_ZN5Botan17ct_expand_top_bitITkNSt3__117unsigned_integralEmEET_S2_:
   28|  23.4k|BOTAN_FORCE_INLINE constexpr T ct_expand_top_bit(T a) {
   29|  23.4k|   const T top = CT::value_barrier<T>(a >> (sizeof(T) * 8 - 1));
   30|  23.4k|   return static_cast<T>(0) - top;
   31|  23.4k|}
_ZN5Botan6chooseITkNSt3__117unsigned_integralEmEET_S2_S2_S2_:
  216|  19.7k|BOTAN_FORCE_INLINE constexpr T choose(T mask, T a, T b) {
  217|       |   //return (mask & a) | (~mask & b);
  218|  19.7k|   return (b ^ (mask & (a ^ b)));
  219|  19.7k|}
_ZN5Botan10ct_is_zeroITkNSt3__117unsigned_integralEmEET_S2_:
   37|  23.4k|BOTAN_FORCE_INLINE constexpr T ct_is_zero(T x) {
   38|  23.4k|   return ct_expand_top_bit<T>(~x & (x - 1));
   39|  23.4k|}
_ZN5Botan10ct_is_zeroITkNSt3__117unsigned_integralEhEET_S2_:
   37|    297|BOTAN_FORCE_INLINE constexpr T ct_is_zero(T x) {
   38|    297|   return ct_expand_top_bit<T>(~x & (x - 1));
   39|    297|}
_ZN5Botan17ct_expand_top_bitITkNSt3__117unsigned_integralEhEET_S2_:
   28|    297|BOTAN_FORCE_INLINE constexpr T ct_expand_top_bit(T a) {
   29|    297|   const T top = CT::value_barrier<T>(a >> (sizeof(T) * 8 - 1));
   30|    297|   return static_cast<T>(0) - top;
   31|    297|}
_ZN5Botan6chooseITkNSt3__117unsigned_integralEhEET_S2_S2_S2_:
  216|    297|BOTAN_FORCE_INLINE constexpr T choose(T mask, T a, T b) {
  217|       |   //return (mask & a) | (~mask & b);
  218|    297|   return (b ^ (mask & (a ^ b)));
  219|    297|}

_ZN5Botan13reverse_bytesITkNSt3__117unsigned_integralEmQooooooeqstT_Li1EeqstS2_Li2EeqstS2_Li4EeqstS2_Li8EEES2_S2_:
   27|  9.29k|inline constexpr T reverse_bytes(T x) {
   28|       |   if constexpr(sizeof(T) == 1) {
   29|       |      return x;
   30|       |   } else if constexpr(sizeof(T) == 2) {
   31|       |#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap16)
   32|       |      return static_cast<T>(__builtin_bswap16(x));
   33|       |#else
   34|       |      return static_cast<T>((x << 8) | (x >> 8));
   35|       |#endif
   36|       |   } else if constexpr(sizeof(T) == 4) {
   37|       |#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap32)
   38|       |      return static_cast<T>(__builtin_bswap32(x));
   39|       |#else
   40|       |      // MSVC at least recognizes this as a bswap
   41|       |      return static_cast<T>(((x & 0x000000FF) << 24) | ((x & 0x0000FF00) << 8) | ((x & 0x00FF0000) >> 8) |
   42|       |                            ((x & 0xFF000000) >> 24));
   43|       |#endif
   44|  9.29k|   } else if constexpr(sizeof(T) == 8) {
   45|  9.29k|#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap64)
   46|  9.29k|      return static_cast<T>(__builtin_bswap64(x));
   47|       |#else
   48|       |      uint32_t hi = static_cast<uint32_t>(x >> 32);
   49|       |      uint32_t lo = static_cast<uint32_t>(x);
   50|       |
   51|       |      hi = reverse_bytes(hi);
   52|       |      lo = reverse_bytes(lo);
   53|       |
   54|       |      return (static_cast<T>(lo) << 32) | hi;
   55|       |#endif
   56|  9.29k|   }
   57|  9.29k|}

_ZN5Botan2CT4MaskImEC2Em:
  637|  3.95k|      constexpr explicit Mask(T m) : m_mask(m) {}
_ZNK5Botan2CT4MaskImE5valueEv:
  630|  4.87k|      constexpr T value() const { return value_barrier<T>(m_mask); }
_ZN5Botan2CT4MaskImE7is_zeroEm:
  437|  1.66k|      static constexpr Mask<T> is_zero(T x) { return Mask<T>(ct_is_zero<T>(value_barrier<T>(x))); }
_ZN5Botan2CT8unpoisonITkNSt3__18integralEmEEvRKT_:
  112|    891|constexpr void unpoison(const T& p) {
  113|    891|   unpoison(&p, 1);
  114|    891|}
_ZN5Botan2CT8unpoisonImEEvPKT_m:
   67|  1.78k|constexpr inline void unpoison(const T* p, size_t n) {
   68|       |#if defined(BOTAN_HAS_VALGRIND)
   69|       |   if(!std::is_constant_evaluated()) {
   70|       |      VALGRIND_MAKE_MEM_DEFINED(p, n * sizeof(T));
   71|       |   }
   72|       |#endif
   73|       |
   74|  1.78k|   BOTAN_UNUSED(p, n);
  ------------------
  |  |  144|  1.78k|#define BOTAN_UNUSED Botan::ignore_params
  ------------------
   75|  1.78k|}
_ZN5Botan2CT4MaskImE6expandEm:
  392|  1.36k|      static constexpr Mask<T> expand(T v) { return ~Mask<T>::is_zero(value_barrier<T>(v)); }
_ZNK5Botan2CT4MaskImEcoEv:
  533|  1.98k|      constexpr Mask<T> operator~() const { return Mask<T>(~value()); }
_ZNK5Botan2CT4MaskImE7as_boolEv:
  614|    297|      constexpr bool as_bool() const { return unpoisoned_value() != 0; }
_ZNK5Botan2CT4MaskImE16unpoisoned_valueEv:
  598|    297|      constexpr T unpoisoned_value() const {
  599|    297|         T r = value();
  600|    297|         CT::unpoison(r);
  601|    297|         return r;
  602|    297|      }
_ZNK5Botan2CT4MaskImE8select_nEPmPKmS5_m:
  565|    752|      constexpr void select_n(T output[], const T x[], const T y[], size_t len) const {
  566|    752|         const T mask = value();
  567|  20.5k|         for(size_t i = 0; i != len; ++i) {
  ------------------
  |  Branch (567:28): [True: 19.7k, False: 752]
  ------------------
  568|  19.7k|            output[i] = choose(mask, x[i], y[i]);
  569|  19.7k|         }
  570|    752|      }
_ZN5Botan2CT4MaskIhE11expand_boolEb:
  397|    297|      static constexpr Mask<T> expand_bool(bool v) { return Mask<T>::expand(static_cast<T>(v)); }
_ZN5Botan2CT4MaskIhE6expandEh:
  392|    297|      static constexpr Mask<T> expand(T v) { return ~Mask<T>::is_zero(value_barrier<T>(v)); }
_ZN5Botan2CT4MaskIhE7is_zeroEh:
  437|    297|      static constexpr Mask<T> is_zero(T x) { return Mask<T>(ct_is_zero<T>(value_barrier<T>(x))); }
_ZN5Botan2CT4MaskIhEC2Eh:
  637|    594|      constexpr explicit Mask(T m) : m_mask(m) {}
_ZNK5Botan2CT4MaskIhEcoEv:
  533|    297|      constexpr Mask<T> operator~() const { return Mask<T>(~value()); }
_ZNK5Botan2CT4MaskIhE5valueEv:
  630|    594|      constexpr T value() const { return value_barrier<T>(m_mask); }
_ZNK5Botan2CT4MaskIhE6selectEhh:
  548|    297|      constexpr T select(T x, T y) const { return choose(value(), x, y); }
_ZN5Botan2CT20conditional_copy_memImEENS0_4MaskIT_EES3_PS3_PKS3_S7_m:
  738|    752|constexpr inline Mask<T> conditional_copy_mem(T cnd, T* dest, const T* if_set, const T* if_unset, size_t elems) {
  739|    752|   const auto mask = CT::Mask<T>::expand(cnd);
  740|    752|   return CT::conditional_copy_mem(mask, dest, if_set, if_unset, elems);
  741|    752|}
_ZN5Botan2CT20conditional_copy_memImEENS0_4MaskIT_EES4_PS3_PKS3_S7_m:
  732|    752|constexpr inline Mask<T> conditional_copy_mem(Mask<T> mask, T* dest, const T* if_set, const T* if_unset, size_t elems) {
  733|    752|   mask.select_n(dest, if_set, if_unset, elems);
  734|    752|   return mask;
  735|    752|}
_ZN5Botan2CTeoENS0_4MaskImEES2_:
  523|    307|      friend Mask<T> operator^(Mask<T> x, Mask<T> y) { return Mask<T>(x.value() ^ y.value()); }

_ZN5Botan11checked_mulITkNSt3__117unsigned_integralEmEENS1_8optionalIT_EES3_S3_:
   46|  1.64k|constexpr inline std::optional<T> checked_mul(T a, T b) {
   47|       |   // Multiplication by 1U is a hack to work around C's insane
   48|       |   // integer promotion rules.
   49|       |   // https://stackoverflow.com/questions/24795651
   50|  1.64k|   const T r = (1U * a) * b;
   51|       |   // If a == 0 then the multiply certainly did not overflow
   52|       |   // Otherwise r / a == b unless overflow occurred
   53|  1.64k|   if(a != 0 && r / a != b) {
  ------------------
  |  Branch (53:7): [True: 1.64k, False: 0]
  |  Branch (53:17): [True: 0, False: 1.64k]
  ------------------
   54|      0|      return {};
   55|      0|   }
   56|  1.64k|   return r;
   57|  1.64k|}

_ZN5Botan7load_beImJNSt3__14spanIKhLm8EEEEEEDaDpOT0_:
  504|  9.07k|inline constexpr auto load_be(ParamTs&&... params) {
  505|  9.07k|   return detail::load_any<std::endian::big, OutT>(std::forward<ParamTs>(params)...);
  506|  9.07k|}
_ZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEmTkNS_6ranges16contiguous_rangeIhEENS2_4spanIKhLm8EEEQnt15custom_loadableINS0_19wrapped_type_helperIu14__remove_cvrefIT0_EE4typeEEEESA_OT1_:
  278|  9.07k|inline constexpr WrappedOutT load_any(InR&& in_range) {
  279|  9.07k|   using OutT = detail::wrapped_type<WrappedOutT>;
  280|  9.07k|   ranges::assert_exact_byte_length<sizeof(OutT)>(in_range);
  281|       |
  282|  9.07k|   return detail::wrap_strong_type_or_enum<WrappedOutT>([&]() -> OutT {
  283|       |      // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  284|       |      // internally to copy ranges on a byte-by-byte basis, which is not allowed
  285|       |      // in a `constexpr` context.
  286|  9.07k|      if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  287|  9.07k|         return fallback_load_any<endianness, OutT>(std::forward<InR>(in_range));
  288|  9.07k|      } else {
  289|  9.07k|         const std::span in{in_range};
  290|  9.07k|         if constexpr(sizeof(OutT) == 1) {
  291|  9.07k|            return static_cast<OutT>(in[0]);
  292|  9.07k|         } else if constexpr(endianness == std::endian::native) {
  293|  9.07k|            return typecast_copy<OutT>(in);
  294|  9.07k|         } else {
  295|  9.07k|            static_assert(opposite(endianness) == std::endian::native);
  296|  9.07k|            return reverse_bytes(typecast_copy<OutT>(in));
  297|  9.07k|         }
  298|  9.07k|      }
  299|  9.07k|   }());
  300|  9.07k|}
_ZN5Botan6detail24wrap_strong_type_or_enumITkNS0_20unsigned_integralishEmTkNSt3__117unsigned_integralEmEEDaT0_:
  200|  9.29k|constexpr auto wrap_strong_type_or_enum(T t) {
  201|       |   if constexpr(std::is_enum_v<OutT>) {
  202|       |      return static_cast<OutT>(t);
  203|  9.29k|   } else {
  204|  9.29k|      return Botan::wrap_strong_type<OutT>(t);
  205|  9.29k|   }
  206|  9.29k|}
_ZZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEmTkNS_6ranges16contiguous_rangeIhEENS2_4spanIKhLm8EEEQnt15custom_loadableINS0_19wrapped_type_helperIu14__remove_cvrefIT0_EE4typeEEEESA_OT1_ENKUlvE_clEv:
  282|  9.07k|   return detail::wrap_strong_type_or_enum<WrappedOutT>([&]() -> OutT {
  283|       |      // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  284|       |      // internally to copy ranges on a byte-by-byte basis, which is not allowed
  285|       |      // in a `constexpr` context.
  286|  9.07k|      if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  ------------------
  |  Branch (286:10): [Folded, False: 9.07k]
  ------------------
  287|      0|         return fallback_load_any<endianness, OutT>(std::forward<InR>(in_range));
  288|  9.07k|      } else {
  289|  9.07k|         const std::span in{in_range};
  290|       |         if constexpr(sizeof(OutT) == 1) {
  291|       |            return static_cast<OutT>(in[0]);
  292|       |         } else if constexpr(endianness == std::endian::native) {
  293|       |            return typecast_copy<OutT>(in);
  294|  9.07k|         } else {
  295|  9.07k|            static_assert(opposite(endianness) == std::endian::native);
  296|  9.07k|            return reverse_bytes(typecast_copy<OutT>(in));
  297|  9.07k|         }
  298|  9.07k|      }
  299|  9.07k|   }());
_ZN5Botan7load_beImJRNSt3__15arrayIhLm8EEEEEEDaDpOT0_:
  504|    226|inline constexpr auto load_be(ParamTs&&... params) {
  505|    226|   return detail::load_any<std::endian::big, OutT>(std::forward<ParamTs>(params)...);
  506|    226|}
_ZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEmTkNS_6ranges16contiguous_rangeIhEERNS2_5arrayIhLm8EEEQnt15custom_loadableINS0_19wrapped_type_helperIu14__remove_cvrefIT0_EE4typeEEEESA_OT1_:
  278|    226|inline constexpr WrappedOutT load_any(InR&& in_range) {
  279|    226|   using OutT = detail::wrapped_type<WrappedOutT>;
  280|    226|   ranges::assert_exact_byte_length<sizeof(OutT)>(in_range);
  281|       |
  282|    226|   return detail::wrap_strong_type_or_enum<WrappedOutT>([&]() -> OutT {
  283|       |      // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  284|       |      // internally to copy ranges on a byte-by-byte basis, which is not allowed
  285|       |      // in a `constexpr` context.
  286|    226|      if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  287|    226|         return fallback_load_any<endianness, OutT>(std::forward<InR>(in_range));
  288|    226|      } else {
  289|    226|         const std::span in{in_range};
  290|    226|         if constexpr(sizeof(OutT) == 1) {
  291|    226|            return static_cast<OutT>(in[0]);
  292|    226|         } else if constexpr(endianness == std::endian::native) {
  293|    226|            return typecast_copy<OutT>(in);
  294|    226|         } else {
  295|    226|            static_assert(opposite(endianness) == std::endian::native);
  296|    226|            return reverse_bytes(typecast_copy<OutT>(in));
  297|    226|         }
  298|    226|      }
  299|    226|   }());
  300|    226|}
_ZZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEmTkNS_6ranges16contiguous_rangeIhEERNS2_5arrayIhLm8EEEQnt15custom_loadableINS0_19wrapped_type_helperIu14__remove_cvrefIT0_EE4typeEEEESA_OT1_ENKUlvE_clEv:
  282|    226|   return detail::wrap_strong_type_or_enum<WrappedOutT>([&]() -> OutT {
  283|       |      // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  284|       |      // internally to copy ranges on a byte-by-byte basis, which is not allowed
  285|       |      // in a `constexpr` context.
  286|    226|      if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  ------------------
  |  Branch (286:10): [Folded, False: 226]
  ------------------
  287|      0|         return fallback_load_any<endianness, OutT>(std::forward<InR>(in_range));
  288|    226|      } else {
  289|    226|         const std::span in{in_range};
  290|       |         if constexpr(sizeof(OutT) == 1) {
  291|       |            return static_cast<OutT>(in[0]);
  292|       |         } else if constexpr(endianness == std::endian::native) {
  293|       |            return typecast_copy<OutT>(in);
  294|    226|         } else {
  295|    226|            static_assert(opposite(endianness) == std::endian::native);
  296|    226|            return reverse_bytes(typecast_copy<OutT>(in));
  297|    226|         }
  298|    226|      }
  299|    226|   }());

_ZN5Botan14zeroize_bufferITkNSt3__117unsigned_integralEmEEvPT_m:
   37|  1.84k|inline void zeroize_buffer(T buf[], size_t n) {
   38|  1.84k|   if(n > 0) {
  ------------------
  |  Branch (38:7): [True: 1.83k, False: 10]
  ------------------
   39|  1.83k|      std::memset(buf, 0, sizeof(T) * n);
   40|  1.83k|   }
   41|  1.84k|}

_ZN5Botan10word8_add3ITkNS_8WordTypeEmEET_PS1_PKS1_S4_S1_:
  294|  2.85k|inline constexpr auto word8_add3(W z[8], const W x[8], const W y[8], W carry) -> W {
  295|  2.85k|#if defined(BOTAN_MP_USE_X86_64_ASM)
  296|  2.85k|   if(std::same_as<W, uint64_t> && !std::is_constant_evaluated()) {
  ------------------
  |  Branch (296:7): [True: 0, Folded]
  |  Branch (296:36): [True: 0, Folded]
  ------------------
  297|  2.85k|      asm volatile(ADD_OR_SUBTRACT(DO_8_TIMES(ADDSUB3_OP, "adcq"))
  298|  2.85k|                   : [carry] "=r"(carry)
  299|  2.85k|                   : [x] "r"(x), [y] "r"(y), [z] "r"(z), "0"(carry)
  300|  2.85k|                   : "cc", "memory");
  301|  2.85k|      return carry;
  302|  2.85k|   }
  303|      0|#endif
  304|       |
  305|      0|   z[0] = word_add(x[0], y[0], &carry);
  306|      0|   z[1] = word_add(x[1], y[1], &carry);
  307|      0|   z[2] = word_add(x[2], y[2], &carry);
  308|      0|   z[3] = word_add(x[3], y[3], &carry);
  309|      0|   z[4] = word_add(x[4], y[4], &carry);
  310|      0|   z[5] = word_add(x[5], y[5], &carry);
  311|      0|   z[6] = word_add(x[6], y[6], &carry);
  312|      0|   z[7] = word_add(x[7], y[7], &carry);
  313|      0|   return carry;
  314|  2.85k|}
_ZN5Botan8word_addITkNS_8WordTypeEmEET_S1_S1_PS1_:
  231|  48.9k|inline constexpr auto word_add(W x, W y, W* carry) -> W {
  232|  48.9k|#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_addc)
  233|  48.9k|   if(!std::is_constant_evaluated()) {
  ------------------
  |  Branch (233:7): [True: 48.9k, Folded]
  ------------------
  234|       |      if constexpr(std::same_as<W, unsigned int>) {
  235|       |         return __builtin_addc(x, y, *carry & 1, carry);
  236|  48.9k|      } else if constexpr(std::same_as<W, unsigned long>) {
  237|  48.9k|         return __builtin_addcl(x, y, *carry & 1, carry);
  238|       |      } else if constexpr(std::same_as<W, unsigned long long>) {
  239|       |         return __builtin_addcll(x, y, *carry & 1, carry);
  240|       |      }
  241|  48.9k|   }
  242|      0|#endif
  243|       |
  244|       |   if constexpr(WordInfo<W>::dword_is_native && use_dword_for_word_add) {
  245|       |      /*
  246|       |      TODO(Botan4) this is largely a performance hack for GCCs that don't
  247|       |      support __builtin_addc, if we increase the minimum supported version of
  248|       |      GCC to GCC 14 then we can remove this and not worry about it
  249|       |      */
  250|       |      const W cb = *carry & 1;
  251|       |      const auto s = typename WordInfo<W>::dword(x) + y + cb;
  252|       |      *carry = static_cast<W>(s >> WordInfo<W>::bits);
  253|       |      return static_cast<W>(s);
  254|  48.9k|   } else {
  255|  48.9k|      const W cb = *carry & 1;
  256|  48.9k|      W z = x + y;
  257|  48.9k|      W c1 = (z < x);
  258|  48.9k|      z += cb;
  259|  48.9k|      *carry = c1 | (z < cb);
  260|  48.9k|      return z;
  261|  48.9k|   }
  262|  48.9k|}
_ZN5Botan10word8_sub3ITkNS_8WordTypeEmEET_PS1_PKS1_S4_S1_:
  371|  4.57k|inline constexpr auto word8_sub3(W z[8], const W x[8], const W y[8], W carry) -> W {
  372|  4.57k|#if defined(BOTAN_MP_USE_X86_64_ASM)
  373|  4.57k|   if(std::same_as<W, uint64_t> && !std::is_constant_evaluated()) {
  ------------------
  |  Branch (373:7): [True: 0, Folded]
  |  Branch (373:36): [True: 0, Folded]
  ------------------
  374|  4.57k|      asm volatile(ADD_OR_SUBTRACT(DO_8_TIMES(ADDSUB3_OP, "sbbq"))
  375|  4.57k|                   : [carry] "=r"(carry)
  376|  4.57k|                   : [x] "r"(x), [y] "r"(y), [z] "r"(z), "0"(carry)
  377|  4.57k|                   : "cc", "memory");
  378|  4.57k|      return carry;
  379|  4.57k|   }
  380|      0|#endif
  381|       |
  382|      0|   z[0] = word_sub(x[0], y[0], &carry);
  383|      0|   z[1] = word_sub(x[1], y[1], &carry);
  384|      0|   z[2] = word_sub(x[2], y[2], &carry);
  385|      0|   z[3] = word_sub(x[3], y[3], &carry);
  386|      0|   z[4] = word_sub(x[4], y[4], &carry);
  387|      0|   z[5] = word_sub(x[5], y[5], &carry);
  388|      0|   z[6] = word_sub(x[6], y[6], &carry);
  389|      0|   z[7] = word_sub(x[7], y[7], &carry);
  390|      0|   return carry;
  391|  4.57k|}
_ZN5Botan8word_subITkNS_8WordTypeEmEET_S1_S1_PS1_:
  320|  30.9k|inline constexpr auto word_sub(W x, W y, W* carry) -> W {
  321|  30.9k|#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_subc)
  322|  30.9k|   if(!std::is_constant_evaluated()) {
  ------------------
  |  Branch (322:7): [True: 30.9k, Folded]
  ------------------
  323|       |      if constexpr(std::same_as<W, unsigned int>) {
  324|       |         return __builtin_subc(x, y, *carry & 1, carry);
  325|  30.9k|      } else if constexpr(std::same_as<W, unsigned long>) {
  326|  30.9k|         return __builtin_subcl(x, y, *carry & 1, carry);
  327|       |      } else if constexpr(std::same_as<W, unsigned long long>) {
  328|       |         return __builtin_subcll(x, y, *carry & 1, carry);
  329|       |      }
  330|  30.9k|   }
  331|      0|#endif
  332|       |
  333|      0|   const W cb = *carry & 1;
  334|  30.9k|   W t0 = x - y;
  335|  30.9k|   W c1 = (t0 > x);
  336|  30.9k|   W z = t0 - cb;
  337|  30.9k|   *carry = c1 | (z > t0);
  338|  30.9k|   return z;
  339|  30.9k|}
_ZN5Botan10word_madd2ITkNS_8WordTypeEmEET_S1_S1_PS1_:
   90|    242|inline constexpr auto word_madd2(W a, W b, W* c) -> W {
   91|    242|#if defined(BOTAN_MP_USE_X86_64_ASM)
   92|    242|   if(std::same_as<W, uint64_t> && !std::is_constant_evaluated()) {
  ------------------
  |  Branch (92:7): [True: 0, Folded]
  |  Branch (92:36): [True: 0, Folded]
  ------------------
   93|    242|      asm(R"(
   94|    242|         mulq %[b]
   95|    242|         addq %[c],%[a]
   96|    242|         adcq $0,%[carry]
   97|    242|         )"
   98|    242|          : [a] "=a"(a), [b] "=rm"(b), [carry] "=&d"(*c)
   99|    242|          : "0"(a), "1"(b), [c] "g"(*c)
  100|    242|          : "cc");
  101|       |
  102|    242|      return a;
  103|    242|   }
  104|       |#elif defined(BOTAN_MP_USE_AARCH64_ASM)
  105|       |   if(std::same_as<W, uint64_t> && !std::is_constant_evaluated()) {
  106|       |      W lo = 0;
  107|       |      W hi = 0;
  108|       |      asm(R"(
  109|       |         mul  %[lo], %[a], %[b]
  110|       |         umulh %[hi], %[a], %[b]
  111|       |         adds %[lo], %[lo], %[c]
  112|       |         adc  %[hi], %[hi], xzr
  113|       |         )"
  114|       |          : [lo] "=&r"(lo), [hi] "=&r"(hi)
  115|       |          : [a] "r"(a), [b] "r"(b), [c] "r"(*c)
  116|       |          : "cc");
  117|       |
  118|       |      *c = hi;
  119|       |      return lo;
  120|       |   }
  121|       |#endif
  122|       |
  123|      0|   typedef typename WordInfo<W>::dword dword;
  124|      0|   const dword s = dword(a) * b + *c;
  125|      0|   *c = static_cast<W>(s >> WordInfo<W>::bits);
  126|      0|   return static_cast<W>(s);
  127|    242|}
_ZN5Botan11word8_madd3ITkNS_8WordTypeEmEET_PS1_PKS1_S1_S1_:
  423|  70.4k|inline constexpr auto word8_madd3(W z[8], const W x[8], W y, W carry) -> W {
  424|  70.4k|#if defined(BOTAN_MP_USE_X86_64_ASM)
  425|  70.4k|   if(std::same_as<W, uint64_t> && !std::is_constant_evaluated()) {
  ------------------
  |  Branch (425:7): [True: 0, Folded]
  |  Branch (425:36): [True: 0, Folded]
  ------------------
  426|  70.4k|      asm volatile(DO_8_TIMES(MULADD_OP, "")
  427|  70.4k|                   : [carry] "=r"(carry)
  428|  70.4k|                   : [z] "r"(z), [x] "r"(x), [y] "rm"(y), "0"(carry)
  429|  70.4k|                   : "cc", "%rax", "%rdx", "memory");
  430|  70.4k|      return carry;
  431|  70.4k|   }
  432|      0|#endif
  433|       |
  434|      0|   z[0] = word_madd3(x[0], y, z[0], &carry);
  435|      0|   z[1] = word_madd3(x[1], y, z[1], &carry);
  436|      0|   z[2] = word_madd3(x[2], y, z[2], &carry);
  437|      0|   z[3] = word_madd3(x[3], y, z[3], &carry);
  438|      0|   z[4] = word_madd3(x[4], y, z[4], &carry);
  439|      0|   z[5] = word_madd3(x[5], y, z[5], &carry);
  440|      0|   z[6] = word_madd3(x[6], y, z[6], &carry);
  441|      0|   z[7] = word_madd3(x[7], y, z[7], &carry);
  442|      0|   return carry;
  443|  70.4k|}
_ZN5Botan10word_madd3ITkNS_8WordTypeEmEET_S1_S1_S1_PS1_:
  133|  75.6k|inline constexpr auto word_madd3(W a, W b, W c, W* d) -> W {
  134|  75.6k|#if defined(BOTAN_MP_USE_X86_64_ASM)
  135|  75.6k|   if(std::same_as<W, uint64_t> && !std::is_constant_evaluated()) {
  ------------------
  |  Branch (135:7): [True: 0, Folded]
  |  Branch (135:36): [True: 0, Folded]
  ------------------
  136|  75.6k|      asm(R"(
  137|  75.6k|         mulq %[b]
  138|  75.6k|
  139|  75.6k|         addq %[c],%[a]
  140|  75.6k|         adcq $0,%[carry]
  141|  75.6k|
  142|  75.6k|         addq %[d],%[a]
  143|  75.6k|         adcq $0,%[carry]
  144|  75.6k|         )"
  145|  75.6k|          : [a] "=a"(a), [b] "=rm"(b), [carry] "=&d"(*d)
  146|  75.6k|          : "0"(a), "1"(b), [c] "g"(c), [d] "g"(*d)
  147|  75.6k|          : "cc");
  148|       |
  149|  75.6k|      return a;
  150|  75.6k|   }
  151|       |#elif defined(BOTAN_MP_USE_AARCH64_ASM)
  152|       |   if(std::same_as<W, uint64_t> && !std::is_constant_evaluated()) {
  153|       |      W lo = 0;
  154|       |      W hi = 0;
  155|       |      asm(R"(
  156|       |         mul  %[lo], %[a], %[b]
  157|       |         umulh %[hi], %[a], %[b]
  158|       |         adds %[lo], %[lo], %[c]
  159|       |         adc  %[hi], %[hi], xzr
  160|       |         adds %[lo], %[lo], %[d]
  161|       |         adc  %[hi], %[hi], xzr
  162|       |         )"
  163|       |          : [lo] "=&r"(lo), [hi] "=&r"(hi)
  164|       |          : [a] "r"(a), [b] "r"(b), [c] "r"(c), [d] "r"(*d)
  165|       |          : "cc");
  166|       |
  167|       |      *d = hi;
  168|       |      return lo;
  169|       |   }
  170|       |#endif
  171|       |
  172|      0|   typedef typename WordInfo<W>::dword dword;
  173|      0|   const dword s = dword(a) * b + c + *d;
  174|      0|   *d = static_cast<W>(s >> WordInfo<W>::bits);
  175|      0|   return static_cast<W>(s);
  176|  75.6k|}
_ZN5Botan10word8_add2ITkNS_8WordTypeEmEET_PS1_PKS1_S1_:
  268|  2.85k|inline constexpr auto word8_add2(W x[8], const W y[8], W carry) -> W {
  269|  2.85k|#if defined(BOTAN_MP_USE_X86_64_ASM)
  270|  2.85k|   if(std::same_as<W, uint64_t> && !std::is_constant_evaluated()) {
  ------------------
  |  Branch (270:7): [True: 0, Folded]
  |  Branch (270:36): [True: 0, Folded]
  ------------------
  271|  2.85k|      asm volatile(ADD_OR_SUBTRACT(DO_8_TIMES(ADDSUB2_OP, "adcq"))
  272|  2.85k|                   : [carry] "=r"(carry)
  273|  2.85k|                   : [x] "r"(x), [y] "r"(y), "0"(carry)
  274|  2.85k|                   : "cc", "memory");
  275|  2.85k|      return carry;
  276|  2.85k|   }
  277|      0|#endif
  278|       |
  279|      0|   x[0] = word_add(x[0], y[0], &carry);
  280|      0|   x[1] = word_add(x[1], y[1], &carry);
  281|      0|   x[2] = word_add(x[2], y[2], &carry);
  282|      0|   x[3] = word_add(x[3], y[3], &carry);
  283|      0|   x[4] = word_add(x[4], y[4], &carry);
  284|      0|   x[5] = word_add(x[5], y[5], &carry);
  285|      0|   x[6] = word_add(x[6], y[6], &carry);
  286|      0|   x[7] = word_add(x[7], y[7], &carry);
  287|      0|   return carry;
  288|  2.85k|}
_ZN5Botan10word8_sub2ITkNS_8WordTypeEmEET_PS1_PKS1_S1_:
  345|    893|inline constexpr auto word8_sub2(W x[8], const W y[8], W carry) -> W {
  346|    893|#if defined(BOTAN_MP_USE_X86_64_ASM)
  347|    893|   if(std::same_as<W, uint64_t> && !std::is_constant_evaluated()) {
  ------------------
  |  Branch (347:7): [True: 0, Folded]
  |  Branch (347:36): [True: 0, Folded]
  ------------------
  348|    893|      asm volatile(ADD_OR_SUBTRACT(DO_8_TIMES(ADDSUB2_OP, "sbbq"))
  349|    893|                   : [carry] "=r"(carry)
  350|    893|                   : [x] "r"(x), [y] "r"(y), "0"(carry)
  351|    893|                   : "cc", "memory");
  352|    893|      return carry;
  353|    893|   }
  354|      0|#endif
  355|       |
  356|      0|   x[0] = word_sub(x[0], y[0], &carry);
  357|      0|   x[1] = word_sub(x[1], y[1], &carry);
  358|      0|   x[2] = word_sub(x[2], y[2], &carry);
  359|      0|   x[3] = word_sub(x[3], y[3], &carry);
  360|      0|   x[4] = word_sub(x[4], y[4], &carry);
  361|      0|   x[5] = word_sub(x[5], y[5], &carry);
  362|      0|   x[6] = word_sub(x[6], y[6], &carry);
  363|      0|   x[7] = word_sub(x[7], y[7], &carry);
  364|      0|   return carry;
  365|    893|}
_ZN5Botan5word3ImEC2Ev:
  458|    613|      constexpr word3() : m_w(0) {}
_ZN5Botan5word3ImE3mulEmm:
  460|   121k|      inline constexpr void mul(W x, W y) { m_w += static_cast<W3>(x) * y; }
_ZN5Botan5word3ImE7extractEv:
  466|  19.7k|      inline constexpr W extract() {
  467|  19.7k|         W r = static_cast<W>(m_w);
  468|  19.7k|         m_w >>= WordInfo<W>::bits;
  469|  19.7k|         return r;
  470|  19.7k|      }
_ZN5Botan5word3ImE6mul_x2Emm:
  462|  24.1k|      inline constexpr void mul_x2(W x, W y) { m_w += static_cast<W3>(x) * y * 2; }

_ZN5Botan11bigint_add3ITkNS_8WordTypeEmEET_PS1_PKS1_mS4_m:
  120|    445|inline constexpr auto bigint_add3(W z[], const W x[], size_t x_size, const W y[], size_t y_size) -> W {
  121|    445|   if(x_size < y_size) {
  ------------------
  |  Branch (121:7): [True: 0, False: 445]
  ------------------
  122|      0|      return bigint_add3(z, y, y_size, x, x_size);
  123|      0|   }
  124|       |
  125|    445|   W carry = 0;
  126|       |
  127|    445|   const size_t blocks = y_size - (y_size % 8);
  128|       |
  129|  3.29k|   for(size_t i = 0; i != blocks; i += 8) {
  ------------------
  |  Branch (129:22): [True: 2.85k, False: 445]
  ------------------
  130|  2.85k|      carry = word8_add3(z + i, x + i, y + i, carry);
  131|  2.85k|   }
  132|       |
  133|  1.08k|   for(size_t i = blocks; i != y_size; ++i) {
  ------------------
  |  Branch (133:27): [True: 644, False: 445]
  ------------------
  134|    644|      z[i] = word_add(x[i], y[i], &carry);
  135|    644|   }
  136|       |
  137|    445|   for(size_t i = y_size; i != x_size; ++i) {
  ------------------
  |  Branch (137:27): [True: 0, False: 445]
  ------------------
  138|      0|      z[i] = word_add(x[i], static_cast<W>(0), &carry);
  139|      0|   }
  140|       |
  141|    445|   return carry;
  142|    445|}
_ZN5Botan14bigint_linmul3ITkNS_8WordTypeEmEEvPT_PKS1_mS1_:
  416|    242|inline constexpr void bigint_linmul3(W z[], const W x[], size_t x_size, W y) {
  417|    242|   const size_t blocks = x_size - (x_size % 8);
  418|       |
  419|    242|   W carry = 0;
  420|       |
  421|    242|   for(size_t i = 0; i != blocks; i += 8) {
  ------------------
  |  Branch (421:22): [True: 0, False: 242]
  ------------------
  422|      0|      carry = word8_linmul3(z + i, x + i, y, carry);
  423|      0|   }
  424|       |
  425|    484|   for(size_t i = blocks; i != x_size; ++i) {
  ------------------
  |  Branch (425:27): [True: 242, False: 242]
  ------------------
  426|    242|      z[i] = word_madd2(x[i], y, &carry);
  427|    242|   }
  428|       |
  429|    242|   z[x_size] = carry;
  430|    242|}
_ZN5Botan15bigint_ct_is_eqITkNS_8WordTypeEmEENS_2CT4MaskIT_EEPKS3_mS6_m:
  519|    297|inline constexpr auto bigint_ct_is_eq(const W x[], size_t x_size, const W y[], size_t y_size) -> CT::Mask<W> {
  520|    297|   const size_t common_elems = std::min(x_size, y_size);
  521|       |
  522|    297|   W diff = 0;
  523|       |
  524|  15.4k|   for(size_t i = 0; i != common_elems; i++) {
  ------------------
  |  Branch (524:22): [True: 15.1k, False: 297]
  ------------------
  525|  15.1k|      diff |= (x[i] ^ y[i]);
  526|  15.1k|   }
  527|       |
  528|       |   // If any bits were set in high part of x/y, then they are not equal
  529|    297|   if(x_size < y_size) {
  ------------------
  |  Branch (529:7): [True: 297, False: 0]
  ------------------
  530|  9.28k|      for(size_t i = x_size; i != y_size; i++) {
  ------------------
  |  Branch (530:30): [True: 8.98k, False: 297]
  ------------------
  531|  8.98k|         diff |= y[i];
  532|  8.98k|      }
  533|    297|   } else if(y_size < x_size) {
  ------------------
  |  Branch (533:14): [True: 0, False: 0]
  ------------------
  534|      0|      for(size_t i = y_size; i != x_size; i++) {
  ------------------
  |  Branch (534:30): [True: 0, False: 0]
  ------------------
  535|      0|         diff |= x[i];
  536|      0|      }
  537|      0|   }
  538|       |
  539|    297|   return CT::Mask<W>::is_zero(diff);
  540|    297|}
_ZN5Botan14bigint_sub_absITkNS_8WordTypeEmEENS_2CT4MaskIT_EEPS3_PKS3_S7_mS5_:
  279|    752|inline constexpr auto bigint_sub_abs(W z[], const W x[], const W y[], size_t N, W ws[]) -> CT::Mask<W> {
  280|       |   // Subtract in both direction then conditional copy out the result
  281|       |
  282|    752|   W* ws0 = ws;
  283|    752|   W* ws1 = ws + N;
  284|       |
  285|    752|   W borrow0 = 0;
  286|    752|   W borrow1 = 0;
  287|       |
  288|    752|   const size_t blocks = N - (N % 8);
  289|       |
  290|  3.04k|   for(size_t i = 0; i != blocks; i += 8) {
  ------------------
  |  Branch (290:22): [True: 2.28k, False: 752]
  ------------------
  291|  2.28k|      borrow0 = word8_sub3(ws0 + i, x + i, y + i, borrow0);
  292|  2.28k|      borrow1 = word8_sub3(ws1 + i, y + i, x + i, borrow1);
  293|  2.28k|   }
  294|       |
  295|  2.22k|   for(size_t i = blocks; i != N; ++i) {
  ------------------
  |  Branch (295:27): [True: 1.46k, False: 752]
  ------------------
  296|  1.46k|      ws0[i] = word_sub(x[i], y[i], &borrow0);
  297|  1.46k|      ws1[i] = word_sub(y[i], x[i], &borrow1);
  298|  1.46k|   }
  299|       |
  300|    752|   return CT::conditional_copy_mem(borrow0, z, ws1, ws0, N);
  301|    752|}
_ZN5Botan11bigint_add2ITkNS_8WordTypeEmEET_PS1_mPKS1_m:
   94|  1.33k|inline constexpr auto bigint_add2(W x[], size_t x_size, const W y[], size_t y_size) -> W {
   95|  1.33k|   W carry = 0;
   96|       |
   97|  1.33k|   BOTAN_ASSERT(x_size >= y_size, "Expected sizes");
  ------------------
  |  |   64|  1.33k|   do {                                                                                 \
  |  |   65|  1.33k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                                     \
  |  |   66|  1.33k|      if(!(expr)) {                                                                     \
  |  |  ------------------
  |  |  |  Branch (66:10): [True: 0, False: 1.33k]
  |  |  ------------------
  |  |   67|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                            \
  |  |   68|      0|         Botan::assertion_failure(#expr, assertion_made, __func__, __FILE__, __LINE__); \
  |  |   69|      0|      }                                                                                 \
  |  |   70|  1.33k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (70:12): [Folded, False: 1.33k]
  |  |  ------------------
  ------------------
   98|       |
   99|  1.33k|   const size_t blocks = y_size - (y_size % 8);
  100|       |
  101|  4.18k|   for(size_t i = 0; i != blocks; i += 8) {
  ------------------
  |  Branch (101:22): [True: 2.85k, False: 1.33k]
  ------------------
  102|  2.85k|      carry = word8_add2(x + i, y + i, carry);
  103|  2.85k|   }
  104|       |
  105|  2.86k|   for(size_t i = blocks; i != y_size; ++i) {
  ------------------
  |  Branch (105:27): [True: 1.53k, False: 1.33k]
  ------------------
  106|  1.53k|      x[i] = word_add(x[i], y[i], &carry);
  107|  1.53k|   }
  108|       |
  109|  23.8k|   for(size_t i = y_size; i != x_size; ++i) {
  ------------------
  |  Branch (109:27): [True: 22.5k, False: 1.33k]
  ------------------
  110|  22.5k|      x[i] = word_add(x[i], static_cast<W>(0), &carry);
  111|  22.5k|   }
  112|       |
  113|  1.33k|   return carry;
  114|  1.33k|}
_ZN5Botan14bigint_cnd_addITkNS_8WordTypeEmEET_S1_PS1_PKS1_m:
   45|    307|inline constexpr W bigint_cnd_add(W cnd, W x[], const W y[], size_t size) {
   46|    307|   const auto mask = CT::Mask<W>::expand(cnd).value();
   47|       |
   48|    307|   W carry = 0;
   49|       |
   50|  24.4k|   for(size_t i = 0; i != size; ++i) {
  ------------------
  |  Branch (50:22): [True: 24.1k, False: 307]
  ------------------
   51|  24.1k|      x[i] = word_add(x[i], y[i] & mask, &carry);
   52|  24.1k|   }
   53|       |
   54|    307|   return (mask & carry);
   55|    307|}
_ZN5Botan14bigint_cnd_subITkNS_8WordTypeEmEET_S1_PS1_PKS1_m:
   62|    307|inline constexpr auto bigint_cnd_sub(W cnd, W x[], const W y[], size_t size) -> W {
   63|    307|   const auto mask = CT::Mask<W>::expand(cnd).value();
   64|       |
   65|    307|   W carry = 0;
   66|       |
   67|  24.4k|   for(size_t i = 0; i != size; ++i) {
  ------------------
  |  Branch (67:22): [True: 24.1k, False: 307]
  ------------------
   68|  24.1k|      x[i] = word_sub(x[i], y[i] & mask, &carry);
   69|  24.1k|   }
   70|       |
   71|    307|   return (mask & carry);
   72|    307|}
_ZN5Botan11bigint_sub2ITkNS_8WordTypeEmEET_PS1_mPKS1_m:
  148|    138|inline constexpr auto bigint_sub2(W x[], size_t x_size, const W y[], size_t y_size) -> W {
  149|    138|   W borrow = 0;
  150|       |
  151|    138|   BOTAN_ASSERT(x_size >= y_size, "Expected sizes");
  ------------------
  |  |   64|    138|   do {                                                                                 \
  |  |   65|    138|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                                     \
  |  |   66|    138|      if(!(expr)) {                                                                     \
  |  |  ------------------
  |  |  |  Branch (66:10): [True: 0, False: 138]
  |  |  ------------------
  |  |   67|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                            \
  |  |   68|      0|         Botan::assertion_failure(#expr, assertion_made, __func__, __FILE__, __LINE__); \
  |  |   69|      0|      }                                                                                 \
  |  |   70|    138|   } while(0)
  |  |  ------------------
  |  |  |  Branch (70:12): [Folded, False: 138]
  |  |  ------------------
  ------------------
  152|       |
  153|    138|   const size_t blocks = y_size - (y_size % 8);
  154|       |
  155|  1.03k|   for(size_t i = 0; i != blocks; i += 8) {
  ------------------
  |  Branch (155:22): [True: 893, False: 138]
  ------------------
  156|    893|      borrow = word8_sub2(x + i, y + i, borrow);
  157|    893|   }
  158|       |
  159|    338|   for(size_t i = blocks; i != y_size; ++i) {
  ------------------
  |  Branch (159:27): [True: 200, False: 138]
  ------------------
  160|    200|      x[i] = word_sub(x[i], y[i], &borrow);
  161|    200|   }
  162|       |
  163|  3.81k|   for(size_t i = y_size; i != x_size; ++i) {
  ------------------
  |  Branch (163:27): [True: 3.67k, False: 138]
  ------------------
  164|  3.67k|      x[i] = word_sub(x[i], static_cast<W>(0), &borrow);
  165|  3.67k|   }
  166|       |
  167|    138|   return borrow;
  168|    138|}

_ZN5Botan8round_upEmm:
   26|    297|constexpr inline size_t round_up(size_t n, size_t align_to) {
   27|       |   // Arguably returning n in this case would also be sensible
   28|    297|   BOTAN_ARG_CHECK(align_to != 0, "align_to must not be 0");
  ------------------
  |  |   35|    297|   do {                                                          \
  |  |   36|    297|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|    297|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 297]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|    297|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 297]
  |  |  ------------------
  ------------------
   29|       |
   30|    297|   if(n % align_to > 0) {
  ------------------
  |  Branch (30:7): [True: 268, False: 29]
  ------------------
   31|    268|      const size_t adj = align_to - (n % align_to);
   32|    268|      BOTAN_ARG_CHECK(n + adj >= n, "Integer overflow during rounding");
  ------------------
  |  |   35|    268|   do {                                                          \
  |  |   36|    268|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|    268|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 268]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|    268|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 268]
  |  |  ------------------
  ------------------
   33|    268|      n += adj;
   34|    268|   }
   35|    297|   return n;
   36|    297|}

_ZN5Botan2CT13value_barrierITkNSt3__117unsigned_integralEmQntsr3stdE7same_asIbT_EEES3_S3_:
   43|  31.3k|constexpr inline T value_barrier(T x) {
   44|  31.3k|   if(std::is_constant_evaluated()) {
  ------------------
  |  Branch (44:7): [Folded, False: 31.3k]
  ------------------
   45|      0|      return x;
   46|  31.3k|   } else {
   47|  31.3k|#if defined(BOTAN_CT_VALUE_BARRIER_USE_ASM)
   48|       |      /*
   49|       |      * We may want a "stronger" statement such as
   50|       |      *     asm volatile("" : "+r,m"(x) : : "memory);
   51|       |      * (see https://theunixzoo.co.uk/blog/2021-10-14-preventing-optimisations.html)
   52|       |      * however the current approach seems sufficient with current compilers,
   53|       |      * and is minimally damaging with regards to degrading code generation.
   54|       |      */
   55|  31.3k|      asm("" : "+r"(x) : /* no input */);  // NOLINT(*-no-assembler)
   56|  31.3k|      return x;
   57|       |#elif defined(BOTAN_CT_VALUE_BARRIER_USE_VOLATILE)
   58|       |      volatile T vx = x;
   59|       |      return vx;
   60|       |#else
   61|       |      return x;
   62|       |#endif
   63|  31.3k|   }
   64|  31.3k|}
_ZN5Botan2CT13value_barrierITkNSt3__117unsigned_integralEhQntsr3stdE7same_asIbT_EEES3_S3_:
   43|  1.48k|constexpr inline T value_barrier(T x) {
   44|  1.48k|   if(std::is_constant_evaluated()) {
  ------------------
  |  Branch (44:7): [Folded, False: 1.48k]
  ------------------
   45|      0|      return x;
   46|  1.48k|   } else {
   47|  1.48k|#if defined(BOTAN_CT_VALUE_BARRIER_USE_ASM)
   48|       |      /*
   49|       |      * We may want a "stronger" statement such as
   50|       |      *     asm volatile("" : "+r,m"(x) : : "memory);
   51|       |      * (see https://theunixzoo.co.uk/blog/2021-10-14-preventing-optimisations.html)
   52|       |      * however the current approach seems sufficient with current compilers,
   53|       |      * and is minimally damaging with regards to degrading code generation.
   54|       |      */
   55|  1.48k|      asm("" : "+r"(x) : /* no input */);  // NOLINT(*-no-assembler)
   56|  1.48k|      return x;
   57|       |#elif defined(BOTAN_CT_VALUE_BARRIER_USE_VOLATILE)
   58|       |      volatile T vx = x;
   59|       |      return vx;
   60|       |#else
   61|       |      return x;
   62|       |#endif
   63|  1.48k|   }
   64|  1.48k|}

_ZN5Botan13ignore_paramsIJPKmmEEEvDpRKT_:
  142|  1.78k|constexpr void ignore_params([[maybe_unused]] const T&... args) {}

_ZN5BotanneERKNS_6BigIntES2_:
 1323|    297|inline bool operator!=(const BigInt& a, const BigInt& b) {
 1324|    297|   return !a.is_equal(b);
 1325|    297|}
_ZN5Botan6BigIntD2Ev:
  185|    891|      ~BigInt() { _const_time_unpoison(); }
_ZN5Botan6BigInt8swap_regERNSt3__16vectorImNS_16secure_allocatorImEEEE:
  218|    297|      BOTAN_DEPRECATED("Deprecated no replacement") void swap_reg(secure_vector<word>& reg) {
  219|    297|         m_data.swap(reg);
  220|       |         // sign left unchanged
  221|    297|      }
_ZN5Botan6BigInt5clearEv:
  441|    297|      void clear() {
  442|    297|         m_data.set_to_zero();
  443|    297|         m_signedness = Positive;
  444|    297|      }
_ZNK5Botan6BigInt7word_atEm:
  601|    121|      word word_at(size_t n) const { return m_data.get_word_at(n); }
_ZNK5Botan6BigInt4signEv:
  641|  1.47k|      Sign sign() const { return (m_signedness); }
_ZN5Botan6BigInt8set_signENS0_4SignE:
  663|    594|      void set_sign(Sign sign) {
  664|    594|         if(sign == Negative && is_zero()) {
  ------------------
  |  Branch (664:13): [True: 0, False: 594]
  |  Branch (664:33): [True: 0, False: 0]
  ------------------
  665|      0|            sign = Positive;
  666|      0|         }
  667|       |
  668|    594|         m_signedness = sign;
  669|    594|      }
_ZNK5Botan6BigInt4sizeEv:
  681|  2.16k|      size_t size() const { return m_data.size(); }
_ZNK5Botan6BigInt9sig_wordsEv:
  687|    891|      size_t sig_words() const { return m_data.sig_words(); }
_ZN5Botan6BigInt12mutable_dataEv:
  712|    292|      BOTAN_DEPRECATED("Deprecated no replacement") word* mutable_data() { return m_data.mutable_data(); }
_ZNK5Botan6BigInt7grow_toEm:
  738|    297|      BOTAN_DEPRECATED("Deprecated no replacement") void grow_to(size_t n) const { m_data.grow_to(n); }
_ZNK5Botan6BigInt5_dataEv:
 1033|  1.35k|      const word* _data() const { return m_data.const_data(); }
_ZN5Botan6BigInt4Data12mutable_dataEv:
 1083|    292|            word* mutable_data() {
 1084|    292|               invalidate_sig_words();
 1085|    292|               return m_reg.data();
 1086|    292|            }
_ZNK5Botan6BigInt4Data10const_dataEv:
 1088|  2.24k|            const word* const_data() const { return m_reg.data(); }
_ZNK5Botan6BigInt4Data11get_word_atEm:
 1099|    121|            word get_word_at(size_t n) const {
 1100|    121|               if(n < m_reg.size()) {
  ------------------
  |  Branch (1100:19): [True: 121, False: 0]
  ------------------
 1101|    121|                  return m_reg[n];
 1102|    121|               }
 1103|      0|               return 0;
 1104|    121|            }
_ZNK5Botan6BigInt4Data7grow_toEm:
 1126|    297|            void grow_to(size_t n) const {
 1127|    297|               if(n > size()) {
  ------------------
  |  Branch (1127:19): [True: 297, False: 0]
  ------------------
 1128|    297|                  if(n <= m_reg.capacity()) {
  ------------------
  |  Branch (1128:22): [True: 0, False: 297]
  ------------------
 1129|      0|                     m_reg.resize(n);
 1130|    297|                  } else {
 1131|    297|                     m_reg.resize(n + (8 - (n % 8)));
 1132|    297|                  }
 1133|    297|               }
 1134|    297|            }
_ZNK5Botan6BigInt4Data4sizeEv:
 1136|  3.35k|            size_t size() const { return m_reg.size(); }
_ZN5Botan6BigInt4Data4swapERNSt3__16vectorImNS_16secure_allocatorImEEEE:
 1156|    594|            void swap(secure_vector<word>& reg) noexcept {
 1157|    594|               m_reg.swap(reg);
 1158|    594|               invalidate_sig_words();
 1159|    594|            }
_ZNK5Botan6BigInt4Data20invalidate_sig_wordsEv:
 1161|    886|            void invalidate_sig_words() const noexcept { m_sig_words = sig_words_npos; }
_ZNK5Botan6BigInt4Data9sig_wordsEv:
 1163|    891|            size_t sig_words() const {
 1164|    891|               if(m_sig_words == sig_words_npos) {
  ------------------
  |  Branch (1164:19): [True: 594, False: 297]
  ------------------
 1165|    594|                  m_sig_words = calc_sig_words();
 1166|    594|               }
 1167|    891|               return m_sig_words;
 1168|    891|            }
_ZN5Botan6BigIntC2Ev:
   45|    594|      BigInt() = default;
_ZN5Botan6BigIntC2ERKS0_:
   88|    297|      BigInt(const BigInt& other) = default;

_ZN5Botan9clear_memImEEvPT_m:
  118|    297|inline constexpr void clear_mem(T* ptr, size_t n) {
  119|    297|   clear_bytes(ptr, sizeof(T) * n);
  120|    297|}
_ZN5Botan11clear_bytesEPvm:
  101|    297|inline constexpr void clear_bytes(void* ptr, size_t bytes) {
  102|    297|   if(bytes > 0) {
  ------------------
  |  Branch (102:7): [True: 0, False: 297]
  ------------------
  103|      0|      std::memset(ptr, 0, bytes);
  104|      0|   }
  105|    297|}
_ZN5Botan13typecast_copyImTkNS_6ranges16contiguous_rangeENSt3__14spanIKhLm8EEEQaaaasr3stdE26is_default_constructible_vIT_Esr3stdE23is_trivially_copyable_vIS6_Esr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISE_EESF_E4type10value_typeEEEES6_RKSB_:
  210|  9.07k|inline constexpr ToT typecast_copy(const FromR& src) {
  211|  9.07k|   ToT dst;  // NOLINT(*-member-init)
  212|  9.07k|   typecast_copy(dst, src);
  213|  9.07k|   return dst;
  214|  9.07k|}
_ZN5Botan13typecast_copyImTkNS_6ranges16contiguous_rangeENSt3__14spanIKhLm8EEEQaaaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISD_EESE_E4type10value_typeEEsr3stdE23is_trivially_copyable_vIT_Entsr3std6rangesE5rangeISK_EEEvRSK_RKSA_:
  188|  9.07k|inline constexpr void typecast_copy(ToT& out, const FromR& in) {
  189|  9.07k|   typecast_copy(std::span<ToT, 1>(&out, 1), in);
  190|  9.07k|}
_ZN5Botan13typecast_copyITkNS_6ranges23contiguous_output_rangeENSt3__14spanImLm1EEETkNS1_16contiguous_rangeENS3_IKhLm8EEEQaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISE_EESF_E4type10value_typeEEsr3stdE23is_trivially_copyable_vINS7_IXsr21__is_primary_templateINS8_Iu14__remove_cvrefIDTclL_ZNSA_5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENSG_ISO_EESP_E4type10value_typeEEEEvOSL_RKSB_:
  176|  9.07k|inline constexpr void typecast_copy(ToR&& out /* NOLINT(*-std-forward) */, const FromR& in) {
  177|  9.07k|   ranges::assert_equal_byte_lengths(out, in);
  178|  9.07k|   std::memcpy(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  179|  9.07k|}
_ZN5Botan8copy_memITkNS_6ranges23contiguous_output_rangeENSt3__14spanIhLm18446744073709551615EEETkNS1_16contiguous_rangeENS3_IKhLm18446744073709551615EEEQaasr3stdE9is_same_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISE_EESF_E4type10value_typeENS7_IXsr21__is_primary_templateINS8_Iu14__remove_cvrefIDTclL_ZNSA_5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENSG_ISO_EESP_E4type10value_typeEEsr3stdE23is_trivially_copyable_vIST_EEEvOSB_RKSL_:
  160|    226|inline constexpr void copy_mem(OutR&& out /* NOLINT(*-std-forward) */, const InR& in) {
  161|    226|   ranges::assert_equal_byte_lengths(out, in);
  162|    226|   if(std::is_constant_evaluated()) {
  ------------------
  |  Branch (162:7): [Folded, False: 226]
  ------------------
  163|      0|      std::copy(std::ranges::begin(in), std::ranges::end(in), std::ranges::begin(out));
  164|    226|   } else if(ranges::size_bytes(out) > 0) {
  ------------------
  |  Branch (164:14): [True: 226, False: 0]
  ------------------
  165|    226|      std::memmove(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  166|    226|   }
  167|    226|}
_ZN5Botan13typecast_copyImTkNS_6ranges16contiguous_rangeENSt3__14spanIhLm8EEEQaaaasr3stdE26is_default_constructible_vIT_Esr3stdE23is_trivially_copyable_vIS5_Esr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISD_EESE_E4type10value_typeEEEES5_RKSA_:
  210|    226|inline constexpr ToT typecast_copy(const FromR& src) {
  211|    226|   ToT dst;  // NOLINT(*-member-init)
  212|    226|   typecast_copy(dst, src);
  213|    226|   return dst;
  214|    226|}
_ZN5Botan13typecast_copyImTkNS_6ranges16contiguous_rangeENSt3__14spanIhLm8EEEQaaaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISC_EESD_E4type10value_typeEEsr3stdE23is_trivially_copyable_vIT_Entsr3std6rangesE5rangeISJ_EEEvRSJ_RKS9_:
  188|    226|inline constexpr void typecast_copy(ToT& out, const FromR& in) {
  189|    226|   typecast_copy(std::span<ToT, 1>(&out, 1), in);
  190|    226|}
_ZN5Botan13typecast_copyITkNS_6ranges23contiguous_output_rangeENSt3__14spanImLm1EEETkNS1_16contiguous_rangeENS3_IhLm8EEEQaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISD_EESE_E4type10value_typeEEsr3stdE23is_trivially_copyable_vINS6_IXsr21__is_primary_templateINS7_Iu14__remove_cvrefIDTclL_ZNS9_5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENSF_ISN_EESO_E4type10value_typeEEEEvOSK_RKSA_:
  176|    226|inline constexpr void typecast_copy(ToR&& out /* NOLINT(*-std-forward) */, const FromR& in) {
  177|    226|   ranges::assert_equal_byte_lengths(out, in);
  178|    226|   std::memcpy(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  179|    226|}

_ZN5Botan6ranges24assert_exact_byte_lengthILm8ETkNS0_14spanable_rangeENSt3__14spanIhLm8EEEEEvRKT0_:
   77|    226|inline constexpr void assert_exact_byte_length(const R& r) {
   78|    226|   const std::span s{r};
   79|    226|   if constexpr(statically_spanable_range<R>) {
   80|    226|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   81|       |   } else {
   82|       |      if(s.size_bytes() != expected) {
   83|       |         memory_region_size_violation();
   84|       |      }
   85|       |   }
   86|    226|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm8ETkNS0_14spanable_rangeENSt3__14spanIKhLm8EEEEEvRKT0_:
   77|  18.1k|inline constexpr void assert_exact_byte_length(const R& r) {
   78|  18.1k|   const std::span s{r};
   79|  18.1k|   if constexpr(statically_spanable_range<R>) {
   80|  18.1k|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   81|       |   } else {
   82|       |      if(s.size_bytes() != expected) {
   83|       |         memory_region_size_violation();
   84|       |      }
   85|       |   }
   86|  18.1k|}
_ZN5Botan6ranges25assert_equal_byte_lengthsITkNS0_14spanable_rangeENSt3__14spanImLm1EEETpTkNS0_14spanable_rangeEJNS3_IKhLm8EEEEEEvRKT_DpRKT0_QgtsZT0_Li0E:
  100|  9.07k|{
  101|  9.07k|   const std::span s0{r0};
  102|       |
  103|  9.07k|   if constexpr(statically_spanable_range<R0>) {
  104|  9.07k|      constexpr size_t expected_size = s0.size_bytes();
  105|  9.07k|      (assert_exact_byte_length<expected_size>(rs), ...);
  106|       |   } else {
  107|       |      const size_t expected_size = s0.size_bytes();
  108|       |      const bool correct_size =
  109|       |         ((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...);
  110|       |
  111|       |      if(!correct_size) {
  112|       |         memory_region_size_violation();
  113|       |      }
  114|       |   }
  115|  9.07k|}
_ZN5Botan6ranges10size_bytesITkNS0_14spanable_rangeENSt3__14spanImLm1EEEEEmRKT_:
   59|  9.29k|inline constexpr size_t size_bytes(const spanable_range auto& r) {
   60|  9.29k|   return std::span{r}.size_bytes();
   61|  9.29k|}
_ZN5Botan6ranges25assert_equal_byte_lengthsITkNS0_14spanable_rangeENSt3__14spanIhLm18446744073709551615EEETpTkNS0_14spanable_rangeEJNS3_IKhLm18446744073709551615EEEEEEvRKT_DpRKT0_QgtsZT0_Li0E:
  100|    226|{
  101|    226|   const std::span s0{r0};
  102|       |
  103|       |   if constexpr(statically_spanable_range<R0>) {
  104|       |      constexpr size_t expected_size = s0.size_bytes();
  105|       |      (assert_exact_byte_length<expected_size>(rs), ...);
  106|    226|   } else {
  107|    226|      const size_t expected_size = s0.size_bytes();
  108|    226|      const bool correct_size =
  109|    226|         ((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...);
  110|       |
  111|    226|      if(!correct_size) {
  ------------------
  |  Branch (111:10): [True: 0, False: 226]
  ------------------
  112|      0|         memory_region_size_violation();
  113|      0|      }
  114|    226|   }
  115|    226|}
_ZN5Botan6ranges10size_bytesITkNS0_14spanable_rangeENSt3__14spanIhLm18446744073709551615EEEEEmRKT_:
   59|    452|inline constexpr size_t size_bytes(const spanable_range auto& r) {
   60|    452|   return std::span{r}.size_bytes();
   61|    452|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm8ETkNS0_14spanable_rangeENSt3__15arrayIhLm8EEEEEvRKT0_:
   77|    226|inline constexpr void assert_exact_byte_length(const R& r) {
   78|    226|   const std::span s{r};
   79|    226|   if constexpr(statically_spanable_range<R>) {
   80|    226|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   81|       |   } else {
   82|       |      if(s.size_bytes() != expected) {
   83|       |         memory_region_size_violation();
   84|       |      }
   85|       |   }
   86|    226|}
_ZN5Botan6ranges25assert_equal_byte_lengthsITkNS0_14spanable_rangeENSt3__14spanImLm1EEETpTkNS0_14spanable_rangeEJNS3_IhLm8EEEEEEvRKT_DpRKT0_QgtsZT0_Li0E:
  100|    226|{
  101|    226|   const std::span s0{r0};
  102|       |
  103|    226|   if constexpr(statically_spanable_range<R0>) {
  104|    226|      constexpr size_t expected_size = s0.size_bytes();
  105|    226|      (assert_exact_byte_length<expected_size>(rs), ...);
  106|       |   } else {
  107|       |      const size_t expected_size = s0.size_bytes();
  108|       |      const bool correct_size =
  109|       |         ((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...);
  110|       |
  111|       |      if(!correct_size) {
  112|       |         memory_region_size_violation();
  113|       |      }
  114|       |   }
  115|    226|}

_ZN5Botan16secure_allocatorImE10deallocateEPmm:
  102|  1.64k|      void deallocate(T* p, std::size_t n) { deallocate_memory(p, n, sizeof(T)); }
_ZN5Botan16secure_allocatorImE8allocateEm:
   95|  1.64k|      T* allocate(std::size_t n) { return static_cast<T*>(allocate_memory(n, sizeof(T))); }

_ZN5Botan16wrap_strong_typeImRmQoosr3stdE18constructible_fromIT_T0_Eaasr8conceptsE11strong_typeIS2_Esr3stdE18constructible_fromINS2_12wrapped_typeES3_EEEDcOS3_:
  353|  9.29k|[[nodiscard]] constexpr decltype(auto) wrap_strong_type(ParamT&& t) {
  354|  9.29k|   if constexpr(std::same_as<std::remove_cvref_t<ParamT>, T>) {
  355|       |      // Noop, if the parameter type already is the desired return type.
  356|  9.29k|      return std::forward<ParamT>(t);
  357|       |   } else if constexpr(std::constructible_from<T, ParamT>) {
  358|       |      // Implicit conversion from the parameter type to the return type.
  359|       |      return T{std::forward<ParamT>(t)};
  360|       |   } else {
  361|       |      // Explicitly calling the wrapped type's constructor to support
  362|       |      // implicit conversions on types that mark their constructors as explicit.
  363|       |      static_assert(concepts::strong_type<T> && std::constructible_from<typename T::wrapped_type, ParamT>);
  364|       |      return T{typename T::wrapped_type{std::forward<ParamT>(t)}};
  365|       |   }
  366|  9.29k|}

_Z4fuzzNSt3__14spanIKhLm18446744073709551615EEE:
   12|    314|void fuzz(std::span<const uint8_t> in) {
   13|    314|   if(in.size() > 8192 / 8) {
  ------------------
  |  Branch (13:7): [True: 17, False: 297]
  ------------------
   14|     17|      return;
   15|     17|   }
   16|       |
   17|    297|   const Botan::BigInt x = Botan::BigInt::from_bytes(in);
   18|       |
   19|    297|   const Botan::BigInt x_sqr = square(x);
   20|    297|   const Botan::BigInt x_mul = x * x;
   21|       |
   22|    297|   FUZZER_ASSERT_EQUAL(x_sqr, x_mul);
  ------------------
  |  |   79|    297|   do {                                                                                      \
  |  |   80|    297|      if((x) != (y)) {                                                                       \
  |  |  ------------------
  |  |  |  Branch (80:10): [True: 0, False: 297]
  |  |  ------------------
  |  |   81|      0|         FUZZER_WRITE_AND_CRASH(#x << " = " << (x) << " != " << #y << " = " << (y) << "\n"); \
  |  |  ------------------
  |  |  |  |   70|      0|   do {                                                                                                       \
  |  |  |  |   71|      0|      std::cerr << expr << " @ Line " << __LINE__ << " in " << __FILE__ << "\n"; /* NOLINT(*-macro-paren*) */ \
  |  |  |  |   72|      0|      abort();                                                                                                \
  |  |  |  |   73|      0|   } while(0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (73:12): [Folded, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   82|      0|      }                                                                                      \
  |  |   83|    297|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 297]
  |  |  ------------------
  ------------------
   23|    297|}

LLVMFuzzerInitialize:
   28|      2|extern "C" int LLVMFuzzerInitialize(int* /*argc*/, char*** /*argv*/) {
   29|       |   /*
   30|       |   * This disables the mlock pool, as overwrites within the pool are
   31|       |   * opaque to ASan or other instrumentation.
   32|       |   */
   33|      2|   ::setenv("BOTAN_MLOCK_POOL_SIZE", "0", 1);
   34|      2|   return 0;
   35|      2|}
LLVMFuzzerTestOneInput:
   39|    324|extern "C" int LLVMFuzzerTestOneInput(const uint8_t in[], size_t len) {
   40|    324|   if(len <= max_fuzzer_input_size) {
  ------------------
  |  Branch (40:7): [True: 314, False: 10]
  ------------------
   41|    314|      try {
   42|    314|         fuzz(std::span<const uint8_t>(in, len));
   43|    314|      } catch(const std::exception& e) {
   44|      0|         std::cerr << "Uncaught exception from fuzzer driver " << e.what() << "\n";
   45|      0|         abort();
   46|      0|      } catch(...) {
   47|      0|         std::cerr << "Uncaught exception from fuzzer driver (unknown type)\n";
   48|      0|         abort();
   49|      0|      }
   50|    314|   }
   51|    324|   return 0;
   52|    324|}

_ZN5Botan6BigInt6squareERNSt3__16vectorImNS_16secure_allocatorImEEEE:
  191|    297|BigInt& BigInt::square(secure_vector<word>& ws) {
  192|    297|   const size_t sw = sig_words();
  193|       |
  194|    297|   secure_vector<word> z(2 * sw);
  195|    297|   ws.resize(z.size());
  196|       |
  197|    297|   bigint_sqr(z.data(), z.size(), _data(), size(), sw, ws.data(), ws.size());
  198|       |
  199|    297|   swap_reg(z);
  200|    297|   set_sign(BigInt::Positive);
  201|       |
  202|    297|   return (*this);
  203|    297|}

_ZN5BotanmlERKNS_6BigIntES2_:
   57|    297|BigInt operator*(const BigInt& x, const BigInt& y) {
   58|    297|   const size_t x_sw = x.sig_words();
   59|    297|   const size_t y_sw = y.sig_words();
   60|       |
   61|    297|   BigInt z = BigInt::with_capacity(x.size() + y.size());
   62|       |
   63|    297|   if(x_sw == 1 && y_sw > 0) {
  ------------------
  |  Branch (63:7): [True: 121, False: 176]
  |  Branch (63:20): [True: 121, False: 0]
  ------------------
   64|    121|      bigint_linmul3(z.mutable_data(), y._data(), y_sw, x.word_at(0));
   65|    176|   } else if(y_sw == 1 && x_sw > 0) {
  ------------------
  |  Branch (65:14): [True: 0, False: 176]
  |  Branch (65:27): [True: 0, False: 0]
  ------------------
   66|      0|      bigint_linmul3(z.mutable_data(), x._data(), x_sw, y.word_at(0));
   67|    176|   } else if(x_sw > 0 && y_sw > 0) {
  ------------------
  |  Branch (67:14): [True: 171, False: 5]
  |  Branch (67:26): [True: 171, False: 0]
  ------------------
   68|    171|      secure_vector<word> workspace(z.size());
   69|       |
   70|    171|      bigint_mul(z.mutable_data(),
   71|    171|                 z.size(),
   72|    171|                 x._data(),
   73|    171|                 x.size(),
   74|    171|                 x_sw,
   75|    171|                 y._data(),
   76|    171|                 y.size(),
   77|    171|                 y_sw,
   78|    171|                 workspace.data(),
   79|    171|                 workspace.size());
   80|    171|   }
   81|       |
   82|    297|   z.cond_flip_sign(x_sw > 0 && y_sw > 0 && x.sign() != y.sign());
  ------------------
  |  Branch (82:21): [True: 292, False: 5]
  |  Branch (82:33): [True: 292, False: 0]
  |  Branch (82:45): [True: 0, False: 292]
  ------------------
   83|       |
   84|    297|   return z;
   85|    297|}

_ZN5Botan6BigInt13with_capacityEm:
   51|    297|BigInt BigInt::with_capacity(size_t size) {
   52|    297|   BigInt bn;
   53|    297|   bn.grow_to(size);
   54|    297|   return bn;
   55|    297|}
_ZN5Botan6BigInt10from_bytesENSt3__14spanIKhLm18446744073709551615EEE:
   83|    297|BigInt BigInt::from_bytes(std::span<const uint8_t> input) {
   84|    297|   BigInt r;
   85|    297|   r.assign_from_bytes(input);
   86|    297|   return r;
   87|    297|}
_ZNK5Botan6BigInt8is_equalERKS0_:
  156|    297|bool BigInt::is_equal(const BigInt& other) const {
  157|    297|   if(this->sign() != other.sign()) {
  ------------------
  |  Branch (157:7): [True: 0, False: 297]
  ------------------
  158|      0|      return false;
  159|      0|   }
  160|       |
  161|    297|   return bigint_ct_is_eq(this->_data(), this->size(), other._data(), other.size()).as_bool();
  162|    297|}
_ZN5Botan6BigInt4Data11set_to_zeroEv:
  191|    297|void BigInt::Data::set_to_zero() {
  192|    297|   m_reg.resize(m_reg.capacity());
  193|    297|   clear_mem(m_reg.data(), m_reg.size());
  194|    297|   m_sig_words = 0;
  195|    297|}
_ZNK5Botan6BigInt4Data14calc_sig_wordsEv:
  215|    594|size_t BigInt::Data::calc_sig_words() const {
  216|    594|   const size_t sz = m_reg.size();
  217|    594|   size_t sig = sz;
  218|       |
  219|    594|   word sub = 1;
  220|       |
  221|  22.3k|   for(size_t i = 0; i != sz; ++i) {
  ------------------
  |  Branch (221:22): [True: 21.7k, False: 594]
  ------------------
  222|  21.7k|      const word w = m_reg[sz - i - 1];
  223|  21.7k|      sub &= ct_is_zero(w);
  224|  21.7k|      sig -= sub;
  225|  21.7k|   }
  226|       |
  227|       |   /*
  228|       |   * This depends on the data so is poisoned, but unpoison it here as
  229|       |   * later conditionals are made on the size.
  230|       |   */
  231|    594|   CT::unpoison(sig);
  232|       |
  233|    594|   return sig;
  234|    594|}
_ZN5Botan6BigInt17assign_from_bytesENSt3__14spanIKhLm18446744073709551615EEE:
  425|    297|void BigInt::assign_from_bytes(std::span<const uint8_t> bytes) {
  426|    297|   clear();
  427|       |
  428|    297|   const size_t length = bytes.size();
  429|    297|   const size_t full_words = length / sizeof(word);
  430|    297|   const size_t extra_bytes = length % sizeof(word);
  431|       |
  432|    297|   secure_vector<word> reg((round_up(full_words + (extra_bytes > 0 ? 1 : 0), 8)));
  ------------------
  |  Branch (432:52): [True: 226, False: 71]
  ------------------
  433|       |
  434|  9.37k|   for(size_t i = 0; i != full_words; ++i) {
  ------------------
  |  Branch (434:22): [True: 9.07k, False: 297]
  ------------------
  435|  9.07k|      reg[i] = load_be<word>(bytes.last<sizeof(word)>());
  436|  9.07k|      bytes = bytes.first(bytes.size() - sizeof(word));
  437|  9.07k|   }
  438|       |
  439|    297|   if(!bytes.empty()) {
  ------------------
  |  Branch (439:7): [True: 226, False: 71]
  ------------------
  440|    226|      BOTAN_ASSERT_NOMSG(extra_bytes == bytes.size());
  ------------------
  |  |   77|    226|   do {                                                                     \
  |  |   78|    226|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|    226|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 226]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|    226|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 226]
  |  |  ------------------
  ------------------
  441|    226|      std::array<uint8_t, sizeof(word)> last_partial_word = {0};
  442|    226|      copy_mem(std::span{last_partial_word}.last(extra_bytes), bytes);
  443|    226|      reg[full_words] = load_be<word>(last_partial_word);
  444|    226|   }
  445|       |
  446|    297|   m_data.swap(reg);
  447|    297|}
_ZN5Botan6BigInt14cond_flip_signEb:
  521|    297|void BigInt::cond_flip_sign(bool predicate) {
  522|       |   // This code is assuming Negative == 0, Positive == 1
  523|       |
  524|    297|   const auto mask = CT::Mask<uint8_t>::expand_bool(predicate);
  525|       |
  526|    297|   const uint8_t current_sign = static_cast<uint8_t>(sign());
  527|       |
  528|    297|   const uint8_t new_sign = mask.select(current_sign ^ 1, current_sign);
  529|       |
  530|    297|   set_sign(static_cast<Sign>(new_sign));
  531|    297|}
_ZNK5Botan6BigInt20_const_time_unpoisonEv:
  559|    891|void BigInt::_const_time_unpoison() const {
  560|    891|   CT::unpoison(m_data.const_data(), m_data.size());
  561|    891|}

_ZN5Botan17bigint_comba_sqr4EPmPKm:
   17|      4|void bigint_comba_sqr4(word z[8], const word x[4]) {
   18|      4|   word3<word> accum;
   19|       |
   20|      4|   accum.mul(x[0], x[0]);
   21|      4|   z[0] = accum.extract();
   22|      4|   accum.mul_x2(x[0], x[1]);
   23|      4|   z[1] = accum.extract();
   24|      4|   accum.mul_x2(x[0], x[2]);
   25|      4|   accum.mul(x[1], x[1]);
   26|      4|   z[2] = accum.extract();
   27|      4|   accum.mul_x2(x[0], x[3]);
   28|      4|   accum.mul_x2(x[1], x[2]);
   29|      4|   z[3] = accum.extract();
   30|      4|   accum.mul_x2(x[1], x[3]);
   31|      4|   accum.mul(x[2], x[2]);
   32|      4|   z[4] = accum.extract();
   33|      4|   accum.mul_x2(x[2], x[3]);
   34|      4|   z[5] = accum.extract();
   35|      4|   accum.mul(x[3], x[3]);
   36|      4|   z[6] = accum.extract();
   37|      4|   z[7] = accum.extract();
   38|      4|}
_ZN5Botan17bigint_comba_mul4EPmPKmS2_:
   43|     18|void bigint_comba_mul4(word z[8], const word x[4], const word y[4]) {
   44|     18|   word3<word> accum;
   45|       |
   46|     18|   accum.mul(x[0], y[0]);
   47|     18|   z[0] = accum.extract();
   48|     18|   accum.mul(x[0], y[1]);
   49|     18|   accum.mul(x[1], y[0]);
   50|     18|   z[1] = accum.extract();
   51|     18|   accum.mul(x[0], y[2]);
   52|     18|   accum.mul(x[1], y[1]);
   53|     18|   accum.mul(x[2], y[0]);
   54|     18|   z[2] = accum.extract();
   55|     18|   accum.mul(x[0], y[3]);
   56|     18|   accum.mul(x[1], y[2]);
   57|     18|   accum.mul(x[2], y[1]);
   58|     18|   accum.mul(x[3], y[0]);
   59|     18|   z[3] = accum.extract();
   60|     18|   accum.mul(x[1], y[3]);
   61|     18|   accum.mul(x[2], y[2]);
   62|     18|   accum.mul(x[3], y[1]);
   63|     18|   z[4] = accum.extract();
   64|     18|   accum.mul(x[2], y[3]);
   65|     18|   accum.mul(x[3], y[2]);
   66|     18|   z[5] = accum.extract();
   67|     18|   accum.mul(x[3], y[3]);
   68|     18|   z[6] = accum.extract();
   69|     18|   z[7] = accum.extract();
   70|     18|}
_ZN5Botan17bigint_comba_sqr6EPmPKm:
   75|      4|void bigint_comba_sqr6(word z[12], const word x[6]) {
   76|      4|   word3<word> accum;
   77|       |
   78|      4|   accum.mul(x[0], x[0]);
   79|      4|   z[0] = accum.extract();
   80|      4|   accum.mul_x2(x[0], x[1]);
   81|      4|   z[1] = accum.extract();
   82|      4|   accum.mul_x2(x[0], x[2]);
   83|      4|   accum.mul(x[1], x[1]);
   84|      4|   z[2] = accum.extract();
   85|      4|   accum.mul_x2(x[0], x[3]);
   86|      4|   accum.mul_x2(x[1], x[2]);
   87|      4|   z[3] = accum.extract();
   88|      4|   accum.mul_x2(x[0], x[4]);
   89|      4|   accum.mul_x2(x[1], x[3]);
   90|      4|   accum.mul(x[2], x[2]);
   91|      4|   z[4] = accum.extract();
   92|      4|   accum.mul_x2(x[0], x[5]);
   93|      4|   accum.mul_x2(x[1], x[4]);
   94|      4|   accum.mul_x2(x[2], x[3]);
   95|      4|   z[5] = accum.extract();
   96|      4|   accum.mul_x2(x[1], x[5]);
   97|      4|   accum.mul_x2(x[2], x[4]);
   98|      4|   accum.mul(x[3], x[3]);
   99|      4|   z[6] = accum.extract();
  100|      4|   accum.mul_x2(x[2], x[5]);
  101|      4|   accum.mul_x2(x[3], x[4]);
  102|      4|   z[7] = accum.extract();
  103|      4|   accum.mul_x2(x[3], x[5]);
  104|      4|   accum.mul(x[4], x[4]);
  105|      4|   z[8] = accum.extract();
  106|      4|   accum.mul_x2(x[4], x[5]);
  107|      4|   z[9] = accum.extract();
  108|      4|   accum.mul(x[5], x[5]);
  109|      4|   z[10] = accum.extract();
  110|      4|   z[11] = accum.extract();
  111|      4|}
_ZN5Botan17bigint_comba_mul6EPmPKmS2_:
  116|     10|void bigint_comba_mul6(word z[12], const word x[6], const word y[6]) {
  117|     10|   word3<word> accum;
  118|       |
  119|     10|   accum.mul(x[0], y[0]);
  120|     10|   z[0] = accum.extract();
  121|     10|   accum.mul(x[0], y[1]);
  122|     10|   accum.mul(x[1], y[0]);
  123|     10|   z[1] = accum.extract();
  124|     10|   accum.mul(x[0], y[2]);
  125|     10|   accum.mul(x[1], y[1]);
  126|     10|   accum.mul(x[2], y[0]);
  127|     10|   z[2] = accum.extract();
  128|     10|   accum.mul(x[0], y[3]);
  129|     10|   accum.mul(x[1], y[2]);
  130|     10|   accum.mul(x[2], y[1]);
  131|     10|   accum.mul(x[3], y[0]);
  132|     10|   z[3] = accum.extract();
  133|     10|   accum.mul(x[0], y[4]);
  134|     10|   accum.mul(x[1], y[3]);
  135|     10|   accum.mul(x[2], y[2]);
  136|     10|   accum.mul(x[3], y[1]);
  137|     10|   accum.mul(x[4], y[0]);
  138|     10|   z[4] = accum.extract();
  139|     10|   accum.mul(x[0], y[5]);
  140|     10|   accum.mul(x[1], y[4]);
  141|     10|   accum.mul(x[2], y[3]);
  142|     10|   accum.mul(x[3], y[2]);
  143|     10|   accum.mul(x[4], y[1]);
  144|     10|   accum.mul(x[5], y[0]);
  145|     10|   z[5] = accum.extract();
  146|     10|   accum.mul(x[1], y[5]);
  147|     10|   accum.mul(x[2], y[4]);
  148|     10|   accum.mul(x[3], y[3]);
  149|     10|   accum.mul(x[4], y[2]);
  150|     10|   accum.mul(x[5], y[1]);
  151|     10|   z[6] = accum.extract();
  152|     10|   accum.mul(x[2], y[5]);
  153|     10|   accum.mul(x[3], y[4]);
  154|     10|   accum.mul(x[4], y[3]);
  155|     10|   accum.mul(x[5], y[2]);
  156|     10|   z[7] = accum.extract();
  157|     10|   accum.mul(x[3], y[5]);
  158|     10|   accum.mul(x[4], y[4]);
  159|     10|   accum.mul(x[5], y[3]);
  160|     10|   z[8] = accum.extract();
  161|     10|   accum.mul(x[4], y[5]);
  162|     10|   accum.mul(x[5], y[4]);
  163|     10|   z[9] = accum.extract();
  164|     10|   accum.mul(x[5], y[5]);
  165|     10|   z[10] = accum.extract();
  166|     10|   z[11] = accum.extract();
  167|     10|}
_ZN5Botan17bigint_comba_sqr8EPmPKm:
  293|      2|void bigint_comba_sqr8(word z[16], const word x[8]) {
  294|      2|   word3<word> accum;
  295|       |
  296|      2|   accum.mul(x[0], x[0]);
  297|      2|   z[0] = accum.extract();
  298|      2|   accum.mul_x2(x[0], x[1]);
  299|      2|   z[1] = accum.extract();
  300|      2|   accum.mul_x2(x[0], x[2]);
  301|      2|   accum.mul(x[1], x[1]);
  302|      2|   z[2] = accum.extract();
  303|      2|   accum.mul_x2(x[0], x[3]);
  304|      2|   accum.mul_x2(x[1], x[2]);
  305|      2|   z[3] = accum.extract();
  306|      2|   accum.mul_x2(x[0], x[4]);
  307|      2|   accum.mul_x2(x[1], x[3]);
  308|      2|   accum.mul(x[2], x[2]);
  309|      2|   z[4] = accum.extract();
  310|      2|   accum.mul_x2(x[0], x[5]);
  311|      2|   accum.mul_x2(x[1], x[4]);
  312|      2|   accum.mul_x2(x[2], x[3]);
  313|      2|   z[5] = accum.extract();
  314|      2|   accum.mul_x2(x[0], x[6]);
  315|      2|   accum.mul_x2(x[1], x[5]);
  316|      2|   accum.mul_x2(x[2], x[4]);
  317|      2|   accum.mul(x[3], x[3]);
  318|      2|   z[6] = accum.extract();
  319|      2|   accum.mul_x2(x[0], x[7]);
  320|      2|   accum.mul_x2(x[1], x[6]);
  321|      2|   accum.mul_x2(x[2], x[5]);
  322|      2|   accum.mul_x2(x[3], x[4]);
  323|      2|   z[7] = accum.extract();
  324|      2|   accum.mul_x2(x[1], x[7]);
  325|      2|   accum.mul_x2(x[2], x[6]);
  326|      2|   accum.mul_x2(x[3], x[5]);
  327|      2|   accum.mul(x[4], x[4]);
  328|      2|   z[8] = accum.extract();
  329|      2|   accum.mul_x2(x[2], x[7]);
  330|      2|   accum.mul_x2(x[3], x[6]);
  331|      2|   accum.mul_x2(x[4], x[5]);
  332|      2|   z[9] = accum.extract();
  333|      2|   accum.mul_x2(x[3], x[7]);
  334|      2|   accum.mul_x2(x[4], x[6]);
  335|      2|   accum.mul(x[5], x[5]);
  336|      2|   z[10] = accum.extract();
  337|      2|   accum.mul_x2(x[4], x[7]);
  338|      2|   accum.mul_x2(x[5], x[6]);
  339|      2|   z[11] = accum.extract();
  340|      2|   accum.mul_x2(x[5], x[7]);
  341|      2|   accum.mul(x[6], x[6]);
  342|      2|   z[12] = accum.extract();
  343|      2|   accum.mul_x2(x[6], x[7]);
  344|      2|   z[13] = accum.extract();
  345|      2|   accum.mul(x[7], x[7]);
  346|      2|   z[14] = accum.extract();
  347|      2|   z[15] = accum.extract();
  348|      2|}
_ZN5Botan17bigint_comba_mul8EPmPKmS2_:
  353|      7|void bigint_comba_mul8(word z[16], const word x[8], const word y[8]) {
  354|      7|   word3<word> accum;
  355|       |
  356|      7|   accum.mul(x[0], y[0]);
  357|      7|   z[0] = accum.extract();
  358|      7|   accum.mul(x[0], y[1]);
  359|      7|   accum.mul(x[1], y[0]);
  360|      7|   z[1] = accum.extract();
  361|      7|   accum.mul(x[0], y[2]);
  362|      7|   accum.mul(x[1], y[1]);
  363|      7|   accum.mul(x[2], y[0]);
  364|      7|   z[2] = accum.extract();
  365|      7|   accum.mul(x[0], y[3]);
  366|      7|   accum.mul(x[1], y[2]);
  367|      7|   accum.mul(x[2], y[1]);
  368|      7|   accum.mul(x[3], y[0]);
  369|      7|   z[3] = accum.extract();
  370|      7|   accum.mul(x[0], y[4]);
  371|      7|   accum.mul(x[1], y[3]);
  372|      7|   accum.mul(x[2], y[2]);
  373|      7|   accum.mul(x[3], y[1]);
  374|      7|   accum.mul(x[4], y[0]);
  375|      7|   z[4] = accum.extract();
  376|      7|   accum.mul(x[0], y[5]);
  377|      7|   accum.mul(x[1], y[4]);
  378|      7|   accum.mul(x[2], y[3]);
  379|      7|   accum.mul(x[3], y[2]);
  380|      7|   accum.mul(x[4], y[1]);
  381|      7|   accum.mul(x[5], y[0]);
  382|      7|   z[5] = accum.extract();
  383|      7|   accum.mul(x[0], y[6]);
  384|      7|   accum.mul(x[1], y[5]);
  385|      7|   accum.mul(x[2], y[4]);
  386|      7|   accum.mul(x[3], y[3]);
  387|      7|   accum.mul(x[4], y[2]);
  388|      7|   accum.mul(x[5], y[1]);
  389|      7|   accum.mul(x[6], y[0]);
  390|      7|   z[6] = accum.extract();
  391|      7|   accum.mul(x[0], y[7]);
  392|      7|   accum.mul(x[1], y[6]);
  393|      7|   accum.mul(x[2], y[5]);
  394|      7|   accum.mul(x[3], y[4]);
  395|      7|   accum.mul(x[4], y[3]);
  396|      7|   accum.mul(x[5], y[2]);
  397|      7|   accum.mul(x[6], y[1]);
  398|      7|   accum.mul(x[7], y[0]);
  399|      7|   z[7] = accum.extract();
  400|      7|   accum.mul(x[1], y[7]);
  401|      7|   accum.mul(x[2], y[6]);
  402|      7|   accum.mul(x[3], y[5]);
  403|      7|   accum.mul(x[4], y[4]);
  404|      7|   accum.mul(x[5], y[3]);
  405|      7|   accum.mul(x[6], y[2]);
  406|      7|   accum.mul(x[7], y[1]);
  407|      7|   z[8] = accum.extract();
  408|      7|   accum.mul(x[2], y[7]);
  409|      7|   accum.mul(x[3], y[6]);
  410|      7|   accum.mul(x[4], y[5]);
  411|      7|   accum.mul(x[5], y[4]);
  412|      7|   accum.mul(x[6], y[3]);
  413|      7|   accum.mul(x[7], y[2]);
  414|      7|   z[9] = accum.extract();
  415|      7|   accum.mul(x[3], y[7]);
  416|      7|   accum.mul(x[4], y[6]);
  417|      7|   accum.mul(x[5], y[5]);
  418|      7|   accum.mul(x[6], y[4]);
  419|      7|   accum.mul(x[7], y[3]);
  420|      7|   z[10] = accum.extract();
  421|      7|   accum.mul(x[4], y[7]);
  422|      7|   accum.mul(x[5], y[6]);
  423|      7|   accum.mul(x[6], y[5]);
  424|      7|   accum.mul(x[7], y[4]);
  425|      7|   z[11] = accum.extract();
  426|      7|   accum.mul(x[5], y[7]);
  427|      7|   accum.mul(x[6], y[6]);
  428|      7|   accum.mul(x[7], y[5]);
  429|      7|   z[12] = accum.extract();
  430|      7|   accum.mul(x[6], y[7]);
  431|      7|   accum.mul(x[7], y[6]);
  432|      7|   z[13] = accum.extract();
  433|      7|   accum.mul(x[7], y[7]);
  434|      7|   z[14] = accum.extract();
  435|      7|   z[15] = accum.extract();
  436|      7|}
_ZN5Botan17bigint_comba_sqr9EPmPKm:
  441|      5|void bigint_comba_sqr9(word z[18], const word x[9]) {
  442|      5|   word3<word> accum;
  443|       |
  444|      5|   accum.mul(x[0], x[0]);
  445|      5|   z[0] = accum.extract();
  446|      5|   accum.mul_x2(x[0], x[1]);
  447|      5|   z[1] = accum.extract();
  448|      5|   accum.mul_x2(x[0], x[2]);
  449|      5|   accum.mul(x[1], x[1]);
  450|      5|   z[2] = accum.extract();
  451|      5|   accum.mul_x2(x[0], x[3]);
  452|      5|   accum.mul_x2(x[1], x[2]);
  453|      5|   z[3] = accum.extract();
  454|      5|   accum.mul_x2(x[0], x[4]);
  455|      5|   accum.mul_x2(x[1], x[3]);
  456|      5|   accum.mul(x[2], x[2]);
  457|      5|   z[4] = accum.extract();
  458|      5|   accum.mul_x2(x[0], x[5]);
  459|      5|   accum.mul_x2(x[1], x[4]);
  460|      5|   accum.mul_x2(x[2], x[3]);
  461|      5|   z[5] = accum.extract();
  462|      5|   accum.mul_x2(x[0], x[6]);
  463|      5|   accum.mul_x2(x[1], x[5]);
  464|      5|   accum.mul_x2(x[2], x[4]);
  465|      5|   accum.mul(x[3], x[3]);
  466|      5|   z[6] = accum.extract();
  467|      5|   accum.mul_x2(x[0], x[7]);
  468|      5|   accum.mul_x2(x[1], x[6]);
  469|      5|   accum.mul_x2(x[2], x[5]);
  470|      5|   accum.mul_x2(x[3], x[4]);
  471|      5|   z[7] = accum.extract();
  472|      5|   accum.mul_x2(x[0], x[8]);
  473|      5|   accum.mul_x2(x[1], x[7]);
  474|      5|   accum.mul_x2(x[2], x[6]);
  475|      5|   accum.mul_x2(x[3], x[5]);
  476|      5|   accum.mul(x[4], x[4]);
  477|      5|   z[8] = accum.extract();
  478|      5|   accum.mul_x2(x[1], x[8]);
  479|      5|   accum.mul_x2(x[2], x[7]);
  480|      5|   accum.mul_x2(x[3], x[6]);
  481|      5|   accum.mul_x2(x[4], x[5]);
  482|      5|   z[9] = accum.extract();
  483|      5|   accum.mul_x2(x[2], x[8]);
  484|      5|   accum.mul_x2(x[3], x[7]);
  485|      5|   accum.mul_x2(x[4], x[6]);
  486|      5|   accum.mul(x[5], x[5]);
  487|      5|   z[10] = accum.extract();
  488|      5|   accum.mul_x2(x[3], x[8]);
  489|      5|   accum.mul_x2(x[4], x[7]);
  490|      5|   accum.mul_x2(x[5], x[6]);
  491|      5|   z[11] = accum.extract();
  492|      5|   accum.mul_x2(x[4], x[8]);
  493|      5|   accum.mul_x2(x[5], x[7]);
  494|      5|   accum.mul(x[6], x[6]);
  495|      5|   z[12] = accum.extract();
  496|      5|   accum.mul_x2(x[5], x[8]);
  497|      5|   accum.mul_x2(x[6], x[7]);
  498|      5|   z[13] = accum.extract();
  499|      5|   accum.mul_x2(x[6], x[8]);
  500|      5|   accum.mul(x[7], x[7]);
  501|      5|   z[14] = accum.extract();
  502|      5|   accum.mul_x2(x[7], x[8]);
  503|      5|   z[15] = accum.extract();
  504|      5|   accum.mul(x[8], x[8]);
  505|      5|   z[16] = accum.extract();
  506|      5|   z[17] = accum.extract();
  507|      5|}
_ZN5Botan17bigint_comba_mul9EPmPKmS2_:
  512|      5|void bigint_comba_mul9(word z[18], const word x[9], const word y[9]) {
  513|      5|   word3<word> accum;
  514|       |
  515|      5|   accum.mul(x[0], y[0]);
  516|      5|   z[0] = accum.extract();
  517|      5|   accum.mul(x[0], y[1]);
  518|      5|   accum.mul(x[1], y[0]);
  519|      5|   z[1] = accum.extract();
  520|      5|   accum.mul(x[0], y[2]);
  521|      5|   accum.mul(x[1], y[1]);
  522|      5|   accum.mul(x[2], y[0]);
  523|      5|   z[2] = accum.extract();
  524|      5|   accum.mul(x[0], y[3]);
  525|      5|   accum.mul(x[1], y[2]);
  526|      5|   accum.mul(x[2], y[1]);
  527|      5|   accum.mul(x[3], y[0]);
  528|      5|   z[3] = accum.extract();
  529|      5|   accum.mul(x[0], y[4]);
  530|      5|   accum.mul(x[1], y[3]);
  531|      5|   accum.mul(x[2], y[2]);
  532|      5|   accum.mul(x[3], y[1]);
  533|      5|   accum.mul(x[4], y[0]);
  534|      5|   z[4] = accum.extract();
  535|      5|   accum.mul(x[0], y[5]);
  536|      5|   accum.mul(x[1], y[4]);
  537|      5|   accum.mul(x[2], y[3]);
  538|      5|   accum.mul(x[3], y[2]);
  539|      5|   accum.mul(x[4], y[1]);
  540|      5|   accum.mul(x[5], y[0]);
  541|      5|   z[5] = accum.extract();
  542|      5|   accum.mul(x[0], y[6]);
  543|      5|   accum.mul(x[1], y[5]);
  544|      5|   accum.mul(x[2], y[4]);
  545|      5|   accum.mul(x[3], y[3]);
  546|      5|   accum.mul(x[4], y[2]);
  547|      5|   accum.mul(x[5], y[1]);
  548|      5|   accum.mul(x[6], y[0]);
  549|      5|   z[6] = accum.extract();
  550|      5|   accum.mul(x[0], y[7]);
  551|      5|   accum.mul(x[1], y[6]);
  552|      5|   accum.mul(x[2], y[5]);
  553|      5|   accum.mul(x[3], y[4]);
  554|      5|   accum.mul(x[4], y[3]);
  555|      5|   accum.mul(x[5], y[2]);
  556|      5|   accum.mul(x[6], y[1]);
  557|      5|   accum.mul(x[7], y[0]);
  558|      5|   z[7] = accum.extract();
  559|      5|   accum.mul(x[0], y[8]);
  560|      5|   accum.mul(x[1], y[7]);
  561|      5|   accum.mul(x[2], y[6]);
  562|      5|   accum.mul(x[3], y[5]);
  563|      5|   accum.mul(x[4], y[4]);
  564|      5|   accum.mul(x[5], y[3]);
  565|      5|   accum.mul(x[6], y[2]);
  566|      5|   accum.mul(x[7], y[1]);
  567|      5|   accum.mul(x[8], y[0]);
  568|      5|   z[8] = accum.extract();
  569|      5|   accum.mul(x[1], y[8]);
  570|      5|   accum.mul(x[2], y[7]);
  571|      5|   accum.mul(x[3], y[6]);
  572|      5|   accum.mul(x[4], y[5]);
  573|      5|   accum.mul(x[5], y[4]);
  574|      5|   accum.mul(x[6], y[3]);
  575|      5|   accum.mul(x[7], y[2]);
  576|      5|   accum.mul(x[8], y[1]);
  577|      5|   z[9] = accum.extract();
  578|      5|   accum.mul(x[2], y[8]);
  579|      5|   accum.mul(x[3], y[7]);
  580|      5|   accum.mul(x[4], y[6]);
  581|      5|   accum.mul(x[5], y[5]);
  582|      5|   accum.mul(x[6], y[4]);
  583|      5|   accum.mul(x[7], y[3]);
  584|      5|   accum.mul(x[8], y[2]);
  585|      5|   z[10] = accum.extract();
  586|      5|   accum.mul(x[3], y[8]);
  587|      5|   accum.mul(x[4], y[7]);
  588|      5|   accum.mul(x[5], y[6]);
  589|      5|   accum.mul(x[6], y[5]);
  590|      5|   accum.mul(x[7], y[4]);
  591|      5|   accum.mul(x[8], y[3]);
  592|      5|   z[11] = accum.extract();
  593|      5|   accum.mul(x[4], y[8]);
  594|      5|   accum.mul(x[5], y[7]);
  595|      5|   accum.mul(x[6], y[6]);
  596|      5|   accum.mul(x[7], y[5]);
  597|      5|   accum.mul(x[8], y[4]);
  598|      5|   z[12] = accum.extract();
  599|      5|   accum.mul(x[5], y[8]);
  600|      5|   accum.mul(x[6], y[7]);
  601|      5|   accum.mul(x[7], y[6]);
  602|      5|   accum.mul(x[8], y[5]);
  603|      5|   z[13] = accum.extract();
  604|      5|   accum.mul(x[6], y[8]);
  605|      5|   accum.mul(x[7], y[7]);
  606|      5|   accum.mul(x[8], y[6]);
  607|      5|   z[14] = accum.extract();
  608|      5|   accum.mul(x[7], y[8]);
  609|      5|   accum.mul(x[8], y[7]);
  610|      5|   z[15] = accum.extract();
  611|      5|   accum.mul(x[8], y[8]);
  612|      5|   z[16] = accum.extract();
  613|      5|   z[17] = accum.extract();
  614|      5|}
_ZN5Botan18bigint_comba_sqr16EPmPKm:
  619|    162|void bigint_comba_sqr16(word z[32], const word x[16]) {
  620|    162|   word3<word> accum;
  621|       |
  622|    162|   accum.mul(x[0], x[0]);
  623|    162|   z[0] = accum.extract();
  624|    162|   accum.mul_x2(x[0], x[1]);
  625|    162|   z[1] = accum.extract();
  626|    162|   accum.mul_x2(x[0], x[2]);
  627|    162|   accum.mul(x[1], x[1]);
  628|    162|   z[2] = accum.extract();
  629|    162|   accum.mul_x2(x[0], x[3]);
  630|    162|   accum.mul_x2(x[1], x[2]);
  631|    162|   z[3] = accum.extract();
  632|    162|   accum.mul_x2(x[0], x[4]);
  633|    162|   accum.mul_x2(x[1], x[3]);
  634|    162|   accum.mul(x[2], x[2]);
  635|    162|   z[4] = accum.extract();
  636|    162|   accum.mul_x2(x[0], x[5]);
  637|    162|   accum.mul_x2(x[1], x[4]);
  638|    162|   accum.mul_x2(x[2], x[3]);
  639|    162|   z[5] = accum.extract();
  640|    162|   accum.mul_x2(x[0], x[6]);
  641|    162|   accum.mul_x2(x[1], x[5]);
  642|    162|   accum.mul_x2(x[2], x[4]);
  643|    162|   accum.mul(x[3], x[3]);
  644|    162|   z[6] = accum.extract();
  645|    162|   accum.mul_x2(x[0], x[7]);
  646|    162|   accum.mul_x2(x[1], x[6]);
  647|    162|   accum.mul_x2(x[2], x[5]);
  648|    162|   accum.mul_x2(x[3], x[4]);
  649|    162|   z[7] = accum.extract();
  650|    162|   accum.mul_x2(x[0], x[8]);
  651|    162|   accum.mul_x2(x[1], x[7]);
  652|    162|   accum.mul_x2(x[2], x[6]);
  653|    162|   accum.mul_x2(x[3], x[5]);
  654|    162|   accum.mul(x[4], x[4]);
  655|    162|   z[8] = accum.extract();
  656|    162|   accum.mul_x2(x[0], x[9]);
  657|    162|   accum.mul_x2(x[1], x[8]);
  658|    162|   accum.mul_x2(x[2], x[7]);
  659|    162|   accum.mul_x2(x[3], x[6]);
  660|    162|   accum.mul_x2(x[4], x[5]);
  661|    162|   z[9] = accum.extract();
  662|    162|   accum.mul_x2(x[0], x[10]);
  663|    162|   accum.mul_x2(x[1], x[9]);
  664|    162|   accum.mul_x2(x[2], x[8]);
  665|    162|   accum.mul_x2(x[3], x[7]);
  666|    162|   accum.mul_x2(x[4], x[6]);
  667|    162|   accum.mul(x[5], x[5]);
  668|    162|   z[10] = accum.extract();
  669|    162|   accum.mul_x2(x[0], x[11]);
  670|    162|   accum.mul_x2(x[1], x[10]);
  671|    162|   accum.mul_x2(x[2], x[9]);
  672|    162|   accum.mul_x2(x[3], x[8]);
  673|    162|   accum.mul_x2(x[4], x[7]);
  674|    162|   accum.mul_x2(x[5], x[6]);
  675|    162|   z[11] = accum.extract();
  676|    162|   accum.mul_x2(x[0], x[12]);
  677|    162|   accum.mul_x2(x[1], x[11]);
  678|    162|   accum.mul_x2(x[2], x[10]);
  679|    162|   accum.mul_x2(x[3], x[9]);
  680|    162|   accum.mul_x2(x[4], x[8]);
  681|    162|   accum.mul_x2(x[5], x[7]);
  682|    162|   accum.mul(x[6], x[6]);
  683|    162|   z[12] = accum.extract();
  684|    162|   accum.mul_x2(x[0], x[13]);
  685|    162|   accum.mul_x2(x[1], x[12]);
  686|    162|   accum.mul_x2(x[2], x[11]);
  687|    162|   accum.mul_x2(x[3], x[10]);
  688|    162|   accum.mul_x2(x[4], x[9]);
  689|    162|   accum.mul_x2(x[5], x[8]);
  690|    162|   accum.mul_x2(x[6], x[7]);
  691|    162|   z[13] = accum.extract();
  692|    162|   accum.mul_x2(x[0], x[14]);
  693|    162|   accum.mul_x2(x[1], x[13]);
  694|    162|   accum.mul_x2(x[2], x[12]);
  695|    162|   accum.mul_x2(x[3], x[11]);
  696|    162|   accum.mul_x2(x[4], x[10]);
  697|    162|   accum.mul_x2(x[5], x[9]);
  698|    162|   accum.mul_x2(x[6], x[8]);
  699|    162|   accum.mul(x[7], x[7]);
  700|    162|   z[14] = accum.extract();
  701|    162|   accum.mul_x2(x[0], x[15]);
  702|    162|   accum.mul_x2(x[1], x[14]);
  703|    162|   accum.mul_x2(x[2], x[13]);
  704|    162|   accum.mul_x2(x[3], x[12]);
  705|    162|   accum.mul_x2(x[4], x[11]);
  706|    162|   accum.mul_x2(x[5], x[10]);
  707|    162|   accum.mul_x2(x[6], x[9]);
  708|    162|   accum.mul_x2(x[7], x[8]);
  709|    162|   z[15] = accum.extract();
  710|    162|   accum.mul_x2(x[1], x[15]);
  711|    162|   accum.mul_x2(x[2], x[14]);
  712|    162|   accum.mul_x2(x[3], x[13]);
  713|    162|   accum.mul_x2(x[4], x[12]);
  714|    162|   accum.mul_x2(x[5], x[11]);
  715|    162|   accum.mul_x2(x[6], x[10]);
  716|    162|   accum.mul_x2(x[7], x[9]);
  717|    162|   accum.mul(x[8], x[8]);
  718|    162|   z[16] = accum.extract();
  719|    162|   accum.mul_x2(x[2], x[15]);
  720|    162|   accum.mul_x2(x[3], x[14]);
  721|    162|   accum.mul_x2(x[4], x[13]);
  722|    162|   accum.mul_x2(x[5], x[12]);
  723|    162|   accum.mul_x2(x[6], x[11]);
  724|    162|   accum.mul_x2(x[7], x[10]);
  725|    162|   accum.mul_x2(x[8], x[9]);
  726|    162|   z[17] = accum.extract();
  727|    162|   accum.mul_x2(x[3], x[15]);
  728|    162|   accum.mul_x2(x[4], x[14]);
  729|    162|   accum.mul_x2(x[5], x[13]);
  730|    162|   accum.mul_x2(x[6], x[12]);
  731|    162|   accum.mul_x2(x[7], x[11]);
  732|    162|   accum.mul_x2(x[8], x[10]);
  733|    162|   accum.mul(x[9], x[9]);
  734|    162|   z[18] = accum.extract();
  735|    162|   accum.mul_x2(x[4], x[15]);
  736|    162|   accum.mul_x2(x[5], x[14]);
  737|    162|   accum.mul_x2(x[6], x[13]);
  738|    162|   accum.mul_x2(x[7], x[12]);
  739|    162|   accum.mul_x2(x[8], x[11]);
  740|    162|   accum.mul_x2(x[9], x[10]);
  741|    162|   z[19] = accum.extract();
  742|    162|   accum.mul_x2(x[5], x[15]);
  743|    162|   accum.mul_x2(x[6], x[14]);
  744|    162|   accum.mul_x2(x[7], x[13]);
  745|    162|   accum.mul_x2(x[8], x[12]);
  746|    162|   accum.mul_x2(x[9], x[11]);
  747|    162|   accum.mul(x[10], x[10]);
  748|    162|   z[20] = accum.extract();
  749|    162|   accum.mul_x2(x[6], x[15]);
  750|    162|   accum.mul_x2(x[7], x[14]);
  751|    162|   accum.mul_x2(x[8], x[13]);
  752|    162|   accum.mul_x2(x[9], x[12]);
  753|    162|   accum.mul_x2(x[10], x[11]);
  754|    162|   z[21] = accum.extract();
  755|    162|   accum.mul_x2(x[7], x[15]);
  756|    162|   accum.mul_x2(x[8], x[14]);
  757|    162|   accum.mul_x2(x[9], x[13]);
  758|    162|   accum.mul_x2(x[10], x[12]);
  759|    162|   accum.mul(x[11], x[11]);
  760|    162|   z[22] = accum.extract();
  761|    162|   accum.mul_x2(x[8], x[15]);
  762|    162|   accum.mul_x2(x[9], x[14]);
  763|    162|   accum.mul_x2(x[10], x[13]);
  764|    162|   accum.mul_x2(x[11], x[12]);
  765|    162|   z[23] = accum.extract();
  766|    162|   accum.mul_x2(x[9], x[15]);
  767|    162|   accum.mul_x2(x[10], x[14]);
  768|    162|   accum.mul_x2(x[11], x[13]);
  769|    162|   accum.mul(x[12], x[12]);
  770|    162|   z[24] = accum.extract();
  771|    162|   accum.mul_x2(x[10], x[15]);
  772|    162|   accum.mul_x2(x[11], x[14]);
  773|    162|   accum.mul_x2(x[12], x[13]);
  774|    162|   z[25] = accum.extract();
  775|    162|   accum.mul_x2(x[11], x[15]);
  776|    162|   accum.mul_x2(x[12], x[14]);
  777|    162|   accum.mul(x[13], x[13]);
  778|    162|   z[26] = accum.extract();
  779|    162|   accum.mul_x2(x[12], x[15]);
  780|    162|   accum.mul_x2(x[13], x[14]);
  781|    162|   z[27] = accum.extract();
  782|    162|   accum.mul_x2(x[13], x[15]);
  783|    162|   accum.mul(x[14], x[14]);
  784|    162|   z[28] = accum.extract();
  785|    162|   accum.mul_x2(x[14], x[15]);
  786|    162|   z[29] = accum.extract();
  787|    162|   accum.mul(x[15], x[15]);
  788|    162|   z[30] = accum.extract();
  789|    162|   z[31] = accum.extract();
  790|    162|}
_ZN5Botan18bigint_comba_mul16EPmPKmS2_:
  795|    318|void bigint_comba_mul16(word z[32], const word x[16], const word y[16]) {
  796|    318|   word3<word> accum;
  797|       |
  798|    318|   accum.mul(x[0], y[0]);
  799|    318|   z[0] = accum.extract();
  800|    318|   accum.mul(x[0], y[1]);
  801|    318|   accum.mul(x[1], y[0]);
  802|    318|   z[1] = accum.extract();
  803|    318|   accum.mul(x[0], y[2]);
  804|    318|   accum.mul(x[1], y[1]);
  805|    318|   accum.mul(x[2], y[0]);
  806|    318|   z[2] = accum.extract();
  807|    318|   accum.mul(x[0], y[3]);
  808|    318|   accum.mul(x[1], y[2]);
  809|    318|   accum.mul(x[2], y[1]);
  810|    318|   accum.mul(x[3], y[0]);
  811|    318|   z[3] = accum.extract();
  812|    318|   accum.mul(x[0], y[4]);
  813|    318|   accum.mul(x[1], y[3]);
  814|    318|   accum.mul(x[2], y[2]);
  815|    318|   accum.mul(x[3], y[1]);
  816|    318|   accum.mul(x[4], y[0]);
  817|    318|   z[4] = accum.extract();
  818|    318|   accum.mul(x[0], y[5]);
  819|    318|   accum.mul(x[1], y[4]);
  820|    318|   accum.mul(x[2], y[3]);
  821|    318|   accum.mul(x[3], y[2]);
  822|    318|   accum.mul(x[4], y[1]);
  823|    318|   accum.mul(x[5], y[0]);
  824|    318|   z[5] = accum.extract();
  825|    318|   accum.mul(x[0], y[6]);
  826|    318|   accum.mul(x[1], y[5]);
  827|    318|   accum.mul(x[2], y[4]);
  828|    318|   accum.mul(x[3], y[3]);
  829|    318|   accum.mul(x[4], y[2]);
  830|    318|   accum.mul(x[5], y[1]);
  831|    318|   accum.mul(x[6], y[0]);
  832|    318|   z[6] = accum.extract();
  833|    318|   accum.mul(x[0], y[7]);
  834|    318|   accum.mul(x[1], y[6]);
  835|    318|   accum.mul(x[2], y[5]);
  836|    318|   accum.mul(x[3], y[4]);
  837|    318|   accum.mul(x[4], y[3]);
  838|    318|   accum.mul(x[5], y[2]);
  839|    318|   accum.mul(x[6], y[1]);
  840|    318|   accum.mul(x[7], y[0]);
  841|    318|   z[7] = accum.extract();
  842|    318|   accum.mul(x[0], y[8]);
  843|    318|   accum.mul(x[1], y[7]);
  844|    318|   accum.mul(x[2], y[6]);
  845|    318|   accum.mul(x[3], y[5]);
  846|    318|   accum.mul(x[4], y[4]);
  847|    318|   accum.mul(x[5], y[3]);
  848|    318|   accum.mul(x[6], y[2]);
  849|    318|   accum.mul(x[7], y[1]);
  850|    318|   accum.mul(x[8], y[0]);
  851|    318|   z[8] = accum.extract();
  852|    318|   accum.mul(x[0], y[9]);
  853|    318|   accum.mul(x[1], y[8]);
  854|    318|   accum.mul(x[2], y[7]);
  855|    318|   accum.mul(x[3], y[6]);
  856|    318|   accum.mul(x[4], y[5]);
  857|    318|   accum.mul(x[5], y[4]);
  858|    318|   accum.mul(x[6], y[3]);
  859|    318|   accum.mul(x[7], y[2]);
  860|    318|   accum.mul(x[8], y[1]);
  861|    318|   accum.mul(x[9], y[0]);
  862|    318|   z[9] = accum.extract();
  863|    318|   accum.mul(x[0], y[10]);
  864|    318|   accum.mul(x[1], y[9]);
  865|    318|   accum.mul(x[2], y[8]);
  866|    318|   accum.mul(x[3], y[7]);
  867|    318|   accum.mul(x[4], y[6]);
  868|    318|   accum.mul(x[5], y[5]);
  869|    318|   accum.mul(x[6], y[4]);
  870|    318|   accum.mul(x[7], y[3]);
  871|    318|   accum.mul(x[8], y[2]);
  872|    318|   accum.mul(x[9], y[1]);
  873|    318|   accum.mul(x[10], y[0]);
  874|    318|   z[10] = accum.extract();
  875|    318|   accum.mul(x[0], y[11]);
  876|    318|   accum.mul(x[1], y[10]);
  877|    318|   accum.mul(x[2], y[9]);
  878|    318|   accum.mul(x[3], y[8]);
  879|    318|   accum.mul(x[4], y[7]);
  880|    318|   accum.mul(x[5], y[6]);
  881|    318|   accum.mul(x[6], y[5]);
  882|    318|   accum.mul(x[7], y[4]);
  883|    318|   accum.mul(x[8], y[3]);
  884|    318|   accum.mul(x[9], y[2]);
  885|    318|   accum.mul(x[10], y[1]);
  886|    318|   accum.mul(x[11], y[0]);
  887|    318|   z[11] = accum.extract();
  888|    318|   accum.mul(x[0], y[12]);
  889|    318|   accum.mul(x[1], y[11]);
  890|    318|   accum.mul(x[2], y[10]);
  891|    318|   accum.mul(x[3], y[9]);
  892|    318|   accum.mul(x[4], y[8]);
  893|    318|   accum.mul(x[5], y[7]);
  894|    318|   accum.mul(x[6], y[6]);
  895|    318|   accum.mul(x[7], y[5]);
  896|    318|   accum.mul(x[8], y[4]);
  897|    318|   accum.mul(x[9], y[3]);
  898|    318|   accum.mul(x[10], y[2]);
  899|    318|   accum.mul(x[11], y[1]);
  900|    318|   accum.mul(x[12], y[0]);
  901|    318|   z[12] = accum.extract();
  902|    318|   accum.mul(x[0], y[13]);
  903|    318|   accum.mul(x[1], y[12]);
  904|    318|   accum.mul(x[2], y[11]);
  905|    318|   accum.mul(x[3], y[10]);
  906|    318|   accum.mul(x[4], y[9]);
  907|    318|   accum.mul(x[5], y[8]);
  908|    318|   accum.mul(x[6], y[7]);
  909|    318|   accum.mul(x[7], y[6]);
  910|    318|   accum.mul(x[8], y[5]);
  911|    318|   accum.mul(x[9], y[4]);
  912|    318|   accum.mul(x[10], y[3]);
  913|    318|   accum.mul(x[11], y[2]);
  914|    318|   accum.mul(x[12], y[1]);
  915|    318|   accum.mul(x[13], y[0]);
  916|    318|   z[13] = accum.extract();
  917|    318|   accum.mul(x[0], y[14]);
  918|    318|   accum.mul(x[1], y[13]);
  919|    318|   accum.mul(x[2], y[12]);
  920|    318|   accum.mul(x[3], y[11]);
  921|    318|   accum.mul(x[4], y[10]);
  922|    318|   accum.mul(x[5], y[9]);
  923|    318|   accum.mul(x[6], y[8]);
  924|    318|   accum.mul(x[7], y[7]);
  925|    318|   accum.mul(x[8], y[6]);
  926|    318|   accum.mul(x[9], y[5]);
  927|    318|   accum.mul(x[10], y[4]);
  928|    318|   accum.mul(x[11], y[3]);
  929|    318|   accum.mul(x[12], y[2]);
  930|    318|   accum.mul(x[13], y[1]);
  931|    318|   accum.mul(x[14], y[0]);
  932|    318|   z[14] = accum.extract();
  933|    318|   accum.mul(x[0], y[15]);
  934|    318|   accum.mul(x[1], y[14]);
  935|    318|   accum.mul(x[2], y[13]);
  936|    318|   accum.mul(x[3], y[12]);
  937|    318|   accum.mul(x[4], y[11]);
  938|    318|   accum.mul(x[5], y[10]);
  939|    318|   accum.mul(x[6], y[9]);
  940|    318|   accum.mul(x[7], y[8]);
  941|    318|   accum.mul(x[8], y[7]);
  942|    318|   accum.mul(x[9], y[6]);
  943|    318|   accum.mul(x[10], y[5]);
  944|    318|   accum.mul(x[11], y[4]);
  945|    318|   accum.mul(x[12], y[3]);
  946|    318|   accum.mul(x[13], y[2]);
  947|    318|   accum.mul(x[14], y[1]);
  948|    318|   accum.mul(x[15], y[0]);
  949|    318|   z[15] = accum.extract();
  950|    318|   accum.mul(x[1], y[15]);
  951|    318|   accum.mul(x[2], y[14]);
  952|    318|   accum.mul(x[3], y[13]);
  953|    318|   accum.mul(x[4], y[12]);
  954|    318|   accum.mul(x[5], y[11]);
  955|    318|   accum.mul(x[6], y[10]);
  956|    318|   accum.mul(x[7], y[9]);
  957|    318|   accum.mul(x[8], y[8]);
  958|    318|   accum.mul(x[9], y[7]);
  959|    318|   accum.mul(x[10], y[6]);
  960|    318|   accum.mul(x[11], y[5]);
  961|    318|   accum.mul(x[12], y[4]);
  962|    318|   accum.mul(x[13], y[3]);
  963|    318|   accum.mul(x[14], y[2]);
  964|    318|   accum.mul(x[15], y[1]);
  965|    318|   z[16] = accum.extract();
  966|    318|   accum.mul(x[2], y[15]);
  967|    318|   accum.mul(x[3], y[14]);
  968|    318|   accum.mul(x[4], y[13]);
  969|    318|   accum.mul(x[5], y[12]);
  970|    318|   accum.mul(x[6], y[11]);
  971|    318|   accum.mul(x[7], y[10]);
  972|    318|   accum.mul(x[8], y[9]);
  973|    318|   accum.mul(x[9], y[8]);
  974|    318|   accum.mul(x[10], y[7]);
  975|    318|   accum.mul(x[11], y[6]);
  976|    318|   accum.mul(x[12], y[5]);
  977|    318|   accum.mul(x[13], y[4]);
  978|    318|   accum.mul(x[14], y[3]);
  979|    318|   accum.mul(x[15], y[2]);
  980|    318|   z[17] = accum.extract();
  981|    318|   accum.mul(x[3], y[15]);
  982|    318|   accum.mul(x[4], y[14]);
  983|    318|   accum.mul(x[5], y[13]);
  984|    318|   accum.mul(x[6], y[12]);
  985|    318|   accum.mul(x[7], y[11]);
  986|    318|   accum.mul(x[8], y[10]);
  987|    318|   accum.mul(x[9], y[9]);
  988|    318|   accum.mul(x[10], y[8]);
  989|    318|   accum.mul(x[11], y[7]);
  990|    318|   accum.mul(x[12], y[6]);
  991|    318|   accum.mul(x[13], y[5]);
  992|    318|   accum.mul(x[14], y[4]);
  993|    318|   accum.mul(x[15], y[3]);
  994|    318|   z[18] = accum.extract();
  995|    318|   accum.mul(x[4], y[15]);
  996|    318|   accum.mul(x[5], y[14]);
  997|    318|   accum.mul(x[6], y[13]);
  998|    318|   accum.mul(x[7], y[12]);
  999|    318|   accum.mul(x[8], y[11]);
 1000|    318|   accum.mul(x[9], y[10]);
 1001|    318|   accum.mul(x[10], y[9]);
 1002|    318|   accum.mul(x[11], y[8]);
 1003|    318|   accum.mul(x[12], y[7]);
 1004|    318|   accum.mul(x[13], y[6]);
 1005|    318|   accum.mul(x[14], y[5]);
 1006|    318|   accum.mul(x[15], y[4]);
 1007|    318|   z[19] = accum.extract();
 1008|    318|   accum.mul(x[5], y[15]);
 1009|    318|   accum.mul(x[6], y[14]);
 1010|    318|   accum.mul(x[7], y[13]);
 1011|    318|   accum.mul(x[8], y[12]);
 1012|    318|   accum.mul(x[9], y[11]);
 1013|    318|   accum.mul(x[10], y[10]);
 1014|    318|   accum.mul(x[11], y[9]);
 1015|    318|   accum.mul(x[12], y[8]);
 1016|    318|   accum.mul(x[13], y[7]);
 1017|    318|   accum.mul(x[14], y[6]);
 1018|    318|   accum.mul(x[15], y[5]);
 1019|    318|   z[20] = accum.extract();
 1020|    318|   accum.mul(x[6], y[15]);
 1021|    318|   accum.mul(x[7], y[14]);
 1022|    318|   accum.mul(x[8], y[13]);
 1023|    318|   accum.mul(x[9], y[12]);
 1024|    318|   accum.mul(x[10], y[11]);
 1025|    318|   accum.mul(x[11], y[10]);
 1026|    318|   accum.mul(x[12], y[9]);
 1027|    318|   accum.mul(x[13], y[8]);
 1028|    318|   accum.mul(x[14], y[7]);
 1029|    318|   accum.mul(x[15], y[6]);
 1030|    318|   z[21] = accum.extract();
 1031|    318|   accum.mul(x[7], y[15]);
 1032|    318|   accum.mul(x[8], y[14]);
 1033|    318|   accum.mul(x[9], y[13]);
 1034|    318|   accum.mul(x[10], y[12]);
 1035|    318|   accum.mul(x[11], y[11]);
 1036|    318|   accum.mul(x[12], y[10]);
 1037|    318|   accum.mul(x[13], y[9]);
 1038|    318|   accum.mul(x[14], y[8]);
 1039|    318|   accum.mul(x[15], y[7]);
 1040|    318|   z[22] = accum.extract();
 1041|    318|   accum.mul(x[8], y[15]);
 1042|    318|   accum.mul(x[9], y[14]);
 1043|    318|   accum.mul(x[10], y[13]);
 1044|    318|   accum.mul(x[11], y[12]);
 1045|    318|   accum.mul(x[12], y[11]);
 1046|    318|   accum.mul(x[13], y[10]);
 1047|    318|   accum.mul(x[14], y[9]);
 1048|    318|   accum.mul(x[15], y[8]);
 1049|    318|   z[23] = accum.extract();
 1050|    318|   accum.mul(x[9], y[15]);
 1051|    318|   accum.mul(x[10], y[14]);
 1052|    318|   accum.mul(x[11], y[13]);
 1053|    318|   accum.mul(x[12], y[12]);
 1054|    318|   accum.mul(x[13], y[11]);
 1055|    318|   accum.mul(x[14], y[10]);
 1056|    318|   accum.mul(x[15], y[9]);
 1057|    318|   z[24] = accum.extract();
 1058|    318|   accum.mul(x[10], y[15]);
 1059|    318|   accum.mul(x[11], y[14]);
 1060|    318|   accum.mul(x[12], y[13]);
 1061|    318|   accum.mul(x[13], y[12]);
 1062|    318|   accum.mul(x[14], y[11]);
 1063|    318|   accum.mul(x[15], y[10]);
 1064|    318|   z[25] = accum.extract();
 1065|    318|   accum.mul(x[11], y[15]);
 1066|    318|   accum.mul(x[12], y[14]);
 1067|    318|   accum.mul(x[13], y[13]);
 1068|    318|   accum.mul(x[14], y[12]);
 1069|    318|   accum.mul(x[15], y[11]);
 1070|    318|   z[26] = accum.extract();
 1071|    318|   accum.mul(x[12], y[15]);
 1072|    318|   accum.mul(x[13], y[14]);
 1073|    318|   accum.mul(x[14], y[13]);
 1074|    318|   accum.mul(x[15], y[12]);
 1075|    318|   z[27] = accum.extract();
 1076|    318|   accum.mul(x[13], y[15]);
 1077|    318|   accum.mul(x[14], y[14]);
 1078|    318|   accum.mul(x[15], y[13]);
 1079|    318|   z[28] = accum.extract();
 1080|    318|   accum.mul(x[14], y[15]);
 1081|    318|   accum.mul(x[15], y[14]);
 1082|    318|   z[29] = accum.extract();
 1083|    318|   accum.mul(x[15], y[15]);
 1084|    318|   z[30] = accum.extract();
 1085|    318|   z[31] = accum.extract();
 1086|    318|}
_ZN5Botan18bigint_comba_sqr24EPmPKm:
 1091|     16|void bigint_comba_sqr24(word z[48], const word x[24]) {
 1092|     16|   word3<word> accum;
 1093|       |
 1094|     16|   accum.mul(x[0], x[0]);
 1095|     16|   z[0] = accum.extract();
 1096|     16|   accum.mul_x2(x[0], x[1]);
 1097|     16|   z[1] = accum.extract();
 1098|     16|   accum.mul_x2(x[0], x[2]);
 1099|     16|   accum.mul(x[1], x[1]);
 1100|     16|   z[2] = accum.extract();
 1101|     16|   accum.mul_x2(x[0], x[3]);
 1102|     16|   accum.mul_x2(x[1], x[2]);
 1103|     16|   z[3] = accum.extract();
 1104|     16|   accum.mul_x2(x[0], x[4]);
 1105|     16|   accum.mul_x2(x[1], x[3]);
 1106|     16|   accum.mul(x[2], x[2]);
 1107|     16|   z[4] = accum.extract();
 1108|     16|   accum.mul_x2(x[0], x[5]);
 1109|     16|   accum.mul_x2(x[1], x[4]);
 1110|     16|   accum.mul_x2(x[2], x[3]);
 1111|     16|   z[5] = accum.extract();
 1112|     16|   accum.mul_x2(x[0], x[6]);
 1113|     16|   accum.mul_x2(x[1], x[5]);
 1114|     16|   accum.mul_x2(x[2], x[4]);
 1115|     16|   accum.mul(x[3], x[3]);
 1116|     16|   z[6] = accum.extract();
 1117|     16|   accum.mul_x2(x[0], x[7]);
 1118|     16|   accum.mul_x2(x[1], x[6]);
 1119|     16|   accum.mul_x2(x[2], x[5]);
 1120|     16|   accum.mul_x2(x[3], x[4]);
 1121|     16|   z[7] = accum.extract();
 1122|     16|   accum.mul_x2(x[0], x[8]);
 1123|     16|   accum.mul_x2(x[1], x[7]);
 1124|     16|   accum.mul_x2(x[2], x[6]);
 1125|     16|   accum.mul_x2(x[3], x[5]);
 1126|     16|   accum.mul(x[4], x[4]);
 1127|     16|   z[8] = accum.extract();
 1128|     16|   accum.mul_x2(x[0], x[9]);
 1129|     16|   accum.mul_x2(x[1], x[8]);
 1130|     16|   accum.mul_x2(x[2], x[7]);
 1131|     16|   accum.mul_x2(x[3], x[6]);
 1132|     16|   accum.mul_x2(x[4], x[5]);
 1133|     16|   z[9] = accum.extract();
 1134|     16|   accum.mul_x2(x[0], x[10]);
 1135|     16|   accum.mul_x2(x[1], x[9]);
 1136|     16|   accum.mul_x2(x[2], x[8]);
 1137|     16|   accum.mul_x2(x[3], x[7]);
 1138|     16|   accum.mul_x2(x[4], x[6]);
 1139|     16|   accum.mul(x[5], x[5]);
 1140|     16|   z[10] = accum.extract();
 1141|     16|   accum.mul_x2(x[0], x[11]);
 1142|     16|   accum.mul_x2(x[1], x[10]);
 1143|     16|   accum.mul_x2(x[2], x[9]);
 1144|     16|   accum.mul_x2(x[3], x[8]);
 1145|     16|   accum.mul_x2(x[4], x[7]);
 1146|     16|   accum.mul_x2(x[5], x[6]);
 1147|     16|   z[11] = accum.extract();
 1148|     16|   accum.mul_x2(x[0], x[12]);
 1149|     16|   accum.mul_x2(x[1], x[11]);
 1150|     16|   accum.mul_x2(x[2], x[10]);
 1151|     16|   accum.mul_x2(x[3], x[9]);
 1152|     16|   accum.mul_x2(x[4], x[8]);
 1153|     16|   accum.mul_x2(x[5], x[7]);
 1154|     16|   accum.mul(x[6], x[6]);
 1155|     16|   z[12] = accum.extract();
 1156|     16|   accum.mul_x2(x[0], x[13]);
 1157|     16|   accum.mul_x2(x[1], x[12]);
 1158|     16|   accum.mul_x2(x[2], x[11]);
 1159|     16|   accum.mul_x2(x[3], x[10]);
 1160|     16|   accum.mul_x2(x[4], x[9]);
 1161|     16|   accum.mul_x2(x[5], x[8]);
 1162|     16|   accum.mul_x2(x[6], x[7]);
 1163|     16|   z[13] = accum.extract();
 1164|     16|   accum.mul_x2(x[0], x[14]);
 1165|     16|   accum.mul_x2(x[1], x[13]);
 1166|     16|   accum.mul_x2(x[2], x[12]);
 1167|     16|   accum.mul_x2(x[3], x[11]);
 1168|     16|   accum.mul_x2(x[4], x[10]);
 1169|     16|   accum.mul_x2(x[5], x[9]);
 1170|     16|   accum.mul_x2(x[6], x[8]);
 1171|     16|   accum.mul(x[7], x[7]);
 1172|     16|   z[14] = accum.extract();
 1173|     16|   accum.mul_x2(x[0], x[15]);
 1174|     16|   accum.mul_x2(x[1], x[14]);
 1175|     16|   accum.mul_x2(x[2], x[13]);
 1176|     16|   accum.mul_x2(x[3], x[12]);
 1177|     16|   accum.mul_x2(x[4], x[11]);
 1178|     16|   accum.mul_x2(x[5], x[10]);
 1179|     16|   accum.mul_x2(x[6], x[9]);
 1180|     16|   accum.mul_x2(x[7], x[8]);
 1181|     16|   z[15] = accum.extract();
 1182|     16|   accum.mul_x2(x[0], x[16]);
 1183|     16|   accum.mul_x2(x[1], x[15]);
 1184|     16|   accum.mul_x2(x[2], x[14]);
 1185|     16|   accum.mul_x2(x[3], x[13]);
 1186|     16|   accum.mul_x2(x[4], x[12]);
 1187|     16|   accum.mul_x2(x[5], x[11]);
 1188|     16|   accum.mul_x2(x[6], x[10]);
 1189|     16|   accum.mul_x2(x[7], x[9]);
 1190|     16|   accum.mul(x[8], x[8]);
 1191|     16|   z[16] = accum.extract();
 1192|     16|   accum.mul_x2(x[0], x[17]);
 1193|     16|   accum.mul_x2(x[1], x[16]);
 1194|     16|   accum.mul_x2(x[2], x[15]);
 1195|     16|   accum.mul_x2(x[3], x[14]);
 1196|     16|   accum.mul_x2(x[4], x[13]);
 1197|     16|   accum.mul_x2(x[5], x[12]);
 1198|     16|   accum.mul_x2(x[6], x[11]);
 1199|     16|   accum.mul_x2(x[7], x[10]);
 1200|     16|   accum.mul_x2(x[8], x[9]);
 1201|     16|   z[17] = accum.extract();
 1202|     16|   accum.mul_x2(x[0], x[18]);
 1203|     16|   accum.mul_x2(x[1], x[17]);
 1204|     16|   accum.mul_x2(x[2], x[16]);
 1205|     16|   accum.mul_x2(x[3], x[15]);
 1206|     16|   accum.mul_x2(x[4], x[14]);
 1207|     16|   accum.mul_x2(x[5], x[13]);
 1208|     16|   accum.mul_x2(x[6], x[12]);
 1209|     16|   accum.mul_x2(x[7], x[11]);
 1210|     16|   accum.mul_x2(x[8], x[10]);
 1211|     16|   accum.mul(x[9], x[9]);
 1212|     16|   z[18] = accum.extract();
 1213|     16|   accum.mul_x2(x[0], x[19]);
 1214|     16|   accum.mul_x2(x[1], x[18]);
 1215|     16|   accum.mul_x2(x[2], x[17]);
 1216|     16|   accum.mul_x2(x[3], x[16]);
 1217|     16|   accum.mul_x2(x[4], x[15]);
 1218|     16|   accum.mul_x2(x[5], x[14]);
 1219|     16|   accum.mul_x2(x[6], x[13]);
 1220|     16|   accum.mul_x2(x[7], x[12]);
 1221|     16|   accum.mul_x2(x[8], x[11]);
 1222|     16|   accum.mul_x2(x[9], x[10]);
 1223|     16|   z[19] = accum.extract();
 1224|     16|   accum.mul_x2(x[0], x[20]);
 1225|     16|   accum.mul_x2(x[1], x[19]);
 1226|     16|   accum.mul_x2(x[2], x[18]);
 1227|     16|   accum.mul_x2(x[3], x[17]);
 1228|     16|   accum.mul_x2(x[4], x[16]);
 1229|     16|   accum.mul_x2(x[5], x[15]);
 1230|     16|   accum.mul_x2(x[6], x[14]);
 1231|     16|   accum.mul_x2(x[7], x[13]);
 1232|     16|   accum.mul_x2(x[8], x[12]);
 1233|     16|   accum.mul_x2(x[9], x[11]);
 1234|     16|   accum.mul(x[10], x[10]);
 1235|     16|   z[20] = accum.extract();
 1236|     16|   accum.mul_x2(x[0], x[21]);
 1237|     16|   accum.mul_x2(x[1], x[20]);
 1238|     16|   accum.mul_x2(x[2], x[19]);
 1239|     16|   accum.mul_x2(x[3], x[18]);
 1240|     16|   accum.mul_x2(x[4], x[17]);
 1241|     16|   accum.mul_x2(x[5], x[16]);
 1242|     16|   accum.mul_x2(x[6], x[15]);
 1243|     16|   accum.mul_x2(x[7], x[14]);
 1244|     16|   accum.mul_x2(x[8], x[13]);
 1245|     16|   accum.mul_x2(x[9], x[12]);
 1246|     16|   accum.mul_x2(x[10], x[11]);
 1247|     16|   z[21] = accum.extract();
 1248|     16|   accum.mul_x2(x[0], x[22]);
 1249|     16|   accum.mul_x2(x[1], x[21]);
 1250|     16|   accum.mul_x2(x[2], x[20]);
 1251|     16|   accum.mul_x2(x[3], x[19]);
 1252|     16|   accum.mul_x2(x[4], x[18]);
 1253|     16|   accum.mul_x2(x[5], x[17]);
 1254|     16|   accum.mul_x2(x[6], x[16]);
 1255|     16|   accum.mul_x2(x[7], x[15]);
 1256|     16|   accum.mul_x2(x[8], x[14]);
 1257|     16|   accum.mul_x2(x[9], x[13]);
 1258|     16|   accum.mul_x2(x[10], x[12]);
 1259|     16|   accum.mul(x[11], x[11]);
 1260|     16|   z[22] = accum.extract();
 1261|     16|   accum.mul_x2(x[0], x[23]);
 1262|     16|   accum.mul_x2(x[1], x[22]);
 1263|     16|   accum.mul_x2(x[2], x[21]);
 1264|     16|   accum.mul_x2(x[3], x[20]);
 1265|     16|   accum.mul_x2(x[4], x[19]);
 1266|     16|   accum.mul_x2(x[5], x[18]);
 1267|     16|   accum.mul_x2(x[6], x[17]);
 1268|     16|   accum.mul_x2(x[7], x[16]);
 1269|     16|   accum.mul_x2(x[8], x[15]);
 1270|     16|   accum.mul_x2(x[9], x[14]);
 1271|     16|   accum.mul_x2(x[10], x[13]);
 1272|     16|   accum.mul_x2(x[11], x[12]);
 1273|     16|   z[23] = accum.extract();
 1274|     16|   accum.mul_x2(x[1], x[23]);
 1275|     16|   accum.mul_x2(x[2], x[22]);
 1276|     16|   accum.mul_x2(x[3], x[21]);
 1277|     16|   accum.mul_x2(x[4], x[20]);
 1278|     16|   accum.mul_x2(x[5], x[19]);
 1279|     16|   accum.mul_x2(x[6], x[18]);
 1280|     16|   accum.mul_x2(x[7], x[17]);
 1281|     16|   accum.mul_x2(x[8], x[16]);
 1282|     16|   accum.mul_x2(x[9], x[15]);
 1283|     16|   accum.mul_x2(x[10], x[14]);
 1284|     16|   accum.mul_x2(x[11], x[13]);
 1285|     16|   accum.mul(x[12], x[12]);
 1286|     16|   z[24] = accum.extract();
 1287|     16|   accum.mul_x2(x[2], x[23]);
 1288|     16|   accum.mul_x2(x[3], x[22]);
 1289|     16|   accum.mul_x2(x[4], x[21]);
 1290|     16|   accum.mul_x2(x[5], x[20]);
 1291|     16|   accum.mul_x2(x[6], x[19]);
 1292|     16|   accum.mul_x2(x[7], x[18]);
 1293|     16|   accum.mul_x2(x[8], x[17]);
 1294|     16|   accum.mul_x2(x[9], x[16]);
 1295|     16|   accum.mul_x2(x[10], x[15]);
 1296|     16|   accum.mul_x2(x[11], x[14]);
 1297|     16|   accum.mul_x2(x[12], x[13]);
 1298|     16|   z[25] = accum.extract();
 1299|     16|   accum.mul_x2(x[3], x[23]);
 1300|     16|   accum.mul_x2(x[4], x[22]);
 1301|     16|   accum.mul_x2(x[5], x[21]);
 1302|     16|   accum.mul_x2(x[6], x[20]);
 1303|     16|   accum.mul_x2(x[7], x[19]);
 1304|     16|   accum.mul_x2(x[8], x[18]);
 1305|     16|   accum.mul_x2(x[9], x[17]);
 1306|     16|   accum.mul_x2(x[10], x[16]);
 1307|     16|   accum.mul_x2(x[11], x[15]);
 1308|     16|   accum.mul_x2(x[12], x[14]);
 1309|     16|   accum.mul(x[13], x[13]);
 1310|     16|   z[26] = accum.extract();
 1311|     16|   accum.mul_x2(x[4], x[23]);
 1312|     16|   accum.mul_x2(x[5], x[22]);
 1313|     16|   accum.mul_x2(x[6], x[21]);
 1314|     16|   accum.mul_x2(x[7], x[20]);
 1315|     16|   accum.mul_x2(x[8], x[19]);
 1316|     16|   accum.mul_x2(x[9], x[18]);
 1317|     16|   accum.mul_x2(x[10], x[17]);
 1318|     16|   accum.mul_x2(x[11], x[16]);
 1319|     16|   accum.mul_x2(x[12], x[15]);
 1320|     16|   accum.mul_x2(x[13], x[14]);
 1321|     16|   z[27] = accum.extract();
 1322|     16|   accum.mul_x2(x[5], x[23]);
 1323|     16|   accum.mul_x2(x[6], x[22]);
 1324|     16|   accum.mul_x2(x[7], x[21]);
 1325|     16|   accum.mul_x2(x[8], x[20]);
 1326|     16|   accum.mul_x2(x[9], x[19]);
 1327|     16|   accum.mul_x2(x[10], x[18]);
 1328|     16|   accum.mul_x2(x[11], x[17]);
 1329|     16|   accum.mul_x2(x[12], x[16]);
 1330|     16|   accum.mul_x2(x[13], x[15]);
 1331|     16|   accum.mul(x[14], x[14]);
 1332|     16|   z[28] = accum.extract();
 1333|     16|   accum.mul_x2(x[6], x[23]);
 1334|     16|   accum.mul_x2(x[7], x[22]);
 1335|     16|   accum.mul_x2(x[8], x[21]);
 1336|     16|   accum.mul_x2(x[9], x[20]);
 1337|     16|   accum.mul_x2(x[10], x[19]);
 1338|     16|   accum.mul_x2(x[11], x[18]);
 1339|     16|   accum.mul_x2(x[12], x[17]);
 1340|     16|   accum.mul_x2(x[13], x[16]);
 1341|     16|   accum.mul_x2(x[14], x[15]);
 1342|     16|   z[29] = accum.extract();
 1343|     16|   accum.mul_x2(x[7], x[23]);
 1344|     16|   accum.mul_x2(x[8], x[22]);
 1345|     16|   accum.mul_x2(x[9], x[21]);
 1346|     16|   accum.mul_x2(x[10], x[20]);
 1347|     16|   accum.mul_x2(x[11], x[19]);
 1348|     16|   accum.mul_x2(x[12], x[18]);
 1349|     16|   accum.mul_x2(x[13], x[17]);
 1350|     16|   accum.mul_x2(x[14], x[16]);
 1351|     16|   accum.mul(x[15], x[15]);
 1352|     16|   z[30] = accum.extract();
 1353|     16|   accum.mul_x2(x[8], x[23]);
 1354|     16|   accum.mul_x2(x[9], x[22]);
 1355|     16|   accum.mul_x2(x[10], x[21]);
 1356|     16|   accum.mul_x2(x[11], x[20]);
 1357|     16|   accum.mul_x2(x[12], x[19]);
 1358|     16|   accum.mul_x2(x[13], x[18]);
 1359|     16|   accum.mul_x2(x[14], x[17]);
 1360|     16|   accum.mul_x2(x[15], x[16]);
 1361|     16|   z[31] = accum.extract();
 1362|     16|   accum.mul_x2(x[9], x[23]);
 1363|     16|   accum.mul_x2(x[10], x[22]);
 1364|     16|   accum.mul_x2(x[11], x[21]);
 1365|     16|   accum.mul_x2(x[12], x[20]);
 1366|     16|   accum.mul_x2(x[13], x[19]);
 1367|     16|   accum.mul_x2(x[14], x[18]);
 1368|     16|   accum.mul_x2(x[15], x[17]);
 1369|     16|   accum.mul(x[16], x[16]);
 1370|     16|   z[32] = accum.extract();
 1371|     16|   accum.mul_x2(x[10], x[23]);
 1372|     16|   accum.mul_x2(x[11], x[22]);
 1373|     16|   accum.mul_x2(x[12], x[21]);
 1374|     16|   accum.mul_x2(x[13], x[20]);
 1375|     16|   accum.mul_x2(x[14], x[19]);
 1376|     16|   accum.mul_x2(x[15], x[18]);
 1377|     16|   accum.mul_x2(x[16], x[17]);
 1378|     16|   z[33] = accum.extract();
 1379|     16|   accum.mul_x2(x[11], x[23]);
 1380|     16|   accum.mul_x2(x[12], x[22]);
 1381|     16|   accum.mul_x2(x[13], x[21]);
 1382|     16|   accum.mul_x2(x[14], x[20]);
 1383|     16|   accum.mul_x2(x[15], x[19]);
 1384|     16|   accum.mul_x2(x[16], x[18]);
 1385|     16|   accum.mul(x[17], x[17]);
 1386|     16|   z[34] = accum.extract();
 1387|     16|   accum.mul_x2(x[12], x[23]);
 1388|     16|   accum.mul_x2(x[13], x[22]);
 1389|     16|   accum.mul_x2(x[14], x[21]);
 1390|     16|   accum.mul_x2(x[15], x[20]);
 1391|     16|   accum.mul_x2(x[16], x[19]);
 1392|     16|   accum.mul_x2(x[17], x[18]);
 1393|     16|   z[35] = accum.extract();
 1394|     16|   accum.mul_x2(x[13], x[23]);
 1395|     16|   accum.mul_x2(x[14], x[22]);
 1396|     16|   accum.mul_x2(x[15], x[21]);
 1397|     16|   accum.mul_x2(x[16], x[20]);
 1398|     16|   accum.mul_x2(x[17], x[19]);
 1399|     16|   accum.mul(x[18], x[18]);
 1400|     16|   z[36] = accum.extract();
 1401|     16|   accum.mul_x2(x[14], x[23]);
 1402|     16|   accum.mul_x2(x[15], x[22]);
 1403|     16|   accum.mul_x2(x[16], x[21]);
 1404|     16|   accum.mul_x2(x[17], x[20]);
 1405|     16|   accum.mul_x2(x[18], x[19]);
 1406|     16|   z[37] = accum.extract();
 1407|     16|   accum.mul_x2(x[15], x[23]);
 1408|     16|   accum.mul_x2(x[16], x[22]);
 1409|     16|   accum.mul_x2(x[17], x[21]);
 1410|     16|   accum.mul_x2(x[18], x[20]);
 1411|     16|   accum.mul(x[19], x[19]);
 1412|     16|   z[38] = accum.extract();
 1413|     16|   accum.mul_x2(x[16], x[23]);
 1414|     16|   accum.mul_x2(x[17], x[22]);
 1415|     16|   accum.mul_x2(x[18], x[21]);
 1416|     16|   accum.mul_x2(x[19], x[20]);
 1417|     16|   z[39] = accum.extract();
 1418|     16|   accum.mul_x2(x[17], x[23]);
 1419|     16|   accum.mul_x2(x[18], x[22]);
 1420|     16|   accum.mul_x2(x[19], x[21]);
 1421|     16|   accum.mul(x[20], x[20]);
 1422|     16|   z[40] = accum.extract();
 1423|     16|   accum.mul_x2(x[18], x[23]);
 1424|     16|   accum.mul_x2(x[19], x[22]);
 1425|     16|   accum.mul_x2(x[20], x[21]);
 1426|     16|   z[41] = accum.extract();
 1427|     16|   accum.mul_x2(x[19], x[23]);
 1428|     16|   accum.mul_x2(x[20], x[22]);
 1429|     16|   accum.mul(x[21], x[21]);
 1430|     16|   z[42] = accum.extract();
 1431|     16|   accum.mul_x2(x[20], x[23]);
 1432|     16|   accum.mul_x2(x[21], x[22]);
 1433|     16|   z[43] = accum.extract();
 1434|     16|   accum.mul_x2(x[21], x[23]);
 1435|     16|   accum.mul(x[22], x[22]);
 1436|     16|   z[44] = accum.extract();
 1437|     16|   accum.mul_x2(x[22], x[23]);
 1438|     16|   z[45] = accum.extract();
 1439|     16|   accum.mul(x[23], x[23]);
 1440|     16|   z[46] = accum.extract();
 1441|     16|   z[47] = accum.extract();
 1442|     16|}
_ZN5Botan18bigint_comba_mul24EPmPKmS2_:
 1447|     62|void bigint_comba_mul24(word z[48], const word x[24], const word y[24]) {
 1448|     62|   word3<word> accum;
 1449|       |
 1450|     62|   accum.mul(x[0], y[0]);
 1451|     62|   z[0] = accum.extract();
 1452|     62|   accum.mul(x[0], y[1]);
 1453|     62|   accum.mul(x[1], y[0]);
 1454|     62|   z[1] = accum.extract();
 1455|     62|   accum.mul(x[0], y[2]);
 1456|     62|   accum.mul(x[1], y[1]);
 1457|     62|   accum.mul(x[2], y[0]);
 1458|     62|   z[2] = accum.extract();
 1459|     62|   accum.mul(x[0], y[3]);
 1460|     62|   accum.mul(x[1], y[2]);
 1461|     62|   accum.mul(x[2], y[1]);
 1462|     62|   accum.mul(x[3], y[0]);
 1463|     62|   z[3] = accum.extract();
 1464|     62|   accum.mul(x[0], y[4]);
 1465|     62|   accum.mul(x[1], y[3]);
 1466|     62|   accum.mul(x[2], y[2]);
 1467|     62|   accum.mul(x[3], y[1]);
 1468|     62|   accum.mul(x[4], y[0]);
 1469|     62|   z[4] = accum.extract();
 1470|     62|   accum.mul(x[0], y[5]);
 1471|     62|   accum.mul(x[1], y[4]);
 1472|     62|   accum.mul(x[2], y[3]);
 1473|     62|   accum.mul(x[3], y[2]);
 1474|     62|   accum.mul(x[4], y[1]);
 1475|     62|   accum.mul(x[5], y[0]);
 1476|     62|   z[5] = accum.extract();
 1477|     62|   accum.mul(x[0], y[6]);
 1478|     62|   accum.mul(x[1], y[5]);
 1479|     62|   accum.mul(x[2], y[4]);
 1480|     62|   accum.mul(x[3], y[3]);
 1481|     62|   accum.mul(x[4], y[2]);
 1482|     62|   accum.mul(x[5], y[1]);
 1483|     62|   accum.mul(x[6], y[0]);
 1484|     62|   z[6] = accum.extract();
 1485|     62|   accum.mul(x[0], y[7]);
 1486|     62|   accum.mul(x[1], y[6]);
 1487|     62|   accum.mul(x[2], y[5]);
 1488|     62|   accum.mul(x[3], y[4]);
 1489|     62|   accum.mul(x[4], y[3]);
 1490|     62|   accum.mul(x[5], y[2]);
 1491|     62|   accum.mul(x[6], y[1]);
 1492|     62|   accum.mul(x[7], y[0]);
 1493|     62|   z[7] = accum.extract();
 1494|     62|   accum.mul(x[0], y[8]);
 1495|     62|   accum.mul(x[1], y[7]);
 1496|     62|   accum.mul(x[2], y[6]);
 1497|     62|   accum.mul(x[3], y[5]);
 1498|     62|   accum.mul(x[4], y[4]);
 1499|     62|   accum.mul(x[5], y[3]);
 1500|     62|   accum.mul(x[6], y[2]);
 1501|     62|   accum.mul(x[7], y[1]);
 1502|     62|   accum.mul(x[8], y[0]);
 1503|     62|   z[8] = accum.extract();
 1504|     62|   accum.mul(x[0], y[9]);
 1505|     62|   accum.mul(x[1], y[8]);
 1506|     62|   accum.mul(x[2], y[7]);
 1507|     62|   accum.mul(x[3], y[6]);
 1508|     62|   accum.mul(x[4], y[5]);
 1509|     62|   accum.mul(x[5], y[4]);
 1510|     62|   accum.mul(x[6], y[3]);
 1511|     62|   accum.mul(x[7], y[2]);
 1512|     62|   accum.mul(x[8], y[1]);
 1513|     62|   accum.mul(x[9], y[0]);
 1514|     62|   z[9] = accum.extract();
 1515|     62|   accum.mul(x[0], y[10]);
 1516|     62|   accum.mul(x[1], y[9]);
 1517|     62|   accum.mul(x[2], y[8]);
 1518|     62|   accum.mul(x[3], y[7]);
 1519|     62|   accum.mul(x[4], y[6]);
 1520|     62|   accum.mul(x[5], y[5]);
 1521|     62|   accum.mul(x[6], y[4]);
 1522|     62|   accum.mul(x[7], y[3]);
 1523|     62|   accum.mul(x[8], y[2]);
 1524|     62|   accum.mul(x[9], y[1]);
 1525|     62|   accum.mul(x[10], y[0]);
 1526|     62|   z[10] = accum.extract();
 1527|     62|   accum.mul(x[0], y[11]);
 1528|     62|   accum.mul(x[1], y[10]);
 1529|     62|   accum.mul(x[2], y[9]);
 1530|     62|   accum.mul(x[3], y[8]);
 1531|     62|   accum.mul(x[4], y[7]);
 1532|     62|   accum.mul(x[5], y[6]);
 1533|     62|   accum.mul(x[6], y[5]);
 1534|     62|   accum.mul(x[7], y[4]);
 1535|     62|   accum.mul(x[8], y[3]);
 1536|     62|   accum.mul(x[9], y[2]);
 1537|     62|   accum.mul(x[10], y[1]);
 1538|     62|   accum.mul(x[11], y[0]);
 1539|     62|   z[11] = accum.extract();
 1540|     62|   accum.mul(x[0], y[12]);
 1541|     62|   accum.mul(x[1], y[11]);
 1542|     62|   accum.mul(x[2], y[10]);
 1543|     62|   accum.mul(x[3], y[9]);
 1544|     62|   accum.mul(x[4], y[8]);
 1545|     62|   accum.mul(x[5], y[7]);
 1546|     62|   accum.mul(x[6], y[6]);
 1547|     62|   accum.mul(x[7], y[5]);
 1548|     62|   accum.mul(x[8], y[4]);
 1549|     62|   accum.mul(x[9], y[3]);
 1550|     62|   accum.mul(x[10], y[2]);
 1551|     62|   accum.mul(x[11], y[1]);
 1552|     62|   accum.mul(x[12], y[0]);
 1553|     62|   z[12] = accum.extract();
 1554|     62|   accum.mul(x[0], y[13]);
 1555|     62|   accum.mul(x[1], y[12]);
 1556|     62|   accum.mul(x[2], y[11]);
 1557|     62|   accum.mul(x[3], y[10]);
 1558|     62|   accum.mul(x[4], y[9]);
 1559|     62|   accum.mul(x[5], y[8]);
 1560|     62|   accum.mul(x[6], y[7]);
 1561|     62|   accum.mul(x[7], y[6]);
 1562|     62|   accum.mul(x[8], y[5]);
 1563|     62|   accum.mul(x[9], y[4]);
 1564|     62|   accum.mul(x[10], y[3]);
 1565|     62|   accum.mul(x[11], y[2]);
 1566|     62|   accum.mul(x[12], y[1]);
 1567|     62|   accum.mul(x[13], y[0]);
 1568|     62|   z[13] = accum.extract();
 1569|     62|   accum.mul(x[0], y[14]);
 1570|     62|   accum.mul(x[1], y[13]);
 1571|     62|   accum.mul(x[2], y[12]);
 1572|     62|   accum.mul(x[3], y[11]);
 1573|     62|   accum.mul(x[4], y[10]);
 1574|     62|   accum.mul(x[5], y[9]);
 1575|     62|   accum.mul(x[6], y[8]);
 1576|     62|   accum.mul(x[7], y[7]);
 1577|     62|   accum.mul(x[8], y[6]);
 1578|     62|   accum.mul(x[9], y[5]);
 1579|     62|   accum.mul(x[10], y[4]);
 1580|     62|   accum.mul(x[11], y[3]);
 1581|     62|   accum.mul(x[12], y[2]);
 1582|     62|   accum.mul(x[13], y[1]);
 1583|     62|   accum.mul(x[14], y[0]);
 1584|     62|   z[14] = accum.extract();
 1585|     62|   accum.mul(x[0], y[15]);
 1586|     62|   accum.mul(x[1], y[14]);
 1587|     62|   accum.mul(x[2], y[13]);
 1588|     62|   accum.mul(x[3], y[12]);
 1589|     62|   accum.mul(x[4], y[11]);
 1590|     62|   accum.mul(x[5], y[10]);
 1591|     62|   accum.mul(x[6], y[9]);
 1592|     62|   accum.mul(x[7], y[8]);
 1593|     62|   accum.mul(x[8], y[7]);
 1594|     62|   accum.mul(x[9], y[6]);
 1595|     62|   accum.mul(x[10], y[5]);
 1596|     62|   accum.mul(x[11], y[4]);
 1597|     62|   accum.mul(x[12], y[3]);
 1598|     62|   accum.mul(x[13], y[2]);
 1599|     62|   accum.mul(x[14], y[1]);
 1600|     62|   accum.mul(x[15], y[0]);
 1601|     62|   z[15] = accum.extract();
 1602|     62|   accum.mul(x[0], y[16]);
 1603|     62|   accum.mul(x[1], y[15]);
 1604|     62|   accum.mul(x[2], y[14]);
 1605|     62|   accum.mul(x[3], y[13]);
 1606|     62|   accum.mul(x[4], y[12]);
 1607|     62|   accum.mul(x[5], y[11]);
 1608|     62|   accum.mul(x[6], y[10]);
 1609|     62|   accum.mul(x[7], y[9]);
 1610|     62|   accum.mul(x[8], y[8]);
 1611|     62|   accum.mul(x[9], y[7]);
 1612|     62|   accum.mul(x[10], y[6]);
 1613|     62|   accum.mul(x[11], y[5]);
 1614|     62|   accum.mul(x[12], y[4]);
 1615|     62|   accum.mul(x[13], y[3]);
 1616|     62|   accum.mul(x[14], y[2]);
 1617|     62|   accum.mul(x[15], y[1]);
 1618|     62|   accum.mul(x[16], y[0]);
 1619|     62|   z[16] = accum.extract();
 1620|     62|   accum.mul(x[0], y[17]);
 1621|     62|   accum.mul(x[1], y[16]);
 1622|     62|   accum.mul(x[2], y[15]);
 1623|     62|   accum.mul(x[3], y[14]);
 1624|     62|   accum.mul(x[4], y[13]);
 1625|     62|   accum.mul(x[5], y[12]);
 1626|     62|   accum.mul(x[6], y[11]);
 1627|     62|   accum.mul(x[7], y[10]);
 1628|     62|   accum.mul(x[8], y[9]);
 1629|     62|   accum.mul(x[9], y[8]);
 1630|     62|   accum.mul(x[10], y[7]);
 1631|     62|   accum.mul(x[11], y[6]);
 1632|     62|   accum.mul(x[12], y[5]);
 1633|     62|   accum.mul(x[13], y[4]);
 1634|     62|   accum.mul(x[14], y[3]);
 1635|     62|   accum.mul(x[15], y[2]);
 1636|     62|   accum.mul(x[16], y[1]);
 1637|     62|   accum.mul(x[17], y[0]);
 1638|     62|   z[17] = accum.extract();
 1639|     62|   accum.mul(x[0], y[18]);
 1640|     62|   accum.mul(x[1], y[17]);
 1641|     62|   accum.mul(x[2], y[16]);
 1642|     62|   accum.mul(x[3], y[15]);
 1643|     62|   accum.mul(x[4], y[14]);
 1644|     62|   accum.mul(x[5], y[13]);
 1645|     62|   accum.mul(x[6], y[12]);
 1646|     62|   accum.mul(x[7], y[11]);
 1647|     62|   accum.mul(x[8], y[10]);
 1648|     62|   accum.mul(x[9], y[9]);
 1649|     62|   accum.mul(x[10], y[8]);
 1650|     62|   accum.mul(x[11], y[7]);
 1651|     62|   accum.mul(x[12], y[6]);
 1652|     62|   accum.mul(x[13], y[5]);
 1653|     62|   accum.mul(x[14], y[4]);
 1654|     62|   accum.mul(x[15], y[3]);
 1655|     62|   accum.mul(x[16], y[2]);
 1656|     62|   accum.mul(x[17], y[1]);
 1657|     62|   accum.mul(x[18], y[0]);
 1658|     62|   z[18] = accum.extract();
 1659|     62|   accum.mul(x[0], y[19]);
 1660|     62|   accum.mul(x[1], y[18]);
 1661|     62|   accum.mul(x[2], y[17]);
 1662|     62|   accum.mul(x[3], y[16]);
 1663|     62|   accum.mul(x[4], y[15]);
 1664|     62|   accum.mul(x[5], y[14]);
 1665|     62|   accum.mul(x[6], y[13]);
 1666|     62|   accum.mul(x[7], y[12]);
 1667|     62|   accum.mul(x[8], y[11]);
 1668|     62|   accum.mul(x[9], y[10]);
 1669|     62|   accum.mul(x[10], y[9]);
 1670|     62|   accum.mul(x[11], y[8]);
 1671|     62|   accum.mul(x[12], y[7]);
 1672|     62|   accum.mul(x[13], y[6]);
 1673|     62|   accum.mul(x[14], y[5]);
 1674|     62|   accum.mul(x[15], y[4]);
 1675|     62|   accum.mul(x[16], y[3]);
 1676|     62|   accum.mul(x[17], y[2]);
 1677|     62|   accum.mul(x[18], y[1]);
 1678|     62|   accum.mul(x[19], y[0]);
 1679|     62|   z[19] = accum.extract();
 1680|     62|   accum.mul(x[0], y[20]);
 1681|     62|   accum.mul(x[1], y[19]);
 1682|     62|   accum.mul(x[2], y[18]);
 1683|     62|   accum.mul(x[3], y[17]);
 1684|     62|   accum.mul(x[4], y[16]);
 1685|     62|   accum.mul(x[5], y[15]);
 1686|     62|   accum.mul(x[6], y[14]);
 1687|     62|   accum.mul(x[7], y[13]);
 1688|     62|   accum.mul(x[8], y[12]);
 1689|     62|   accum.mul(x[9], y[11]);
 1690|     62|   accum.mul(x[10], y[10]);
 1691|     62|   accum.mul(x[11], y[9]);
 1692|     62|   accum.mul(x[12], y[8]);
 1693|     62|   accum.mul(x[13], y[7]);
 1694|     62|   accum.mul(x[14], y[6]);
 1695|     62|   accum.mul(x[15], y[5]);
 1696|     62|   accum.mul(x[16], y[4]);
 1697|     62|   accum.mul(x[17], y[3]);
 1698|     62|   accum.mul(x[18], y[2]);
 1699|     62|   accum.mul(x[19], y[1]);
 1700|     62|   accum.mul(x[20], y[0]);
 1701|     62|   z[20] = accum.extract();
 1702|     62|   accum.mul(x[0], y[21]);
 1703|     62|   accum.mul(x[1], y[20]);
 1704|     62|   accum.mul(x[2], y[19]);
 1705|     62|   accum.mul(x[3], y[18]);
 1706|     62|   accum.mul(x[4], y[17]);
 1707|     62|   accum.mul(x[5], y[16]);
 1708|     62|   accum.mul(x[6], y[15]);
 1709|     62|   accum.mul(x[7], y[14]);
 1710|     62|   accum.mul(x[8], y[13]);
 1711|     62|   accum.mul(x[9], y[12]);
 1712|     62|   accum.mul(x[10], y[11]);
 1713|     62|   accum.mul(x[11], y[10]);
 1714|     62|   accum.mul(x[12], y[9]);
 1715|     62|   accum.mul(x[13], y[8]);
 1716|     62|   accum.mul(x[14], y[7]);
 1717|     62|   accum.mul(x[15], y[6]);
 1718|     62|   accum.mul(x[16], y[5]);
 1719|     62|   accum.mul(x[17], y[4]);
 1720|     62|   accum.mul(x[18], y[3]);
 1721|     62|   accum.mul(x[19], y[2]);
 1722|     62|   accum.mul(x[20], y[1]);
 1723|     62|   accum.mul(x[21], y[0]);
 1724|     62|   z[21] = accum.extract();
 1725|     62|   accum.mul(x[0], y[22]);
 1726|     62|   accum.mul(x[1], y[21]);
 1727|     62|   accum.mul(x[2], y[20]);
 1728|     62|   accum.mul(x[3], y[19]);
 1729|     62|   accum.mul(x[4], y[18]);
 1730|     62|   accum.mul(x[5], y[17]);
 1731|     62|   accum.mul(x[6], y[16]);
 1732|     62|   accum.mul(x[7], y[15]);
 1733|     62|   accum.mul(x[8], y[14]);
 1734|     62|   accum.mul(x[9], y[13]);
 1735|     62|   accum.mul(x[10], y[12]);
 1736|     62|   accum.mul(x[11], y[11]);
 1737|     62|   accum.mul(x[12], y[10]);
 1738|     62|   accum.mul(x[13], y[9]);
 1739|     62|   accum.mul(x[14], y[8]);
 1740|     62|   accum.mul(x[15], y[7]);
 1741|     62|   accum.mul(x[16], y[6]);
 1742|     62|   accum.mul(x[17], y[5]);
 1743|     62|   accum.mul(x[18], y[4]);
 1744|     62|   accum.mul(x[19], y[3]);
 1745|     62|   accum.mul(x[20], y[2]);
 1746|     62|   accum.mul(x[21], y[1]);
 1747|     62|   accum.mul(x[22], y[0]);
 1748|     62|   z[22] = accum.extract();
 1749|     62|   accum.mul(x[0], y[23]);
 1750|     62|   accum.mul(x[1], y[22]);
 1751|     62|   accum.mul(x[2], y[21]);
 1752|     62|   accum.mul(x[3], y[20]);
 1753|     62|   accum.mul(x[4], y[19]);
 1754|     62|   accum.mul(x[5], y[18]);
 1755|     62|   accum.mul(x[6], y[17]);
 1756|     62|   accum.mul(x[7], y[16]);
 1757|     62|   accum.mul(x[8], y[15]);
 1758|     62|   accum.mul(x[9], y[14]);
 1759|     62|   accum.mul(x[10], y[13]);
 1760|     62|   accum.mul(x[11], y[12]);
 1761|     62|   accum.mul(x[12], y[11]);
 1762|     62|   accum.mul(x[13], y[10]);
 1763|     62|   accum.mul(x[14], y[9]);
 1764|     62|   accum.mul(x[15], y[8]);
 1765|     62|   accum.mul(x[16], y[7]);
 1766|     62|   accum.mul(x[17], y[6]);
 1767|     62|   accum.mul(x[18], y[5]);
 1768|     62|   accum.mul(x[19], y[4]);
 1769|     62|   accum.mul(x[20], y[3]);
 1770|     62|   accum.mul(x[21], y[2]);
 1771|     62|   accum.mul(x[22], y[1]);
 1772|     62|   accum.mul(x[23], y[0]);
 1773|     62|   z[23] = accum.extract();
 1774|     62|   accum.mul(x[1], y[23]);
 1775|     62|   accum.mul(x[2], y[22]);
 1776|     62|   accum.mul(x[3], y[21]);
 1777|     62|   accum.mul(x[4], y[20]);
 1778|     62|   accum.mul(x[5], y[19]);
 1779|     62|   accum.mul(x[6], y[18]);
 1780|     62|   accum.mul(x[7], y[17]);
 1781|     62|   accum.mul(x[8], y[16]);
 1782|     62|   accum.mul(x[9], y[15]);
 1783|     62|   accum.mul(x[10], y[14]);
 1784|     62|   accum.mul(x[11], y[13]);
 1785|     62|   accum.mul(x[12], y[12]);
 1786|     62|   accum.mul(x[13], y[11]);
 1787|     62|   accum.mul(x[14], y[10]);
 1788|     62|   accum.mul(x[15], y[9]);
 1789|     62|   accum.mul(x[16], y[8]);
 1790|     62|   accum.mul(x[17], y[7]);
 1791|     62|   accum.mul(x[18], y[6]);
 1792|     62|   accum.mul(x[19], y[5]);
 1793|     62|   accum.mul(x[20], y[4]);
 1794|     62|   accum.mul(x[21], y[3]);
 1795|     62|   accum.mul(x[22], y[2]);
 1796|     62|   accum.mul(x[23], y[1]);
 1797|     62|   z[24] = accum.extract();
 1798|     62|   accum.mul(x[2], y[23]);
 1799|     62|   accum.mul(x[3], y[22]);
 1800|     62|   accum.mul(x[4], y[21]);
 1801|     62|   accum.mul(x[5], y[20]);
 1802|     62|   accum.mul(x[6], y[19]);
 1803|     62|   accum.mul(x[7], y[18]);
 1804|     62|   accum.mul(x[8], y[17]);
 1805|     62|   accum.mul(x[9], y[16]);
 1806|     62|   accum.mul(x[10], y[15]);
 1807|     62|   accum.mul(x[11], y[14]);
 1808|     62|   accum.mul(x[12], y[13]);
 1809|     62|   accum.mul(x[13], y[12]);
 1810|     62|   accum.mul(x[14], y[11]);
 1811|     62|   accum.mul(x[15], y[10]);
 1812|     62|   accum.mul(x[16], y[9]);
 1813|     62|   accum.mul(x[17], y[8]);
 1814|     62|   accum.mul(x[18], y[7]);
 1815|     62|   accum.mul(x[19], y[6]);
 1816|     62|   accum.mul(x[20], y[5]);
 1817|     62|   accum.mul(x[21], y[4]);
 1818|     62|   accum.mul(x[22], y[3]);
 1819|     62|   accum.mul(x[23], y[2]);
 1820|     62|   z[25] = accum.extract();
 1821|     62|   accum.mul(x[3], y[23]);
 1822|     62|   accum.mul(x[4], y[22]);
 1823|     62|   accum.mul(x[5], y[21]);
 1824|     62|   accum.mul(x[6], y[20]);
 1825|     62|   accum.mul(x[7], y[19]);
 1826|     62|   accum.mul(x[8], y[18]);
 1827|     62|   accum.mul(x[9], y[17]);
 1828|     62|   accum.mul(x[10], y[16]);
 1829|     62|   accum.mul(x[11], y[15]);
 1830|     62|   accum.mul(x[12], y[14]);
 1831|     62|   accum.mul(x[13], y[13]);
 1832|     62|   accum.mul(x[14], y[12]);
 1833|     62|   accum.mul(x[15], y[11]);
 1834|     62|   accum.mul(x[16], y[10]);
 1835|     62|   accum.mul(x[17], y[9]);
 1836|     62|   accum.mul(x[18], y[8]);
 1837|     62|   accum.mul(x[19], y[7]);
 1838|     62|   accum.mul(x[20], y[6]);
 1839|     62|   accum.mul(x[21], y[5]);
 1840|     62|   accum.mul(x[22], y[4]);
 1841|     62|   accum.mul(x[23], y[3]);
 1842|     62|   z[26] = accum.extract();
 1843|     62|   accum.mul(x[4], y[23]);
 1844|     62|   accum.mul(x[5], y[22]);
 1845|     62|   accum.mul(x[6], y[21]);
 1846|     62|   accum.mul(x[7], y[20]);
 1847|     62|   accum.mul(x[8], y[19]);
 1848|     62|   accum.mul(x[9], y[18]);
 1849|     62|   accum.mul(x[10], y[17]);
 1850|     62|   accum.mul(x[11], y[16]);
 1851|     62|   accum.mul(x[12], y[15]);
 1852|     62|   accum.mul(x[13], y[14]);
 1853|     62|   accum.mul(x[14], y[13]);
 1854|     62|   accum.mul(x[15], y[12]);
 1855|     62|   accum.mul(x[16], y[11]);
 1856|     62|   accum.mul(x[17], y[10]);
 1857|     62|   accum.mul(x[18], y[9]);
 1858|     62|   accum.mul(x[19], y[8]);
 1859|     62|   accum.mul(x[20], y[7]);
 1860|     62|   accum.mul(x[21], y[6]);
 1861|     62|   accum.mul(x[22], y[5]);
 1862|     62|   accum.mul(x[23], y[4]);
 1863|     62|   z[27] = accum.extract();
 1864|     62|   accum.mul(x[5], y[23]);
 1865|     62|   accum.mul(x[6], y[22]);
 1866|     62|   accum.mul(x[7], y[21]);
 1867|     62|   accum.mul(x[8], y[20]);
 1868|     62|   accum.mul(x[9], y[19]);
 1869|     62|   accum.mul(x[10], y[18]);
 1870|     62|   accum.mul(x[11], y[17]);
 1871|     62|   accum.mul(x[12], y[16]);
 1872|     62|   accum.mul(x[13], y[15]);
 1873|     62|   accum.mul(x[14], y[14]);
 1874|     62|   accum.mul(x[15], y[13]);
 1875|     62|   accum.mul(x[16], y[12]);
 1876|     62|   accum.mul(x[17], y[11]);
 1877|     62|   accum.mul(x[18], y[10]);
 1878|     62|   accum.mul(x[19], y[9]);
 1879|     62|   accum.mul(x[20], y[8]);
 1880|     62|   accum.mul(x[21], y[7]);
 1881|     62|   accum.mul(x[22], y[6]);
 1882|     62|   accum.mul(x[23], y[5]);
 1883|     62|   z[28] = accum.extract();
 1884|     62|   accum.mul(x[6], y[23]);
 1885|     62|   accum.mul(x[7], y[22]);
 1886|     62|   accum.mul(x[8], y[21]);
 1887|     62|   accum.mul(x[9], y[20]);
 1888|     62|   accum.mul(x[10], y[19]);
 1889|     62|   accum.mul(x[11], y[18]);
 1890|     62|   accum.mul(x[12], y[17]);
 1891|     62|   accum.mul(x[13], y[16]);
 1892|     62|   accum.mul(x[14], y[15]);
 1893|     62|   accum.mul(x[15], y[14]);
 1894|     62|   accum.mul(x[16], y[13]);
 1895|     62|   accum.mul(x[17], y[12]);
 1896|     62|   accum.mul(x[18], y[11]);
 1897|     62|   accum.mul(x[19], y[10]);
 1898|     62|   accum.mul(x[20], y[9]);
 1899|     62|   accum.mul(x[21], y[8]);
 1900|     62|   accum.mul(x[22], y[7]);
 1901|     62|   accum.mul(x[23], y[6]);
 1902|     62|   z[29] = accum.extract();
 1903|     62|   accum.mul(x[7], y[23]);
 1904|     62|   accum.mul(x[8], y[22]);
 1905|     62|   accum.mul(x[9], y[21]);
 1906|     62|   accum.mul(x[10], y[20]);
 1907|     62|   accum.mul(x[11], y[19]);
 1908|     62|   accum.mul(x[12], y[18]);
 1909|     62|   accum.mul(x[13], y[17]);
 1910|     62|   accum.mul(x[14], y[16]);
 1911|     62|   accum.mul(x[15], y[15]);
 1912|     62|   accum.mul(x[16], y[14]);
 1913|     62|   accum.mul(x[17], y[13]);
 1914|     62|   accum.mul(x[18], y[12]);
 1915|     62|   accum.mul(x[19], y[11]);
 1916|     62|   accum.mul(x[20], y[10]);
 1917|     62|   accum.mul(x[21], y[9]);
 1918|     62|   accum.mul(x[22], y[8]);
 1919|     62|   accum.mul(x[23], y[7]);
 1920|     62|   z[30] = accum.extract();
 1921|     62|   accum.mul(x[8], y[23]);
 1922|     62|   accum.mul(x[9], y[22]);
 1923|     62|   accum.mul(x[10], y[21]);
 1924|     62|   accum.mul(x[11], y[20]);
 1925|     62|   accum.mul(x[12], y[19]);
 1926|     62|   accum.mul(x[13], y[18]);
 1927|     62|   accum.mul(x[14], y[17]);
 1928|     62|   accum.mul(x[15], y[16]);
 1929|     62|   accum.mul(x[16], y[15]);
 1930|     62|   accum.mul(x[17], y[14]);
 1931|     62|   accum.mul(x[18], y[13]);
 1932|     62|   accum.mul(x[19], y[12]);
 1933|     62|   accum.mul(x[20], y[11]);
 1934|     62|   accum.mul(x[21], y[10]);
 1935|     62|   accum.mul(x[22], y[9]);
 1936|     62|   accum.mul(x[23], y[8]);
 1937|     62|   z[31] = accum.extract();
 1938|     62|   accum.mul(x[9], y[23]);
 1939|     62|   accum.mul(x[10], y[22]);
 1940|     62|   accum.mul(x[11], y[21]);
 1941|     62|   accum.mul(x[12], y[20]);
 1942|     62|   accum.mul(x[13], y[19]);
 1943|     62|   accum.mul(x[14], y[18]);
 1944|     62|   accum.mul(x[15], y[17]);
 1945|     62|   accum.mul(x[16], y[16]);
 1946|     62|   accum.mul(x[17], y[15]);
 1947|     62|   accum.mul(x[18], y[14]);
 1948|     62|   accum.mul(x[19], y[13]);
 1949|     62|   accum.mul(x[20], y[12]);
 1950|     62|   accum.mul(x[21], y[11]);
 1951|     62|   accum.mul(x[22], y[10]);
 1952|     62|   accum.mul(x[23], y[9]);
 1953|     62|   z[32] = accum.extract();
 1954|     62|   accum.mul(x[10], y[23]);
 1955|     62|   accum.mul(x[11], y[22]);
 1956|     62|   accum.mul(x[12], y[21]);
 1957|     62|   accum.mul(x[13], y[20]);
 1958|     62|   accum.mul(x[14], y[19]);
 1959|     62|   accum.mul(x[15], y[18]);
 1960|     62|   accum.mul(x[16], y[17]);
 1961|     62|   accum.mul(x[17], y[16]);
 1962|     62|   accum.mul(x[18], y[15]);
 1963|     62|   accum.mul(x[19], y[14]);
 1964|     62|   accum.mul(x[20], y[13]);
 1965|     62|   accum.mul(x[21], y[12]);
 1966|     62|   accum.mul(x[22], y[11]);
 1967|     62|   accum.mul(x[23], y[10]);
 1968|     62|   z[33] = accum.extract();
 1969|     62|   accum.mul(x[11], y[23]);
 1970|     62|   accum.mul(x[12], y[22]);
 1971|     62|   accum.mul(x[13], y[21]);
 1972|     62|   accum.mul(x[14], y[20]);
 1973|     62|   accum.mul(x[15], y[19]);
 1974|     62|   accum.mul(x[16], y[18]);
 1975|     62|   accum.mul(x[17], y[17]);
 1976|     62|   accum.mul(x[18], y[16]);
 1977|     62|   accum.mul(x[19], y[15]);
 1978|     62|   accum.mul(x[20], y[14]);
 1979|     62|   accum.mul(x[21], y[13]);
 1980|     62|   accum.mul(x[22], y[12]);
 1981|     62|   accum.mul(x[23], y[11]);
 1982|     62|   z[34] = accum.extract();
 1983|     62|   accum.mul(x[12], y[23]);
 1984|     62|   accum.mul(x[13], y[22]);
 1985|     62|   accum.mul(x[14], y[21]);
 1986|     62|   accum.mul(x[15], y[20]);
 1987|     62|   accum.mul(x[16], y[19]);
 1988|     62|   accum.mul(x[17], y[18]);
 1989|     62|   accum.mul(x[18], y[17]);
 1990|     62|   accum.mul(x[19], y[16]);
 1991|     62|   accum.mul(x[20], y[15]);
 1992|     62|   accum.mul(x[21], y[14]);
 1993|     62|   accum.mul(x[22], y[13]);
 1994|     62|   accum.mul(x[23], y[12]);
 1995|     62|   z[35] = accum.extract();
 1996|     62|   accum.mul(x[13], y[23]);
 1997|     62|   accum.mul(x[14], y[22]);
 1998|     62|   accum.mul(x[15], y[21]);
 1999|     62|   accum.mul(x[16], y[20]);
 2000|     62|   accum.mul(x[17], y[19]);
 2001|     62|   accum.mul(x[18], y[18]);
 2002|     62|   accum.mul(x[19], y[17]);
 2003|     62|   accum.mul(x[20], y[16]);
 2004|     62|   accum.mul(x[21], y[15]);
 2005|     62|   accum.mul(x[22], y[14]);
 2006|     62|   accum.mul(x[23], y[13]);
 2007|     62|   z[36] = accum.extract();
 2008|     62|   accum.mul(x[14], y[23]);
 2009|     62|   accum.mul(x[15], y[22]);
 2010|     62|   accum.mul(x[16], y[21]);
 2011|     62|   accum.mul(x[17], y[20]);
 2012|     62|   accum.mul(x[18], y[19]);
 2013|     62|   accum.mul(x[19], y[18]);
 2014|     62|   accum.mul(x[20], y[17]);
 2015|     62|   accum.mul(x[21], y[16]);
 2016|     62|   accum.mul(x[22], y[15]);
 2017|     62|   accum.mul(x[23], y[14]);
 2018|     62|   z[37] = accum.extract();
 2019|     62|   accum.mul(x[15], y[23]);
 2020|     62|   accum.mul(x[16], y[22]);
 2021|     62|   accum.mul(x[17], y[21]);
 2022|     62|   accum.mul(x[18], y[20]);
 2023|     62|   accum.mul(x[19], y[19]);
 2024|     62|   accum.mul(x[20], y[18]);
 2025|     62|   accum.mul(x[21], y[17]);
 2026|     62|   accum.mul(x[22], y[16]);
 2027|     62|   accum.mul(x[23], y[15]);
 2028|     62|   z[38] = accum.extract();
 2029|     62|   accum.mul(x[16], y[23]);
 2030|     62|   accum.mul(x[17], y[22]);
 2031|     62|   accum.mul(x[18], y[21]);
 2032|     62|   accum.mul(x[19], y[20]);
 2033|     62|   accum.mul(x[20], y[19]);
 2034|     62|   accum.mul(x[21], y[18]);
 2035|     62|   accum.mul(x[22], y[17]);
 2036|     62|   accum.mul(x[23], y[16]);
 2037|     62|   z[39] = accum.extract();
 2038|     62|   accum.mul(x[17], y[23]);
 2039|     62|   accum.mul(x[18], y[22]);
 2040|     62|   accum.mul(x[19], y[21]);
 2041|     62|   accum.mul(x[20], y[20]);
 2042|     62|   accum.mul(x[21], y[19]);
 2043|     62|   accum.mul(x[22], y[18]);
 2044|     62|   accum.mul(x[23], y[17]);
 2045|     62|   z[40] = accum.extract();
 2046|     62|   accum.mul(x[18], y[23]);
 2047|     62|   accum.mul(x[19], y[22]);
 2048|     62|   accum.mul(x[20], y[21]);
 2049|     62|   accum.mul(x[21], y[20]);
 2050|     62|   accum.mul(x[22], y[19]);
 2051|     62|   accum.mul(x[23], y[18]);
 2052|     62|   z[41] = accum.extract();
 2053|     62|   accum.mul(x[19], y[23]);
 2054|     62|   accum.mul(x[20], y[22]);
 2055|     62|   accum.mul(x[21], y[21]);
 2056|     62|   accum.mul(x[22], y[20]);
 2057|     62|   accum.mul(x[23], y[19]);
 2058|     62|   z[42] = accum.extract();
 2059|     62|   accum.mul(x[20], y[23]);
 2060|     62|   accum.mul(x[21], y[22]);
 2061|     62|   accum.mul(x[22], y[21]);
 2062|     62|   accum.mul(x[23], y[20]);
 2063|     62|   z[43] = accum.extract();
 2064|     62|   accum.mul(x[21], y[23]);
 2065|     62|   accum.mul(x[22], y[22]);
 2066|     62|   accum.mul(x[23], y[21]);
 2067|     62|   z[44] = accum.extract();
 2068|     62|   accum.mul(x[22], y[23]);
 2069|     62|   accum.mul(x[23], y[22]);
 2070|     62|   z[45] = accum.extract();
 2071|     62|   accum.mul(x[23], y[23]);
 2072|     62|   z[46] = accum.extract();
 2073|     62|   z[47] = accum.extract();
 2074|     62|}

_ZN5Botan12basecase_mulEPmmPKmmS2_m:
   20|    365|void basecase_mul(word z[], size_t z_size, const word x[], size_t x_size, const word y[], size_t y_size) {
   21|    365|   if(z_size < x_size + y_size) {
  ------------------
  |  Branch (21:7): [True: 0, False: 365]
  ------------------
   22|      0|      throw Invalid_Argument("basecase_mul z_size too small");
   23|      0|   }
   24|       |
   25|    365|   const size_t x_size_8 = x_size - (x_size % 8);
   26|       |
   27|    365|   zeroize_buffer(z, z_size);
   28|       |
   29|  9.32k|   for(size_t i = 0; i != y_size; ++i) {
  ------------------
  |  Branch (29:22): [True: 8.96k, False: 365]
  ------------------
   30|  8.96k|      const word y_i = y[i];
   31|       |
   32|  8.96k|      word carry = 0;
   33|       |
   34|  32.5k|      for(size_t j = 0; j != x_size_8; j += 8) {
  ------------------
  |  Branch (34:25): [True: 23.5k, False: 8.96k]
  ------------------
   35|  23.5k|         carry = word8_madd3(z + i + j, x + j, y_i, carry);
   36|  23.5k|      }
   37|       |
   38|  49.7k|      for(size_t j = x_size_8; j != x_size; ++j) {
  ------------------
  |  Branch (38:32): [True: 40.8k, False: 8.96k]
  ------------------
   39|  40.8k|         z[i + j] = word_madd3(x[j], y_i, z[i + j], &carry);
   40|  40.8k|      }
   41|       |
   42|  8.96k|      z[x_size + i] = carry;
   43|  8.96k|   }
   44|    365|}
_ZN5Botan12basecase_sqrEPmmPKmm:
   46|    259|void basecase_sqr(word z[], size_t z_size, const word x[], size_t x_size) {
   47|    259|   if(z_size < 2 * x_size) {
  ------------------
  |  Branch (47:7): [True: 0, False: 259]
  ------------------
   48|      0|      throw Invalid_Argument("basecase_sqr z_size too small");
   49|      0|   }
   50|       |
   51|    259|   const size_t x_size_8 = x_size - (x_size % 8);
   52|       |
   53|    259|   zeroize_buffer(z, z_size);
   54|       |
   55|  8.31k|   for(size_t i = 0; i != x_size; ++i) {
  ------------------
  |  Branch (55:22): [True: 8.05k, False: 259]
  ------------------
   56|  8.05k|      const word x_i = x[i];
   57|       |
   58|  8.05k|      word carry = 0;
   59|       |
   60|  54.9k|      for(size_t j = 0; j != x_size_8; j += 8) {
  ------------------
  |  Branch (60:25): [True: 46.8k, False: 8.05k]
  ------------------
   61|  46.8k|         carry = word8_madd3(z + i + j, x + j, x_i, carry);
   62|  46.8k|      }
   63|       |
   64|  42.9k|      for(size_t j = x_size_8; j != x_size; ++j) {
  ------------------
  |  Branch (64:32): [True: 34.8k, False: 8.05k]
  ------------------
   65|  34.8k|         z[i + j] = word_madd3(x[j], x_i, z[i + j], &carry);
   66|  34.8k|      }
   67|       |
   68|  8.05k|      z[x_size + i] = carry;
   69|  8.05k|   }
   70|    259|}
_ZN5Botan10bigint_mulEPmmPKmmmS2_mmS0_m:
  292|    171|                size_t ws_size) {
  293|    171|   zeroize_buffer(z, z_size);
  294|       |
  295|    171|   if(x_sw == 1) {
  ------------------
  |  Branch (295:7): [True: 0, False: 171]
  ------------------
  296|      0|      bigint_linmul3(z, y, y_sw, x[0]);
  297|    171|   } else if(y_sw == 1) {
  ------------------
  |  Branch (297:14): [True: 0, False: 171]
  ------------------
  298|      0|      bigint_linmul3(z, x, x_sw, y[0]);
  299|    171|   } else if(sized_for_comba_mul<4>(x_sw, x_size, y_sw, y_size, z_size)) {
  ------------------
  |  Branch (299:14): [True: 18, False: 153]
  ------------------
  300|     18|      bigint_comba_mul4(z, x, y);
  301|    153|   } else if(sized_for_comba_mul<6>(x_sw, x_size, y_sw, y_size, z_size)) {
  ------------------
  |  Branch (301:14): [True: 10, False: 143]
  ------------------
  302|     10|      bigint_comba_mul6(z, x, y);
  303|    143|   } else if(sized_for_comba_mul<8>(x_sw, x_size, y_sw, y_size, z_size)) {
  ------------------
  |  Branch (303:14): [True: 7, False: 136]
  ------------------
  304|      7|      bigint_comba_mul8(z, x, y);
  305|    136|   } else if(sized_for_comba_mul<9>(x_sw, x_size, y_sw, y_size, z_size)) {
  ------------------
  |  Branch (305:14): [True: 5, False: 131]
  ------------------
  306|      5|      bigint_comba_mul9(z, x, y);
  307|    131|   } else if(sized_for_comba_mul<16>(x_sw, x_size, y_sw, y_size, z_size)) {
  ------------------
  |  Branch (307:14): [True: 15, False: 116]
  ------------------
  308|     15|      bigint_comba_mul16(z, x, y);
  309|    116|   } else if(sized_for_comba_mul<24>(x_sw, x_size, y_sw, y_size, z_size)) {
  ------------------
  |  Branch (309:14): [True: 17, False: 99]
  ------------------
  310|     17|      bigint_comba_mul24(z, x, y);
  311|     99|   } else if(x_sw < KARATSUBA_MULTIPLY_THRESHOLD || y_sw < KARATSUBA_MULTIPLY_THRESHOLD || workspace == nullptr) {
  ------------------
  |  Branch (311:14): [True: 14, False: 85]
  |  Branch (311:53): [True: 0, False: 85]
  |  Branch (311:92): [True: 0, False: 85]
  ------------------
  312|     14|      basecase_mul(z, z_size, x, x_sw, y, y_sw);
  313|     85|   } else {
  314|     85|      const size_t N = karatsuba_size(z_size, x_size, x_sw, y_size, y_sw);
  315|       |
  316|     85|      if(N > 0 && z_size >= 2 * N && ws_size >= 2 * N) {
  ------------------
  |  Branch (316:10): [True: 85, False: 0]
  |  Branch (316:19): [True: 85, False: 0]
  |  Branch (316:38): [True: 85, False: 0]
  ------------------
  317|     85|         karatsuba_mul(z, x, y, N, workspace);
  318|     85|      } else {
  319|      0|         basecase_mul(z, z_size, x, x_sw, y, y_sw);
  320|      0|      }
  321|     85|   }
  322|    171|}
_ZN5Botan10bigint_sqrEPmmPKmmmS0_m:
  327|    297|void bigint_sqr(word z[], size_t z_size, const word x[], size_t x_size, size_t x_sw, word workspace[], size_t ws_size) {
  328|    297|   zeroize_buffer(z, z_size);
  329|       |
  330|    297|   BOTAN_ASSERT(z_size / 2 >= x_sw, "Output size is sufficient");
  ------------------
  |  |   64|    297|   do {                                                                                 \
  |  |   65|    297|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                                     \
  |  |   66|    297|      if(!(expr)) {                                                                     \
  |  |  ------------------
  |  |  |  Branch (66:10): [True: 0, False: 297]
  |  |  ------------------
  |  |   67|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                            \
  |  |   68|      0|         Botan::assertion_failure(#expr, assertion_made, __func__, __FILE__, __LINE__); \
  |  |   69|      0|      }                                                                                 \
  |  |   70|    297|   } while(0)
  |  |  ------------------
  |  |  |  Branch (70:12): [Folded, False: 297]
  |  |  ------------------
  ------------------
  331|       |
  332|    297|   if(x_sw == 1) {
  ------------------
  |  Branch (332:7): [True: 121, False: 176]
  ------------------
  333|    121|      bigint_linmul3(z, x, x_sw, x[0]);
  334|    176|   } else if(sized_for_comba_sqr<4>(x_sw, x_size, z_size)) {
  ------------------
  |  Branch (334:14): [True: 4, False: 172]
  ------------------
  335|      4|      bigint_comba_sqr4(z, x);
  336|    172|   } else if(sized_for_comba_sqr<6>(x_sw, x_size, z_size)) {
  ------------------
  |  Branch (336:14): [True: 4, False: 168]
  ------------------
  337|      4|      bigint_comba_sqr6(z, x);
  338|    168|   } else if(sized_for_comba_sqr<8>(x_sw, x_size, z_size)) {
  ------------------
  |  Branch (338:14): [True: 2, False: 166]
  ------------------
  339|      2|      bigint_comba_sqr8(z, x);
  340|    166|   } else if(sized_for_comba_sqr<9>(x_sw, x_size, z_size)) {
  ------------------
  |  Branch (340:14): [True: 5, False: 161]
  ------------------
  341|      5|      bigint_comba_sqr9(z, x);
  342|    161|   } else if(sized_for_comba_sqr<16>(x_sw, x_size, z_size)) {
  ------------------
  |  Branch (342:14): [True: 3, False: 158]
  ------------------
  343|      3|      bigint_comba_sqr16(z, x);
  344|    158|   } else if(sized_for_comba_sqr<24>(x_sw, x_size, z_size)) {
  ------------------
  |  Branch (344:14): [True: 1, False: 157]
  ------------------
  345|      1|      bigint_comba_sqr24(z, x);
  346|    157|   } else if(x_size < KARATSUBA_SQUARE_THRESHOLD || workspace == nullptr) {
  ------------------
  |  Branch (346:14): [True: 37, False: 120]
  |  Branch (346:53): [True: 2, False: 118]
  ------------------
  347|     39|      basecase_sqr(z, z_size, x, x_sw);
  348|    118|   } else {
  349|    118|      const size_t N = karatsuba_size(z_size, x_size, x_sw);
  350|       |
  351|    118|      if(N > 0 && z_size >= 2 * N && ws_size >= 2 * N) {
  ------------------
  |  Branch (351:10): [True: 65, False: 53]
  |  Branch (351:19): [True: 65, False: 0]
  |  Branch (351:38): [True: 65, False: 0]
  ------------------
  352|     65|         karatsuba_sqr(z, x, N, workspace);
  353|     65|      } else {
  354|     53|         basecase_sqr(z, z_size, x, x_sw);
  355|     53|      }
  356|    118|   }
  357|    297|}
mp_karat.cpp:_ZN5Botan12_GLOBAL__N_114karatsuba_sizeEmmmmm:
  203|     85|size_t karatsuba_size(size_t z_size, size_t x_size, size_t x_sw, size_t y_size, size_t y_sw) {
  204|     85|   if(x_sw > x_size || x_sw > y_size || y_sw > x_size || y_sw > y_size) {
  ------------------
  |  Branch (204:7): [True: 0, False: 85]
  |  Branch (204:24): [True: 0, False: 85]
  |  Branch (204:41): [True: 0, False: 85]
  |  Branch (204:58): [True: 0, False: 85]
  ------------------
  205|      0|      return 0;
  206|      0|   }
  207|       |
  208|     85|   if(((x_size == x_sw) && (x_size % 2 != 0)) || ((y_size == y_sw) && (y_size % 2 != 0))) {
  ------------------
  |  Branch (208:8): [True: 20, False: 65]
  |  Branch (208:28): [True: 0, False: 20]
  |  Branch (208:51): [True: 20, False: 65]
  |  Branch (208:71): [True: 0, False: 20]
  ------------------
  209|      0|      return 0;
  210|      0|   }
  211|       |
  212|     85|   const size_t start = (x_sw > y_sw) ? x_sw : y_sw;
  ------------------
  |  Branch (212:25): [True: 0, False: 85]
  ------------------
  213|     85|   const size_t end = (x_size < y_size) ? x_size : y_size;
  ------------------
  |  Branch (213:23): [True: 0, False: 85]
  ------------------
  214|       |
  215|     85|   if(start == end) {
  ------------------
  |  Branch (215:7): [True: 20, False: 65]
  ------------------
  216|     20|      if(start % 2 != 0) {
  ------------------
  |  Branch (216:10): [True: 0, False: 20]
  ------------------
  217|      0|         return 0;
  218|      0|      }
  219|     20|      return start;
  220|     20|   }
  221|       |
  222|    102|   for(size_t j = start; j <= end; ++j) {
  ------------------
  |  Branch (222:26): [True: 102, False: 0]
  ------------------
  223|    102|      if(j % 2 != 0) {
  ------------------
  |  Branch (223:10): [True: 37, False: 65]
  ------------------
  224|     37|         continue;
  225|     37|      }
  226|       |
  227|     65|      if(2 * j > z_size) {
  ------------------
  |  Branch (227:10): [True: 0, False: 65]
  ------------------
  228|      0|         return 0;
  229|      0|      }
  230|       |
  231|     65|      if(x_sw <= j && j <= x_size && y_sw <= j && j <= y_size) {
  ------------------
  |  Branch (231:10): [True: 65, False: 0]
  |  Branch (231:23): [True: 65, False: 0]
  |  Branch (231:38): [True: 65, False: 0]
  |  Branch (231:51): [True: 65, False: 0]
  ------------------
  232|     65|         if(j % 4 == 2 && (j + 2) <= x_size && (j + 2) <= y_size && 2 * (j + 2) <= z_size) {
  ------------------
  |  Branch (232:13): [True: 42, False: 23]
  |  Branch (232:27): [True: 42, False: 0]
  |  Branch (232:48): [True: 42, False: 0]
  |  Branch (232:69): [True: 42, False: 0]
  ------------------
  233|     42|            return j + 2;
  234|     42|         }
  235|     23|         return j;
  236|     65|      }
  237|     65|   }
  238|       |
  239|      0|   return 0;
  240|     65|}
mp_karat.cpp:_ZN5Botan12_GLOBAL__N_113karatsuba_mulEPmPKmS3_mS1_:
   80|  1.00k|void karatsuba_mul(word z[], const word x[], const word y[], size_t N, word workspace[]) {
   81|  1.00k|   if(N < KARATSUBA_MULTIPLY_THRESHOLD || N % 2 != 0) {
  ------------------
  |  Branch (81:7): [True: 699, False: 307]
  |  Branch (81:43): [True: 0, False: 307]
  ------------------
   82|    699|      switch(N) {
   83|      0|         case 6:
  ------------------
  |  Branch (83:10): [True: 0, False: 699]
  ------------------
   84|      0|            return bigint_comba_mul6(z, x, y);
   85|      0|         case 8:
  ------------------
  |  Branch (85:10): [True: 0, False: 699]
  ------------------
   86|      0|            return bigint_comba_mul8(z, x, y);
   87|      0|         case 9:
  ------------------
  |  Branch (87:10): [True: 0, False: 699]
  ------------------
   88|      0|            return bigint_comba_mul9(z, x, y);
   89|    303|         case 16:
  ------------------
  |  Branch (89:10): [True: 303, False: 396]
  ------------------
   90|    303|            return bigint_comba_mul16(z, x, y);
   91|     45|         case 24:
  ------------------
  |  Branch (91:10): [True: 45, False: 654]
  ------------------
   92|     45|            return bigint_comba_mul24(z, x, y);
   93|    351|         default:
  ------------------
  |  Branch (93:10): [True: 351, False: 348]
  ------------------
   94|    351|            return basecase_mul(z, 2 * N, x, N, y, N);
   95|    699|      }
   96|    699|   }
   97|       |
   98|    307|   const size_t N2 = N / 2;
   99|       |
  100|    307|   const word* x0 = x;
  101|    307|   const word* x1 = x + N2;
  102|    307|   const word* y0 = y;
  103|    307|   const word* y1 = y + N2;
  104|    307|   word* z0 = z;
  105|    307|   word* z1 = z + N;
  106|       |
  107|    307|   word* ws0 = workspace;
  108|    307|   word* ws1 = workspace + N;
  109|       |
  110|    307|   zeroize_buffer(workspace, 2 * N);
  111|       |
  112|       |   /*
  113|       |   * If either of cmp0 or cmp1 is zero then z0 or z1 resp is zero here,
  114|       |   * resulting in a no-op - z0*z1 will be equal to zero so we don't need to do
  115|       |   * anything, zeroize_buffer above already set the correct result.
  116|       |   *
  117|       |   * However we ignore the result of the comparisons and always perform the
  118|       |   * subtractions and recursively multiply to avoid the timing channel.
  119|       |   */
  120|       |
  121|       |   // First compute (X_lo - X_hi)*(Y_hi - Y_lo)
  122|    307|   const auto cmp0 = bigint_sub_abs(z0, x0, x1, N2, workspace);
  123|    307|   const auto cmp1 = bigint_sub_abs(z1, y1, y0, N2, workspace);
  124|    307|   const auto neg_mask = ~(cmp0 ^ cmp1);
  125|       |
  126|    307|   karatsuba_mul(ws0, z0, z1, N2, ws1);
  127|       |
  128|       |   // Compute X_lo * Y_lo
  129|    307|   karatsuba_mul(z0, x0, y0, N2, ws1);
  130|       |
  131|       |   // Compute X_hi * Y_hi
  132|    307|   karatsuba_mul(z1, x1, y1, N2, ws1);
  133|       |
  134|    307|   const word ws_carry = bigint_add3(ws1, z0, N, z1, N);
  135|    307|   word z_carry = bigint_add2(z + N2, N, ws1, N);
  136|       |
  137|    307|   z_carry += bigint_add2(z + N + N2, N2, &ws_carry, 1);
  138|    307|   bigint_add2(z + N + N2, N2, &z_carry, 1);
  139|       |
  140|    307|   zeroize_buffer(workspace + N, N2);
  141|       |
  142|    307|   bigint_cnd_add(neg_mask.value(), z + N2, workspace, 2 * N - N2);
  143|    307|   bigint_cnd_sub((~neg_mask).value(), z + N2, workspace, 2 * N - N2);
  144|    307|}
mp_karat.cpp:_ZN5Botan12_GLOBAL__N_114karatsuba_sizeEmmm:
  245|    118|size_t karatsuba_size(size_t z_size, size_t x_size, size_t x_sw) {
  246|    118|   if(x_sw == x_size) {
  ------------------
  |  Branch (246:7): [True: 20, False: 98]
  ------------------
  247|     20|      if(x_sw % 2 != 0) {
  ------------------
  |  Branch (247:10): [True: 0, False: 20]
  ------------------
  248|      0|         return 0;
  249|      0|      }
  250|     20|      return x_sw;
  251|     20|   }
  252|       |
  253|    151|   for(size_t j = x_sw; j <= x_size; ++j) {
  ------------------
  |  Branch (253:25): [True: 151, False: 0]
  ------------------
  254|    151|      if(j % 2 != 0) {
  ------------------
  |  Branch (254:10): [True: 53, False: 98]
  ------------------
  255|     53|         continue;
  256|     53|      }
  257|       |
  258|     98|      if(2 * j > z_size) {
  ------------------
  |  Branch (258:10): [True: 53, False: 45]
  ------------------
  259|     53|         return 0;
  260|     53|      }
  261|       |
  262|     45|      if(j % 4 == 2 && (j + 2) <= x_size && 2 * (j + 2) <= z_size) {
  ------------------
  |  Branch (262:10): [True: 29, False: 16]
  |  Branch (262:24): [True: 29, False: 0]
  |  Branch (262:45): [True: 0, False: 29]
  ------------------
  263|      0|         return j + 2;
  264|      0|      }
  265|     45|      return j;
  266|     45|   }
  267|       |
  268|      0|   return 0;
  269|     98|}
mp_karat.cpp:_ZN5Botan12_GLOBAL__N_113karatsuba_sqrEPmPKmmS1_:
  149|    479|void karatsuba_sqr(word z[], const word x[], size_t N, word workspace[]) {
  150|    479|   if(N < KARATSUBA_SQUARE_THRESHOLD || N % 2 != 0) {
  ------------------
  |  Branch (150:7): [True: 314, False: 165]
  |  Branch (150:41): [True: 27, False: 138]
  ------------------
  151|    341|      switch(N) {
  152|      0|         case 6:
  ------------------
  |  Branch (152:10): [True: 0, False: 341]
  ------------------
  153|      0|            return bigint_comba_sqr6(z, x);
  154|      0|         case 8:
  ------------------
  |  Branch (154:10): [True: 0, False: 341]
  ------------------
  155|      0|            return bigint_comba_sqr8(z, x);
  156|      0|         case 9:
  ------------------
  |  Branch (156:10): [True: 0, False: 341]
  ------------------
  157|      0|            return bigint_comba_sqr9(z, x);
  158|    159|         case 16:
  ------------------
  |  Branch (158:10): [True: 159, False: 182]
  ------------------
  159|    159|            return bigint_comba_sqr16(z, x);
  160|     15|         case 24:
  ------------------
  |  Branch (160:10): [True: 15, False: 326]
  ------------------
  161|     15|            return bigint_comba_sqr24(z, x);
  162|    167|         default:
  ------------------
  |  Branch (162:10): [True: 167, False: 174]
  ------------------
  163|    167|            return basecase_sqr(z, 2 * N, x, N);
  164|    341|      }
  165|    341|   }
  166|       |
  167|    138|   const size_t N2 = N / 2;
  168|       |
  169|    138|   const word* x0 = x;
  170|    138|   const word* x1 = x + N2;
  171|    138|   word* z0 = z;
  172|    138|   word* z1 = z + N;
  173|       |
  174|    138|   word* ws0 = workspace;
  175|    138|   word* ws1 = workspace + N;
  176|       |
  177|    138|   zeroize_buffer(workspace, 2 * N);
  178|       |
  179|       |   // See comment in karatsuba_mul
  180|    138|   bigint_sub_abs(z0, x0, x1, N2, workspace);
  181|    138|   karatsuba_sqr(ws0, z0, N2, ws1);
  182|       |
  183|    138|   karatsuba_sqr(z0, x0, N2, ws1);
  184|    138|   karatsuba_sqr(z1, x1, N2, ws1);
  185|       |
  186|    138|   const word ws_carry = bigint_add3(ws1, z0, N, z1, N);
  187|    138|   word z_carry = bigint_add2(z + N2, N, ws1, N);
  188|       |
  189|    138|   z_carry += bigint_add2(z + N + N2, N2, &ws_carry, 1);
  190|    138|   bigint_add2(z + N + N2, N2, &z_carry, 1);
  191|       |
  192|       |   /*
  193|       |   * This is only actually required if cmp (result of bigint_sub_abs) is != 0,
  194|       |   * however if cmp==0 then ws0[0:N] == 0 and avoiding the jump hides a
  195|       |   * timing channel.
  196|       |   */
  197|    138|   bigint_sub2(z + N2, 2 * N - N2, ws0, N);
  198|    138|}
mp_karat.cpp:_ZN5Botan12_GLOBAL__N_119sized_for_comba_mulILm4EEEbmmmmm:
  272|    171|inline bool sized_for_comba_mul(size_t x_sw, size_t x_size, size_t y_sw, size_t y_size, size_t z_size) {
  273|    171|   return (x_sw <= SZ && x_size >= SZ && y_sw <= SZ && y_size >= SZ && z_size >= 2 * SZ);
  ------------------
  |  Branch (273:12): [True: 18, False: 153]
  |  Branch (273:26): [True: 18, False: 0]
  |  Branch (273:42): [True: 18, False: 0]
  |  Branch (273:56): [True: 18, False: 0]
  |  Branch (273:72): [True: 18, False: 0]
  ------------------
  274|    171|}
mp_karat.cpp:_ZN5Botan12_GLOBAL__N_119sized_for_comba_mulILm6EEEbmmmmm:
  272|    153|inline bool sized_for_comba_mul(size_t x_sw, size_t x_size, size_t y_sw, size_t y_size, size_t z_size) {
  273|    153|   return (x_sw <= SZ && x_size >= SZ && y_sw <= SZ && y_size >= SZ && z_size >= 2 * SZ);
  ------------------
  |  Branch (273:12): [True: 10, False: 143]
  |  Branch (273:26): [True: 10, False: 0]
  |  Branch (273:42): [True: 10, False: 0]
  |  Branch (273:56): [True: 10, False: 0]
  |  Branch (273:72): [True: 10, False: 0]
  ------------------
  274|    153|}
mp_karat.cpp:_ZN5Botan12_GLOBAL__N_119sized_for_comba_mulILm8EEEbmmmmm:
  272|    143|inline bool sized_for_comba_mul(size_t x_sw, size_t x_size, size_t y_sw, size_t y_size, size_t z_size) {
  273|    143|   return (x_sw <= SZ && x_size >= SZ && y_sw <= SZ && y_size >= SZ && z_size >= 2 * SZ);
  ------------------
  |  Branch (273:12): [True: 7, False: 136]
  |  Branch (273:26): [True: 7, False: 0]
  |  Branch (273:42): [True: 7, False: 0]
  |  Branch (273:56): [True: 7, False: 0]
  |  Branch (273:72): [True: 7, False: 0]
  ------------------
  274|    143|}
mp_karat.cpp:_ZN5Botan12_GLOBAL__N_119sized_for_comba_mulILm9EEEbmmmmm:
  272|    136|inline bool sized_for_comba_mul(size_t x_sw, size_t x_size, size_t y_sw, size_t y_size, size_t z_size) {
  273|    136|   return (x_sw <= SZ && x_size >= SZ && y_sw <= SZ && y_size >= SZ && z_size >= 2 * SZ);
  ------------------
  |  Branch (273:12): [True: 5, False: 131]
  |  Branch (273:26): [True: 5, False: 0]
  |  Branch (273:42): [True: 5, False: 0]
  |  Branch (273:56): [True: 5, False: 0]
  |  Branch (273:72): [True: 5, False: 0]
  ------------------
  274|    136|}
mp_karat.cpp:_ZN5Botan12_GLOBAL__N_119sized_for_comba_mulILm16EEEbmmmmm:
  272|    131|inline bool sized_for_comba_mul(size_t x_sw, size_t x_size, size_t y_sw, size_t y_size, size_t z_size) {
  273|    131|   return (x_sw <= SZ && x_size >= SZ && y_sw <= SZ && y_size >= SZ && z_size >= 2 * SZ);
  ------------------
  |  Branch (273:12): [True: 15, False: 116]
  |  Branch (273:26): [True: 15, False: 0]
  |  Branch (273:42): [True: 15, False: 0]
  |  Branch (273:56): [True: 15, False: 0]
  |  Branch (273:72): [True: 15, False: 0]
  ------------------
  274|    131|}
mp_karat.cpp:_ZN5Botan12_GLOBAL__N_119sized_for_comba_mulILm24EEEbmmmmm:
  272|    116|inline bool sized_for_comba_mul(size_t x_sw, size_t x_size, size_t y_sw, size_t y_size, size_t z_size) {
  273|    116|   return (x_sw <= SZ && x_size >= SZ && y_sw <= SZ && y_size >= SZ && z_size >= 2 * SZ);
  ------------------
  |  Branch (273:12): [True: 17, False: 99]
  |  Branch (273:26): [True: 17, False: 0]
  |  Branch (273:42): [True: 17, False: 0]
  |  Branch (273:56): [True: 17, False: 0]
  |  Branch (273:72): [True: 17, False: 0]
  ------------------
  274|    116|}
mp_karat.cpp:_ZN5Botan12_GLOBAL__N_119sized_for_comba_sqrILm4EEEbmmm:
  277|    176|inline bool sized_for_comba_sqr(size_t x_sw, size_t x_size, size_t z_size) {
  278|    176|   return (x_sw <= SZ && x_size >= SZ && z_size >= 2 * SZ);
  ------------------
  |  Branch (278:12): [True: 23, False: 153]
  |  Branch (278:26): [True: 23, False: 0]
  |  Branch (278:42): [True: 4, False: 19]
  ------------------
  279|    176|}
mp_karat.cpp:_ZN5Botan12_GLOBAL__N_119sized_for_comba_sqrILm6EEEbmmm:
  277|    172|inline bool sized_for_comba_sqr(size_t x_sw, size_t x_size, size_t z_size) {
  278|    172|   return (x_sw <= SZ && x_size >= SZ && z_size >= 2 * SZ);
  ------------------
  |  Branch (278:12): [True: 29, False: 143]
  |  Branch (278:26): [True: 29, False: 0]
  |  Branch (278:42): [True: 4, False: 25]
  ------------------
  279|    172|}
mp_karat.cpp:_ZN5Botan12_GLOBAL__N_119sized_for_comba_sqrILm8EEEbmmm:
  277|    168|inline bool sized_for_comba_sqr(size_t x_sw, size_t x_size, size_t z_size) {
  278|    168|   return (x_sw <= SZ && x_size >= SZ && z_size >= 2 * SZ);
  ------------------
  |  Branch (278:12): [True: 32, False: 136]
  |  Branch (278:26): [True: 32, False: 0]
  |  Branch (278:42): [True: 2, False: 30]
  ------------------
  279|    168|}
mp_karat.cpp:_ZN5Botan12_GLOBAL__N_119sized_for_comba_sqrILm9EEEbmmm:
  277|    166|inline bool sized_for_comba_sqr(size_t x_sw, size_t x_size, size_t z_size) {
  278|    166|   return (x_sw <= SZ && x_size >= SZ && z_size >= 2 * SZ);
  ------------------
  |  Branch (278:12): [True: 35, False: 131]
  |  Branch (278:26): [True: 21, False: 14]
  |  Branch (278:42): [True: 5, False: 16]
  ------------------
  279|    166|}
mp_karat.cpp:_ZN5Botan12_GLOBAL__N_119sized_for_comba_sqrILm16EEEbmmm:
  277|    161|inline bool sized_for_comba_sqr(size_t x_sw, size_t x_size, size_t z_size) {
  278|    161|   return (x_sw <= SZ && x_size >= SZ && z_size >= 2 * SZ);
  ------------------
  |  Branch (278:12): [True: 45, False: 116]
  |  Branch (278:26): [True: 31, False: 14]
  |  Branch (278:42): [True: 3, False: 28]
  ------------------
  279|    161|}
mp_karat.cpp:_ZN5Botan12_GLOBAL__N_119sized_for_comba_sqrILm24EEEbmmm:
  277|    158|inline bool sized_for_comba_sqr(size_t x_sw, size_t x_size, size_t z_size) {
  278|    158|   return (x_sw <= SZ && x_size >= SZ && z_size >= 2 * SZ);
  ------------------
  |  Branch (278:12): [True: 59, False: 99]
  |  Branch (278:26): [True: 34, False: 25]
  |  Branch (278:42): [True: 1, False: 33]
  ------------------
  279|    158|}

_ZN5Botan6squareERKNS_6BigIntE:
  184|    297|BigInt square(const BigInt& x) {
  185|    297|   BigInt z = x;
  186|    297|   secure_vector<word> ws;
  187|    297|   z.square(ws);
  188|    297|   return z;
  189|    297|}

_ZN5Botan15allocate_memoryEmm:
   21|  1.64k|BOTAN_MALLOC_FN void* allocate_memory(size_t elems, size_t elem_size) {
   22|  1.64k|   if(elems == 0 || elem_size == 0) {
  ------------------
  |  Branch (22:7): [True: 0, False: 1.64k]
  |  Branch (22:21): [True: 0, False: 1.64k]
  ------------------
   23|      0|      return nullptr;
   24|      0|   }
   25|       |
   26|       |   // Some calloc implementations do not check for overflow (?!?)
   27|  1.64k|   if(!checked_mul(elems, elem_size).has_value()) {
  ------------------
  |  Branch (27:7): [True: 0, False: 1.64k]
  ------------------
   28|      0|      throw std::bad_alloc();
   29|      0|   }
   30|       |
   31|       |#if defined(BOTAN_HAS_LOCKING_ALLOCATOR)
   32|       |   // NOLINTNEXTLINE(*-const-correctness) bug in clang-tidy
   33|       |   if(void* p = mlock_allocator::instance().allocate(elems, elem_size)) {
   34|       |      return p;
   35|       |   }
   36|       |#endif
   37|       |
   38|       |#if defined(BOTAN_TARGET_OS_HAS_ALLOC_CONCEAL)
   39|       |   void* ptr = ::calloc_conceal(elems, elem_size);
   40|       |#else
   41|       |   // NOLINTNEXTLINE(*-const-correctness) bug in clang-tidy
   42|  1.64k|   void* ptr = std::calloc(elems, elem_size);  // NOLINT(*-no-malloc,*-owning-memory)
   43|  1.64k|#endif
   44|  1.64k|   if(ptr == nullptr) {
  ------------------
  |  Branch (44:7): [True: 0, False: 1.64k]
  ------------------
   45|      0|      [[unlikely]] throw std::bad_alloc();
   46|      0|   }
   47|  1.64k|   return ptr;
   48|  1.64k|}
_ZN5Botan17deallocate_memoryEPvmm:
   50|  1.64k|void deallocate_memory(void* p, size_t elems, size_t elem_size) {
   51|  1.64k|   if(p == nullptr) {
  ------------------
  |  Branch (51:7): [True: 0, False: 1.64k]
  ------------------
   52|      0|      [[unlikely]] return;
   53|      0|   }
   54|       |
   55|  1.64k|   secure_scrub_memory(p, elems * elem_size);
   56|       |
   57|       |#if defined(BOTAN_HAS_LOCKING_ALLOCATOR)
   58|       |   if(mlock_allocator::instance().deallocate(p, elems, elem_size)) {
   59|       |      return;
   60|       |   }
   61|       |#endif
   62|       |
   63|  1.64k|   std::free(p);  // NOLINT(*-no-malloc,*-owning-memory)
   64|  1.64k|}

_ZN5Botan19secure_scrub_memoryEPvm:
   25|  1.64k|void secure_scrub_memory(void* ptr, size_t n) {
   26|  1.64k|   return secure_zeroize_buffer(ptr, n);
   27|  1.64k|}
_ZN5Botan21secure_zeroize_bufferEPvm:
   29|  1.64k|void secure_zeroize_buffer(void* ptr, size_t n) {
   30|  1.64k|   if(n == 0) {
  ------------------
  |  Branch (30:7): [True: 0, False: 1.64k]
  ------------------
   31|      0|      return;
   32|      0|   }
   33|       |
   34|       |#if defined(BOTAN_TARGET_OS_HAS_RTLSECUREZEROMEMORY)
   35|       |   ::RtlSecureZeroMemory(ptr, n);
   36|       |
   37|       |#elif defined(BOTAN_TARGET_OS_HAS_EXPLICIT_BZERO)
   38|  1.64k|   ::explicit_bzero(ptr, n);
   39|       |
   40|       |#elif defined(BOTAN_TARGET_OS_HAS_EXPLICIT_MEMSET)
   41|       |   (void)::explicit_memset(ptr, 0, n);
   42|       |
   43|       |#else
   44|       |   /*
   45|       |   * Call memset through a static volatile pointer, which the compiler should
   46|       |   * not elide. This construct should be safe in conforming compilers, but who
   47|       |   * knows. This has been checked to generate the expected code, which saves the
   48|       |   * memset address in the data segment and unconditionally loads and jumps to
   49|       |   * that address, with the following targets:
   50|       |   *
   51|       |   * x86-64: Clang 19, GCC 6, 11, 13, 14
   52|       |   * riscv64: GCC 14
   53|       |   * aarch64: GCC 14
   54|       |   * armv7: GCC 14
   55|       |   *
   56|       |   * Actually all of them generated the expected jump even without marking the
   57|       |   * function pointer as volatile. However this seems worth including as an
   58|       |   * additional precaution.
   59|       |   */
   60|       |   static void* (*const volatile memset_ptr)(void*, int, size_t) = std::memset;
   61|       |   (memset_ptr)(ptr, 0, n);
   62|       |#endif
   63|  1.64k|}

