------------------
  123|      0|         return "NO_OBJECT";
  124|     46|      default:
  ------------------
  |  Branch (124:7): [True: 46, False: 438]
  ------------------
  125|     46|         return "CLASS(" + std::to_string(static_cast<size_t>(type)) + ")";
  126|    484|   }
  127|    484|}
_ZN5Botan18asn1_tag_to_stringENS_9ASN1_TypeE:
  129|    457|std::string asn1_tag_to_string(ASN1_Type type) {
  130|    457|   switch(type) {
  131|    223|      case ASN1_Type::Sequence:
  ------------------
  |  Branch (131:7): [True: 223, False: 234]
  ------------------
  132|    223|         return "SEQUENCE";
  133|       |
  134|      6|      case ASN1_Type::Set:
  ------------------
  |  Branch (134:7): [True: 6, False: 451]
  ------------------
  135|      6|         return "SET";
  136|       |
  137|      2|      case ASN1_Type::PrintableString:
  ------------------
  |  Branch (137:7): [True: 2, False: 455]
  ------------------
  138|      2|         return "PRINTABLE STRING";
  139|       |
  140|      2|      case ASN1_Type::NumericString:
  ------------------
  |  Branch (140:7): [True: 2, False: 455]
  ------------------
  141|      2|         return "NUMERIC STRING";
  142|       |
  143|      2|      case ASN1_Type::Ia5String:
  ------------------
  |  Branch (143:7): [True: 2, False: 455]
  ------------------
  144|      2|         return "IA5 STRING";
  145|       |
  146|      2|      case ASN1_Type::TeletexString:
  ------------------
  |  Branch (146:7): [True: 2, False: 455]
  ------------------
  147|      2|         return "T61 STRING";
  148|       |
  149|     44|      case ASN1_Type::Utf8String:
  ------------------
  |  Branch (149:7): [True: 44, False: 413]
  ------------------
  150|     44|         return "UTF8 STRING";
  151|       |
  152|      1|      case ASN1_Type::VisibleString:
  ------------------
  |  Branch (152:7): [True: 1, False: 456]
  ------------------
  153|      1|         return "VISIBLE STRING";
  154|       |
  155|      2|      case ASN1_Type::BmpString:
  ------------------
  |  Branch (155:7): [True: 2, False: 455]
  ------------------
  156|      2|         return "BMP STRING";
  157|       |
  158|      2|      case ASN1_Type::UniversalString:
  ------------------
  |  Branch (158:7): [True: 2, False: 455]
  ------------------
  159|      2|         return "UNIVERSAL STRING";
  160|       |
  161|      2|      case ASN1_Type::UtcTime:
  ------------------
  |  Branch (161:7): [True: 2, False: 455]
  ------------------
  162|      2|         return "UTC TIME";
  163|       |
  164|      3|      case ASN1_Type::GeneralizedTime:
  ------------------
  |  Branch (164:7): [True: 3, False: 454]
  ------------------
  165|      3|         return "GENERALIZED TIME";
  166|       |
  167|      8|      case ASN1_Type::OctetString:
  ------------------
  |  Branch (167:7): [True: 8, False: 449]
  ------------------
  168|      8|         return "OCTET STRING";
  169|       |
  170|      6|      case ASN1_Type::BitString:
  ------------------
  |  Branch (170:7): [True: 6, False: 451]
  ------------------
  171|      6|         return "BIT STRING";
  172|       |
  173|     17|      case ASN1_Type::Enumerated:
  ------------------
  |  Branch (173:7): [True: 17, False: 440]
  ------------------
  174|     17|         return "ENUMERATED";
  175|       |
  176|      5|      case ASN1_Type::Integer:
  ------------------
  |  Branch (176:7): [True: 5, False: 452]
  ------------------
  177|      5|         return "INTEGER";
  178|       |
  179|      2|      case ASN1_Type::Null:
  ------------------
  |  Branch (179:7): [True: 2, False: 455]
  ------------------
  180|      2|         return "NULL";
  181|       |
  182|      6|      case ASN1_Type::ObjectId:
  ------------------
  |  Branch (182:7): [True: 6, False: 451]
  ------------------
  183|      6|         return "OBJECT";
  184|       |
  185|      3|      case ASN1_Type::Boolean:
  ------------------
  |  Branch (185:7): [True: 3, False: 454]
  ------------------
  186|      3|         return "BOOLEAN";
  187|       |
  188|      0|      case ASN1_Type::NoObject:
  ------------------
  |  Branch (188:7): [True: 0, False: 457]
  ------------------
  189|      0|         return "NO_OBJECT";
  190|       |
  191|    119|      default:
  ------------------
  |  Branch (191:7): [True: 119, False: 338]
  ------------------
  192|    119|         return "TAG(" + std::to_string(static_cast<uint32_t>(type)) + ")";
  193|    457|   }
  194|    457|}
_ZN5Botan18BER_Decoding_ErrorC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
  199|  1.09k|BER_Decoding_Error::BER_Decoding_Error(std::string_view err) : Decoding_Error(fmt("BER: {}", err)) {}
_ZN5Botan11BER_Bad_TagC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEEj:
  201|     55|BER_Bad_Tag::BER_Bad_Tag(std::string_view str, uint32_t tagging) : BER_Decoding_Error(fmt("{}: {}", str, tagging)) {}
_ZN5Botan4ASN19to_stringERKNS_10BER_ObjectE:
  224|    195|std::string to_string(const BER_Object& obj) {
  225|    195|   return bytes_to_string(obj.data());
  226|    195|}

_ZN5Botan3OIDC2ESt16initializer_listIjE:
   98|  1.27k|OID::OID(std::initializer_list<uint32_t> init) : m_id(init) {
   99|  1.27k|   oid_valid_check(m_id);
  100|  1.27k|}
_ZNK5Botan3OID11encode_intoERNS_11DER_EncoderE:
  185|    203|void OID::encode_into(DER_Encoder& der) const {
  186|    203|   if(m_id.size() < 2) {
  ------------------
  |  Branch (186:7): [True: 0, False: 203]
  ------------------
  187|      0|      throw Invalid_Argument("OID::encode_into: OID is invalid");
  188|      0|   }
  189|       |
  190|    203|   auto append = [](std::vector<uint8_t>& encoding, uint32_t z) {
  191|    203|      if(z <= 0x7F) {
  192|    203|         encoding.push_back(static_cast<uint8_t>(z));
  193|    203|      } else {
  194|    203|         const size_t z7 = (high_bit(z) + 7 - 1) / 7;
  195|       |
  196|    203|         for(size_t j = 0; j != z7; ++j) {
  197|    203|            uint8_t zp = static_cast<uint8_t>(z >> (7 * (z7 - j - 1)) & 0x7F);
  198|       |
  199|    203|            if(j != z7 - 1) {
  200|    203|               zp |= 0x80;
  201|    203|            }
  202|       |
  203|    203|            encoding.push_back(zp);
  204|    203|         }
  205|    203|      }
  206|    203|   };
  207|       |
  208|    203|   std::vector<uint8_t> encoding;
  209|       |
  210|       |   // We know 40 * root can't overflow because root is between 0 and 2
  211|    203|   auto first = checked_add(40 * m_id[0], m_id[1]);
  212|    203|   BOTAN_ASSERT_NOMSG(first.has_value());
  ------------------
  |  |   77|    203|   do {                                                                     \
  |  |   78|    203|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|    203|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 203]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|    203|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 203]
  |  |  ------------------
  ------------------
  213|       |
  214|    203|   append(encoding, *first);
  215|       |
  216|    249|   for(size_t i = 2; i != m_id.size(); ++i) {
  ------------------
  |  Branch (216:22): [True: 46, False: 203]
  ------------------
  217|     46|      append(encoding, m_id[i]);
  218|     46|   }
  219|    203|   der.add_object(ASN1_Type::ObjectId, ASN1_Class::Universal, encoding);
  220|    203|}
_ZN5Botan3OID11decode_fromERNS_11BER_DecoderE:
  225|  2.61k|void OID::decode_from(BER_Decoder& decoder) {
  226|  2.61k|   const BER_Object obj = decoder.get_next_object();
  227|  2.61k|   if(obj.tagging() != (ASN1_Class::Universal | ASN1_Type::ObjectId)) {
  ------------------
  |  Branch (227:7): [True: 55, False: 2.55k]
  ------------------
  228|     55|      throw BER_Bad_Tag("Error decoding OID, unknown tag", obj.tagging());
  229|     55|   }
  230|       |
  231|  2.55k|   if(obj.length() == 0) {
  ------------------
  |  Branch (231:7): [True: 1, False: 2.55k]
  ------------------
  232|      1|      throw BER_Decoding_Error("OID encoding is too short");
  233|      1|   }
  234|       |
  235|  2.55k|   auto consume = [](BufferSlicer& data) -> uint32_t {
  236|  2.55k|      BOTAN_ASSERT_NOMSG(!data.empty());
  237|  2.55k|      uint32_t b = data.take_byte();
  238|       |
  239|  2.55k|      if(b > 0x7F) {
  240|  2.55k|         b &= 0x7F;
  241|       |
  242|       |         // Even BER requires that the OID have minimal length, ie that
  243|       |         // the first byte of a multibyte encoding cannot be zero
  244|       |         // See X.690 section 8.19.2
  245|  2.55k|         if(b == 0) {
  246|  2.55k|            throw Decoding_Error("Leading zero byte in multibyte OID encoding");
  247|  2.55k|         }
  248|       |
  249|  2.55k|         while(true) {
  250|  2.55k|            if(data.empty()) {
  251|  2.55k|               throw Decoding_Error("Truncated OID value");
  252|  2.55k|            }
  253|       |
  254|  2.55k|            const uint8_t next = data.take_byte();
  255|  2.55k|            const bool more = (next & 0x80) == 0x80;
  256|  2.55k|            const uint8_t value = next & 0x7F;
  257|       |
  258|  2.55k|            if((b >> (32 - 7)) != 0) {
  259|  2.55k|               throw Decoding_Error("OID component overflow");
  260|  2.55k|            }
  261|       |
  262|  2.55k|            b = (b << 7) | value;
  263|       |
  264|  2.55k|            if(!more) {
  265|  2.55k|               break;
  266|  2.55k|            }
  267|  2.55k|         }
  268|  2.55k|      }
  269|       |
  270|  2.55k|      return b;
  271|  2.55k|   };
  272|       |
  273|  2.55k|   BufferSlicer data(obj.data());
  274|  2.55k|   std::vector<uint32_t> parts;
  275|  17.0k|   while(!data.empty()) {
  ------------------
  |  Branch (275:10): [True: 14.4k, False: 2.55k]
  ------------------
  276|  14.4k|      const uint32_t comp = consume(data);
  277|       |
  278|  14.4k|      if(parts.empty()) {
  ------------------
  |  Branch (278:10): [True: 2.53k, False: 11.9k]
  ------------------
  279|       |         // divide into root and second arc
  280|       |
  281|  2.53k|         const uint32_t root_arc = [](uint32_t b0) -> uint32_t {
  282|  2.53k|            if(b0 < 40) {
  283|  2.53k|               return 0;
  284|  2.53k|            } else if(b0 < 80) {
  285|  2.53k|               return 1;
  286|  2.53k|            } else {
  287|  2.53k|               return 2;
  288|  2.53k|            }
  289|  2.53k|         }(comp);
  290|       |
  291|  2.53k|         parts.push_back(root_arc);
  292|  2.53k|         BOTAN_ASSERT_NOMSG(comp >= 40 * root_arc);
  ------------------
  |  |   77|  2.53k|   do {                                                                     \
  |  |   78|  2.53k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|  2.53k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 2.53k]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|  2.53k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 2.53k]
  |  |  ------------------
  ------------------
  293|  2.53k|         parts.push_back(comp - 40 * root_arc);
  294|  11.9k|      } else {
  295|  11.9k|         parts.push_back(comp);
  296|  11.9k|      }
  297|  14.4k|   }
  298|       |
  299|  2.55k|   m_id = parts;
  300|  2.55k|}
asn1_oid.cpp:_ZN5Botan12_GLOBAL__N_115oid_valid_checkENSt3__14spanIKjLm18446744073709551615EEE:
   26|  1.27k|void oid_valid_check(std::span<const uint32_t> oid) {
   27|  1.27k|   BOTAN_ARG_CHECK(oid.size() >= 2, "OID too short to be valid");
  ------------------
  |  |   35|  1.27k|   do {                                                          \
  |  |   36|  1.27k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  1.27k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 1.27k]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|  1.27k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 1.27k]
  |  |  ------------------
  ------------------
   28|  1.27k|   BOTAN_ARG_CHECK(oid[0] <= 2, "OID root out of range");
  ------------------
  |  |   35|  1.27k|   do {                                                          \
  |  |   36|  1.27k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  1.27k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 1.27k]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|  1.27k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 1.27k]
  |  |  ------------------
  ------------------
   29|  1.27k|   BOTAN_ARG_CHECK(oid[1] <= 39 || oid[0] == 2, "OID second arc too large");
  ------------------
  |  |   35|  1.27k|   do {                                                          \
  |  |   36|  1.27k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  1.27k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:12): [True: 1.27k, False: 0]
  |  |  |  Branch (37:12): [True: 0, False: 0]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|  1.27k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 1.27k]
  |  |  ------------------
  ------------------
   30|       |   // This last is a limitation of using 32 bit integers when decoding
   31|       |   // not a limitation of ASN.1 object identifiers in general
   32|  1.27k|   BOTAN_ARG_CHECK(oid[1] <= 0xFFFFFFAF, "OID second arc too large");
  ------------------
  |  |   35|  1.27k|   do {                                                          \
  |  |   36|  1.27k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  1.27k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 1.27k]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|  1.27k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 1.27k]
  |  |  ------------------
  ------------------
   33|  1.27k|}
asn1_oid.cpp:_ZZNK5Botan3OID11encode_intoERNS_11DER_EncoderEENK3$_0clERNSt3__16vectorIhNS4_9allocatorIhEEEEj:
  190|    249|   auto append = [](std::vector<uint8_t>& encoding, uint32_t z) {
  191|    249|      if(z <= 0x7F) {
  ------------------
  |  Branch (191:10): [True: 174, False: 75]
  ------------------
  192|    174|         encoding.push_back(static_cast<uint8_t>(z));
  193|    174|      } else {
  194|     75|         const size_t z7 = (high_bit(z) + 7 - 1) / 7;
  195|       |
  196|    354|         for(size_t j = 0; j != z7; ++j) {
  ------------------
  |  Branch (196:28): [True: 279, False: 75]
  ------------------
  197|    279|            uint8_t zp = static_cast<uint8_t>(z >> (7 * (z7 - j - 1)) & 0x7F);
  198|       |
  199|    279|            if(j != z7 - 1) {
  ------------------
  |  Branch (199:16): [True: 204, False: 75]
  ------------------
  200|    204|               zp |= 0x80;
  201|    204|            }
  202|       |
  203|    279|            encoding.push_back(zp);
  204|    279|         }
  205|     75|      }
  206|    249|   };
asn1_oid.cpp:_ZZN5Botan3OID11decode_fromERNS_11BER_DecoderEENK3$_0clERNS_12BufferSlicerE:
  235|  14.4k|   auto consume = [](BufferSlicer& data) -> uint32_t {
  236|  14.4k|      BOTAN_ASSERT_NOMSG(!data.empty());
  ------------------
  |  |   77|  14.4k|   do {                                                                     \
  |  |   78|  14.4k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|  14.4k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 14.4k]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|  14.4k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 14.4k]
  |  |  ------------------
  ------------------
  237|  14.4k|      uint32_t b = data.take_byte();
  238|       |
  239|  14.4k|      if(b > 0x7F) {
  ------------------
  |  Branch (239:10): [True: 1.14k, False: 13.3k]
  ------------------
  240|  1.14k|         b &= 0x7F;
  241|       |
  242|       |         // Even BER requires that the OID have minimal length, ie that
  243|       |         // the first byte of a multibyte encoding cannot be zero
  244|       |         // See X.690 section 8.19.2
  245|  1.14k|         if(b == 0) {
  ------------------
  |  Branch (245:13): [True: 2, False: 1.14k]
  ------------------
  246|      2|            throw Decoding_Error("Leading zero byte in multibyte OID encoding");
  247|      2|         }
  248|       |
  249|  2.03k|         while(true) {
  ------------------
  |  Branch (249:16): [True: 2.03k, Folded]
  ------------------
  250|  2.03k|            if(data.empty()) {
  ------------------
  |  Branch (250:16): [True: 17, False: 2.01k]
  ------------------
  251|     17|               throw Decoding_Error("Truncated OID value");
  252|     17|            }
  253|       |
  254|  2.01k|            const uint8_t next = data.take_byte();
  255|  2.01k|            const bool more = (next & 0x80) == 0x80;
  256|  2.01k|            const uint8_t value = next & 0x7F;
  257|       |
  258|  2.01k|            if((b >> (32 - 7)) != 0) {
  ------------------
  |  Branch (258:16): [True: 17, False: 2.00k]
  ------------------
  259|     17|               throw Decoding_Error("OID component overflow");
  260|     17|            }
  261|       |
  262|  2.00k|            b = (b << 7) | value;
  263|       |
  264|  2.00k|            if(!more) {
  ------------------
  |  Branch (264:16): [True: 1.10k, False: 894]
  ------------------
  265|  1.10k|               break;
  266|  1.10k|            }
  267|  2.00k|         }
  268|  1.14k|      }
  269|       |
  270|  14.4k|      return b;
  271|  14.4k|   };
asn1_oid.cpp:_ZZN5Botan3OID11decode_fromERNS_11BER_DecoderEENK3$_1clEj:
  281|  2.53k|         const uint32_t root_arc = [](uint32_t b0) -> uint32_t {
  282|  2.53k|            if(b0 < 40) {
  ------------------
  |  Branch (282:16): [True: 437, False: 2.10k]
  ------------------
  283|    437|               return 0;
  284|  2.10k|            } else if(b0 < 80) {
  ------------------
  |  Branch (284:23): [True: 1.41k, False: 689]
  ------------------
  285|  1.41k|               return 1;
  286|  1.41k|            } else {
  287|    689|               return 2;
  288|    689|            }
  289|  2.53k|         }(comp);

_ZN5Botan11ASN1_StringC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEENS_9ASN1_TypeE:
  135|    399|ASN1_String::ASN1_String(std::string_view str, ASN1_Type t) : m_utf8_str(str), m_tag(t) {
  136|    399|   if(!is_utf8_subset_string_type(m_tag)) {
  ------------------
  |  Branch (136:7): [True: 0, False: 399]
  ------------------
  137|      0|      throw Invalid_Argument("ASN1_String only supports encoding to UTF-8 or a UTF-8 subset");
  138|      0|   }
  139|       |
  140|    399|   if(!is_valid_asn1_string_content(m_utf8_str, m_tag)) {
  ------------------
  |  Branch (140:7): [True: 0, False: 399]
  ------------------
  141|      0|      throw Invalid_Argument(fmt("ASN1_String: Invalid {} encoding", asn1_tag_to_string(m_tag)));
  142|      0|   }
  143|    399|}
_ZN5Botan11ASN1_StringC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
  145|    399|ASN1_String::ASN1_String(std::string_view str) : ASN1_String(str, choose_encoding(str)) {}
_ZN5Botan11ASN1_String11decode_fromERNS_11BER_DecoderE:
  162|    385|void ASN1_String::decode_from(BER_Decoder& source) {
  163|    385|   const BER_Object obj = source.get_next_object();
  164|       |
  165|    385|   if(obj.get_class() != ASN1_Class::Universal || !is_asn1_string_type(obj.type())) {
  ------------------
  |  Branch (165:7): [True: 4, False: 381]
  |  Branch (165:51): [True: 59, False: 322]
  ------------------
  166|     63|      auto typ = static_cast<uint32_t>(obj.type());
  167|     63|      auto cls = static_cast<uint32_t>(obj.get_class());
  168|     63|      throw Decoding_Error(fmt("ASN1_String: Unknown string type {}/{}", typ, cls));
  169|     63|   }
  170|       |
  171|    322|   m_tag = obj.type();
  172|    322|   m_data.assign(obj.bits(), obj.bits() + obj.length());
  173|       |
  174|    322|   if(m_tag == ASN1_Type::BmpString) {
  ------------------
  |  Branch (174:7): [True: 77, False: 245]
  ------------------
  175|     77|      m_utf8_str = ucs2_to_utf8(m_data);
  176|    245|   } else if(m_tag == ASN1_Type::UniversalString) {
  ------------------
  |  Branch (176:14): [True: 89, False: 156]
  ------------------
  177|     89|      m_utf8_str = ucs4_to_utf8(m_data);
  178|    156|   } else if(m_tag == ASN1_Type::TeletexString) {
  ------------------
  |  Branch (178:14): [True: 32, False: 124]
  ------------------
  179|       |      /*
  180|       |      TeletexString is nominally ITU T.61 not ISO-8859-1 but it seems
  181|       |      the majority of implementations actually used that charset here.
  182|       |      */
  183|     32|      m_utf8_str = latin1_to_utf8(m_data);
  184|    124|   } else {
  185|       |      // All other supported string types are UTF-8 or some subset thereof
  186|    124|      m_utf8_str = ASN1::to_string(obj);
  187|       |
  188|    124|      if(!is_valid_asn1_string_content(m_utf8_str, m_tag)) {
  ------------------
  |  Branch (188:10): [True: 46, False: 78]
  ------------------
  189|     46|         throw Decoding_Error(fmt("ASN1_String: Invalid {} encoding", asn1_tag_to_string(m_tag)));
  190|     46|      }
  191|    124|   }
  192|    322|}
asn1_str.cpp:_ZN5Botan12_GLOBAL__N_119is_asn1_string_typeENS_9ASN1_TypeE:
   99|    381|bool is_asn1_string_type(ASN1_Type tag) {
  100|    381|   return (is_utf8_subset_string_type(tag) || tag == ASN1_Type::TeletexString || tag == ASN1_Type::BmpString ||
  ------------------
  |  Branch (100:12): [True: 124, False: 257]
  |  Branch (100:47): [True: 32, False: 225]
  |  Branch (100:82): [True: 77, False: 148]
  ------------------
  101|    148|           tag == ASN1_Type::UniversalString);
  ------------------
  |  Branch (101:12): [True: 89, False: 59]
  ------------------
  102|    381|}
asn1_str.cpp:_ZN5Botan12_GLOBAL__N_126is_utf8_subset_string_typeENS_9ASN1_TypeE:
   94|  1.30k|bool is_utf8_subset_string_type(ASN1_Type tag) {
   95|  1.30k|   return (tag == ASN1_Type::NumericString || tag == ASN1_Type::PrintableString || tag == ASN1_Type::VisibleString ||
  ------------------
  |  Branch (95:12): [True: 10, False: 1.29k]
  |  Branch (95:47): [True: 802, False: 491]
  |  Branch (95:84): [True: 20, False: 471]
  ------------------
   96|    471|           tag == ASN1_Type::Ia5String || tag == ASN1_Type::Utf8String);
  ------------------
  |  Branch (96:12): [True: 16, False: 455]
  |  Branch (96:43): [True: 198, False: 257]
  ------------------
   97|  1.30k|}
asn1_str.cpp:_ZN5Botan12_GLOBAL__N_128is_valid_asn1_string_contentERKNSt3__112basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEENS_9ASN1_TypeE:
  104|    523|bool is_valid_asn1_string_content(const std::string& str, ASN1_Type tag) {
  105|    523|   BOTAN_ASSERT_NOMSG(is_utf8_subset_string_type(tag));
  ------------------
  |  |   77|    523|   do {                                                                     \
  |  |   78|    523|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|    523|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 523]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|    523|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 523]
  |  |  ------------------
  ------------------
  106|       |
  107|    523|   switch(tag) {
  108|     99|      case ASN1_Type::Utf8String:
  ------------------
  |  Branch (108:7): [True: 99, False: 424]
  ------------------
  109|     99|         return is_valid_utf8(str);
  110|      5|      case ASN1_Type::NumericString:
  ------------------
  |  Branch (110:7): [True: 5, False: 518]
  ------------------
  111|    406|      case ASN1_Type::PrintableString:
  ------------------
  |  Branch (111:7): [True: 401, False: 122]
  ------------------
  112|    414|      case ASN1_Type::Ia5String:
  ------------------
  |  Branch (112:7): [True: 8, False: 515]
  ------------------
  113|    424|      case ASN1_Type::VisibleString:
  ------------------
  |  Branch (113:7): [True: 10, False: 513]
  ------------------
  114|    424|         return g_char_validator.valid_encoding(str, tag);
  115|      0|      default:
  ------------------
  |  Branch (115:7): [True: 0, False: 523]
  ------------------
  116|      0|         return false;
  117|    523|   }
  118|    523|}
asn1_str.cpp:_ZNK5Botan12_GLOBAL__N_131ASN1_String_Codepoint_Validator14valid_encodingENSt3__117basic_string_viewIcNS2_11char_traitsIcEEEENS_9ASN1_TypeE:
   25|    823|      constexpr bool valid_encoding(std::string_view str, ASN1_Type tag) const {
   26|    823|         const uint8_t mask = mask_for(tag);
   27|    823|         for(const char c : str) {
  ------------------
  |  Branch (27:27): [True: 21, False: 820]
  ------------------
   28|     21|            const uint8_t codepoint = static_cast<uint8_t>(c);
   29|     21|            const bool is_valid = (m_table[codepoint] & mask) != 0;
   30|       |
   31|     21|            if(!is_valid) {
  ------------------
  |  Branch (31:16): [True: 3, False: 18]
  ------------------
   32|      3|               return false;
   33|      3|            }
   34|     21|         }
   35|       |
   36|    820|         return true;
   37|    823|      }
asn1_str.cpp:_ZN5Botan12_GLOBAL__N_131ASN1_String_Codepoint_Validator8mask_forENS_9ASN1_TypeE:
   45|    823|      static constexpr uint8_t mask_for(ASN1_Type tag) {
   46|    823|         switch(tag) {
   47|      5|            case ASN1_Type::NumericString:
  ------------------
  |  Branch (47:13): [True: 5, False: 818]
  ------------------
   48|      5|               return Numeric_String;
   49|    800|            case ASN1_Type::PrintableString:
  ------------------
  |  Branch (49:13): [True: 800, False: 23]
  ------------------
   50|    800|               return Printable_String;
   51|      8|            case ASN1_Type::Ia5String:
  ------------------
  |  Branch (51:13): [True: 8, False: 815]
  ------------------
   52|      8|               return IA5_String;
   53|     10|            case ASN1_Type::VisibleString:
  ------------------
  |  Branch (53:13): [True: 10, False: 813]
  ------------------
   54|     10|               return Visible_String;
   55|      0|            default:
  ------------------
  |  Branch (55:13): [True: 0, False: 823]
  ------------------
   56|      0|               return 0;
   57|    823|         }
   58|    823|      }
asn1_str.cpp:_ZN5Botan12_GLOBAL__N_115choose_encodingENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
  120|    399|ASN1_Type choose_encoding(std::string_view str) {
  121|    399|   if(g_char_validator.valid_encoding(str, ASN1_Type::PrintableString)) {
  ------------------
  |  Branch (121:7): [True: 399, False: 0]
  ------------------
  122|    399|      return ASN1_Type::PrintableString;
  123|    399|   } else {
  124|      0|      return ASN1_Type::Utf8String;
  125|      0|   }
  126|    399|}

_ZN5Botan9ASN1_TimeC2EthhhhhNS_9ASN1_TypeE:
   43|     42|      m_year(year), m_month(month), m_day(day), m_hour(hour), m_minute(minute), m_second(second), m_tag(tag) {
   44|     42|   if(tag != ASN1_Type::UtcTime && tag != ASN1_Type::GeneralizedTime) {
  ------------------
  |  Branch (44:7): [True: 28, False: 14]
  |  Branch (44:36): [True: 0, False: 28]
  ------------------
   45|      0|      throw Invalid_Argument("ASN1_Time tag must be UtcTime or GeneralizedTime");
   46|      0|   }
   47|       |
   48|       |   /*
   49|       |   * RFC 5280 Section 4.1.2.5:
   50|       |   *    To indicate that a certificate has no well-defined expiration date,
   51|       |   *    the notAfter SHOULD be assigned the GeneralizedTime value of
   52|       |   *    99991231235959Z.
   53|       |   */
   54|     42|   const uint16_t min_year = 1950;
   55|     42|   const uint16_t max_year = (tag == ASN1_Type::UtcTime) ? 2049 : 9999;
  ------------------
  |  Branch (55:30): [True: 14, False: 28]
  ------------------
   56|       |
   57|     42|   if(m_year < min_year || m_year > max_year) {
  ------------------
  |  Branch (57:7): [True: 3, False: 39]
  |  Branch (57:28): [True: 0, False: 39]
  ------------------
   58|      3|      throw Invalid_Argument(fmt("ASN1_Time year {} is out of range ({} to {})", m_year, min_year, max_year));
   59|      3|   }
   60|       |
   61|     39|   if(m_month < 1 || m_month > 12) {
  ------------------
  |  Branch (61:7): [True: 3, False: 36]
  |  Branch (61:22): [True: 4, False: 32]
  ------------------
   62|      7|      throw Invalid_Argument(fmt("ASN1_Time month {} is out of range", static_cast<uint32_t>(m_month)));
   63|      7|   }
   64|       |
   65|     32|   constexpr uint8_t days_in_month[12] = {31, 28, 31, 30, 31, 30, 31, 31, 30, 31, 30, 31};
   66|       |
   67|     32|   const bool is_leap_year = (m_year % 4 == 0) && (m_year % 100 != 0 || m_year % 400 == 0);
  ------------------
  |  Branch (67:30): [True: 17, False: 15]
  |  Branch (67:52): [True: 9, False: 8]
  |  Branch (67:73): [True: 3, False: 5]
  ------------------
   68|     32|   const uint8_t max_day = (m_month == 2 && is_leap_year) ? 29 : days_in_month[m_month - 1];
  ------------------
  |  Branch (68:29): [True: 4, False: 28]
  |  Branch (68:45): [True: 1, False: 3]
  ------------------
   69|       |
   70|     32|   if(m_day < 1 || m_day > max_day) {
  ------------------
  |  Branch (70:7): [True: 1, False: 31]
  |  Branch (70:20): [True: 9, False: 22]
  ------------------
   71|     10|      throw Invalid_Argument(fmt("ASN1_Time day {} is out of range for month {}",
   72|     10|                                 static_cast<uint32_t>(m_day),
   73|     10|                                 static_cast<uint32_t>(m_month)));
   74|     10|   }
   75|       |
   76|     22|   if(m_hour > 23) {
  ------------------
  |  Branch (76:7): [True: 6, False: 16]
  ------------------
   77|      6|      throw Invalid_Argument(fmt("ASN1_Time hour {} is out of range", static_cast<uint32_t>(m_hour)));
   78|      6|   }
   79|       |
   80|     16|   if(m_minute > 59) {
  ------------------
  |  Branch (80:7): [True: 2, False: 14]
  ------------------
   81|      2|      throw Invalid_Argument(fmt("ASN1_Time minute {} is out of range", static_cast<uint32_t>(m_minute)));
   82|      2|   }
   83|       |
   84|       |   /*
   85|       |   * RFC 5280 is silent on the issue of leap seconds in certificate fields, but both
   86|       |   * OpenSSL and Go reject which suggests they are rarely if ever used in practice.
   87|       |   */
   88|     14|   if(m_second > 59) {
  ------------------
  |  Branch (88:7): [True: 4, False: 10]
  ------------------
   89|      4|      throw Invalid_Argument(fmt("ASN1_Time second {} is out of range", static_cast<uint32_t>(m_second)));
   90|      4|   }
   91|     14|}
_ZN5Botan9ASN1_Time11from_stringENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEENS_9ASN1_TypeE:
  109|     71|ASN1_Time ASN1_Time::from_string(std::string_view t_spec, ASN1_Type tag) {
  110|     71|   BOTAN_ARG_CHECK(tag == ASN1_Type::UtcTime || tag == ASN1_Type::GeneralizedTime, "Invalid tag for ASN1_Time");
  ------------------
  |  |   35|     71|   do {                                                          \
  |  |   36|     71|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|    118|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:12): [True: 24, False: 47]
  |  |  |  Branch (37:12): [True: 47, False: 0]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|     71|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 71]
  |  |  ------------------
  ------------------
  111|       |
  112|     71|   if(tag == ASN1_Type::GeneralizedTime) {
  ------------------
  |  Branch (112:7): [True: 47, False: 24]
  ------------------
  113|     47|      BOTAN_ARG_CHECK(t_spec.size() == 15, "Invalid GeneralizedTime input string");
  ------------------
  |  |   35|     47|   do {                                                          \
  |  |   36|     47|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|     47|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 6, False: 41]
  |  |  ------------------
  |  |   38|      6|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      6|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      6|      }                                                          \
  |  |   41|     47|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 47]
  |  |  ------------------
  ------------------
  114|     47|   } else {
  115|     24|      BOTAN_ARG_CHECK(t_spec.size() == 13, "Invalid UTCTime input string");
  ------------------
  |  |   35|     24|   do {                                                          \
  |  |   36|     24|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|     24|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 7, False: 17]
  |  |  ------------------
  |  |   38|      7|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      7|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      7|      }                                                          \
  |  |   41|     24|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 24]
  |  |  ------------------
  ------------------
  116|     24|   }
  117|       |
  118|     71|   BOTAN_ARG_CHECK(t_spec.back() == 'Z', "Botan does not support ASN1 times with timezones other than Z");
  ------------------
  |  |   35|     71|   do {                                                          \
  |  |   36|     71|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|     71|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 6, False: 65]
  |  |  ------------------
  |  |   38|      6|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      6|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      6|      }                                                          \
  |  |   41|     71|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 71]
  |  |  ------------------
  ------------------
  119|       |
  120|     71|   const size_t field_len = 2;
  121|     71|   const size_t year_len = (tag == ASN1_Type::UtcTime) ? 2 : 4;
  ------------------
  |  Branch (121:28): [True: 17, False: 54]
  ------------------
  122|       |
  123|     71|   const size_t year_start = 0;
  124|     71|   const size_t month_start = year_start + year_len;
  125|     71|   const size_t day_start = month_start + field_len;
  126|     71|   const size_t hour_start = day_start + field_len;
  127|     71|   const size_t min_start = hour_start + field_len;
  128|     71|   const size_t sec_start = min_start + field_len;
  129|       |
  130|     71|   uint32_t year = to_u32bit(t_spec.substr(year_start, year_len));
  131|     71|   const uint32_t month = to_u32bit(t_spec.substr(month_start, field_len));
  132|     71|   const uint32_t day = to_u32bit(t_spec.substr(day_start, field_len));
  133|     71|   const uint32_t hour = to_u32bit(t_spec.substr(hour_start, field_len));
  134|     71|   const uint32_t minute = to_u32bit(t_spec.substr(min_start, field_len));
  135|     71|   const uint32_t second = to_u32bit(t_spec.substr(sec_start, field_len));
  136|       |
  137|     71|   if(tag == ASN1_Type::UtcTime) {
  ------------------
  |  Branch (137:7): [True: 14, False: 57]
  ------------------
  138|       |      // Interpret the two digit year by the 1950/2050 split (RFC 5280 Section 4.1.2.5.1)
  139|     14|      year += (year >= 50) ? 1900 : 2000;
  ------------------
  |  Branch (139:15): [True: 4, False: 10]
  ------------------
  140|     14|   }
  141|       |
  142|     71|   return ASN1_Time(static_cast<uint16_t>(year),
  143|     71|                    static_cast<uint8_t>(month),
  144|     71|                    static_cast<uint8_t>(day),
  145|     71|                    static_cast<uint8_t>(hour),
  146|     71|                    static_cast<uint8_t>(minute),
  147|     71|                    static_cast<uint8_t>(second),
  148|     71|                    tag);
  149|     71|}
_ZN5Botan9ASN1_Time11decode_fromERNS_11BER_DecoderE:
  168|    368|void ASN1_Time::decode_from(BER_Decoder& source) {
  169|    368|   const BER_Object ber_time = source.get_next_object();
  170|       |
  171|    368|   if(ber_time.get_class() != ASN1_Class::Universal ||
  ------------------
  |  Branch (171:7): [True: 218, False: 150]
  ------------------
  172|    297|      (ber_time.type() != ASN1_Type::UtcTime && ber_time.type() != ASN1_Type::GeneralizedTime)) {
  ------------------
  |  Branch (172:8): [True: 126, False: 24]
  |  Branch (172:49): [True: 79, False: 47]
  ------------------
  173|    297|      throw Decoding_Error(fmt("ASN1_Time: Unexpected tag {}/{}",
  174|    297|                               static_cast<uint32_t>(ber_time.type()),
  175|    297|                               static_cast<uint32_t>(ber_time.get_class())));
  176|    297|   }
  177|       |
  178|     71|   try {
  179|       |      // Assigning only after a successful parse means that a decoding error
  180|       |      // cannot leave this object in a partially written state
  181|     71|      *this = ASN1_Time::from_string(ASN1::to_string(ber_time), ber_time.type());
  182|     71|   } catch(Invalid_Argument& e) {
  183|     61|      throw Decoding_Error(fmt("Invalid ASN1_Time encoding: {}", e.what()));
  184|     61|   }
  185|     71|}

_ZN5Botan11BER_DecoderD2Ev:
  456|  13.4k|BER_Decoder::~BER_Decoder() = default;
_ZNK5Botan11BER_Decoder10more_itemsEv:
  461|  2.71k|bool BER_Decoder::more_items() const {
  462|  2.71k|   if(m_source->end_of_data() && !m_pushed.is_set()) {
  ------------------
  |  Branch (462:7): [True: 437, False: 2.28k]
  |  Branch (462:34): [True: 437, False: 0]
  ------------------
  463|    437|      return false;
  464|    437|   }
  465|  2.28k|   return true;
  466|  2.71k|}
_ZN5Botan11BER_Decoder10verify_endEv:
  471|  1.79k|BER_Decoder& BER_Decoder::verify_end() {
  472|  1.79k|   return verify_end("BER_Decoder::verify_end called, but data remains");
  473|  1.79k|}
_ZN5Botan11BER_Decoder10verify_endENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
  478|  1.79k|BER_Decoder& BER_Decoder::verify_end(std::string_view err) {
  479|  1.79k|   if(!m_source->end_of_data() || m_pushed.is_set()) {
  ------------------
  |  Branch (479:7): [True: 22, False: 1.77k]
  |  Branch (479:35): [True: 49, False: 1.72k]
  ------------------
  480|     71|      throw Decoding_Error(err);
  481|     71|   }
  482|  1.72k|   return (*this);
  483|  1.79k|}
_ZN5Botan11BER_Decoder14read_next_byteEv:
  495|  24.5k|std::optional<uint8_t> BER_Decoder::read_next_byte() {
  496|  24.5k|   BOTAN_ASSERT_NOMSG(m_source != nullptr);
  ------------------
  |  |   77|  24.5k|   do {                                                                     \
  |  |   78|  24.5k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|  24.5k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 24.5k]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|  24.5k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 24.5k]
  |  |  ------------------
  ------------------
  497|  24.5k|   uint8_t b = 0;
  498|  24.5k|   if(m_source->read_byte(b) != 0) {
  ------------------
  |  Branch (498:7): [True: 22.0k, False: 2.48k]
  ------------------
  499|  22.0k|      return b;
  500|  22.0k|   } else {
  501|  2.48k|      return {};
  502|  2.48k|   }
  503|  24.5k|}
_ZN5Botan11BER_Decoder15get_next_objectEv:
  516|  18.6k|BER_Object BER_Decoder::get_next_object() {
  517|  18.6k|   BER_Object next;
  518|       |
  519|  18.6k|   if(m_pushed.is_set()) {
  ------------------
  |  Branch (519:7): [True: 1.06k, False: 17.6k]
  ------------------
  520|  1.06k|      std::swap(next, m_pushed);
  521|  1.06k|      return next;
  522|  1.06k|   }
  523|       |
  524|  17.6k|   for(;;) {
  525|  17.6k|      ASN1_Type type_tag = ASN1_Type::NoObject;
  526|  17.6k|      ASN1_Class class_tag = ASN1_Class::NoObject;
  527|  17.6k|      decode_tag(m_source, type_tag, class_tag);
  528|  17.6k|      next.set_tagging(type_tag, class_tag);
  529|  17.6k|      if(next.is_set() == false) {  // no more objects
  ------------------
  |  Branch (529:10): [True: 1.17k, False: 16.4k]
  ------------------
  530|  1.17k|         return next;
  531|  1.17k|      }
  532|       |
  533|  16.4k|      const size_t allow_indef = m_limits.allow_ber_encoding() ? m_limits.max_nested_indefinite_length() : 0;
  ------------------
  |  Branch (533:34): [True: 0, False: 16.4k]
  ------------------
  534|  16.4k|      const bool der_mode = m_limits.require_der_encoding();
  535|  16.4k|      const auto dl = decode_length(m_source, allow_indef, der_mode, is_constructed(class_tag));
  536|       |
  537|       |      // Per X.690 8.1.5 the only valid EOC encoding is the two-octet
  538|       |      // sequence 0x00 0x00. Reject any other length encoding on a tag of
  539|       |      // (Eoc, Universal) before we consume the "content" bytes.
  540|  16.4k|      if(type_tag == ASN1_Type::Eoc && class_tag == ASN1_Class::Universal &&
  ------------------
  |  Branch (540:10): [True: 1.36k, False: 15.0k]
  |  Branch (540:40): [True: 39, False: 1.32k]
  ------------------
  541|     39|         (dl.content_length() != 0 || dl.indefinite_length())) {
  ------------------
  |  Branch (541:11): [True: 34, False: 5]
  |  Branch (541:39): [True: 0, False: 5]
  ------------------
  542|     34|         throw BER_Decoding_Error("EOC marker with non-zero length");
  543|     34|      }
  544|       |
  545|  16.3k|      if(const auto max_size = m_limits.max_object_size(); max_size && dl.content_length() > *max_size) {
  ------------------
  |  Branch (545:60): [True: 16.2k, False: 187]
  |  Branch (545:72): [True: 39, False: 16.1k]
  ------------------
  546|     39|         throw BER_Decoding_Error("Encoded object exceeds maximum size");
  547|     39|      }
  548|       |
  549|  16.3k|      if(!m_source->check_available(dl.total_length())) {
  ------------------
  |  Branch (549:10): [True: 110, False: 16.2k]
  ------------------
  550|    110|         throw BER_Decoding_Error("Value truncated");
  551|    110|      }
  552|       |
  553|  16.2k|      uint8_t* out = next.mutable_bits(dl.content_length());
  554|  16.2k|      if(m_source->read(out, dl.content_length()) != dl.content_length()) {
  ------------------
  |  Branch (554:10): [True: 0, False: 16.2k]
  ------------------
  555|      0|         throw BER_Decoding_Error("Value truncated");
  556|      0|      }
  557|       |
  558|  16.2k|      if(dl.indefinite_length()) {
  ------------------
  |  Branch (558:10): [True: 0, False: 16.2k]
  ------------------
  559|       |         // After reading the data consume the 2-byte EOC
  560|      0|         uint8_t eoc[2] = {0xFF, 0xFF};
  561|      0|         if(m_source->read(eoc, 2) != 2 || eoc[0] != 0x00 || eoc[1] != 0x00) {
  ------------------
  |  Branch (561:13): [True: 0, False: 0]
  |  Branch (561:44): [True: 0, False: 0]
  |  Branch (561:62): [True: 0, False: 0]
  ------------------
  562|      0|            throw BER_Decoding_Error("Missing or malformed EOC marker");
  563|      0|         }
  564|      0|      }
  565|       |
  566|  16.2k|      if(next.tagging() == static_cast<uint32_t>(ASN1_Type::Eoc)) {
  ------------------
  |  Branch (566:10): [True: 5, False: 16.2k]
  ------------------
  567|      5|         if(m_limits.require_der_encoding()) {
  ------------------
  |  Branch (567:13): [True: 5, False: 0]
  ------------------
  568|      5|            throw BER_Decoding_Error("Detected EOC marker in DER structure");
  569|      5|         }
  570|       |         // An EOC marker is only valid as an indefinite-length terminator, which
  571|       |         // is consumed above when reading the indefinite-length object. A
  572|       |         // standalone EOC is rejected unless the caller opted to tolerate it.
  573|      0|         if(m_limits.allow_standalone_eoc()) {
  ------------------
  |  Branch (573:13): [True: 0, False: 0]
  ------------------
  574|      0|            continue;
  575|      0|         }
  576|      0|         throw BER_Decoding_Error("Encountered EOC marker outside of indefinite-length encoding");
  577|      0|      }
  578|       |
  579|  16.2k|      break;
  580|  16.2k|   }
  581|       |
  582|  16.2k|   return next;
  583|  17.6k|}
_ZN5Botan11BER_Decoder9push_backERKNS_10BER_ObjectE:
  600|    795|void BER_Decoder::push_back(const BER_Object& obj) {
  601|    795|   if(m_pushed.is_set()) {
  ------------------
  |  Branch (601:7): [True: 0, False: 795]
  ------------------
  602|      0|      throw Invalid_State("BER_Decoder: Only one push back is allowed");
  603|      0|   }
  604|    795|   m_pushed = obj;
  605|    795|}
_ZN5Botan11BER_Decoder9push_backEONS_10BER_ObjectE:
  607|  1.26k|void BER_Decoder::push_back(BER_Object&& obj) {
  608|  1.26k|   if(m_pushed.is_set()) {
  ------------------
  |  Branch (608:7): [True: 0, False: 1.26k]
  ------------------
  609|      0|      throw Invalid_State("BER_Decoder: Only one push back is allowed");
  610|      0|   }
  611|  1.26k|   m_pushed = std::move(obj);
  612|  1.26k|}
_ZN5Botan11BER_Decoder10start_consENS_9ASN1_TypeENS_10ASN1_ClassE:
  614|  9.17k|BER_Decoder BER_Decoder::start_cons(ASN1_Type type_tag, ASN1_Class class_tag) {
  615|  9.17k|   BER_Object obj = get_next_object();
  616|  9.17k|   obj.assert_is_a(type_tag, class_tag | ASN1_Class::Constructed);
  617|       |
  618|       |   // In DER mode the elements of a universal SET must appear in sorted order
  619|  9.17k|   if(m_limits.require_der_encoding() && type_tag == ASN1_Type::Set && class_tag == ASN1_Class::Universal) {
  ------------------
  |  Branch (619:7): [True: 8.62k, False: 548]
  |  Branch (619:42): [True: 560, False: 8.06k]
  |  Branch (619:72): [True: 560, False: 0]
  ------------------
  620|    560|      verify_set_is_sorted(std::span<const uint8_t>{obj.bits(), obj.length()});
  621|    560|   }
  622|       |
  623|  9.17k|   BER_Decoder child(std::move(obj), this);
  624|  9.17k|   return child;
  625|  9.17k|}
_ZN5Botan11BER_Decoder8end_consEv:
  630|  2.70k|BER_Decoder& BER_Decoder::end_cons() {
  631|  2.70k|   if(m_parent == nullptr) {
  ------------------
  |  Branch (631:7): [True: 0, False: 2.70k]
  ------------------
  632|      0|      throw Invalid_State("BER_Decoder::end_cons called with null parent");
  633|      0|   }
  634|  2.70k|   if(!m_source->end_of_data() || m_pushed.is_set()) {
  ------------------
  |  Branch (634:7): [True: 5, False: 2.70k]
  |  Branch (634:35): [True: 0, False: 2.70k]
  ------------------
  635|      5|      throw Decoding_Error("BER_Decoder::end_cons called with data left");
  636|      5|   }
  637|  2.70k|   return (*m_parent);
  638|  2.70k|}
_ZN5Botan11BER_DecoderC2EONS_10BER_ObjectEPS0_:
  641|  8.45k|      m_limits(parent != nullptr ? parent->limits() : BER_Decoder::Limits::BER()), m_parent(parent) {
  ------------------
  |  Branch (641:16): [True: 8.45k, False: 0]
  ------------------
  642|  8.45k|   m_data_src = std::make_unique<DataSource_BERObject>(std::move(obj));
  643|  8.45k|   m_source = m_data_src.get();
  644|  8.45k|}
_ZN5Botan11BER_DecoderC2ENSt3__14spanIKhLm18446744073709551615EEENS0_6LimitsE:
  659|  4.99k|BER_Decoder::BER_Decoder(std::span<const uint8_t> buf, Limits limits) : m_limits(limits) {
  660|  4.99k|   m_data_src = std::make_unique<DataSource_Memory>(buf);
  661|  4.99k|   m_source = m_data_src.get();
  662|  4.99k|}
_ZN5Botan11BER_Decoder6decodeERNS_11ASN1_ObjectENS_9ASN1_TypeENS_10ASN1_ClassE:
  671|  4.90k|BER_Decoder& BER_Decoder::decode(ASN1_Object& obj, ASN1_Type /*unused*/, ASN1_Class /*unused*/) {
  672|  4.90k|   obj.decode_from(*this);
  673|  4.90k|   return (*this);
  674|  4.90k|}
_ZN5Botan11BER_Decoder6decodeERmNS_9ASN1_TypeENS_10ASN1_ClassE:
  721|  1.65k|BER_Decoder& BER_Decoder::decode(size_t& out, ASN1_Type type_tag, ASN1_Class class_tag) {
  722|  1.65k|   BigInt integer;
  723|  1.65k|   decode(integer, type_tag, class_tag);
  724|       |
  725|  1.65k|   if(integer.signum() < 0) {
  ------------------
  |  Branch (725:7): [True: 103, False: 1.54k]
  ------------------
  726|    103|      throw BER_Decoding_Error("Decoded small integer value was negative");
  727|    103|   }
  728|       |
  729|  1.54k|   if(integer.bits() > 32) {
  ------------------
  |  Branch (729:7): [True: 85, False: 1.46k]
  ------------------
  730|     85|      throw BER_Decoding_Error("Decoded integer value larger than expected");
  731|     85|   }
  732|       |
  733|  1.46k|   out = 0;
  734|  6.98k|   for(size_t i = 0; i != 4; ++i) {
  ------------------
  |  Branch (734:22): [True: 5.52k, False: 1.46k]
  ------------------
  735|  5.52k|      out = (out << 8) | integer.byte_at(3 - i);
  736|  5.52k|   }
  737|       |
  738|  1.46k|   return (*this);
  739|  1.54k|}
_ZN5Botan11BER_Decoder6decodeERNS_6BigIntENS_9ASN1_TypeENS_10ASN1_ClassE:
  771|  1.65k|BER_Decoder& BER_Decoder::decode(BigInt& out, ASN1_Type type_tag, ASN1_Class class_tag) {
  772|  1.65k|   const BER_Object obj = get_next_object();
  773|  1.65k|   obj.assert_is_a(type_tag, class_tag);
  774|       |
  775|       |   // An INTEGER must have at least one content octet (X.690 section 8.3.1)
  776|  1.65k|   if(obj.length() == 0) {
  ------------------
  |  Branch (776:7): [True: 3, False: 1.64k]
  ------------------
  777|      3|      throw BER_Decoding_Error("INTEGER encoding has no content octets");
  778|      3|   }
  779|       |
  780|       |   // DER requires minimal INTEGER encoding (X.690 section 8.3.2)
  781|  1.64k|   if(m_limits.require_der_encoding()) {
  ------------------
  |  Branch (781:7): [True: 1.58k, False: 66]
  ------------------
  782|  1.58k|      if(obj.length() > 1) {
  ------------------
  |  Branch (782:10): [True: 251, False: 1.33k]
  ------------------
  783|    251|         if(obj.bits()[0] == 0x00 && (obj.bits()[1] & 0x80) == 0) {
  ------------------
  |  Branch (783:13): [True: 41, False: 210]
  |  Branch (783:38): [True: 4, False: 37]
  ------------------
  784|      4|            throw BER_Decoding_Error("Detected non-minimal INTEGER encoding in DER structure");
  785|      4|         }
  786|    247|         if(obj.bits()[0] == 0xFF && (obj.bits()[1] & 0x80) != 0) {
  ------------------
  |  Branch (786:13): [True: 26, False: 221]
  |  Branch (786:38): [True: 11, False: 15]
  ------------------
  787|     11|            throw BER_Decoding_Error("Detected non-minimal INTEGER encoding in DER structure");
  788|     11|         }
  789|    247|      }
  790|  1.58k|   }
  791|       |
  792|  1.63k|   const uint8_t first = obj.bits()[0];
  793|  1.63k|   const bool negative = (first & 0x80) == 0x80;
  794|       |
  795|  1.63k|   if(negative) {
  ------------------
  |  Branch (795:7): [True: 103, False: 1.53k]
  ------------------
  796|    103|      secure_vector<uint8_t> vec(obj.bits(), obj.bits() + obj.length());
  797|    588|      for(size_t i = obj.length(); i > 0; --i) {
  ------------------
  |  Branch (797:36): [True: 588, False: 0]
  ------------------
  798|    588|         const bool gt0 = (vec[i - 1] > 0);
  799|    588|         vec[i - 1] -= 1;
  800|    588|         if(gt0) {
  ------------------
  |  Branch (800:13): [True: 103, False: 485]
  ------------------
  801|    103|            break;
  802|    103|         }
  803|    588|      }
  804|  29.4k|      for(size_t i = 0; i != obj.length(); ++i) {
  ------------------
  |  Branch (804:25): [True: 29.3k, False: 103]
  ------------------
  805|  29.3k|         vec[i] = ~vec[i];
  806|  29.3k|      }
  807|    103|      out._assign_from_bytes(vec);
  808|    103|      out.flip_sign();
  809|  1.53k|   } else {
  810|  1.53k|      out._assign_from_bytes(obj.data());
  811|  1.53k|   }
  812|       |
  813|  1.63k|   return (*this);
  814|  1.64k|}
_ZN5Botan11BER_Decoder6decodeERNSt3__16vectorIhNS1_9allocatorIhEEEENS_9ASN1_TypeES7_NS_10ASN1_ClassE:
 1018|    969|                                 ASN1_Class class_tag) {
 1019|    969|   if(real_type != ASN1_Type::OctetString && real_type != ASN1_Type::BitString) {
  ------------------
  |  Branch (1019:7): [True: 0, False: 969]
  |  Branch (1019:46): [True: 0, False: 0]
  ------------------
 1020|      0|      throw BER_Bad_Tag("Bad tag for {BIT,OCTET} STRING", static_cast<uint32_t>(real_type));
 1021|      0|   }
 1022|       |
 1023|    969|   asn1_decode_binary_string(buffer, get_next_object(), real_type, type_tag, class_tag, m_limits);
 1024|    969|   return (*this);
 1025|    969|}
_ZN5Botan11BER_Decoder16decode_bitstringERNS_14ASN1_BitStringENS_9ASN1_TypeENS_10ASN1_ClassE:
 1027|    841|BER_Decoder& BER_Decoder::decode_bitstring(ASN1_BitString& out, ASN1_Type type_tag, ASN1_Class class_tag) {
 1028|    841|   const BER_Object obj = get_next_object();
 1029|       |
 1030|    841|   std::vector<uint8_t> bits;
 1031|    841|   uint8_t unused_bits = 0;
 1032|       |
 1033|    841|   if(is_constructed(obj.class_tag())) {
  ------------------
  |  Branch (1033:7): [True: 1, False: 840]
  ------------------
 1034|      1|      obj.assert_is_a(type_tag, class_tag | ASN1_Class::Constructed);
 1035|      1|      if(m_limits.require_der_encoding()) {
  ------------------
  |  Branch (1035:10): [True: 1, False: 0]
  ------------------
 1036|      1|         throw BER_Decoding_Error("Detected constructed string encoding in DER structure");
 1037|      1|      }
 1038|      0|      bits.reserve(obj.length());  // upper possible bound on the output size
 1039|      0|      unused_bits = asn1_concat_constructed_bit_string(bits, obj, m_limits, 0);
 1040|    840|   } else {
 1041|    840|      unused_bits = asn1_bitstring_unused_bits(obj, type_tag, class_tag, m_limits.require_der_encoding());
 1042|    840|      bits.assign(obj.bits() + 1, obj.bits() + obj.length());
 1043|    840|   }
 1044|       |
 1045|    840|   if(unused_bits > 0 && !bits.empty()) {
  ------------------
  |  Branch (1045:7): [True: 4, False: 836]
  |  Branch (1045:26): [True: 4, False: 0]
  ------------------
 1046|      4|      bits.back() &= static_cast<uint8_t>(0xFF << unused_bits);
 1047|      4|   }
 1048|       |
 1049|    840|   out = ASN1_BitString(std::move(bits), unused_bits);
 1050|    840|   return (*this);
 1051|    841|}
_ZN5Botan4ASN120is_single_der_objectENSt3__14spanIKhLm18446744073709551615EEENS_9ASN1_TypeENS_10ASN1_ClassE:
 1085|    414|bool is_single_der_object(std::span<const uint8_t> bytes, ASN1_Type expected_type, ASN1_Class expected_class) {
 1086|    414|   if(bytes.empty()) {
  ------------------
  |  Branch (1086:7): [True: 0, False: 414]
  ------------------
 1087|      0|      return false;
 1088|      0|   }
 1089|       |
 1090|    414|   try {
 1091|    414|      DataSource_Span src(bytes);
 1092|       |
 1093|    414|      ASN1_Type type_tag = ASN1_Type::NoObject;
 1094|    414|      ASN1_Class class_tag = ASN1_Class::NoObject;
 1095|    414|      const size_t tag_bytes = decode_tag(&src, type_tag, class_tag);
 1096|       |
 1097|    414|      if(type_tag != expected_type || class_tag != expected_class) {
  ------------------
  |  Branch (1097:10): [True: 320, False: 94]
  |  Branch (1097:39): [True: 5, False: 89]
  ------------------
 1098|    304|         return false;
 1099|    304|      }
 1100|       |
 1101|    110|      const auto dl = decode_length(&src, /*allow_indef=*/0, /*der_mode=*/true, is_constructed(expected_class));
 1102|       |
 1103|    110|      const size_t header_bytes = tag_bytes + dl.field_length();
 1104|    110|      if(header_bytes > bytes.size()) {
  ------------------
  |  Branch (1104:10): [True: 0, False: 110]
  ------------------
 1105|      0|         return false;
 1106|      0|      }
 1107|    110|      return dl.content_length() == bytes.size() - header_bytes;
 1108|    110|   } catch(Decoding_Error&) {
 1109|     24|      return false;
 1110|     24|   }
 1111|    414|}
_ZN5Botan4ASN122is_der_sequence_headerENSt3__14spanIKhLm18446744073709551615EEE:
 1113|    151|bool is_der_sequence_header(std::span<const uint8_t> bytes) {
 1114|    151|   return is_single_der_object(bytes, ASN1_Type::Sequence, ASN1_Class::Universal | ASN1_Class::Constructed);
 1115|    151|}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_110decode_tagEPNS_10DataSourceERNS_9ASN1_TypeERNS_10ASN1_ClassE:
   29|  18.0k|size_t decode_tag(DataSource* ber, ASN1_Type& type_tag, ASN1_Class& class_tag) {
   30|  18.0k|   auto b = ber->read_byte();
   31|       |
   32|  18.0k|   if(!b) {
  ------------------
  |  Branch (32:7): [True: 1.17k, False: 16.8k]
  ------------------
   33|  1.17k|      type_tag = ASN1_Type::NoObject;
   34|  1.17k|      class_tag = ASN1_Class::NoObject;
   35|  1.17k|      return 0;
   36|  1.17k|   }
   37|       |
   38|  16.8k|   if((*b & 0x1F) != 0x1F) {
  ------------------
  |  Branch (38:7): [True: 16.2k, False: 623]
  ------------------
   39|  16.2k|      type_tag = ASN1_Type(*b & 0x1F);
   40|  16.2k|      class_tag = ASN1_Class(*b & 0xE0);
   41|       |      // The EOC marker is primitive; a constructed universal tag 0 has no
   42|       |      // valid meaning and would otherwise bypass the EOC handling, which
   43|       |      // matches on (Eoc, Universal) exactly
   44|  16.2k|      if(type_tag == ASN1_Type::Eoc && class_tag == ASN1_Class::Constructed) {
  ------------------
  |  Branch (44:10): [True: 1.39k, False: 14.8k]
  |  Branch (44:40): [True: 4, False: 1.38k]
  ------------------
   45|      4|         throw BER_Decoding_Error("EOC tag with constructed encoding");
   46|      4|      }
   47|  16.2k|      return 1;
   48|  16.2k|   }
   49|       |
   50|    623|   size_t tag_bytes = 1;
   51|    623|   class_tag = ASN1_Class(*b & 0xE0);
   52|       |
   53|    623|   uint32_t tag_buf = 0;
   54|  2.22k|   while(true) {
  ------------------
  |  Branch (54:10): [True: 2.22k, Folded]
  ------------------
   55|  2.22k|      b = ber->read_byte();
   56|  2.22k|      if(!b) {
  ------------------
  |  Branch (56:10): [True: 13, False: 2.21k]
  ------------------
   57|     13|         throw BER_Decoding_Error("Long-form tag truncated");
   58|     13|      }
   59|       |      // Reject if shifting in another 7 bits would overflow the uint32_t tag
   60|  2.21k|      if((tag_buf >> 25) != 0) {
  ------------------
  |  Branch (60:10): [True: 17, False: 2.19k]
  ------------------
   61|     17|         throw BER_Decoding_Error("Long-form tag overflowed 32 bits");
   62|     17|      }
   63|       |      // This is required even by BER (see X.690 section 8.1.2.4.2 sentence c).
   64|       |      // Bits 7-1 of the first subsequent octet must not be all zero; this rules
   65|       |      // out both 0x80 (continuation with no data) and 0x00 (a long-form encoding
   66|       |      // of tag value 0, which collides with the EOC marker).
   67|  2.19k|      if(tag_bytes == 1 && (*b & 0x7F) == 0) {
  ------------------
  |  Branch (67:10): [True: 620, False: 1.57k]
  |  Branch (67:28): [True: 5, False: 615]
  ------------------
   68|      5|         throw BER_Decoding_Error("Long form tag with leading zero");
   69|      5|      }
   70|  2.19k|      ++tag_bytes;
   71|  2.19k|      tag_buf = (tag_buf << 7) | (*b & 0x7F);
   72|  2.19k|      if((*b & 0x80) == 0) {
  ------------------
  |  Branch (72:10): [True: 588, False: 1.60k]
  ------------------
   73|    588|         break;
   74|    588|      }
   75|  2.19k|   }
   76|       |   // Per X.690 8.1.2.2, tag values 0-30 shall be encoded in the short form.
   77|       |   // Long-form encoding is reserved for tag values >= 31 (X.690 8.1.2.3).
   78|       |   // This is unconditional and applies to BER as well as DER.
   79|    588|   if(tag_buf <= 30) {
  ------------------
  |  Branch (79:7): [True: 13, False: 575]
  ------------------
   80|     13|      throw BER_Decoding_Error("Long-form tag encoding used for small tag value");
   81|     13|   }
   82|       |
   83|    575|   if(tag_buf == static_cast<uint32_t>(ASN1_Type::NoObject)) {
  ------------------
  |  Branch (83:7): [True: 4, False: 571]
  ------------------
   84|      4|      throw BER_Decoding_Error("Tag value collides with internal sentinel");
   85|      4|   }
   86|       |
   87|       |   // NOLINTNEXTLINE(clang-analyzer-optin.core.EnumCastOutOfRange)
   88|    571|   type_tag = ASN1_Type(tag_buf);
   89|    571|   return tag_bytes;
   90|    575|}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_113decode_lengthEPNS_10DataSourceEmbb:
  135|  16.4k|BerDecodedLength decode_length(DataSource* ber, size_t allow_indef, bool der_mode, bool constructed) {
  136|  16.4k|   uint8_t b = 0;
  137|  16.4k|   if(ber->read_byte(b) == 0) {
  ------------------
  |  Branch (137:7): [True: 117, False: 16.3k]
  ------------------
  138|    117|      throw BER_Decoding_Error("Length field not found");
  139|    117|   }
  140|  16.3k|   if((b & 0x80) == 0) {
  ------------------
  |  Branch (140:7): [True: 16.0k, False: 341]
  ------------------
  141|  16.0k|      return BerDecodedLength(b, 1);
  142|  16.0k|   }
  143|       |
  144|    341|   const size_t num_length_bytes = (b & 0x7F);
  145|    341|   if(num_length_bytes > 4) {
  ------------------
  |  Branch (145:7): [True: 13, False: 328]
  ------------------
  146|     13|      throw BER_Decoding_Error("Length field is too large");
  147|     13|   }
  148|       |
  149|    328|   const size_t field_size = 1 + num_length_bytes;
  150|       |
  151|    328|   if(num_length_bytes == 0) {
  ------------------
  |  Branch (151:7): [True: 4, False: 324]
  ------------------
  152|      4|      if(der_mode) {
  ------------------
  |  Branch (152:10): [True: 4, False: 0]
  ------------------
  153|      4|         throw BER_Decoding_Error("Detected indefinite-length encoding in DER structure");
  154|      4|      } else if(!constructed) {
  ------------------
  |  Branch (154:17): [True: 0, False: 0]
  ------------------
  155|       |         // Indefinite length is only valid for constructed types (X.690 8.1.3.2)
  156|      0|         throw BER_Decoding_Error("Indefinite-length encoding used with non-constructed type");
  157|      0|      } else if(allow_indef == 0) {
  ------------------
  |  Branch (157:17): [True: 0, False: 0]
  ------------------
  158|      0|         throw BER_Decoding_Error("Nested EOC markers too deep, rejecting to avoid stack exhaustion");
  159|      0|      } else {
  160|       |         // find_eoc returns bytes up to and including the EOC marker.
  161|       |         // Return the content length; the caller consumes the EOC separately.
  162|      0|         const size_t eoc_len = find_eoc(ber, /*base_offset=*/0, allow_indef - 1);
  163|      0|         if(eoc_len < 2) {
  ------------------
  |  Branch (163:13): [True: 0, False: 0]
  ------------------
  164|      0|            throw BER_Decoding_Error("Invalid EOC encoding");
  165|      0|         }
  166|      0|         return BerDecodedLength::indefinite(eoc_len - 2, field_size);
  167|      0|      }
  168|      4|   }
  169|       |
  170|    324|   size_t length = 0;
  171|       |
  172|  1.13k|   for(size_t i = 0; i != num_length_bytes; ++i) {
  ------------------
  |  Branch (172:22): [True: 819, False: 316]
  ------------------
  173|    819|      if(ber->read_byte(b) == 0) {
  ------------------
  |  Branch (173:10): [True: 8, False: 811]
  ------------------
  174|      8|         throw BER_Decoding_Error("Corrupted length field");
  175|      8|      }
  176|       |      // Can't overflow since we already checked that num_length_bytes <= 4
  177|    811|      length = (length << 8) | b;
  178|    811|   }
  179|       |
  180|       |   // DER requires shortest possible length encoding
  181|    316|   if(der_mode) {
  ------------------
  |  Branch (181:7): [True: 316, False: 0]
  ------------------
  182|    316|      if(length < 128) {
  ------------------
  |  Branch (182:10): [True: 11, False: 305]
  ------------------
  183|     11|         throw BER_Decoding_Error("Detected non-canonical length encoding in DER structure");
  184|     11|      }
  185|    305|      if(num_length_bytes > 1 && length < (size_t(1) << ((num_length_bytes - 1) * 8))) {
  ------------------
  |  Branch (185:10): [True: 272, False: 33]
  |  Branch (185:34): [True: 2, False: 270]
  ------------------
  186|      2|         throw BER_Decoding_Error("Detected non-canonical length encoding in DER structure");
  187|      2|      }
  188|    305|   }
  189|       |
  190|    303|   return BerDecodedLength(length, field_size);
  191|    316|}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_116BerDecodedLengthC2Emm:
  108|  16.3k|            BerDecodedLength(content_length, field_length, false) {}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_116BerDecodedLengthC2Emmb:
  125|  16.3k|            m_content_length(content_length), m_field_length(field_length), m_indefinite(indefinite) {}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_18peek_tagEPNS_10DataSourceEmRNS_9ASN1_TypeERNS_10ASN1_ClassE:
  197|    705|size_t peek_tag(DataSource* src, size_t offset, ASN1_Type& type_tag, ASN1_Class& class_tag) {
  198|    705|   uint8_t b = 0;
  199|    705|   if(src->peek(&b, 1, offset) == 0) {
  ------------------
  |  Branch (199:7): [True: 0, False: 705]
  ------------------
  200|      0|      type_tag = ASN1_Type::NoObject;
  201|      0|      class_tag = ASN1_Class::NoObject;
  202|      0|      return 0;
  203|      0|   }
  204|       |
  205|    705|   if((b & 0x1F) != 0x1F) {
  ------------------
  |  Branch (205:7): [True: 571, False: 134]
  ------------------
  206|    571|      type_tag = ASN1_Type(b & 0x1F);
  207|    571|      class_tag = ASN1_Class(b & 0xE0);
  208|       |      // The EOC marker is primitive; a constructed universal tag 0 has no
  209|       |      // valid meaning and would otherwise bypass the EOC handling, which
  210|       |      // matches on (Eoc, Universal) exactly
  211|    571|      if(type_tag == ASN1_Type::Eoc && class_tag == ASN1_Class::Constructed) {
  ------------------
  |  Branch (211:10): [True: 82, False: 489]
  |  Branch (211:40): [True: 2, False: 80]
  ------------------
  212|      2|         throw BER_Decoding_Error("EOC tag with constructed encoding");
  213|      2|      }
  214|    569|      return 1;
  215|    571|   }
  216|       |
  217|    134|   class_tag = ASN1_Class(b & 0xE0);
  218|    134|   size_t tag_bytes = 1;
  219|    134|   uint32_t tag_buf = 0;
  220|       |
  221|    439|   while(true) {
  ------------------
  |  Branch (221:10): [True: 439, Folded]
  ------------------
  222|    439|      if(src->peek(&b, 1, offset + tag_bytes) == 0) {
  ------------------
  |  Branch (222:10): [True: 3, False: 436]
  ------------------
  223|      3|         throw BER_Decoding_Error("Long-form tag truncated");
  224|      3|      }
  225|       |      // Reject if shifting in another 7 bits would overflow the uint32_t tag
  226|    436|      if((tag_buf >> 25) != 0) {
  ------------------
  |  Branch (226:10): [True: 11, False: 425]
  ------------------
  227|     11|         throw BER_Decoding_Error("Long-form tag overflowed 32 bits");
  228|     11|      }
  229|       |      // Required even by BER (X.690 section 8.1.2.4.2 sentence c).
  230|       |      // Bits 7-1 of the first subsequent octet must not be all zero; this rules
  231|       |      // out both 0x80 (continuation with no data) and 0x00 (a long-form encoding
  232|       |      // of tag value 0, which collides with the EOC marker).
  233|    425|      if(tag_bytes == 1 && (b & 0x7F) == 0) {
  ------------------
  |  Branch (233:10): [True: 134, False: 291]
  |  Branch (233:28): [True: 2, False: 132]
  ------------------
  234|      2|         throw BER_Decoding_Error("Long form tag with leading zero");
  235|      2|      }
  236|    423|      ++tag_bytes;
  237|    423|      tag_buf = (tag_buf << 7) | (b & 0x7F);
  238|    423|      if((b & 0x80) == 0) {
  ------------------
  |  Branch (238:10): [True: 118, False: 305]
  ------------------
  239|    118|         break;
  240|    118|      }
  241|    423|   }
  242|       |
  243|       |   // Per X.690 8.1.2.2, tag values 0-30 shall be encoded in the short form.
  244|       |   // Long-form encoding is reserved for tag values >= 31 (X.690 8.1.2.3).
  245|       |   // This is unconditional and applies to BER as well as DER.
  246|    118|   if(tag_buf <= 30) {
  ------------------
  |  Branch (246:7): [True: 6, False: 112]
  ------------------
  247|      6|      throw BER_Decoding_Error("Long-form tag encoding used for small tag value");
  248|      6|   }
  249|       |
  250|    112|   if(tag_buf == static_cast<uint32_t>(ASN1_Type::NoObject)) {
  ------------------
  |  Branch (250:7): [True: 1, False: 111]
  ------------------
  251|      1|      throw BER_Decoding_Error("Tag value collides with internal sentinel");
  252|      1|   }
  253|       |
  254|       |   // NOLINTNEXTLINE(clang-analyzer-optin.core.EnumCastOutOfRange)
  255|    111|   type_tag = ASN1_Type(tag_buf);
  256|    111|   return tag_bytes;
  257|    112|}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_111peek_lengthEPNS_10DataSourceEmRmmbb:
  265|    680|   DataSource* src, size_t offset, size_t& field_size, size_t allow_indef, bool constructed, bool der_mode) {
  266|    680|   uint8_t b = 0;
  267|    680|   if(src->peek(&b, 1, offset) == 0) {
  ------------------
  |  Branch (267:7): [True: 9, False: 671]
  ------------------
  268|      9|      throw BER_Decoding_Error("Length field not found");
  269|      9|   }
  270|       |
  271|    671|   field_size = 1;
  272|    671|   if((b & 0x80) == 0) {
  ------------------
  |  Branch (272:7): [True: 582, False: 89]
  ------------------
  273|    582|      return b;
  274|    582|   }
  275|       |
  276|     89|   const size_t num_length_bytes = (b & 0x7F);
  277|     89|   field_size += num_length_bytes;
  278|     89|   if(field_size > 5) {
  ------------------
  |  Branch (278:7): [True: 23, False: 66]
  ------------------
  279|     23|      throw BER_Decoding_Error("Length field is too large");
  280|     23|   }
  281|       |
  282|     66|   if(num_length_bytes == 0) {
  ------------------
  |  Branch (282:7): [True: 1, False: 65]
  ------------------
  283|       |      // Indefinite length is not allowed in DER
  284|      1|      if(der_mode) {
  ------------------
  |  Branch (284:10): [True: 1, False: 0]
  ------------------
  285|      1|         throw BER_Decoding_Error("Detected indefinite-length encoding in DER structure");
  286|      1|      }
  287|       |      // Indefinite length is only valid for constructed types (X.690 8.1.3.2)
  288|      0|      if(!constructed) {
  ------------------
  |  Branch (288:10): [True: 0, False: 0]
  ------------------
  289|      0|         throw BER_Decoding_Error("Indefinite-length encoding used with non-constructed type");
  290|      0|      }
  291|      0|      if(allow_indef == 0) {
  ------------------
  |  Branch (291:10): [True: 0, False: 0]
  ------------------
  292|      0|         throw BER_Decoding_Error("Nested EOC markers too deep, rejecting to avoid stack exhaustion");
  293|      0|      }
  294|      0|      return find_eoc(src, offset + 1, allow_indef - 1);
  295|      0|   }
  296|       |
  297|     65|   size_t length = 0;
  298|    272|   for(size_t i = 0; i < num_length_bytes; ++i) {
  ------------------
  |  Branch (298:22): [True: 208, False: 64]
  ------------------
  299|    208|      if(src->peek(&b, 1, offset + 1 + i) == 0) {
  ------------------
  |  Branch (299:10): [True: 1, False: 207]
  ------------------
  300|      1|         throw BER_Decoding_Error("Corrupted length field");
  301|      1|      }
  302|    207|      if(get_byte<0>(length) != 0) {
  ------------------
  |  Branch (302:10): [True: 0, False: 207]
  ------------------
  303|      0|         throw BER_Decoding_Error("Field length overflow");
  304|      0|      }
  305|    207|      length = (length << 8) | b;
  306|    207|   }
  307|     64|   return length;
  308|     65|}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_114is_constructedENS_10ASN1_ClassE:
   22|  19.8k|bool is_constructed(ASN1_Class class_tag) {
   23|  19.8k|   return (static_cast<uint32_t>(class_tag) & static_cast<uint32_t>(ASN1_Class::Constructed)) != 0;
   24|  19.8k|}
ber_dec.cpp:_ZNK5Botan12_GLOBAL__N_116BerDecodedLength14content_lengthEv:
  114|  64.5k|      size_t content_length() const { return m_content_length; }
ber_dec.cpp:_ZNK5Botan12_GLOBAL__N_116BerDecodedLength17indefinite_lengthEv:
  121|  16.0k|      bool indefinite_length() const { return m_indefinite; }
ber_dec.cpp:_ZNK5Botan12_GLOBAL__N_116BerDecodedLength12total_lengthEv:
  117|  16.1k|      size_t total_length() const { return m_indefinite ? m_content_length + 2 : m_content_length; }
  ------------------
  |  Branch (117:44): [True: 0, False: 16.1k]
  ------------------
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_120verify_set_is_sortedENSt3__14spanIKhLm18446744073709551615EEE:
  426|    560|void verify_set_is_sorted(std::span<const uint8_t> content) {
  427|    560|   DataSource_Span src(content);
  428|    560|   size_t offset = 0;
  429|    560|   std::optional<std::span<const uint8_t>> prev;
  430|       |
  431|  1.16k|   while(offset < content.size()) {
  ------------------
  |  Branch (431:10): [True: 705, False: 455]
  ------------------
  432|    705|      ASN1_Type type_tag = ASN1_Type::NoObject;
  433|    705|      ASN1_Class class_tag = ASN1_Class::NoObject;
  434|    705|      const size_t tag_size = peek_tag(&src, offset, type_tag, class_tag);
  435|       |
  436|    705|      size_t length_size = 0;
  437|    705|      const size_t item_size =
  438|    705|         peek_length(&src, offset + tag_size, length_size, /*allow_indef=*/0, is_constructed(class_tag), true);
  439|       |
  440|    705|      const auto end = checked_add(offset, tag_size, length_size, item_size);
  441|    705|      if(!end || *end > content.size()) {
  ------------------
  |  Branch (441:10): [True: 59, False: 646]
  |  Branch (441:18): [True: 70, False: 576]
  ------------------
  442|     70|         throw BER_Decoding_Error("SET element exceeds available data");
  443|     70|      }
  444|       |
  445|    635|      const auto elem = content.subspan(offset, *end - offset);
  446|    635|      if(prev && std::lexicographical_compare(elem.begin(), elem.end(), prev->begin(), prev->end())) {
  ------------------
  |  Branch (446:10): [True: 95, False: 540]
  |  Branch (446:18): [True: 35, False: 60]
  ------------------
  447|     35|         throw BER_Decoding_Error("Detected unsorted SET in DER structure");
  448|     35|      }
  449|    600|      prev = elem;
  450|    600|      offset = *end;
  451|    600|   }
  452|    560|}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_126asn1_bitstring_unused_bitsERKNS_10BER_ObjectENS_9ASN1_TypeENS_10ASN1_ClassEb:
  970|    839|uint8_t asn1_bitstring_unused_bits(const BER_Object& obj, ASN1_Type type_tag, ASN1_Class class_tag, bool require_der) {
  971|    839|   obj.assert_is_a(type_tag, class_tag);
  972|    839|   BOTAN_ASSERT_NOMSG(!is_constructed(obj));
  ------------------
  |  |   77|    839|   do {                                                                     \
  |  |   78|    839|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|    839|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 839]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|    839|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 839]
  |  |  ------------------
  ------------------
  973|       |
  974|    839|   if(obj.length() == 0) {
  ------------------
  |  Branch (974:7): [True: 1, False: 838]
  ------------------
  975|      1|      throw BER_Decoding_Error("Invalid BIT STRING");
  976|      1|   }
  977|       |
  978|    838|   const uint8_t unused_bits = obj.bits()[0];
  979|       |
  980|    838|   if(unused_bits >= 8) {
  ------------------
  |  Branch (980:7): [True: 5, False: 833]
  ------------------
  981|      5|      throw BER_Decoding_Error("Invalid number of unused bits in BIT STRING");
  982|      5|   }
  983|       |
  984|    833|   if(obj.length() == 1 && unused_bits != 0) {
  ------------------
  |  Branch (984:7): [True: 784, False: 49]
  |  Branch (984:28): [True: 3, False: 781]
  ------------------
  985|      3|      throw BER_Decoding_Error("Invalid BIT STRING");
  986|      3|   }
  987|       |
  988|    830|   if(require_der && unused_bits > 0) {
  ------------------
  |  Branch (988:7): [True: 825, False: 5]
  |  Branch (988:22): [True: 10, False: 815]
  ------------------
  989|     10|      const uint8_t last_byte = obj.bits()[obj.length() - 1];
  990|     10|      if((last_byte & ((1 << unused_bits) - 1)) != 0) {
  ------------------
  |  Branch (990:10): [True: 6, False: 4]
  ------------------
  991|      6|         throw BER_Decoding_Error("Detected non-zero padding bits in BIT STRING in DER structure");
  992|      6|      }
  993|     10|   }
  994|       |
  995|    824|   return unused_bits;
  996|    830|}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_114is_constructedERKNS_10BER_ObjectE:
  818|  1.80k|bool is_constructed(const BER_Object& obj) {
  819|  1.80k|   return is_constructed(obj.class_tag());
  820|  1.80k|}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_115DataSource_SpanC2ENSt3__14spanIKhLm18446744073709551615EEE:
  414|    974|      explicit DataSource_Span(std::span<const uint8_t> buf) : m_buf(buf) {}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_115DataSource_Span4readEPhm:
  392|    959|      size_t read(uint8_t out[], size_t length) override {
  393|    959|         const size_t got = std::min(m_buf.size() - m_offset, length);
  394|    959|         copy_mem(out, m_buf.data() + m_offset, got);
  395|    959|         m_offset += got;
  396|    959|         return got;
  397|    959|      }
ber_dec.cpp:_ZNK5Botan12_GLOBAL__N_115DataSource_Span4peekEPhmm:
  399|  2.03k|      size_t peek(uint8_t out[], size_t length, size_t peek_offset) const override {
  400|  2.03k|         if(peek_offset >= m_buf.size() - m_offset) {
  ------------------
  |  Branch (400:13): [True: 13, False: 2.01k]
  ------------------
  401|     13|            return 0;
  402|     13|         }
  403|  2.01k|         const size_t got = std::min(m_buf.size() - m_offset - peek_offset, length);
  404|  2.01k|         copy_mem(out, m_buf.data() + m_offset + peek_offset, got);
  405|  2.01k|         return got;
  406|  2.03k|      }
ber_dec.cpp:_ZNK5Botan12_GLOBAL__N_116BerDecodedLength12field_lengthEv:
  119|     86|      size_t field_length() const { return m_field_length; }
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_120DataSource_BERObjectC2EONS_10BER_ObjectE:
  379|  8.45k|      explicit DataSource_BERObject(BER_Object&& obj) : m_obj(std::move(obj)) {}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_120DataSource_BERObject4readEPhm:
  349|  60.2k|      size_t read(uint8_t out[], size_t length) override {
  350|  60.2k|         BOTAN_ASSERT_NOMSG(m_offset <= m_obj.length());
  ------------------
  |  |   77|  60.2k|   do {                                                                     \
  |  |   78|  60.2k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|  60.2k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 60.2k]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|  60.2k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 60.2k]
  |  |  ------------------
  ------------------
  351|  60.2k|         const size_t got = std::min<size_t>(m_obj.length() - m_offset, length);
  352|  60.2k|         copy_mem(out, m_obj.bits() + m_offset, got);
  353|  60.2k|         m_offset += got;
  354|  60.2k|         return got;
  355|  60.2k|      }
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_120DataSource_BERObject15check_availableEm:
  370|  11.4k|      bool check_available(size_t n) override {
  371|  11.4k|         BOTAN_ASSERT_NOMSG(m_offset <= m_obj.length());
  ------------------
  |  |   77|  11.4k|   do {                                                                     \
  |  |   78|  11.4k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|  11.4k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 11.4k]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|  11.4k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 11.4k]
  |  |  ------------------
  ------------------
  372|  11.4k|         return (n <= (m_obj.length() - m_offset));
  373|  11.4k|      }
ber_dec.cpp:_ZNK5Botan12_GLOBAL__N_120DataSource_BERObject11end_of_dataEv:
  375|  5.46k|      bool end_of_data() const override { return get_bytes_read() == m_obj.length(); }
ber_dec.cpp:_ZNK5Botan12_GLOBAL__N_120DataSource_BERObject14get_bytes_readEv:
  377|  5.46k|      size_t get_bytes_read() const override { return m_offset; }
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_125asn1_decode_binary_stringINSt3__19allocatorIhEEEEvRNS2_6vectorIhT_EERKNS_10BER_ObjectENS_9ASN1_TypeESC_NS_10ASN1_ClassERKNS_11BER_Decoder6LimitsE:
  912|    969|                               const BER_Decoder::Limits& limits) {
  913|       |   // DER requires BIT STRING and OCTET STRING to use primitive encoding;
  914|       |   // in BER the constructed (fragmented) form is decoded by concatenation
  915|    969|   if(is_constructed(obj)) {
  ------------------
  |  Branch (915:7): [True: 4, False: 965]
  ------------------
  916|      4|      obj.assert_is_a(type_tag, class_tag | ASN1_Class::Constructed);
  917|       |
  918|      4|      if(limits.require_der_encoding()) {
  ------------------
  |  Branch (918:10): [True: 2, False: 2]
  ------------------
  919|      2|         throw BER_Decoding_Error("Detected constructed string encoding in DER structure");
  920|      2|      }
  921|       |
  922|       |      // Concatenate into a temporary so a failed decode leaves buffer unmodified
  923|      2|      std::vector<uint8_t, Alloc> concat;
  924|      2|      concat.reserve(obj.length());  // upper possible bound on the output size
  925|      2|      if(real_type == ASN1_Type::OctetString) {
  ------------------
  |  Branch (925:10): [True: 0, False: 2]
  ------------------
  926|      0|         asn1_concat_constructed_octet_string(concat, obj, limits, 0);
  927|      2|      } else {
  928|      2|         asn1_concat_constructed_bit_string(concat, obj, limits, 0);
  929|      2|      }
  930|      2|      buffer = std::move(concat);
  931|      2|      return;
  932|      4|   }
  933|       |
  934|    965|   obj.assert_is_a(type_tag, class_tag);
  935|       |
  936|    965|   if(real_type == ASN1_Type::OctetString) {
  ------------------
  |  Branch (936:7): [True: 963, False: 2]
  ------------------
  937|    963|      buffer.assign(obj.bits(), obj.bits() + obj.length());
  938|    963|   } else {
  939|      2|      if(obj.length() == 0) {
  ------------------
  |  Branch (939:10): [True: 0, False: 2]
  ------------------
  940|      0|         throw BER_Decoding_Error("Invalid BIT STRING");
  941|      0|      }
  942|       |
  943|      2|      const uint8_t unused_bits = obj.bits()[0];
  944|       |
  945|      2|      if(unused_bits >= 8) {
  ------------------
  |  Branch (945:10): [True: 0, False: 2]
  ------------------
  946|      0|         throw BER_Decoding_Error("Bad number of unused bits in BIT STRING");
  947|      0|      }
  948|       |
  949|       |      // Empty BIT STRING with unused bits > 0 ...
  950|      2|      if(unused_bits > 0 && obj.length() < 2) {
  ------------------
  |  Branch (950:10): [True: 0, False: 2]
  |  Branch (950:29): [True: 0, False: 0]
  ------------------
  951|      0|         throw BER_Decoding_Error("Invalid BIT STRING");
  952|      0|      }
  953|       |
  954|       |      // DER requires unused bits in BIT STRING to be zero (X.690 section 11.2.2)
  955|      2|      if(limits.require_der_encoding() && unused_bits > 0) {
  ------------------
  |  Branch (955:10): [True: 0, False: 2]
  |  Branch (955:43): [True: 0, False: 0]
  ------------------
  956|      0|         const uint8_t last_byte = obj.bits()[obj.length() - 1];
  957|      0|         if((last_byte & ((1 << unused_bits) - 1)) != 0) {
  ------------------
  |  Branch (957:13): [True: 0, False: 0]
  ------------------
  958|      0|            throw BER_Decoding_Error("Detected non-zero padding bits in BIT STRING in DER structure");
  959|      0|         }
  960|      0|      }
  961|       |
  962|      2|      buffer.resize(obj.length() - 1);
  963|       |
  964|      2|      if(obj.length() > 1) {
  ------------------
  |  Branch (964:10): [True: 0, False: 2]
  ------------------
  965|      0|         copy_mem(buffer.data(), obj.bits() + 1, obj.length() - 1);
  966|      0|      }
  967|      2|   }
  968|    965|}

_ZN5Botan11DER_EncoderC2ERNSt3__16vectorIhNS1_9allocatorIhEEEE:
   88|    203|DER_Encoder::DER_Encoder(std::vector<uint8_t>& vec) {
   89|    203|   m_append_output = [&vec](const uint8_t b[], size_t l) {
   90|    203|      if(l > 0) {
   91|    203|         vec.insert(vec.end(), b, b + l);
   92|    203|      }
   93|    203|   };
   94|    203|}
_ZN5Botan11DER_Encoder10add_objectENS_9ASN1_TypeENS_10ASN1_ClassEPKhm:
  284|    203|DER_Encoder& DER_Encoder::add_object(ASN1_Type type_tag, ASN1_Class class_tag, const uint8_t rep[], size_t length) {
  285|    203|   std::vector<uint8_t> hdr;
  286|    203|   encode_tag(hdr, type_tag, class_tag);
  287|    203|   encode_length(hdr, length);
  288|       |
  289|    203|   if(!m_subsequences.empty()) {
  ------------------
  |  Branch (289:7): [True: 0, False: 203]
  ------------------
  290|      0|      m_subsequences[m_subsequences.size() - 1].add_bytes(hdr.data(), hdr.size(), rep, length);
  291|    203|   } else if(m_append_output) {
  ------------------
  |  Branch (291:14): [True: 203, False: 0]
  ------------------
  292|    203|      m_append_output(hdr.data(), hdr.size());
  293|    203|      m_append_output(rep, length);
  294|    203|   } else {
  295|      0|      m_default_outbuf += hdr;
  296|      0|      m_default_outbuf += std::make_pair(rep, length);
  297|      0|   }
  298|       |
  299|    203|   return (*this);
  300|    203|}
der_enc.cpp:_ZN5Botan12_GLOBAL__N_110encode_tagERNSt3__16vectorIhNS1_9allocatorIhEEEENS_9ASN1_TypeENS_10ASN1_ClassE:
   25|    203|void encode_tag(std::vector<uint8_t>& encoded_tag, ASN1_Type type_tag_e, ASN1_Class class_tag_e) {
   26|    203|   const uint32_t type_tag = static_cast<uint32_t>(type_tag_e);
   27|    203|   const uint32_t class_tag = static_cast<uint32_t>(class_tag_e);
   28|       |
   29|    203|   if((class_tag | 0xE0) != 0xE0) {
  ------------------
  |  Branch (29:7): [True: 0, False: 203]
  ------------------
   30|      0|      throw Encoding_Error(fmt("DER_Encoder: Invalid class tag {}", std::to_string(class_tag)));
   31|      0|   }
   32|       |
   33|    203|   if(type_tag <= 30) {
  ------------------
  |  Branch (33:7): [True: 203, False: 0]
  ------------------
   34|    203|      encoded_tag.push_back(static_cast<uint8_t>(type_tag | class_tag));
   35|    203|   } else {
   36|      0|      size_t blocks = high_bit(static_cast<uint32_t>(type_tag)) + 6;
   37|      0|      blocks = (blocks - (blocks % 7)) / 7;
   38|       |
   39|      0|      BOTAN_ASSERT_NOMSG(blocks > 0);
  ------------------
  |  |   77|      0|   do {                                                                     \
  |  |   78|      0|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|      0|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 0]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|      0|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 0]
  |  |  ------------------
  ------------------
   40|       |
   41|      0|      encoded_tag.push_back(static_cast<uint8_t>(class_tag | 0x1F));
   42|      0|      for(size_t i = 0; i != blocks - 1; ++i) {
  ------------------
  |  Branch (42:25): [True: 0, False: 0]
  ------------------
   43|      0|         encoded_tag.push_back(0x80 | ((type_tag >> 7 * (blocks - i - 1)) & 0x7F));
   44|      0|      }
   45|      0|      encoded_tag.push_back(type_tag & 0x7F);
   46|      0|   }
   47|    203|}
der_enc.cpp:_ZN5Botan12_GLOBAL__N_113encode_lengthERNSt3__16vectorIhNS1_9allocatorIhEEEEm:
   52|    203|void encode_length(std::vector<uint8_t>& encoded_length, size_t length) {
   53|    203|   if(length <= 127) {
  ------------------
  |  Branch (53:7): [True: 203, False: 0]
  ------------------
   54|    203|      encoded_length.push_back(static_cast<uint8_t>(length));
   55|    203|   } else {
   56|      0|      const size_t bytes_needed = significant_bytes(length);
   57|       |
   58|      0|      encoded_length.push_back(static_cast<uint8_t>(0x80 | bytes_needed));
   59|       |
   60|      0|      for(size_t i = sizeof(length) - bytes_needed; i < sizeof(length); ++i) {
  ------------------
  |  Branch (60:53): [True: 0, False: 0]
  ------------------
   61|      0|         encoded_length.push_back(get_byte_var(i, length));
   62|      0|      }
   63|      0|   }
   64|    203|}
der_enc.cpp:_ZZN5Botan11DER_EncoderC1ERNSt3__16vectorIhNS1_9allocatorIhEEEEENK3$_0clEPKhm:
   89|    406|   m_append_output = [&vec](const uint8_t b[], size_t l) {
   90|    406|      if(l > 0) {
  ------------------
  |  Branch (90:10): [True: 406, False: 0]
  ------------------
   91|    406|         vec.insert(vec.end(), b, b + l);
   92|    406|      }
   93|    406|   };

_ZNK5Botan6BigInt7byte_atEm:
  118|  5.52k|uint8_t BigInt::byte_at(size_t n) const {
  119|  5.52k|   return get_byte_var(sizeof(word) - (n % sizeof(word)) - 1, word_at(n / sizeof(word)));
  120|  5.52k|}
_ZN5Botan6BigInt4Data11set_to_zeroEv:
  191|  1.56k|void BigInt::Data::set_to_zero() {
  192|  1.56k|   m_reg.resize(m_reg.capacity());
  193|  1.56k|   clear_mem(m_reg.data(), m_reg.size());
  194|  1.56k|   m_sig_words = 0;
  195|  1.56k|}
_ZNK5Botan6BigInt4Data14calc_sig_wordsEv:
  215|  1.56k|size_t BigInt::Data::calc_sig_words() const {
  216|  1.56k|   const size_t sz = m_reg.size();
  217|  1.56k|   size_t sig = sz;
  218|       |
  219|  1.56k|   word sub = 1;
  220|       |
  221|  21.5k|   for(size_t i = 0; i != sz; ++i) {
  ------------------
  |  Branch (221:22): [True: 19.9k, False: 1.56k]
  ------------------
  222|  19.9k|      const word w = m_reg[sz - i - 1];
  223|  19.9k|      sub &= ct_is_zero(w);
  224|  19.9k|      sig -= sub;
  225|  19.9k|   }
  226|       |
  227|       |   /*
  228|       |   * This depends on the data so is poisoned, but unpoison it here as
  229|       |   * later conditionals are made on the size.
  230|       |   */
  231|  1.56k|   CT::unpoison(sig);
  232|       |
  233|  1.56k|   return sig;
  234|  1.56k|}
_ZNK5Botan6BigInt13top_bits_freeEv:
  298|    167|size_t BigInt::top_bits_free() const {
  299|    167|   const size_t words = sig_words();
  300|       |
  301|    167|   const word top_word = word_at(words - 1);
  302|    167|   const size_t bits_used = high_bit(CT::value_barrier(top_word));
  303|    167|   CT::unpoison(bits_used);
  304|    167|   return WordInfo<word>::bits - bits_used;
  305|    167|}
_ZNK5Botan6BigInt4bitsEv:
  307|  1.46k|size_t BigInt::bits() const {
  308|  1.46k|   const size_t words = sig_words();
  309|       |
  310|  1.46k|   if(words == 0) {
  ------------------
  |  Branch (310:7): [True: 1.29k, False: 167]
  ------------------
  311|  1.29k|      return 0;
  312|  1.29k|   }
  313|       |
  314|    167|   const size_t full_words = (words - 1) * WordInfo<word>::bits;
  315|    167|   const size_t top_bits = WordInfo<word>::bits - top_bits_free();
  316|       |
  317|    167|   return full_words + top_bits;
  318|  1.46k|}
_ZN5Botan6BigInt17assign_from_bytesENSt3__14spanIKhLm18446744073709551615EEE:
  425|  1.56k|void BigInt::assign_from_bytes(std::span<const uint8_t> bytes) {
  426|  1.56k|   clear();
  427|       |
  428|  1.56k|   const size_t length = bytes.size();
  429|  1.56k|   const size_t full_words = length / sizeof(word);
  430|  1.56k|   const size_t extra_bytes = length % sizeof(word);
  431|       |
  432|  1.56k|   secure_vector<word> reg((round_up(full_words + (extra_bytes > 0 ? 1 : 0), 8)));
  ------------------
  |  Branch (432:52): [True: 1.55k, False: 11]
  ------------------
  433|       |
  434|  9.41k|   for(size_t i = 0; i != full_words; ++i) {
  ------------------
  |  Branch (434:22): [True: 7.84k, False: 1.56k]
  ------------------
  435|  7.84k|      reg[i] = load_be<word>(bytes.last<sizeof(word)>());
  436|  7.84k|      bytes = bytes.first(bytes.size() - sizeof(word));
  437|  7.84k|   }
  438|       |
  439|  1.56k|   if(!bytes.empty()) {
  ------------------
  |  Branch (439:7): [True: 1.55k, False: 11]
  ------------------
  440|  1.55k|      BOTAN_ASSERT_NOMSG(extra_bytes == bytes.size());
  ------------------
  |  |   77|  1.55k|   do {                                                                     \
  |  |   78|  1.55k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|  1.55k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 1.55k]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|  1.55k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 1.55k]
  |  |  ------------------
  ------------------
  441|  1.55k|      std::array<uint8_t, sizeof(word)> last_partial_word = {0};
  442|  1.55k|      copy_mem(std::span{last_partial_word}.last(extra_bytes), bytes);
  443|  1.55k|      reg[full_words] = load_be<word>(last_partial_word);
  444|  1.55k|   }
  445|       |
  446|  1.56k|   m_data.swap(reg);
  447|  1.56k|}
_ZNK5Botan6BigInt20_const_time_unpoisonEv:
  559|  1.65k|void BigInt::_const_time_unpoison() const {
  560|  1.65k|   CT::unpoison(m_data.const_data(), m_data.size());
  561|  1.65k|}

_ZN5Botan15allocate_memoryEmm:
   21|  6.66k|BOTAN_MALLOC_FN void* allocate_memory(size_t elems, size_t elem_size) {
   22|  6.66k|   if(elems == 0 || elem_size == 0) {
  ------------------
  |  Branch (22:7): [True: 0, False: 6.66k]
  |  Branch (22:21): [True: 0, False: 6.66k]
  ------------------
   23|      0|      return nullptr;
   24|      0|   }
   25|       |
   26|       |   // Some calloc implementations do not check for overflow (?!?)
   27|  6.66k|   if(!checked_mul(elems, elem_size).has_value()) {
  ------------------
  |  Branch (27:7): [True: 0, False: 6.66k]
  ------------------
   28|      0|      throw std::bad_alloc();
   29|      0|   }
   30|       |
   31|       |#if defined(BOTAN_HAS_LOCKING_ALLOCATOR)
   32|       |   // NOLINTNEXTLINE(*-const-correctness) bug in clang-tidy
   33|       |   if(void* p = mlock_allocator::instance().allocate(elems, elem_size)) {
   34|       |      return p;
   35|       |   }
   36|       |#endif
   37|       |
   38|       |#if defined(BOTAN_TARGET_OS_HAS_ALLOC_CONCEAL)
   39|       |   void* ptr = ::calloc_conceal(elems, elem_size);
   40|       |#else
   41|       |   // NOLINTNEXTLINE(*-const-correctness) bug in clang-tidy
   42|  6.66k|   void* ptr = std::calloc(elems, elem_size);  // NOLINT(*-no-malloc,*-owning-memory)
   43|  6.66k|#endif
   44|  6.66k|   if(ptr == nullptr) {
  ------------------
  |  Branch (44:7): [True: 0, False: 6.66k]
  ------------------
   45|      0|      [[unlikely]] throw std::bad_alloc();
   46|      0|   }
   47|  6.66k|   return ptr;
   48|  6.66k|}
_ZN5Botan17deallocate_memoryEPvmm:
   50|  6.66k|void deallocate_memory(void* p, size_t elems, size_t elem_size) {
   51|  6.66k|   if(p == nullptr) {
  ------------------
  |  Branch (51:7): [True: 0, False: 6.66k]
  ------------------
   52|      0|      [[unlikely]] return;
   53|      0|   }
   54|       |
   55|  6.66k|   secure_scrub_memory(p, elems * elem_size);
   56|       |
   57|       |#if defined(BOTAN_HAS_LOCKING_ALLOCATOR)
   58|       |   if(mlock_allocator::instance().deallocate(p, elems, elem_size)) {
   59|       |      return;
   60|       |   }
   61|       |#endif
   62|       |
   63|  6.66k|   std::free(p);  // NOLINT(*-no-malloc,*-owning-memory)
   64|  6.66k|}

_ZN5Botan22throw_invalid_argumentEPKcS1_S1_:
   23|     19|void throw_invalid_argument(const char* message, const char* func, const char* file) {
   24|     19|   throw Invalid_Argument(fmt("{} in {}:{}", message, func, file));
   25|     19|}

_ZN5Botan19next_utf8_codepointENSt3__117basic_string_viewIcNS0_11char_traitsIcEEEERm:
   53|    180|uint32_t next_utf8_codepoint(std::string_view utf8, size_t& pos) {
   54|    180|   auto read_continuation = [&]() -> uint32_t {
   55|    180|      if(pos >= utf8.size()) {
   56|    180|         throw Decoding_Error("Invalid UTF-8 sequence");
   57|    180|      }
   58|    180|      const uint8_t b = static_cast<uint8_t>(utf8[pos++]);
   59|    180|      if((b & 0xC0) != 0x80) {
   60|    180|         throw Decoding_Error("Invalid UTF-8 sequence");
   61|    180|      }
   62|    180|      return b & 0x3F;
   63|    180|   };
   64|       |
   65|    180|   if(pos >= utf8.size()) {
  ------------------
  |  Branch (65:7): [True: 0, False: 180]
  ------------------
   66|      0|      throw Decoding_Error("Invalid UTF-8 sequence");
   67|      0|   }
   68|    180|   const uint8_t lead = static_cast<uint8_t>(utf8[pos++]);
   69|    180|   uint32_t c = 0;
   70|       |
   71|    180|   if(lead <= 0x7F) {
  ------------------
  |  Branch (71:7): [True: 82, False: 98]
  ------------------
   72|     82|      c = lead;
   73|     98|   } else if((lead & 0xE0) == 0xC0) {
  ------------------
  |  Branch (73:14): [True: 11, False: 87]
  ------------------
   74|     11|      c = (lead & 0x1F) << 6;
   75|     11|      c |= read_continuation();
   76|     11|      if(c < 0x80) {
  ------------------
  |  Branch (76:10): [True: 2, False: 9]
  ------------------
   77|      2|         throw Decoding_Error("Overlong UTF-8 sequence");
   78|      2|      }
   79|     87|   } else if((lead & 0xF0) == 0xE0) {
  ------------------
  |  Branch (79:14): [True: 32, False: 55]
  ------------------
   80|     32|      c = (lead & 0x0F) << 12;
   81|     32|      c |= read_continuation() << 6;
   82|     32|      c |= read_continuation();
   83|     32|      if(c < 0x800) {
  ------------------
  |  Branch (83:10): [True: 1, False: 31]
  ------------------
   84|      1|         throw Decoding_Error("Overlong UTF-8 sequence");
   85|      1|      }
   86|     55|   } else if((lead & 0xF8) == 0xF0) {
  ------------------
  |  Branch (86:14): [True: 40, False: 15]
  ------------------
   87|     40|      c = (lead & 0x07) << 18;
   88|     40|      c |= read_continuation() << 12;
   89|     40|      c |= read_continuation() << 6;
   90|     40|      c |= read_continuation();
   91|     40|      if(c < 0x10000) {
  ------------------
  |  Branch (91:10): [True: 5, False: 35]
  ------------------
   92|      5|         throw Decoding_Error("Overlong UTF-8 sequence");
   93|      5|      }
   94|     40|   } else {
   95|     15|      throw Decoding_Error("Invalid UTF-8 sequence");
   96|     15|   }
   97|       |
   98|    157|   if(c > 0x10FFFF) {
  ------------------
  |  Branch (98:7): [True: 3, False: 154]
  ------------------
   99|      3|      throw Decoding_Error("UTF-8 sequence encodes value outside Unicode range");
  100|      3|   }
  101|    154|   if(c >= 0xD800 && c < 0xE000) {
  ------------------
  |  Branch (101:7): [True: 43, False: 111]
  |  Branch (101:22): [True: 12, False: 31]
  ------------------
  102|     12|      throw Decoding_Error("UTF-8 sequence encodes surrogate code point");
  103|     12|   }
  104|       |
  105|    142|   return c;
  106|    154|}
_ZN5Botan13is_valid_utf8ENSt3__117basic_string_viewIcNS0_11char_traitsIcEEEE:
  108|     99|bool is_valid_utf8(std::string_view utf8) {
  109|     99|   try {
  110|     99|      size_t pos = 0;
  111|    279|      while(pos < utf8.size()) {
  ------------------
  |  Branch (111:13): [True: 180, False: 99]
  ------------------
  112|    180|         const uint32_t c = next_utf8_codepoint(utf8, pos);
  113|    180|         BOTAN_UNUSED(c);
  ------------------
  |  |  144|    180|#define BOTAN_UNUSED Botan::ignore_params
  ------------------
  114|    180|      }
  115|     99|   } catch(Decoding_Error&) {
  116|     43|      return false;
  117|     43|   }
  118|     56|   return true;
  119|     99|}
_ZN5Botan12ucs2_to_utf8ENSt3__14spanIKhLm18446744073709551615EEE:
  121|     77|std::string ucs2_to_utf8(std::span<const uint8_t> ucs2) {
  122|     77|   if(ucs2.size() % 2 != 0) {
  ------------------
  |  Branch (122:7): [True: 1, False: 76]
  ------------------
  123|      1|      throw Decoding_Error("Invalid length for UCS-2 string");
  124|      1|   }
  125|       |
  126|     76|   const size_t chars = ucs2.size() / 2;
  127|       |
  128|     76|   std::string s;
  129|    150|   for(size_t i = 0; i != chars; ++i) {
  ------------------
  |  Branch (129:22): [True: 74, False: 76]
  ------------------
  130|     74|      const uint32_t c = load_be<uint16_t>(ucs2.data(), i);
  131|     74|      append_utf8_for(s, c);
  132|     74|   }
  133|       |
  134|     76|   return s;
  135|     77|}
_ZN5Botan12ucs4_to_utf8ENSt3__14spanIKhLm18446744073709551615EEE:
  155|     89|std::string ucs4_to_utf8(std::span<const uint8_t> ucs4) {
  156|     89|   if(ucs4.size() % 4 != 0) {
  ------------------
  |  Branch (156:7): [True: 2, False: 87]
  ------------------
  157|      2|      throw Decoding_Error("Invalid length for UCS-4 string");
  158|      2|   }
  159|       |
  160|     87|   const size_t chars = ucs4.size() / 4;
  161|       |
  162|     87|   std::string s;
  163|    168|   for(size_t i = 0; i != chars; ++i) {
  ------------------
  |  Branch (163:22): [True: 81, False: 87]
  ------------------
  164|     81|      const uint32_t c = load_be<uint32_t>(ucs4.data(), i);
  165|     81|      append_utf8_for(s, c);
  166|     81|   }
  167|       |
  168|     87|   return s;
  169|     89|}
_ZN5Botan14latin1_to_utf8ENSt3__14spanIKhLm18446744073709551615EEE:
  190|     32|std::string latin1_to_utf8(std::span<const uint8_t> chars) {
  191|     32|   std::string s;
  192|    113|   for(const uint8_t b : chars) {
  ------------------
  |  Branch (192:24): [True: 113, False: 32]
  ------------------
  193|    113|      append_utf8_for(s, static_cast<uint32_t>(b));
  194|    113|   }
  195|     32|   return s;
  196|     32|}
charset.cpp:_ZZN5Botan19next_utf8_codepointENSt3__117basic_string_viewIcNS0_11char_traitsIcEEEERmENK3$_0clEv:
   54|    194|   auto read_continuation = [&]() -> uint32_t {
   55|    194|      if(pos >= utf8.size()) {
  ------------------
  |  Branch (55:10): [True: 2, False: 192]
  ------------------
   56|      2|         throw Decoding_Error("Invalid UTF-8 sequence");
   57|      2|      }
   58|    192|      const uint8_t b = static_cast<uint8_t>(utf8[pos++]);
   59|    192|      if((b & 0xC0) != 0x80) {
  ------------------
  |  Branch (59:10): [True: 3, False: 189]
  ------------------
   60|      3|         throw Decoding_Error("Invalid UTF-8 sequence");
   61|      3|      }
   62|    189|      return b & 0x3F;
   63|    192|   };
charset.cpp:_ZN5Botan12_GLOBAL__N_115append_utf8_forERNSt3__112basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEEj:
   17|    268|void append_utf8_for(std::string& s, uint32_t c) {
   18|    268|   if(c >= 0xD800 && c < 0xE000) {
  ------------------
  |  Branch (18:7): [True: 103, False: 165]
  |  Branch (18:22): [True: 9, False: 94]
  ------------------
   19|      9|      throw Decoding_Error("Invalid Unicode character");
   20|      9|   }
   21|       |
   22|    259|   if(c <= 0x7F) {
  ------------------
  |  Branch (22:7): [True: 89, False: 170]
  ------------------
   23|     89|      const uint8_t b0 = static_cast<uint8_t>(c);
   24|     89|      s.push_back(static_cast<char>(b0));
   25|    170|   } else if(c <= 0x7FF) {
  ------------------
  |  Branch (25:14): [True: 46, False: 124]
  ------------------
   26|     46|      const uint8_t b0 = 0xC0 | static_cast<uint8_t>(c >> 6);
   27|     46|      const uint8_t b1 = 0x80 | static_cast<uint8_t>(c & 0x3F);
   28|     46|      s.push_back(static_cast<char>(b0));
   29|     46|      s.push_back(static_cast<char>(b1));
   30|    124|   } else if(c <= 0xFFFF) {
  ------------------
  |  Branch (30:14): [True: 49, False: 75]
  ------------------
   31|     49|      const uint8_t b0 = 0xE0 | static_cast<uint8_t>(c >> 12);
   32|     49|      const uint8_t b1 = 0x80 | static_cast<uint8_t>((c >> 6) & 0x3F);
   33|     49|      const uint8_t b2 = 0x80 | static_cast<uint8_t>(c & 0x3F);
   34|     49|      s.push_back(static_cast<char>(b0));
   35|     49|      s.push_back(static_cast<char>(b1));
   36|     49|      s.push_back(static_cast<char>(b2));
   37|     75|   } else if(c <= 0x10FFFF) {
  ------------------
  |  Branch (37:14): [True: 23, False: 52]
  ------------------
   38|     23|      const uint8_t b0 = 0xF0 | static_cast<uint8_t>(c >> 18);
   39|     23|      const uint8_t b1 = 0x80 | static_cast<uint8_t>((c >> 12) & 0x3F);
   40|     23|      const uint8_t b2 = 0x80 | static_cast<uint8_t>((c >> 6) & 0x3F);
   41|     23|      const uint8_t b3 = 0x80 | static_cast<uint8_t>(c & 0x3F);
   42|     23|      s.push_back(static_cast<char>(b0));
   43|     23|      s.push_back(static_cast<char>(b1));
   44|     23|      s.push_back(static_cast<char>(b2));
   45|     23|      s.push_back(static_cast<char>(b3));
   46|     52|   } else {
   47|     52|      throw Decoding_Error("Invalid Unicode character");
   48|     52|   }
   49|    259|}

_ZN5Botan10DataSource9read_byteERh:
   27|  41.8k|size_t DataSource::read_byte(uint8_t& out) {
   28|  41.8k|   return read(&out, 1);
   29|  41.8k|}
_ZN5Botan10DataSource9read_byteEv:
   34|  20.2k|std::optional<uint8_t> DataSource::read_byte() {
   35|  20.2k|   uint8_t b = 0;
   36|  20.2k|   if(this->read(&b, 1) == 1) {
  ------------------
  |  Branch (36:7): [True: 19.0k, False: 1.18k]
  ------------------
   37|  19.0k|      return b;
   38|  19.0k|   } else {
   39|  1.18k|      return {};
   40|  1.18k|   }
   41|  20.2k|}
_ZN5Botan17DataSource_Memory4readEPhm:
   73|  16.8k|size_t DataSource_Memory::read(uint8_t out[], size_t length) {
   74|  16.8k|   const size_t got = std::min<size_t>(m_source.size() - m_offset, length);
   75|  16.8k|   copy_mem(out, m_source.data() + m_offset, got);
   76|  16.8k|   m_offset += got;
   77|  16.8k|   return got;
   78|  16.8k|}
_ZN5Botan17DataSource_Memory15check_availableEm:
   80|  4.76k|bool DataSource_Memory::check_available(size_t n) {
   81|  4.76k|   return (n <= (m_source.size() - m_offset));
   82|  4.76k|}
_ZNK5Botan17DataSource_Memory11end_of_dataEv:
  101|  1.75k|bool DataSource_Memory::end_of_data() const {
  102|  1.75k|   return (m_offset == m_source.size());
  103|  1.75k|}

_ZN5Botan9ExceptionC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
   71|  2.24k|Exception::Exception(std::string_view msg) : m_msg(msg) {}
_ZN5Botan16Invalid_ArgumentC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
   77|     61|Invalid_Argument::Invalid_Argument(std::string_view msg) : Exception(msg) {}
_ZN5Botan14Decoding_ErrorC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
  125|  2.18k|Decoding_Error::Decoding_Error(std::string_view name) : Exception(name) {}

_ZN5Botan19secure_scrub_memoryEPvm:
   25|  48.3k|void secure_scrub_memory(void* ptr, size_t n) {
   26|  48.3k|   return secure_zeroize_buffer(ptr, n);
   27|  48.3k|}
_ZN5Botan21secure_zeroize_bufferEPvm:
   29|  48.3k|void secure_zeroize_buffer(void* ptr, size_t n) {
   30|  48.3k|   if(n == 0) {
  ------------------
  |  Branch (30:7): [True: 26.1k, False: 22.1k]
  ------------------
   31|  26.1k|      return;
   32|  26.1k|   }
   33|       |
   34|       |#if defined(BOTAN_TARGET_OS_HAS_RTLSECUREZEROMEMORY)
   35|       |   ::RtlSecureZeroMemory(ptr, n);
   36|       |
   37|       |#elif defined(BOTAN_TARGET_OS_HAS_EXPLICIT_BZERO)
   38|  22.1k|   ::explicit_bzero(ptr, n);
   39|       |
   40|       |#elif defined(BOTAN_TARGET_OS_HAS_EXPLICIT_MEMSET)
   41|       |   (void)::explicit_memset(ptr, 0, n);
   42|       |
   43|       |#else
   44|       |   /*
   45|       |   * Call memset through a static volatile pointer, which the compiler should
   46|       |   * not elide. This construct should be safe in conforming compilers, but who
   47|       |   * knows. This has been checked to generate the expected code, which saves the
   48|       |   * memset address in the data segment and unconditionally loads and jumps to
   49|       |   * that address, with the following targets:
   50|       |   *
   51|       |   * x86-64: Clang 19, GCC 6, 11, 13, 14
   52|       |   * riscv64: GCC 14
   53|       |   * aarch64: GCC 14
   54|       |   * armv7: GCC 14
   55|       |   *
   56|       |   * Actually all of them generated the expected jump even without marking the
   57|       |   * function pointer as volatile. However this seems worth including as an
   58|       |   * additional precaution.
   59|       |   */
   60|       |   static void* (*const volatile memset_ptr)(void*, int, size_t) = std::memset;
   61|       |   (memset_ptr)(ptr, 0, n);
   62|       |#endif
   63|  22.1k|}

_ZN5Botan9parse_u32ENSt3__117basic_string_viewIcNS0_11char_traitsIcEEEEb:
   64|    273|std::optional<uint32_t> parse_u32(std::string_view input, bool require_canonical) {
   65|    273|   return parse_decimal_integer<uint32_t>(input, require_canonical);
   66|    273|}
_ZN5Botan9to_u32bitENSt3__117basic_string_viewIcNS0_11char_traitsIcEEEE:
   76|    273|uint32_t to_u32bit(std::string_view input) {
   77|    273|   if(const auto parsed = parse_u32(input)) {
  ------------------
  |  Branch (77:18): [True: 263, False: 10]
  ------------------
   78|    263|      return *parsed;
   79|    263|   } else {
   80|     10|      throw Invalid_Argument(fmt("Failed to parse input '{}' as a 32-bit integer", input));
   81|     10|   }
   82|    273|}
parsing.cpp:_ZN5Botan12_GLOBAL__N_116digit_from_asciiEc:
   23|    609|std::optional<size_t> digit_from_ascii(char c) {
   24|    609|   if(c >= '0' && c <= '9') {
  ------------------
  |  Branch (24:7): [True: 604, False: 5]
  |  Branch (24:19): [True: 599, False: 5]
  ------------------
   25|    599|      return c - '0';
   26|    599|   } else {
   27|     10|      return {};
   28|     10|   }
   29|    609|}
parsing.cpp:_ZN5Botan12_GLOBAL__N_121parse_decimal_integerITkNSt3__117unsigned_integralEjEENS2_8optionalIT_EENS2_17basic_string_viewIcNS2_11char_traitsIcEEEEb:
   32|    273|std::optional<T> parse_decimal_integer(std::string_view input, bool require_canonical) {
   33|    273|   if(input.empty() || input.size() > (std::numeric_limits<T>::digits10 + 1)) {
  ------------------
  |  Branch (33:7): [True: 0, False: 273]
  |  Branch (33:24): [True: 0, False: 273]
  ------------------
   34|      0|      return {};
   35|      0|   }
   36|       |
   37|       |   // The canonical encoding of zero is "0"; no other value starts with a zero
   38|    273|   if(require_canonical && input.size() > 1 && input.front() == '0') {
  ------------------
  |  Branch (38:7): [True: 0, False: 273]
  |  Branch (38:28): [True: 0, False: 0]
  |  Branch (38:48): [True: 0, False: 0]
  ------------------
   39|      0|      return {};
   40|      0|   }
   41|       |
   42|    273|   T accum = 0;
   43|       |
   44|    609|   for(const char c : input) {
  ------------------
  |  Branch (44:21): [True: 609, False: 263]
  ------------------
   45|    609|      if(const auto digit = digit_from_ascii(c)) {
  ------------------
  |  Branch (45:21): [True: 599, False: 10]
  ------------------
   46|    599|         if(accum > (std::numeric_limits<T>::max() - static_cast<T>(*digit)) / 10) {
  ------------------
  |  Branch (46:13): [True: 0, False: 599]
  ------------------
   47|      0|            return {};
   48|      0|         }
   49|    599|         accum = accum * 10 + static_cast<T>(*digit);
   50|    599|      } else {
   51|     10|         return {};
   52|     10|      }
   53|    609|   }
   54|       |
   55|    263|   return accum;
   56|    273|}

_ZN5Botan4OCSP6CertID11decode_fromERNS_11BER_DecoderE:
  109|      1|void CertID::decode_from(BER_Decoder& from) {
  110|       |   /*
  111|       |   * RFC 6960 Section 4.1.1
  112|       |   *
  113|       |   * CertID ::= SEQUENCE {
  114|       |   *    hashAlgorithm       AlgorithmIdentifier,
  115|       |   *    issuerNameHash      OCTET STRING,
  116|       |   *    issuerKeyHash       OCTET STRING,
  117|       |   *    serialNumber        CertificateSerialNumber }
  118|       |   */
  119|      1|   from.start_sequence()
  120|      1|      .decode(m_hash_id)
  121|      1|      .decode(m_issuer_dn_hash, ASN1_Type::OctetString)
  122|      1|      .decode(m_issuer_key_hash, ASN1_Type::OctetString)
  123|      1|      .decode(m_subject_serial)
  124|      1|      .end_cons();
  125|       |
  126|      1|   if(!m_hash_id.parameters_are_null_or_empty()) {
  ------------------
  |  Branch (126:7): [True: 0, False: 1]
  ------------------
  127|      0|      throw Decoding_Error("OCSP CertID hashAlgorithm has unexpected parameters");
  128|      0|   }
  129|      1|}
_ZN5Botan4OCSP14SingleResponse11decode_fromERNS_11BER_DecoderE:
  135|      2|void SingleResponse::decode_from(BER_Decoder& from) {
  136|       |   /*
  137|       |   * RFC 6960 Section 4.2.1
  138|       |   *
  139|       |   * SingleResponse ::= SEQUENCE {
  140|       |   *    certID                       CertID,
  141|       |   *    certStatus                   CertStatus,
  142|       |   *    thisUpdate                   GeneralizedTime,
  143|       |   *    nextUpdate         [0]       EXPLICIT GeneralizedTime OPTIONAL,
  144|       |   *    singleExtensions   [1]       EXPLICIT Extensions OPTIONAL }
  145|       |   *
  146|       |   * CertStatus ::= CHOICE {
  147|       |   *    good        [0]     IMPLICIT NULL,
  148|       |   *    revoked     [1]     IMPLICIT RevokedInfo,
  149|       |   *    unknown     [2]     IMPLICIT UnknownInfo }
  150|       |   *
  151|       |   * RevokedInfo ::= SEQUENCE {
  152|       |   *    revocationTime              GeneralizedTime,
  153|       |   *    revocationReason    [0]     EXPLICIT CRLReason OPTIONAL }
  154|       |   */
  155|      2|   BER_Object cert_status;
  156|      2|   Extensions extensions;
  157|       |
  158|      2|   auto seq = from.start_sequence();
  159|      2|   seq.decode(m_certid)
  160|      2|      .get_next(cert_status)
  161|      2|      .decode(m_thisupdate)
  162|      2|      .decode_optional(m_nextupdate, ASN1_Type(0), ASN1_Class::ContextSpecific | ASN1_Class::Constructed);
  163|       |
  164|      2|   check_generalized_time(m_thisupdate, "thisUpdate");
  165|      2|   if(m_nextupdate.time_is_set()) {
  ------------------
  |  Branch (165:7): [True: 0, False: 2]
  ------------------
  166|      0|      check_generalized_time(m_nextupdate, "nextUpdate");
  167|      0|   }
  168|       |
  169|      2|   if(seq.more_items()) {
  ------------------
  |  Branch (169:7): [True: 0, False: 2]
  ------------------
  170|      0|      const BER_Object next = seq.get_next_object();
  171|      0|      if(next.is_a(1, ASN1_Class::ContextSpecific | ASN1_Class::Constructed)) {
  ------------------
  |  Branch (171:10): [True: 0, False: 0]
  ------------------
  172|      0|         BER_Decoder ext_decoder(next, BER_Decoder::Limits::DER());
  173|      0|         extensions.decode_from(ext_decoder, Extension_Context::OCSP_Response);
  174|      0|         ext_decoder.verify_end();
  175|      0|      } else {
  176|      0|         throw Decoding_Error("Unexpected tag in OCSP SingleResponse");
  177|      0|      }
  178|      0|   }
  179|      2|   seq.end_cons();
  180|       |
  181|      2|   const auto cert_status_class = cert_status.get_class();
  182|      2|   if(cert_status_class != ASN1_Class::ContextSpecific &&
  ------------------
  |  Branch (182:7): [True: 0, False: 2]
  ------------------
  183|      0|      cert_status_class != (ASN1_Class::ContextSpecific | ASN1_Class::Constructed)) {
  ------------------
  |  Branch (183:7): [True: 0, False: 0]
  ------------------
  184|      0|      throw Decoding_Error("OCSP::SingleResponse: certStatus has unexpected class tag");
  185|      0|   }
  186|       |
  187|       |   // TODO: should verify the cert_status body and decode RevokedInfo
  188|      2|   m_cert_status = static_cast<uint32_t>(cert_status.type());
  189|      2|   if(m_cert_status > 2) {
  ------------------
  |  Branch (189:7): [True: 0, False: 2]
  ------------------
  190|      0|      throw Decoding_Error("Unknown OCSP CertStatus tag");
  191|      0|   }
  192|       |
  193|       |   // We don't currently recognize any extensions here so if any are critical we should reject
  194|      2|   m_has_unknown_critical_ext = !extensions.critical_extensions().empty();
  195|      2|}
_ZN5Botan4OCSP8ResponseC2EPKhm:
  274|  2.11k|      m_response_bits(response_bits, response_bits + response_bits_len) {
  275|       |   /*
  276|       |   * RFC 6960 Section 4.2.1
  277|       |   *
  278|       |   * OCSPResponse ::= SEQUENCE {
  279|       |   *    responseStatus         OCSPResponseStatus,
  280|       |   *    responseBytes      [0] EXPLICIT ResponseBytes OPTIONAL }
  281|       |   *
  282|       |   * OCSPResponseStatus ::= ENUMERATED { ... }
  283|       |   *
  284|       |   * ResponseBytes ::= SEQUENCE {
  285|       |   *    responseType   OBJECT IDENTIFIER,
  286|       |   *    response       OCTET STRING }
  287|       |   */
  288|  2.11k|   BER_Decoder outer_decoder(m_response_bits, BER_Decoder::Limits::DER());
  289|  2.11k|   BER_Decoder response_outer = outer_decoder.start_sequence();
  290|       |
  291|  2.11k|   size_t resp_status = 0;
  292|       |
  293|  2.11k|   response_outer.decode(resp_status, ASN1_Type::Enumerated, ASN1_Class::Universal);
  294|       |
  295|       |   /*
  296|       |   RFC 6960 4.2.1
  297|       |
  298|       |   OCSPResponseStatus ::= ENUMERATED {
  299|       |       successful            (0),  -- Response has valid confirmations
  300|       |       malformedRequest      (1),  -- Illegal confirmation request
  301|       |       internalError         (2),  -- Internal error in issuer
  302|       |       tryLater              (3),  -- Try again later
  303|       |                                   -- (4) is not used
  304|       |       sigRequired           (5),  -- Must sign the request
  305|       |       unauthorized          (6)   -- Request unauthorized
  306|       |   }
  307|       |   */
  308|  2.11k|   if(resp_status == 4 || resp_status >= 7) {
  ------------------
  |  Branch (308:7): [True: 747, False: 1.37k]
  |  Branch (308:27): [True: 55, False: 1.31k]
  ------------------
  309|     57|      throw Decoding_Error("Unknown OCSPResponseStatus code");
  310|     57|   }
  311|       |
  312|  2.06k|   m_status = static_cast<Response_Status_Code>(resp_status);
  313|       |
  314|       |   /*
  315|       |   * RFC 6960 4.2.1: "If the value of responseStatus is one of the error
  316|       |   * conditions, the responseBytes field is not set."
  317|       |   */
  318|  2.06k|   const bool successful = (m_status == Response_Status_Code::Successful);
  319|  2.06k|   const bool has_response_bytes = response_outer.more_items();
  320|       |
  321|  2.06k|   if(successful && !has_response_bytes) {
  ------------------
  |  Branch (321:7): [True: 1.29k, False: 765]
  |  Branch (321:21): [True: 2, False: 1.29k]
  ------------------
  322|      2|      throw Decoding_Error("OCSP response with successful status is missing responseBytes");
  323|      2|   }
  324|  2.06k|   if(!successful && has_response_bytes) {
  ------------------
  |  Branch (324:7): [True: 20, False: 2.04k]
  |  Branch (324:22): [True: 2, False: 18]
  ------------------
  325|      2|      throw Decoding_Error("OCSP response with non-successful status includes responseBytes");
  326|      2|   }
  327|       |
  328|  2.05k|   if(successful) {
  ------------------
  |  Branch (328:7): [True: 1.29k, False: 763]
  ------------------
  329|  1.29k|      BER_Decoder response_bytes_ctx = response_outer.start_context_specific(0);
  330|  1.29k|      BER_Decoder response_bytes = response_bytes_ctx.start_sequence();
  331|       |
  332|  1.29k|      response_bytes.decode_and_check(OID({1, 3, 6, 1, 5, 5, 7, 48, 1, 1}), "Unknown response type in OCSP response");
  333|       |
  334|       |      /*
  335|       |      * RFC 6960 Section 4.2.1
  336|       |      *
  337|       |      * BasicOCSPResponse ::= SEQUENCE {
  338|       |      *    tbsResponseData      ResponseData,
  339|       |      *    signatureAlgorithm   AlgorithmIdentifier,
  340|       |      *    signature            BIT STRING,
  341|       |      *    certs            [0] EXPLICIT SEQUENCE OF Certificate OPTIONAL }
  342|       |      */
  343|  1.29k|      BER_Decoder basic_response_decoder(response_bytes.get_next_octet_string(), BER_Decoder::Limits::DER());
  344|  1.29k|      BER_Decoder basicresponse = basic_response_decoder.start_sequence();
  345|       |
  346|  1.29k|      basicresponse.start_sequence()
  347|  1.29k|         .raw_bytes(m_tbs_bits)
  348|  1.29k|         .end_cons()
  349|  1.29k|         .decode(m_sig_algo)
  350|  1.29k|         .decode_octet_aligned_bitstring(m_signature);
  351|  1.29k|      decode_optional_list(basicresponse, ASN1_Type(0), m_certs);
  352|       |
  353|  1.29k|      basicresponse.verify_end();
  354|  1.29k|      basic_response_decoder.verify_end();
  355|       |
  356|       |      /*
  357|       |      * RFC 6960 Section 4.2.1
  358|       |      *
  359|       |      * ResponseData ::= SEQUENCE {
  360|       |      *    version              [0] EXPLICIT Version DEFAULT v1,
  361|       |      *    responderID              ResponderID,
  362|       |      *    producedAt               GeneralizedTime,
  363|       |      *    responses                SEQUENCE OF SingleResponse,
  364|       |      *    responseExtensions   [1] EXPLICIT Extensions OPTIONAL }
  365|       |      *
  366|       |      * ResponderID ::= CHOICE {
  367|       |      *    byName   [1] Name,
  368|       |      *    byKey    [2] KeyHash }
  369|       |      */
  370|  1.29k|      size_t responsedata_version = 0;
  371|  1.29k|      Extensions extensions;
  372|       |
  373|  1.29k|      BER_Decoder tbs_decoder(m_tbs_bits, BER_Decoder::Limits::DER());
  374|  1.29k|      tbs_decoder
  375|  1.29k|         .decode_optional(responsedata_version, ASN1_Type(0), ASN1_Class::ContextSpecific | ASN1_Class::Constructed)
  376|       |
  377|  1.29k|         .decode_optional(m_signer_name, ASN1_Type(1), ASN1_Class::ContextSpecific | ASN1_Class::Constructed)
  378|       |
  379|  1.29k|         .decode_optional_string(
  380|  1.29k|            m_key_hash, ASN1_Type::OctetString, 2, ASN1_Class::ContextSpecific | ASN1_Class::Constructed)
  381|       |
  382|  1.29k|         .decode(m_produced_at)
  383|       |
  384|  1.29k|         .decode_list(m_responses);
  385|       |
  386|  1.29k|      check_generalized_time(m_produced_at, "producedAt");
  387|       |
  388|  1.29k|      if(tbs_decoder.more_items()) {
  ------------------
  |  Branch (388:10): [True: 0, False: 1.29k]
  ------------------
  389|      0|         const BER_Object next = tbs_decoder.get_next_object();
  390|      0|         if(next.is_a(1, ASN1_Class::ContextSpecific | ASN1_Class::Constructed)) {
  ------------------
  |  Branch (390:13): [True: 0, False: 0]
  ------------------
  391|      0|            BER_Decoder ext_decoder(next, BER_Decoder::Limits::DER());
  392|      0|            extensions.decode_from(ext_decoder, Extension_Context::OCSP_Response);
  393|      0|            ext_decoder.verify_end();
  394|      0|         } else {
  395|      0|            throw Decoding_Error("Unexpected tag in OCSP ResponseData");
  396|      0|         }
  397|      0|      }
  398|  1.29k|      tbs_decoder.verify_end();
  399|       |
  400|  1.29k|      const bool has_signer = !m_signer_name.empty();
  401|  1.29k|      const bool has_key_hash = !m_key_hash.empty();
  402|       |
  403|  1.29k|      if(has_signer && has_key_hash) {
  ------------------
  |  Branch (403:10): [True: 0, False: 1.29k]
  |  Branch (403:24): [True: 0, False: 0]
  ------------------
  404|      0|         throw Decoding_Error("OCSP response includes both byName and byKey in responderID field");
  405|      0|      }
  406|  1.29k|      if(!has_signer && !has_key_hash) {
  ------------------
  |  Branch (406:10): [True: 0, False: 1.29k]
  |  Branch (406:25): [True: 0, False: 0]
  ------------------
  407|      0|         throw Decoding_Error("OCSP response contains neither byName nor byKey in responderID field");
  408|      0|      }
  409|  1.29k|      if(has_key_hash && m_key_hash.size() != 20) {
  ------------------
  |  Branch (409:10): [True: 0, False: 1.29k]
  |  Branch (409:26): [True: 0, False: 0]
  ------------------
  410|       |         // KeyHash ::= OCTET STRING -- SHA-1 hash of responder's public key
  411|      0|         throw Decoding_Error("OCSP response contains a byKey with invalid length");
  412|      0|      }
  413|       |
  414|  1.29k|      response_bytes.verify_end();
  415|  1.29k|      response_bytes_ctx.verify_end();
  416|       |
  417|       |      // We don't currently recognize any extensions here so if any are critical we should reject
  418|  1.29k|      m_has_unknown_critical_ext = !extensions.critical_extensions().empty();
  419|  1.29k|   }
  420|       |
  421|  2.05k|   response_outer.verify_end();
  422|  2.05k|   outer_decoder.verify_end();
  423|       |
  424|  2.05k|   if(m_has_unknown_critical_ext == false) {
  ------------------
  |  Branch (424:7): [True: 5, False: 2.05k]
  ------------------
  425|       |      // Check all of the SingleResponse extensions
  426|      5|      for(const auto& sr : m_responses) {
  ------------------
  |  Branch (426:26): [True: 0, False: 5]
  ------------------
  427|      0|         if(sr.has_unknown_critical_extension()) {
  ------------------
  |  Branch (427:13): [True: 0, False: 0]
  ------------------
  428|      0|            m_has_unknown_critical_ext = true;
  429|      0|            break;
  430|      0|         }
  431|      0|      }
  432|      5|   }
  433|  2.05k|}
ocsp.cpp:_ZN5Botan4OCSP12_GLOBAL__N_122check_generalized_timeERKNS_9ASN1_TimeEPKc:
   36|      2|void check_generalized_time(const ASN1_Time& time, const char* field) {
   37|      2|   if(time.tagging() != ASN1_Type::GeneralizedTime) {
  ------------------
  |  Branch (37:7): [True: 2, False: 0]
  ------------------
   38|      2|      throw Decoding_Error(fmt("OCSP response {} was not encoded as GeneralizedTime", field));
   39|      2|   }
   40|      2|}
ocsp.cpp:_ZN5Botan4OCSP12_GLOBAL__N_120decode_optional_listERNS_11BER_DecoderENS_9ASN1_TypeERNSt3__16vectorINS_16X509_CertificateENS5_9allocatorIS7_EEEE:
  200|    813|void decode_optional_list(BER_Decoder& ber, ASN1_Type tag, std::vector<X509_Certificate>& output) {
  201|    813|   const BER_Object obj = ber.get_next_object();
  202|       |
  203|    813|   if(!obj.is_a(tag, ASN1_Class::ContextSpecific | ASN1_Class::Constructed)) {
  ------------------
  |  Branch (203:7): [True: 795, False: 18]
  ------------------
  204|    795|      ber.push_back(obj);
  205|    795|      return;
  206|    795|   }
  207|       |
  208|     18|   BER_Decoder list(obj, BER_Decoder::Limits::DER());
  209|     18|   auto seq = list.start_sequence();
  210|     32|   while(seq.more_items()) {
  ------------------
  |  Branch (210:10): [True: 14, False: 18]
  ------------------
  211|     14|      output.push_back([&] {
  212|     14|         X509_Certificate cert;
  213|     14|         cert.decode_from(seq);
  214|     14|         return cert;
  215|     14|      }());
  216|     14|   }
  217|     18|   seq.end_cons();
  218|     18|   list.verify_end();
  219|     18|}
ocsp.cpp:_ZZN5Botan4OCSP12_GLOBAL__N_120decode_optional_listERNS_11BER_DecoderENS_9ASN1_TypeERNSt3__16vectorINS_16X509_CertificateENS5_9allocatorIS7_EEEEENK3$_0clEv:
  211|     14|      output.push_back([&] {
  212|     14|         X509_Certificate cert;
  213|     14|         cert.decode_from(seq);
  214|     14|         return cert;
  215|     14|      }());

_ZN5Botan7X509_DN11decode_fromERNS_11BER_DecoderE:
  408|    572|void X509_DN::decode_from(BER_Decoder& source) {
  409|    572|   std::vector<uint8_t> bits;
  410|       |
  411|    572|   source.start_sequence().raw_bytes(bits).end_cons();
  412|       |
  413|    572|   BER_Decoder sequence(bits, source.limits());
  414|       |
  415|    572|   std::vector<std::vector<std::pair<OID, ASN1_String>>> rdns;
  416|       |
  417|       |   // Cap AVAs per RDN to bound work for downstream set-based matching.
  418|       |   // No legitimate cert has anywhere near this many AVAs in a single RDN.
  419|    572|   constexpr size_t MAX_AVAS_PER_RDN = 32;
  420|       |
  421|  1.13k|   while(sequence.more_items()) {
  ------------------
  |  Branch (421:10): [True: 568, False: 571]
  ------------------
  422|    568|      BER_Decoder rdn_decoder = sequence.start_set();
  423|       |
  424|    568|      std::vector<std::pair<OID, ASN1_String>> rdn;
  425|    967|      while(rdn_decoder.more_items()) {
  ------------------
  |  Branch (425:13): [True: 399, False: 568]
  ------------------
  426|    399|         OID oid;
  427|    399|         ASN1_String str;
  428|       |
  429|    399|         rdn_decoder.start_sequence()
  430|    399|            .decode(oid)
  431|    399|            .decode(str)  // TODO support Any
  432|    399|            .end_cons();
  433|       |
  434|    399|         rdn.emplace_back(std::move(oid), std::move(str));
  435|       |
  436|    399|         if(rdn.size() > MAX_AVAS_PER_RDN) {
  ------------------
  |  Branch (436:13): [True: 0, False: 399]
  ------------------
  437|      0|            throw Decoding_Error("X.500 RDN has too many attribute-value assertions");
  438|      0|         }
  439|    399|      }
  440|       |
  441|       |      /*
  442|       |      RFC 5280 4.1.2.4:
  443|       |         RelativeDistinguishedName ::=
  444|       |           SET SIZE (1..MAX) OF AttributeTypeAndValue
  445|       |      */
  446|    568|      if(rdn.empty()) {
  ------------------
  |  Branch (446:10): [True: 1, False: 567]
  ------------------
  447|      1|         throw Decoding_Error("X.500 RDN must contain at least one attribute-value assertion");
  448|      1|      }
  449|    567|      rdns.push_back(std::move(rdn));
  450|    567|   }
  451|       |
  452|    571|   auto canonical_bits = canonicalize_dn(rdns);
  453|       |
  454|    571|   m_rdn = std::move(rdns);
  455|    571|   m_dn_bits = std::move(bits);
  456|    571|   m_canonical_dn_bits = std::move(canonical_bits);
  457|    571|}
x509_dn.cpp:_ZN5Botan12_GLOBAL__N_115canonicalize_dnERKNSt3__16vectorINS2_INS1_4pairINS_3OIDENS_11ASN1_StringEEENS1_9allocatorIS6_EEEENS7_IS9_EEEE:
  311|    207|std::vector<uint8_t> canonicalize_dn(const std::vector<std::vector<std::pair<OID, ASN1_String>>>& rdns) {
  312|    207|   auto append_canonical_data = []<typename T>(std::vector<uint8_t>& out, const T& data) {
  313|    207|      const std::array<uint8_t, 8> data_len = store_le(static_cast<uint64_t>(data.size()));
  314|    207|      out.insert(out.end(), data_len.begin(), data_len.end());
  315|    207|      out.insert(out.end(), data.begin(), data.end());
  316|    207|   };
  317|       |
  318|    207|   std::vector<uint8_t> canonical_bits;
  319|       |
  320|    207|   for(const auto& rdn : rdns) {
  ------------------
  |  Branch (320:24): [True: 203, False: 207]
  ------------------
  321|    203|      std::vector<uint8_t> rdn_bits;
  322|       |
  323|    203|      for(const auto& [oid, value] : canonicalize_rdn(rdn)) {
  ------------------
  |  Branch (323:36): [True: 203, False: 203]
  ------------------
  324|    203|         append_canonical_data(rdn_bits, oid.BER_encode());
  325|    203|         append_canonical_data(rdn_bits, value);
  326|    203|      }
  327|       |
  328|    203|      append_canonical_data(canonical_bits, rdn_bits);
  329|    203|   }
  330|       |
  331|    207|   return canonical_bits;
  332|    207|}
x509_dn.cpp:_ZN5Botan12_GLOBAL__N_116canonicalize_rdnERKNSt3__16vectorINS1_4pairINS_3OIDENS_11ASN1_StringEEENS1_9allocatorIS6_EEEE:
  299|    203|std::vector<std::pair<OID, std::string>> canonicalize_rdn(const std::vector<std::pair<OID, ASN1_String>>& rdn) {
  300|    203|   std::vector<std::pair<OID, std::string>> result;
  301|    203|   result.reserve(rdn.size());
  302|    203|   for(const auto& ava : rdn) {
  ------------------
  |  Branch (302:24): [True: 203, False: 203]
  ------------------
  303|    203|      result.emplace_back(ava.first, X500_Char_Iterator::canonicalize(ava.second.value()));
  304|    203|   }
  305|    203|   if(result.size() != 1) {
  ------------------
  |  Branch (305:7): [True: 0, False: 203]
  ------------------
  306|      0|      std::sort(result.begin(), result.end());
  307|      0|   }
  308|    203|   return result;
  309|    203|}
x509_dn.cpp:_ZN5Botan12_GLOBAL__N_118X500_Char_Iterator12canonicalizeENSt3__117basic_string_viewIcNS2_11char_traitsIcEEEE:
  115|    203|      static std::string canonicalize(std::string_view name) {
  116|    203|         std::string result;
  117|    203|         result.reserve(name.size());
  118|       |
  119|    203|         X500_Char_Iterator it(name);
  120|    781|         while(auto c = it.next()) {
  ------------------
  |  Branch (120:21): [True: 578, False: 203]
  ------------------
  121|    578|            result += *c;
  122|    578|         }
  123|       |
  124|    203|         return result;
  125|    203|      }
x509_dn.cpp:_ZN5Botan12_GLOBAL__N_118X500_Char_IteratorC2ENSt3__117basic_string_viewIcNS2_11char_traitsIcEEEE:
   82|    203|      explicit X500_Char_Iterator(std::string_view s) : m_str(s), m_pos(0) {
   83|       |         // Skip leading whitespace
   84|    226|         while(m_pos < m_str.size() && is_space(m_str[m_pos])) {
  ------------------
  |  Branch (84:16): [True: 161, False: 65]
  |  Branch (84:40): [True: 23, False: 138]
  ------------------
   85|     23|            ++m_pos;
   86|     23|         }
   87|    203|      }
x509_dn.cpp:_ZN5Botan12_GLOBAL__N_118X500_Char_Iterator4nextEv:
   90|    781|      std::optional<char> next() {
   91|    781|         if(m_pos >= m_str.size()) {
  ------------------
  |  Branch (91:13): [True: 196, False: 585]
  ------------------
   92|    196|            return std::nullopt;
   93|    196|         }
   94|       |
   95|    585|         if(is_space(m_str[m_pos])) {
  ------------------
  |  Branch (95:13): [True: 23, False: 562]
  ------------------
   96|       |            // Skip the entire whitespace run
   97|     51|            while(m_pos < m_str.size() && is_space(m_str[m_pos])) {
  ------------------
  |  Branch (97:19): [True: 44, False: 7]
  |  Branch (97:43): [True: 28, False: 16]
  ------------------
   98|     28|               ++m_pos;
   99|     28|            }
  100|       |            // Emit a single space only if more content follows (strip trailing ws)
  101|     23|            if(m_pos < m_str.size()) {
  ------------------
  |  Branch (101:16): [True: 16, False: 7]
  ------------------
  102|     16|               return ' ';
  103|     16|            }
  104|      7|            return std::nullopt;
  105|     23|         }
  106|       |
  107|    562|         const char c = m_str[m_pos++];
  108|       |         // Locale-independent ASCII fold; RFC 5280 DN matching does not depend on libc locale
  109|    562|         if(c >= 'A' && c <= 'Z') {
  ------------------
  |  Branch (109:13): [True: 43, False: 519]
  |  Branch (109:25): [True: 20, False: 23]
  ------------------
  110|     20|            return static_cast<char>(c + ('a' - 'A'));
  111|     20|         }
  112|    542|         return c;
  113|    562|      }
x509_dn.cpp:_ZZN5Botan12_GLOBAL__N_115canonicalize_dnERKNSt3__16vectorINS2_INS1_4pairINS_3OIDENS_11ASN1_StringEEENS1_9allocatorIS6_EEEENS7_IS9_EEEEENK3$_0clINS2_IhNS7_IhEEEEEEDaRSH_RKT_:
  312|    406|   auto append_canonical_data = []<typename T>(std::vector<uint8_t>& out, const T& data) {
  313|    406|      const std::array<uint8_t, 8> data_len = store_le(static_cast<uint64_t>(data.size()));
  314|    406|      out.insert(out.end(), data_len.begin(), data_len.end());
  315|    406|      out.insert(out.end(), data.begin(), data.end());
  316|    406|   };
x509_dn.cpp:_ZZN5Botan12_GLOBAL__N_115canonicalize_dnERKNSt3__16vectorINS2_INS1_4pairINS_3OIDENS_11ASN1_StringEEENS1_9allocatorIS6_EEEENS7_IS9_EEEEENK3$_0clINS1_12basic_stringIcNS1_11char_traitsIcEENS7_IcEEEEEEDaRNS2_IhNS7_IhEEEERKT_:
  312|    203|   auto append_canonical_data = []<typename T>(std::vector<uint8_t>& out, const T& data) {
  313|    203|      const std::array<uint8_t, 8> data_len = store_le(static_cast<uint64_t>(data.size()));
  314|    203|      out.insert(out.end(), data_len.begin(), data_len.end());
  315|    203|      out.insert(out.end(), data.begin(), data.end());
  316|    203|   };
x509_dn.cpp:_ZN5Botan12_GLOBAL__N_18is_spaceEc:
   27|    790|bool is_space(char c) {
   28|    790|   return c == ' ' || c == '\t';
  ------------------
  |  Branch (28:11): [True: 34, False: 756]
  |  Branch (28:23): [True: 40, False: 716]
  ------------------
   29|    790|}

_ZNK5Botan11X509_Object11signed_bodyEv:
   66|      1|const std::vector<uint8_t>& X509_Object::signed_body() const {
   67|      1|   if(!m_signed_data) {
  ------------------
  |  Branch (67:7): [True: 0, False: 1]
  ------------------
   68|      0|      throw Invalid_State("X509_Object uninitialized");
   69|      0|   }
   70|      1|   return m_signed_data->m_tbs_bits;
   71|      1|}
_ZN5Botan11X509_Object11decode_fromERNS_11BER_DecoderE:
   93|     14|void X509_Object::decode_from(BER_Decoder& from) {
   94|     14|   auto data = std::make_shared<Signed_Data>();
   95|       |
   96|     14|   from.start_sequence()
   97|     14|      .start_sequence()
   98|     14|      .raw_bytes(data->m_tbs_bits)
   99|     14|      .end_cons()
  100|     14|      .decode(data->m_sig_algo)
  101|     14|      .decode_octet_aligned_bitstring(data->m_sig)
  102|     14|      .end_cons();
  103|       |
  104|     14|   m_signed_data = std::move(data);
  105|     14|   force_decode();
  106|     14|}

_ZN5Botan16X509_CertificateD2Ev:
   85|     14|X509_Certificate::~X509_Certificate() = default;
_ZN5Botan16X509_Certificate12force_decodeEv:
  370|      1|void X509_Certificate::force_decode() {
  371|      1|   m_data.reset();
  372|      1|   m_data = parse_x509_cert_body(*this);
  373|      1|}
x509cert.cpp:_ZN5Botan12_GLOBAL__N_120parse_x509_cert_bodyERKNS_11X509_ObjectE:
  113|      1|std::unique_ptr<X509_Certificate_Data> parse_x509_cert_body(const X509_Object& obj) {
  114|      1|   auto data = std::make_unique<X509_Certificate_Data>();
  115|       |
  116|      1|   BigInt serial_bn;
  117|      1|   BER_Object public_key;
  118|      1|   BER_Object v3_exts_data;
  119|       |
  120|      1|   BER_Decoder(obj.signed_body(), BER_Decoder::Limits::DER())
  121|      1|      .decode_optional(data->m_version, ASN1_Type(0), ASN1_Class::Constructed | ASN1_Class::ContextSpecific)
  122|      1|      .decode(serial_bn)
  123|      1|      .decode(data->m_sig_algo_inner)
  124|      1|      .decode(data->m_issuer_dn)
  125|      1|      .start_sequence()
  126|      1|      .decode(data->m_not_before)
  127|      1|      .decode(data->m_not_after)
  128|      1|      .end_cons()
  129|      1|      .decode(data->m_subject_dn)
  130|      1|      .get_next(public_key)
  131|      1|      .decode_optional_string(data->m_v2_issuer_key_id, ASN1_Type::BitString, 1)
  132|      1|      .decode_optional_string(data->m_v2_subject_key_id, ASN1_Type::BitString, 2)
  133|      1|      .get_next(v3_exts_data)
  134|      1|      .verify_end("TBSCertificate has extra data after extensions block");
  135|       |
  136|      1|   if(data->m_version > 2) {
  ------------------
  |  Branch (136:7): [True: 0, False: 1]
  ------------------
  137|      0|      throw Decoding_Error("Unknown X.509 cert version " + std::to_string(data->m_version));
  138|      0|   }
  139|      1|   if(obj.signature_algorithm() != data->m_sig_algo_inner) {
  ------------------
  |  Branch (139:7): [True: 0, False: 1]
  ------------------
  140|      0|      throw Decoding_Error("X.509 Certificate had differing algorithm identifiers in inner and outer ID fields");
  141|      0|   }
  142|       |
  143|      1|   public_key.assert_is_a(ASN1_Type::Sequence, ASN1_Class::Constructed, "X.509 certificate public key");
  144|       |
  145|       |   // for general sanity convert wire version (0 based) to standards version (v1 .. v3)
  146|      1|   data->m_version += 1;
  147|       |
  148|      1|   data->m_serial = serial_bn.serialize();
  149|       |   // crude method to save the serial's sign; will get lost during decoding, otherwise
  150|      1|   data->m_serial_negative = serial_bn.signum() < 0;
  151|      1|   data->m_subject_dn_bits = ASN1::put_in_sequence(data->m_subject_dn.get_bits());
  152|      1|   data->m_issuer_dn_bits = ASN1::put_in_sequence(data->m_issuer_dn.get_bits());
  153|       |
  154|      1|   data->m_subject_public_key_bits.assign(public_key.bits(), public_key.bits() + public_key.length());
  155|       |
  156|      1|   data->m_subject_public_key_bits_seq = ASN1::put_in_sequence(data->m_subject_public_key_bits);
  157|       |
  158|      1|   BER_Decoder(data->m_subject_public_key_bits, BER_Decoder::Limits::DER())
  159|      1|      .decode(data->m_subject_public_key_algid)
  160|      1|      .decode_octet_aligned_bitstring(data->m_subject_public_key_bitstring)
  161|      1|      .verify_end();
  162|       |
  163|      1|   if(v3_exts_data.is_a(3, ASN1_Class::Constructed | ASN1_Class::ContextSpecific)) {
  ------------------
  |  Branch (163:7): [True: 0, False: 1]
  ------------------
  164|       |      // Path validation will reject a v1/v2 cert with v3 extensions
  165|      0|      BER_Decoder cert_extensions(v3_exts_data, BER_Decoder::Limits::DER());
  166|      0|      data->m_v3_extensions.decode_from(cert_extensions, Extension_Context::Certificate);
  167|      0|      cert_extensions.verify_end();
  168|      1|   } else if(v3_exts_data.is_set()) {
  ------------------
  |  Branch (168:14): [True: 0, False: 1]
  ------------------
  169|      0|      throw BER_Bad_Tag("Unknown tag in X.509 cert", v3_exts_data.tagging());
  170|      0|   }
  171|       |
  172|       |   // Now cache some fields from the extensions
  173|      1|   if(const auto* ext = data->m_v3_extensions.get_extension_object_as<Cert_Extension::Key_Usage>()) {
  ------------------
  |  Branch (173:19): [True: 0, False: 1]
  ------------------
  174|      0|      data->m_key_constraints = ext->get_constraints();
  175|       |      /*
  176|       |      RFC 5280: When the keyUsage extension appears in a certificate,
  177|       |      at least one of the bits MUST be set to 1.
  178|       |      */
  179|      0|      if(data->m_key_constraints.empty()) {
  ------------------
  |  Branch (179:10): [True: 0, False: 0]
  ------------------
  180|      0|         throw Decoding_Error("Certificate has invalid encoding for KeyUsage");
  181|      0|      }
  182|      0|   }
  183|       |
  184|      1|   if(const auto* ext = data->m_v3_extensions.get_extension_object_as<Cert_Extension::Subject_Key_ID>()) {
  ------------------
  |  Branch (184:19): [True: 0, False: 1]
  ------------------
  185|      0|      data->m_subject_key_id = ext->get_key_id();
  186|      0|   }
  187|       |
  188|      1|   if(const auto* ext = data->m_v3_extensions.get_extension_object_as<Cert_Extension::Authority_Key_ID>()) {
  ------------------
  |  Branch (188:19): [True: 0, False: 1]
  ------------------
  189|      0|      data->m_authority_key_id = ext->get_key_id();
  190|      0|   }
  191|       |
  192|      1|   if(const auto* ext = data->m_v3_extensions.get_extension_object_as<Cert_Extension::Name_Constraints>()) {
  ------------------
  |  Branch (192:19): [True: 0, False: 1]
  ------------------
  193|      0|      data->m_name_constraints = ext->get_name_constraints();
  194|      0|   }
  195|       |
  196|      1|   if(const auto* ext = data->m_v3_extensions.get_extension_object_as<Cert_Extension::Extended_Key_Usage>()) {
  ------------------
  |  Branch (196:19): [True: 0, False: 1]
  ------------------
  197|      0|      data->m_extended_key_usage = ext->object_identifiers();
  198|       |      /*
  199|       |      RFC 5280 section 4.2.1.12
  200|       |
  201|       |      "This extension indicates one or more purposes ..."
  202|       |
  203|       |      "If the extension is present, then the certificate MUST only be
  204|       |      used for one of the purposes indicated."
  205|       |
  206|       |      Thus we reject an EKU extension which is empty, since this indicates
  207|       |      the certificate cannot be used for any purpose.
  208|       |      */
  209|      0|      if(data->m_extended_key_usage.empty()) {
  ------------------
  |  Branch (209:10): [True: 0, False: 0]
  ------------------
  210|      0|         throw Decoding_Error("Certificate has invalid empty EKU extension");
  211|      0|      }
  212|      0|   }
  213|       |
  214|      1|   if(const auto* ext = data->m_v3_extensions.get_extension_object_as<Cert_Extension::Basic_Constraints>()) {
  ------------------
  |  Branch (214:19): [True: 0, False: 1]
  ------------------
  215|       |      /*
  216|       |      * RFC 5280 4.2.1.9 requires that conforming CAs "MUST mark the
  217|       |      * extension [basicConstraints] as critical in such certificates"
  218|       |      * but places no such requirement on validators.
  219|       |      */
  220|      0|      if(ext->is_ca() == true) {
  ------------------
  |  Branch (220:10): [True: 0, False: 0]
  ------------------
  221|       |         /*
  222|       |         * RFC 5280 section 4.2.1.3 requires that CAs include KeyUsage in all
  223|       |         * intermediate CA certificates they issue. Currently we accept it being
  224|       |         * missing, as do most other implementations. But it may be worth
  225|       |         * removing this entirely, or alternately adding a warning level
  226|       |         * validation failure for it.
  227|       |         */
  228|      0|         const bool allowed_by_ku =
  229|      0|            data->m_key_constraints.includes(Key_Constraints::KeyCertSign) || data->m_key_constraints.empty();
  ------------------
  |  Branch (229:13): [True: 0, False: 0]
  |  Branch (229:79): [True: 0, False: 0]
  ------------------
  230|       |
  231|       |         /*
  232|       |         * If the extended key usages are set then we must restrict the usage in
  233|       |         * accordance with it as well.
  234|       |         *
  235|       |         * RFC 5280 does not define any extended key usages compatible with certificate
  236|       |         * signing, but some CAs use serverAuth, clientAuth, OCSPSigning, or AnyExtendedKeyUsage
  237|       |         * for this purpose, even though clearly all of these (besides AEKU) are invalid.
  238|       |         * This check at least allows excluding a certificate which is set for only eg
  239|       |         * timestamping or code signing, and that seems about the best we can possibly enforce.
  240|       |         * OpenSSL, BoringSSL, and Go all completely ignore EKUs in determining ability to
  241|       |         * issue certs.
  242|       |         */
  243|      0|         const bool allowed_by_ext_ku = [](const std::vector<OID>& ext_ku) -> bool {
  244|      0|            if(ext_ku.empty()) {
  245|      0|               return true;
  246|      0|            }
  247|       |
  248|      0|            const auto server_auth = OID::from_name("PKIX.ServerAuth");
  249|      0|            const auto client_auth = OID::from_name("PKIX.ClientAuth");
  250|      0|            const auto ocsp_sign = OID::from_name("PKIX.OCSPSigning");
  251|      0|            const auto any_eku = OID::from_name("X509v3.AnyExtendedKeyUsage");
  252|       |
  253|      0|            for(const auto& oid : ext_ku) {
  254|      0|               if(oid == any_eku || oid == server_auth || oid == client_auth || oid == ocsp_sign) {
  255|      0|                  return true;
  256|      0|               }
  257|      0|            }
  258|       |
  259|      0|            return false;
  260|      0|         }(data->m_extended_key_usage);
  261|       |
  262|      0|         if(allowed_by_ku && allowed_by_ext_ku) {
  ------------------
  |  Branch (262:13): [True: 0, False: 0]
  |  Branch (262:30): [True: 0, False: 0]
  ------------------
  263|      0|            data->m_is_ca_certificate = true;
  264|      0|            data->m_path_len_constraint = ext->path_length_constraint();
  265|      0|         }
  266|      0|      }
  267|      0|   }
  268|       |
  269|      1|   if(const auto* ext = data->m_v3_extensions.get_extension_object_as<Cert_Extension::Issuer_Alternative_Name>()) {
  ------------------
  |  Branch (269:19): [True: 0, False: 1]
  ------------------
  270|      0|      data->m_issuer_alt_name = ext->get_alt_name();
  271|      0|   }
  272|       |
  273|      1|   if(const auto* ext = data->m_v3_extensions.get_extension_object_as<Cert_Extension::Subject_Alternative_Name>()) {
  ------------------
  |  Branch (273:19): [True: 0, False: 1]
  ------------------
  274|      0|      data->m_subject_alt_name = ext->get_alt_name();
  275|      0|   }
  276|       |
  277|       |   // This will be set even if SAN parsing failed entirely eg due to a decoding error
  278|       |   // or if the SAN is empty. This is used to guard against using the CN for domain
  279|       |   // name checking.
  280|      1|   const auto san_oid = OID::from_string("X509v3.SubjectAlternativeName");
  281|      1|   data->m_subject_alt_name_exists = data->m_v3_extensions.extension_set(san_oid);
  282|       |
  283|       |   /*
  284|       |   * RFC 9608 Section 4:
  285|       |   *
  286|       |   *   If the noRevAvail certificate extension specified in this document is
  287|       |   *   present or the ocsp-nocheck certificate extension [RFC6960] is
  288|       |   *   present, then Step (a)(3) is skipped.  Otherwise, revocation status
  289|       |   *   determination of the certificate is performed.
  290|       |   */
  291|      1|   data->m_skip_revocation_check =
  292|      1|      data->m_v3_extensions.extension_set(Cert_Extension::NoRevocationAvailable::static_oid()) ||
  ------------------
  |  Branch (292:7): [True: 1, False: 0]
  ------------------
  293|      0|      data->m_v3_extensions.extension_set(Cert_Extension::OCSP_NoCheck::static_oid());
  ------------------
  |  Branch (293:7): [True: 0, False: 0]
  ------------------
  294|       |
  295|      1|   if(const auto* ext = data->m_v3_extensions.get_extension_object_as<Cert_Extension::Certificate_Policies>()) {
  ------------------
  |  Branch (295:19): [True: 0, False: 1]
  ------------------
  296|      0|      data->m_cert_policies = ext->get_policy_oids();
  297|      0|   }
  298|       |
  299|      1|   if(const auto* ext = data->m_v3_extensions.get_extension_object_as<Cert_Extension::Authority_Information_Access>()) {
  ------------------
  |  Branch (299:19): [True: 0, False: 1]
  ------------------
  300|      0|      data->m_ocsp_responders = ext->ocsp_responder_uris();
  301|      0|      data->m_ca_issuers = ext->ca_issuer_uris();
  302|      0|   }
  303|       |
  304|      1|   if(const auto* ext = data->m_v3_extensions.get_extension_object_as<Cert_Extension::CRL_Distribution_Points>()) {
  ------------------
  |  Branch (304:19): [True: 0, False: 1]
  ------------------
  305|      0|      data->m_crl_distribution_points = ext->crl_distribution_point_uris();
  306|      0|   }
  307|       |
  308|       |   /*
  309|       |   Determine if this certificate appears to be self-issued (subject == issuer).
  310|       |   This is only a heuristic used for path building so it's ok it is not precise.
  311|       |   The self-signature is verified during path validation.
  312|       |   */
  313|      1|   if(data->m_subject_dn == data->m_issuer_dn) {
  ------------------
  |  Branch (313:7): [True: 0, False: 1]
  ------------------
  314|      0|      if(!data->m_subject_key_id.empty() && !data->m_authority_key_id.empty()) {
  ------------------
  |  Branch (314:10): [True: 0, False: 0]
  |  Branch (314:45): [True: 0, False: 0]
  ------------------
  315|       |         /*
  316|       |         Both SKID and AKID are set so we can reliably determine self-signed vs
  317|       |         self-issued by comparing the two
  318|       |         */
  319|      0|         data->m_self_signed = (data->m_subject_key_id == data->m_authority_key_id);
  320|      0|      } else {
  321|       |         /*
  322|       |         Without both SKID and AKID we can't determine with certainty. Assume
  323|       |         self-signed since that's by far the common case.
  324|       |         */
  325|      0|         data->m_self_signed = true;
  326|      0|      }
  327|      0|   }
  328|       |
  329|      1|   const std::vector<uint8_t> full_encoding = obj.BER_encode();
  330|       |
  331|      1|   if(auto sha1 = HashFunction::create("SHA-1")) {
  ------------------
  |  Branch (331:12): [True: 0, False: 1]
  ------------------
  332|      0|      sha1->update(data->m_subject_public_key_bitstring);
  333|      0|      data->m_subject_public_key_bitstring_sha1 = sha1->final_stdvec();
  334|       |      // otherwise left as empty, and we will throw if subject_public_key_bitstring_sha1 is called
  335|       |
  336|      0|      sha1->update(full_encoding);
  337|      0|      sha1->final(data->m_cert_data_sha1);
  338|      0|      data->m_fingerprint_sha1 = format_hex_fingerprint(data->m_cert_data_sha1);
  339|       |
  340|      0|      sha1->update(data->m_issuer_dn_bits);
  341|      0|      sha1->final(data->m_issuer_dn_bits_sha1);
  342|       |
  343|      0|      sha1->update(data->m_subject_dn_bits);
  344|      0|      sha1->final(data->m_subject_dn_bits_sha1);
  345|      0|   }
  346|       |
  347|       |   // SHA-256 is a hard dependency of this module
  348|      1|   auto sha256 = HashFunction::create_or_throw("SHA-256");
  349|      1|   sha256->update(data->m_issuer_dn_bits);
  350|      1|   data->m_issuer_dn_bits_sha256 = sha256->final_stdvec();
  351|       |
  352|      1|   sha256->update(data->m_subject_dn_bits);
  353|      1|   data->m_subject_dn_bits_sha256 = sha256->final_stdvec();
  354|       |
  355|      1|   sha256->update(full_encoding);
  356|      1|   sha256->final(data->m_cert_data_sha256);
  357|      1|   data->m_fingerprint_sha256 = format_hex_fingerprint(data->m_cert_data_sha256);
  358|       |
  359|      1|   sha256->update(data->m_subject_public_key_bitstring);
  360|      1|   sha256->final(data->m_subject_public_key_bitstring_sha256);
  361|       |
  362|      1|   return data;
  363|      1|}

