_ZN5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EED2Ev:
   64|      1|      ~AlignmentBuffer() { secure_zeroize_buffer(m_buffer.data(), sizeof(T) * m_buffer.size()); }
_ZN5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EEC2Ev:
   62|      1|      AlignmentBuffer() = default;
_ZN5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE5clearEv:
   71|      7|      void clear() {
   72|      7|         zeroize_buffer(m_buffer.data(), m_buffer.size());
   73|      7|         m_position = 0;
   74|      7|      }
_ZN5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE21handle_unaligned_dataERNS_12BufferSlicerE:
  166|      9|      [[nodiscard]] std::optional<std::span<const T>> handle_unaligned_data(BufferSlicer& slicer) {
  167|       |         // When the final block is to be deferred, we would need to store and
  168|       |         // hold a buffer that contains exactly one block until more data is
  169|       |         // passed or it is explicitly consumed.
  170|      9|         const size_t defer = (defers_final_block()) ? 1 : 0;
  ------------------
  |  Branch (170:31): [True: 0, False: 9]
  ------------------
  171|       |
  172|      9|         if(in_alignment() && slicer.remaining() >= m_buffer.size() + defer) {
  ------------------
  |  Branch (172:13): [True: 9, False: 0]
  |  Branch (172:31): [True: 6, False: 3]
  ------------------
  173|       |            // We are currently in alignment and the passed-in data source
  174|       |            // contains enough data to benefit from aligned processing.
  175|       |            // Therefore, we don't copy anything into the intermittent buffer.
  176|      6|            return std::nullopt;
  177|      6|         }
  178|       |
  179|       |         // Fill the buffer with as much input data as needed to reach alignment
  180|       |         // or until the input source is depleted.
  181|      3|         const auto elements_to_consume = std::min(m_buffer.size() - m_position, slicer.remaining());
  182|      3|         append(slicer.take(elements_to_consume));
  183|       |
  184|       |         // If we collected enough data, we push out one full block. When
  185|       |         // deferring the final block is enabled, we additionally check that
  186|       |         // more input data is available to continue processing a consecutive
  187|       |         // block.
  188|      3|         if(ready_to_consume() && (!defers_final_block() || !slicer.empty())) {
  ------------------
  |  Branch (188:13): [True: 0, False: 3]
  |  Branch (188:36): [True: 0, False: 0]
  |  Branch (188:61): [True: 0, False: 0]
  ------------------
  189|      0|            return consume();
  190|      3|         } else {
  191|      3|            return std::nullopt;
  192|      3|         }
  193|      3|      }
_ZNK5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE18defers_final_blockEv:
  233|     15|      constexpr bool defers_final_block() const {
  234|     15|         return FINAL_BLOCK_STRATEGY == AlignmentBufferFinalBlock::must_be_deferred;
  235|     15|      }
_ZN5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE6appendENSt3__14spanIKhLm18446744073709551615EEE:
   90|      7|      void append(std::span<const T> elements) {
   91|      7|         BOTAN_ASSERT_NOMSG(elements.size() <= elements_until_alignment());
  ------------------
  |  |   77|      7|   do {                                                                     \
  |  |   78|      7|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|      7|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 7]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|      7|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 7]
  |  |  ------------------
  ------------------
   92|      7|         std::copy(elements.begin(), elements.end(), m_buffer.begin() + m_position);
   93|      7|         m_position += elements.size();
   94|      7|      }
_ZNK5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE24elements_until_alignmentEv:
  221|     19|      size_t elements_until_alignment() const { return m_buffer.size() - m_position; }
_ZNK5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE16ready_to_consumeEv:
  231|     15|      bool ready_to_consume() const { return m_position == m_buffer.size(); }
_ZN5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE7consumeEv:
  200|      4|      [[nodiscard]] std::span<const T> consume() {
  201|      4|         BOTAN_ASSERT_NOMSG(ready_to_consume());
  ------------------
  |  |   77|      4|   do {                                                                     \
  |  |   78|      4|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|      4|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 4]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|      4|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 4]
  |  |  ------------------
  ------------------
  202|      4|         m_position = 0;
  203|      4|         return m_buffer;
  204|      4|      }
_ZNK5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE12in_alignmentEv:
  226|     24|      bool in_alignment() const { return m_position == 0; }
_ZNK5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE23aligned_data_to_processERNS_12BufferSlicerE:
  126|      6|      [[nodiscard]] std::tuple<std::span<const uint8_t>, size_t> aligned_data_to_process(BufferSlicer& slicer) const {
  127|      6|         BOTAN_ASSERT_NOMSG(in_alignment());
  ------------------
  |  |   77|      6|   do {                                                                     \
  |  |   78|      6|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|      6|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 6]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|      6|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 6]
  |  |  ------------------
  ------------------
  128|       |
  129|       |         // When the final block is to be deferred, the last block must not be
  130|       |         // selected for processing if there is no (unaligned) extra input data.
  131|      6|         const size_t defer = (defers_final_block()) ? 1 : 0;
  ------------------
  |  Branch (131:31): [True: 0, False: 6]
  ------------------
  132|      6|         const size_t full_blocks_to_process = (slicer.remaining() - defer) / m_buffer.size();
  133|      6|         return {slicer.take(full_blocks_to_process * m_buffer.size()), full_blocks_to_process};
  134|      6|      }
_ZN5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE18fill_up_with_zerosEv:
   79|      4|      void fill_up_with_zeros() {
   80|      4|         if(!ready_to_consume()) {
  ------------------
  |  Branch (80:13): [True: 4, False: 0]
  ------------------
   81|      4|            zeroize_buffer(&m_buffer[m_position], elements_until_alignment());
   82|      4|            m_position = m_buffer.size();
   83|      4|         }
   84|      4|      }
_ZN5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE20directly_modify_lastEm:
  113|      4|      std::span<T> directly_modify_last(size_t elements) {
  114|      4|         BOTAN_ASSERT_NOMSG(size() >= elements);
  ------------------
  |  |   77|      4|   do {                                                                     \
  |  |   78|      4|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|      4|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 4]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|      4|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 4]
  |  |  ------------------
  ------------------
  115|      4|         return std::span(m_buffer).last(elements);
  116|      4|      }
_ZNK5Botan15AlignmentBufferIhLm64ELNS_25AlignmentBufferFinalBlockE0EE4sizeEv:
  217|      4|      constexpr size_t size() const { return m_buffer.size(); }

_ZN5Botan17ct_expand_top_bitITkNSt3__117unsigned_integralEmEET_S2_:
   28|  4.19M|BOTAN_FORCE_INLINE constexpr T ct_expand_top_bit(T a) {
   29|  4.19M|   const T top = CT::value_barrier<T>(a >> (sizeof(T) * 8 - 1));
   30|  4.19M|   return static_cast<T>(0) - top;
   31|  4.19M|}
_ZN5Botan10ct_is_zeroITkNSt3__117unsigned_integralEmEET_S2_:
   37|  3.39M|BOTAN_FORCE_INLINE constexpr T ct_is_zero(T x) {
   38|  3.39M|   return ct_expand_top_bit<T>(~x & (x - 1));
   39|  3.39M|}
_ZN5Botan6chooseITkNSt3__117unsigned_integralEmEET_S2_S2_S2_:
  216|  3.01M|BOTAN_FORCE_INLINE constexpr T choose(T mask, T a, T b) {
  217|       |   //return (mask & a) | (~mask & b);
  218|  3.01M|   return (b ^ (mask & (a ^ b)));
  219|  3.01M|}
_ZN5Botan13is_power_of_2ITkNSt3__117unsigned_integralEmEEbT_:
   62|  46.6k|BOTAN_FORCE_INLINE constexpr bool is_power_of_2(T arg) {
   63|  46.6k|   return (arg != 0) && (arg != 1) && ((arg & static_cast<T>(arg - 1)) == 0);
  ------------------
  |  Branch (63:11): [True: 46.6k, False: 0]
  |  Branch (63:25): [True: 46.6k, False: 0]
  |  Branch (63:39): [True: 20.7k, False: 25.9k]
  ------------------
   64|  46.6k|}
_ZN5Botan8high_bitITkNSt3__117unsigned_integralEmEEmT_:
   73|  17.2k|BOTAN_FORCE_INLINE constexpr size_t high_bit(T n) {
   74|  17.2k|   size_t hb = 0;
   75|       |
   76|   120k|   for(size_t s = 8 * sizeof(T) / 2; s > 0; s /= 2) {
  ------------------
  |  Branch (76:38): [True: 103k, False: 17.2k]
  ------------------
   77|       |      // Equivalent to: ((n >> s) == 0) ? 0 : s;
   78|   103k|      const size_t z = s - ct_if_is_zero_ret<T>(n >> s, s);
   79|   103k|      hb += z;
   80|   103k|      n >>= z;
   81|   103k|   }
   82|       |
   83|  17.2k|   hb += n;
   84|       |
   85|  17.2k|   return hb;
   86|  17.2k|}
_ZN5Botan17ct_if_is_zero_retITkNSt3__117unsigned_integralEmEEmT_m:
   45|  2.39M|BOTAN_FORCE_INLINE constexpr size_t ct_if_is_zero_ret(T x, size_t s) {
   46|       |   /*
   47|       |   Similar to `return ct_is_zero(x) & s` but has to account for possibility that
   48|       |   sizeof(T) is smaller than sizeof(size_t) which would lead to incomplete masking
   49|       |   */
   50|  2.39M|   const T a = ~x & (x - 1);
   51|  2.39M|   const size_t a_top = static_cast<size_t>(CT::value_barrier<T>(a >> (sizeof(T) * 8 - 1)));
   52|  2.39M|   const size_t mask = static_cast<size_t>(0) - a_top;
   53|  2.39M|   return mask & s;
   54|  2.39M|}
_ZN5Botan10ct_is_zeroITkNSt3__117unsigned_integralEhEET_S2_:
   37|  13.6k|BOTAN_FORCE_INLINE constexpr T ct_is_zero(T x) {
   38|  13.6k|   return ct_expand_top_bit<T>(~x & (x - 1));
   39|  13.6k|}
_ZN5Botan17ct_expand_top_bitITkNSt3__117unsigned_integralEhEET_S2_:
   28|  13.6k|BOTAN_FORCE_INLINE constexpr T ct_expand_top_bit(T a) {
   29|  13.6k|   const T top = CT::value_barrier<T>(a >> (sizeof(T) * 8 - 1));
   30|  13.6k|   return static_cast<T>(0) - top;
   31|  13.6k|}
_ZN5Botan6chooseITkNSt3__117unsigned_integralEhEET_S2_S2_S2_:
  216|  13.6k|BOTAN_FORCE_INLINE constexpr T choose(T mask, T a, T b) {
  217|       |   //return (mask & a) | (~mask & b);
  218|  13.6k|   return (b ^ (mask & (a ^ b)));
  219|  13.6k|}
_ZN5Botan3ctzITkNSt3__117unsigned_integralEmEEmT_:
  115|   327k|BOTAN_FORCE_INLINE constexpr size_t ctz(T n) {
  116|       |   /*
  117|       |   * If n == 0 then this function will compute 8*sizeof(T)-1, so
  118|       |   * initialize lb to 1 if n == 0 to produce the expected result.
  119|       |   */
  120|   327k|   size_t lb = ct_if_is_zero_ret<T>(n, 1);
  121|       |
  122|  2.29M|   for(size_t s = 8 * sizeof(T) / 2; s > 0; s /= 2) {
  ------------------
  |  Branch (122:38): [True: 1.96M, False: 327k]
  ------------------
  123|  1.96M|      const T range = (static_cast<T>(1) << s) - 1;
  124|       |      // Equivalent to: ((n & range) == 0) ? s : 0;
  125|  1.96M|      const size_t z = ct_if_is_zero_ret<T>(n & range, s);
  126|  1.96M|      lb += z;
  127|  1.96M|      n >>= z;
  128|  1.96M|   }
  129|       |
  130|   327k|   return lb;
  131|   327k|}
_ZN5Botan6chooseITkNSt3__117unsigned_integralEjEET_S2_S2_S2_:
  216|  1.28k|BOTAN_FORCE_INLINE constexpr T choose(T mask, T a, T b) {
  217|       |   //return (mask & a) | (~mask & b);
  218|  1.28k|   return (b ^ (mask & (a ^ b)));
  219|  1.28k|}
_ZN5Botan8majorityITkNSt3__117unsigned_integralEjEET_S2_S2_S2_:
  222|    640|BOTAN_FORCE_INLINE constexpr T majority(T a, T b, T c) {
  223|       |   /*
  224|       |   Considering each bit of a, b, c individually
  225|       |
  226|       |   If a xor b is set, then c is the deciding vote.
  227|       |
  228|       |   If a xor b is not set then either a and b are both set or both unset.
  229|       |   In either case the value of c doesn't matter, and examining b (or a)
  230|       |   allows us to determine which case we are in.
  231|       |   */
  232|    640|   return choose(a ^ b, c, b);
  233|    640|}

_ZN5Botan13reverse_bytesITkNSt3__117unsigned_integralEmQooooooeqstT_Li1EeqstS2_Li2EeqstS2_Li4EeqstS2_Li8EEES2_S2_:
   27|  2.37k|inline constexpr T reverse_bytes(T x) {
   28|       |   if constexpr(sizeof(T) == 1) {
   29|       |      return x;
   30|       |   } else if constexpr(sizeof(T) == 2) {
   31|       |#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap16)
   32|       |      return static_cast<T>(__builtin_bswap16(x));
   33|       |#else
   34|       |      return static_cast<T>((x << 8) | (x >> 8));
   35|       |#endif
   36|       |   } else if constexpr(sizeof(T) == 4) {
   37|       |#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap32)
   38|       |      return static_cast<T>(__builtin_bswap32(x));
   39|       |#else
   40|       |      // MSVC at least recognizes this as a bswap
   41|       |      return static_cast<T>(((x & 0x000000FF) << 24) | ((x & 0x0000FF00) << 8) | ((x & 0x00FF0000) >> 8) |
   42|       |                            ((x & 0xFF000000) >> 24));
   43|       |#endif
   44|  2.37k|   } else if constexpr(sizeof(T) == 8) {
   45|  2.37k|#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap64)
   46|  2.37k|      return static_cast<T>(__builtin_bswap64(x));
   47|       |#else
   48|       |      uint32_t hi = static_cast<uint32_t>(x >> 32);
   49|       |      uint32_t lo = static_cast<uint32_t>(x);
   50|       |
   51|       |      hi = reverse_bytes(hi);
   52|       |      lo = reverse_bytes(lo);
   53|       |
   54|       |      return (static_cast<T>(lo) << 32) | hi;
   55|       |#endif
   56|  2.37k|   }
   57|  2.37k|}
_ZN5Botan13reverse_bytesITkNSt3__117unsigned_integralEjQooooooeqstT_Li1EeqstS2_Li2EeqstS2_Li4EeqstS2_Li8EEES2_S2_:
   27|     32|inline constexpr T reverse_bytes(T x) {
   28|       |   if constexpr(sizeof(T) == 1) {
   29|       |      return x;
   30|       |   } else if constexpr(sizeof(T) == 2) {
   31|       |#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap16)
   32|       |      return static_cast<T>(__builtin_bswap16(x));
   33|       |#else
   34|       |      return static_cast<T>((x << 8) | (x >> 8));
   35|       |#endif
   36|     32|   } else if constexpr(sizeof(T) == 4) {
   37|     32|#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap32)
   38|     32|      return static_cast<T>(__builtin_bswap32(x));
   39|       |#else
   40|       |      // MSVC at least recognizes this as a bswap
   41|       |      return static_cast<T>(((x & 0x000000FF) << 24) | ((x & 0x0000FF00) << 8) | ((x & 0x00FF0000) >> 8) |
   42|       |                            ((x & 0xFF000000) >> 24));
   43|       |#endif
   44|       |   } else if constexpr(sizeof(T) == 8) {
   45|       |#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap64)
   46|       |      return static_cast<T>(__builtin_bswap64(x));
   47|       |#else
   48|       |      uint32_t hi = static_cast<uint32_t>(x >> 32);
   49|       |      uint32_t lo = static_cast<uint32_t>(x);
   50|       |
   51|       |      hi = reverse_bytes(hi);
   52|       |      lo = reverse_bytes(lo);
   53|       |
   54|       |      return (static_cast<T>(lo) << 32) | hi;
   55|       |#endif
   56|       |   }
   57|     32|}

_ZN5Botan12BufferSlicerC2ENSt3__14spanIKhLm18446744073709551615EEE:
   25|      9|      explicit BufferSlicer(std::span<const uint8_t> buffer) : m_remaining(buffer) {}
_ZN5Botan12BufferSlicer4takeEm:
   37|      9|      std::span<const uint8_t> take(const size_t count) {
   38|      9|         BOTAN_STATE_CHECK(remaining() >= count);
  ------------------
  |  |   51|      9|   do {                                                         \
  |  |   52|      9|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */             \
  |  |   53|      9|      if(!(expr)) {                                             \
  |  |  ------------------
  |  |  |  Branch (53:10): [True: 0, False: 9]
  |  |  ------------------
  |  |   54|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */    \
  |  |   55|      0|         Botan::throw_invalid_state(#expr, __func__, __FILE__); \
  |  |   56|      0|      }                                                         \
  |  |   57|      9|   } while(0)
  |  |  ------------------
  |  |  |  Branch (57:12): [Folded, False: 9]
  |  |  ------------------
  ------------------
   39|      9|         auto result = m_remaining.first(count);
   40|      9|         m_remaining = m_remaining.subspan(count);
   41|      9|         return result;
   42|      9|      }
_ZNK5Botan12BufferSlicer9remainingEv:
   66|     27|      size_t remaining() const { return m_remaining.size(); }
_ZNK5Botan12BufferSlicer5emptyEv:
   68|     18|      bool empty() const { return m_remaining.empty(); }

_ZN5Botan5CPUID3hasENS_10CPUFeatureE:
   94|     29|      static bool has(CPUID::Feature feat) { return state().has_bit(feat.as_u32()); }
_ZN5Botan5CPUID3hasENS_10CPUFeatureES1_:
   99|     10|      static bool has(CPUID::Feature feat1, CPUID::Feature feat2) {
  100|     10|         return state().has_bit(feat1.as_u32() | feat2.as_u32());
  101|     10|      }
_ZN5Botan5CPUID6is_setEjNS_10CPUFeatureE:
  127|      4|      static inline bool is_set(uint32_t allowed, CPUID::Feature bit) {
  128|      4|         const uint32_t feat_bit = bit.as_u32();
  129|      4|         return ((allowed & feat_bit) == feat_bit);
  130|      4|      }
_ZNK5Botan5CPUID10CPUID_Data7has_bitEj:
  144|     39|            bool has_bit(uint32_t bit) const { return (m_processor_features & bit) == bit; }
_ZN5Botan5CPUID5stateEv:
  156|     39|      static CPUID_Data& state() {
  157|     39|         static CPUID::CPUID_Data g_cpuid;
  158|     39|         return g_cpuid;
  159|     39|      }
cpuid_x86.cpp:_ZN5Botan5CPUID6if_setIZNS0_10CPUID_Data19detect_cpu_featuresEjE16x86_CPUID_1_bitsEEjmT_NS_10CPUFeatureEj:
  117|      6|      static inline uint32_t if_set(uint64_t cpuid, T flag, CPUID::Feature bit, uint32_t allowed) {
  118|      6|         const uint64_t flag64 = static_cast<uint64_t>(flag);
  119|      6|         if((cpuid & flag64) == flag64) {
  ------------------
  |  Branch (119:13): [True: 6, False: 0]
  ------------------
  120|      6|            return (bit.as_u32() & allowed);
  121|      6|         } else {
  122|      0|            return 0;
  123|      0|         }
  124|      6|      }
cpuid_x86.cpp:_ZN5Botan5CPUID6if_setIZNS0_10CPUID_Data19detect_cpu_featuresEjE16x86_CPUID_7_bitsEEjmT_NS_10CPUFeatureEj:
  117|      8|      static inline uint32_t if_set(uint64_t cpuid, T flag, CPUID::Feature bit, uint32_t allowed) {
  118|      8|         const uint64_t flag64 = static_cast<uint64_t>(flag);
  119|      8|         if((cpuid & flag64) == flag64) {
  ------------------
  |  Branch (119:13): [True: 4, False: 4]
  ------------------
  120|      4|            return (bit.as_u32() & allowed);
  121|      4|         } else {
  122|      4|            return 0;
  123|      4|         }
  124|      8|      }
cpuid_x86.cpp:_ZN5Botan5CPUID6if_setIZNS0_10CPUID_Data19detect_cpu_featuresEjE18x86_CPUID_7_1_bitsEEjmT_NS_10CPUFeatureEj:
  117|      3|      static inline uint32_t if_set(uint64_t cpuid, T flag, CPUID::Feature bit, uint32_t allowed) {
  118|      3|         const uint64_t flag64 = static_cast<uint64_t>(flag);
  119|      3|         if((cpuid & flag64) == flag64) {
  ------------------
  |  Branch (119:13): [True: 0, False: 3]
  ------------------
  120|      0|            return (bit.as_u32() & allowed);
  121|      3|         } else {
  122|      3|            return 0;
  123|      3|         }
  124|      3|      }

_ZN5Botan10CPUFeatureC2ENS0_3BitE:
   51|     70|      CPUFeature(Bit b) : m_bit(b) {}  // NOLINT(*-explicit-conversions)
_ZNK5Botan10CPUFeature6as_u32Ev:
   53|     63|      uint32_t as_u32() const { return static_cast<uint32_t>(m_bit); }

_ZN5Botan2CT6Choice9from_maskEm:
  303|  16.6k|      constexpr static Choice from_mask(underlying_type v) { return Choice(v); }
_ZNK5Botan2CT6ChoicentEv:
  309|  16.1k|      constexpr Choice operator!() const { return Choice(~value()); }
_ZNK5Botan2CT6ChoiceaaERKS1_:
  311|  16.1k|      constexpr Choice operator&&(const Choice& other) const { return Choice(value() & other.value()); }
_ZNK5Botan2CT6Choice7as_boolEv:
  329|  16.1k|      constexpr bool as_bool() const { return m_value != 0; }
_ZNK5Botan2CT6Choice5valueEv:
  332|  48.3k|      constexpr underlying_type value() const { return value_barrier(m_value); }
_ZN5Botan2CT6ChoiceC2Em:
  341|  64.5k|      constexpr explicit Choice(underlying_type v) : m_value(CT::value_barrier<underlying_type>(v)) {}
_ZN5Botan2CT4MaskImE7is_zeroEm:
  437|  1.74M|      static constexpr Mask<T> is_zero(T x) { return Mask<T>(ct_is_zero<T>(value_barrier<T>(x))); }
_ZNK5Botan2CT4MaskImE5valueEv:
  630|  5.40M|      constexpr T value() const { return value_barrier<T>(m_mask); }
_ZNK5Botan2CT4MaskImEcoEv:
  533|  1.08M|      constexpr Mask<T> operator~() const { return Mask<T>(~value()); }
_ZN5Botan2CT4MaskImE6expandEm:
  392|   996k|      static constexpr Mask<T> expand(T v) { return ~Mask<T>::is_zero(value_barrier<T>(v)); }
_ZNK5Botan2CT4MaskImE6selectEmm:
  548|   968k|      constexpr T select(T x, T y) const { return choose(value(), x, y); }
_ZN5Botan2CT4MaskImE8is_equalEmm:
  442|   695k|      static constexpr Mask<T> is_equal(T x, T y) {
  443|   695k|         const T diff = value_barrier(x) ^ value_barrier(y);
  444|   695k|         return Mask<T>::is_zero(diff);
  445|   695k|      }
_ZN5Botan2CT4MaskImE5is_ltEmm:
  450|   727k|      static constexpr Mask<T> is_lt(T x, T y) {
  451|   727k|         T u = x ^ ((x ^ y) | ((x - y) ^ x));
  452|   727k|         return Mask<T>::expand_top_bit(u);
  453|   727k|      }
_ZN5Botan2CT4MaskImE14expand_top_bitEm:
  415|   793k|      static constexpr Mask<T> expand_top_bit(T v) { return Mask<T>(ct_expand_top_bit<T>(v)); }
_ZN5Botan2CT4MaskImEC2Em:
  637|  4.15M|      constexpr explicit Mask(T m) : m_mask(m) {}
_ZN5Botan2CT8unpoisonITkNSt3__18integralEmEEvRKT_:
  112|   371k|constexpr void unpoison(const T& p) {
  113|   371k|   unpoison(&p, 1);
  114|   371k|}
_ZN5Botan2CT8unpoisonImEEvPKT_m:
   67|   621k|constexpr inline void unpoison(const T* p, size_t n) {
   68|       |#if defined(BOTAN_HAS_VALGRIND)
   69|       |   if(!std::is_constant_evaluated()) {
   70|       |      VALGRIND_MAKE_MEM_DEFINED(p, n * sizeof(T));
   71|       |   }
   72|       |#endif
   73|       |
   74|   621k|   BOTAN_UNUSED(p, n);
  ------------------
  |  |  144|   621k|#define BOTAN_UNUSED Botan::ignore_params
  ------------------
   75|   621k|}
_ZN5Botan2CT20conditional_copy_memImEENS0_4MaskIT_EES3_PS3_PKS3_S7_m:
  738|  13.0k|constexpr inline Mask<T> conditional_copy_mem(T cnd, T* dest, const T* if_set, const T* if_unset, size_t elems) {
  739|  13.0k|   const auto mask = CT::Mask<T>::expand(cnd);
  740|  13.0k|   return CT::conditional_copy_mem(mask, dest, if_set, if_unset, elems);
  741|  13.0k|}
_ZN5Botan2CT20conditional_copy_memImEENS0_4MaskIT_EES4_PS3_PKS3_S7_m:
  732|  13.0k|constexpr inline Mask<T> conditional_copy_mem(Mask<T> mask, T* dest, const T* if_set, const T* if_unset, size_t elems) {
  733|  13.0k|   mask.select_n(dest, if_set, if_unset, elems);
  734|  13.0k|   return mask;
  735|  13.0k|}
_ZNK5Botan2CT4MaskImE8select_nEPmPKmS5_m:
  565|   496k|      constexpr void select_n(T output[], const T x[], const T y[], size_t len) const {
  566|   496k|         const T mask = value();
  567|  2.54M|         for(size_t i = 0; i != len; ++i) {
  ------------------
  |  Branch (567:28): [True: 2.05M, False: 496k]
  ------------------
  568|  2.05M|            output[i] = choose(mask, x[i], y[i]);
  569|  2.05M|         }
  570|   496k|      }
_ZNK5Botan2CT4MaskImE13if_set_returnEm:
  538|  1.10M|      constexpr T if_set_return(T x) const { return value() & x; }
_ZNK5Botan2CT4MaskImE7as_boolEv:
  614|  48.3k|      constexpr bool as_bool() const { return unpoisoned_value() != 0; }
_ZNK5Botan2CT4MaskImE16unpoisoned_valueEv:
  598|  64.9k|      constexpr T unpoisoned_value() const {
  599|  64.9k|         T r = value();
  600|  64.9k|         CT::unpoison(r);
  601|  64.9k|         return r;
  602|  64.9k|      }
_ZNK5Botan2CT4MaskImE11select_maskES2_S2_:
  559|   423k|      Mask<T> select_mask(Mask<T> x, Mask<T> y) const { return Mask<T>(select(x.value(), y.value())); }
_ZN5Botan2CT4MaskImEoRES2_:
  510|   329k|      Mask<T>& operator|=(Mask<T> o) {
  511|   329k|         m_mask |= o.value();
  512|   329k|         return (*this);
  513|   329k|      }
_ZN5Botan2CT4MaskImEaNES2_:
  494|  45.5k|      Mask<T>& operator&=(Mask<T> o) {
  495|  45.5k|         m_mask &= o.value();
  496|  45.5k|         return (*this);
  497|  45.5k|      }
_ZN5Botan2CT4MaskImE11expand_boolEb:
  397|    510|      static constexpr Mask<T> expand_bool(bool v) { return Mask<T>::expand(static_cast<T>(v)); }
_ZN5Botan2CT4MaskIhE11expand_boolEb:
  397|  13.6k|      static constexpr Mask<T> expand_bool(bool v) { return Mask<T>::expand(static_cast<T>(v)); }
_ZN5Botan2CT4MaskIhE6expandEh:
  392|  13.6k|      static constexpr Mask<T> expand(T v) { return ~Mask<T>::is_zero(value_barrier<T>(v)); }
_ZN5Botan2CT4MaskIhE7is_zeroEh:
  437|  13.6k|      static constexpr Mask<T> is_zero(T x) { return Mask<T>(ct_is_zero<T>(value_barrier<T>(x))); }
_ZN5Botan2CT4MaskIhEC2Eh:
  637|  27.2k|      constexpr explicit Mask(T m) : m_mask(m) {}
_ZNK5Botan2CT4MaskIhEcoEv:
  533|  13.6k|      constexpr Mask<T> operator~() const { return Mask<T>(~value()); }
_ZNK5Botan2CT4MaskIhE5valueEv:
  630|  27.2k|      constexpr T value() const { return value_barrier<T>(m_mask); }
_ZNK5Botan2CT4MaskIhE6selectEhh:
  548|  13.6k|      constexpr T select(T x, T y) const { return choose(value(), x, y); }
_ZNK5Botan2CT4MaskImE9as_choiceEv:
  619|  16.6k|      constexpr CT::Choice as_choice() const {
  620|  16.6k|         if constexpr(sizeof(T) >= sizeof(Choice::underlying_type)) {
  621|  16.6k|            return CT::Choice::from_mask(static_cast<Choice::underlying_type>(unpoisoned_value()));
  622|       |         } else {
  623|       |            return CT::Choice::from_int(unpoisoned_value());
  624|       |         }
  625|  16.6k|      }
_ZN5Botan2CT6poisonImEEvPKT_m:
   56|  13.7k|constexpr inline void poison(const T* p, size_t n) {
   57|       |#if defined(BOTAN_HAS_VALGRIND)
   58|       |   if(!std::is_constant_evaluated()) {
   59|       |      VALGRIND_MAKE_MEM_UNDEFINED(p, n * sizeof(T));
   60|       |   }
   61|       |#endif
   62|       |
   63|  13.7k|   BOTAN_UNUSED(p, n);
  ------------------
  |  |  144|  13.7k|#define BOTAN_UNUSED Botan::ignore_params
  ------------------
   64|  13.7k|}
_ZN5Botan2CT4MaskImE6is_gteEmm:
  468|  90.1k|      static constexpr Mask<T> is_gte(T x, T y) { return ~Mask<T>::is_lt(x, y); }
_ZN5Botan2CTorENS0_4MaskImEES2_:
  528|  65.5k|      friend Mask<T> operator|(Mask<T> x, Mask<T> y) { return Mask<T>(x.value() | y.value()); }
_ZN5Botan2CT6Choice8from_intIjQaasr3stdE17unsigned_integralIT_Entsr3stdE7same_asIbS3_EEES1_S3_:
  268|  15.6k|      constexpr static Choice from_int(T v) {
  269|  15.6k|         if constexpr(sizeof(T) <= sizeof(underlying_type)) {
  270|  15.6k|            return !Choice(ct_is_zero<underlying_type>(v));
  271|       |         } else {
  272|       |            // Mask of T that is either |0| or |1|
  273|       |            const T v_is_0 = ct_is_zero<T>(value_barrier<T>(v));
  274|       |
  275|       |            // We want the mask to be set if v != 0 so we must check that
  276|       |            // v_is_0 is itself zero.
  277|       |            //
  278|       |            // Also sizeof(T) may not equal sizeof(underlying_type) so we must
  279|       |            // use ct_is_zero<underlying_type>. It's ok to either truncate or
  280|       |            // zero extend v_is_0 to 32 bits since we know it is |0| or |1|
  281|       |            // so even just the low bit is sufficient.
  282|       |            return Choice(ct_is_zero<underlying_type>(static_cast<underlying_type>(v_is_0)));
  283|       |         }
  284|  15.6k|      }
_ZN5Botan2CT6poisonITkNS_6ranges14spanable_rangeENSt3__14spanIKmLm18446744073709551615EEEQaasr3stdE23is_trivially_copyable_vINS3_11conditionalIXsr21__is_primary_templateINS3_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS3_6ranges5__cpo5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENS3_26indirectly_readable_traitsISE_EESF_E4type10value_typeEEnt17custom_poisonableISB_EEEvRKSB_:
  121|  13.0k|constexpr void poison(const R& r) {
  122|  13.0k|   const std::span s{r};
  123|  13.0k|   poison(s.data(), s.size());
  124|  13.0k|}
_ZN5Botan2CT8unpoisonITkNS_6ranges14spanable_rangeENSt3__16vectorImNS_16secure_allocatorImEEEEQaasr3stdE23is_trivially_copyable_vINS3_11conditionalIXsr21__is_primary_templateINS3_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS3_6ranges5__cpo5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENS3_26indirectly_readable_traitsISF_EESG_E4type10value_typeEEnt19custom_unpoisonableISC_EEEvRKSC_:
  128|  41.6k|constexpr void unpoison(const R& r) {
  129|  41.6k|   const std::span s{r};
  130|  41.6k|   unpoison(s.data(), s.size());
  131|  41.6k|}
_ZN5Botan2CT8unpoisonITkNS_6ranges14spanable_rangeENSt3__14spanIKmLm18446744073709551615EEEQaasr3stdE23is_trivially_copyable_vINS3_11conditionalIXsr21__is_primary_templateINS3_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS3_6ranges5__cpo5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENS3_26indirectly_readable_traitsISE_EESF_E4type10value_typeEEnt19custom_unpoisonableISB_EEEvRKSB_:
  128|  13.0k|constexpr void unpoison(const R& r) {
  129|  13.0k|   const std::span s{r};
  130|  13.0k|   unpoison(s.data(), s.size());
  131|  13.0k|}
_ZN5Botan2CT4MaskImE3setEv:
  382|     96|      static constexpr Mask<T> set() { return Mask<T>(static_cast<T>(~0)); }
_ZN5Botan2CT6poisonITkNS_6ranges14spanable_rangeENSt3__16vectorImNS_16secure_allocatorImEEEEQaasr3stdE23is_trivially_copyable_vINS3_11conditionalIXsr21__is_primary_templateINS3_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS3_6ranges5__cpo5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENS3_26indirectly_readable_traitsISF_EESG_E4type10value_typeEEnt17custom_poisonableISC_EEEvRKSC_:
  121|    688|constexpr void poison(const R& r) {
  122|    688|   const std::span s{r};
  123|    688|   poison(s.data(), s.size());
  124|    688|}
_ZN5Botan2CT22conditional_assign_memImEENS0_4MaskIT_EES3_PS3_PKS3_m:
  749|   443k|constexpr inline Mask<T> conditional_assign_mem(T cnd, T* dest, const T* src, size_t elems) {
  750|   443k|   const auto mask = CT::Mask<T>::expand(cnd);
  751|   443k|   mask.select_n(dest, src, dest, elems);
  752|   443k|   return mask;
  753|   443k|}
_ZN5Botan2CT4MaskImE7clearedEv:
  387|  42.1k|      static constexpr Mask<T> cleared() { return Mask<T>(0); }
_ZNK5Botan2CT4MaskImE17if_not_set_returnEm:
  543|   327k|      constexpr T if_not_set_return(T x) const { return ~value() & x; }
_ZN5Botan2CT16driveby_unpoisonITkNS0_12unpoisonableEmEEDcOT_Qsr3stdE21is_rvalue_reference_vIDtfp_EE:
  245|     43|{
  246|     43|   unpoison(v);
  247|     43|   return std::forward<T>(v);
  248|     43|}
_ZN5Botan2CT12poison_rangeITkNSt3__16ranges5rangeENS2_6vectorINS_14Montgomery_IntENS2_9allocatorIS5_EEEEQ10poisonableINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS3_5__cpo5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISF_EESG_E4type10value_typeEEEEvRKSC_:
  181|     43|constexpr void poison_range(const R& r) {
  182|    688|   for(const auto& v : r) {
  ------------------
  |  Branch (182:22): [True: 688, False: 43]
  ------------------
  183|    688|      poison(v);
  184|    688|   }
  185|     43|}
_ZN5Botan2CT6poisonITkNS0_17custom_poisonableENS_14Montgomery_IntEEEvRKT_:
  138|    688|constexpr void poison(const T& x) {
  139|    688|   x._const_time_poison();
  140|    688|}
_ZN5Botan2CT8unpoisonITkNS0_19custom_unpoisonableENS_14Montgomery_IntEEEvRKT_:
  143|  2.38k|constexpr void unpoison(const T& x) {
  144|  2.38k|   x._const_time_unpoison();
  145|  2.38k|}

_ZN5Botan3fmtIJPKcS2_S2_EEENSt3__112basic_stringIcNS3_11char_traitsIcEENS3_9allocatorIcEEEENS3_17basic_string_viewIcS6_EEDpRKT_:
   53|      1|std::string fmt(std::string_view format, const T&... args) {
   54|      1|   std::ostringstream oss;
   55|      1|   oss.imbue(std::locale::classic());
   56|      1|   fmt_detail::do_fmt(oss, format, args...);
   57|      1|   return oss.str();
   58|      1|}
_ZN5Botan10fmt_detail6do_fmtIPKcJS3_S3_EEEvRNSt3__119basic_ostringstreamIcNS4_11char_traitsIcEENS4_9allocatorIcEEEENS4_17basic_string_viewIcS7_EERKT_DpRKT0_:
   25|      1|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|      1|   size_t i = 0;
   27|       |
   28|      1|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 1, False: 0]
  ------------------
   29|      1|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 1, False: 0]
  |  Branch (29:30): [True: 1, False: 0]
  |  Branch (29:59): [True: 1, False: 0]
  ------------------
   30|      1|         oss << val;
   31|      1|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|      1|      } else {
   33|      0|         oss << format[i];
   34|      0|      }
   35|       |
   36|      0|      i += 1;
   37|      0|   }
   38|      1|}
_ZN5Botan10fmt_detail6do_fmtIPKcJS3_EEEvRNSt3__119basic_ostringstreamIcNS4_11char_traitsIcEENS4_9allocatorIcEEEENS4_17basic_string_viewIcS7_EERKT_DpRKT0_:
   25|      1|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|      1|   size_t i = 0;
   27|       |
   28|      5|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 5, False: 0]
  ------------------
   29|      5|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 1, False: 4]
  |  Branch (29:30): [True: 1, False: 0]
  |  Branch (29:59): [True: 1, False: 0]
  ------------------
   30|      1|         oss << val;
   31|      1|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|      4|      } else {
   33|      4|         oss << format[i];
   34|      4|      }
   35|       |
   36|      4|      i += 1;
   37|      4|   }
   38|      1|}
_ZN5Botan10fmt_detail6do_fmtIPKcJEEEvRNSt3__119basic_ostringstreamIcNS4_11char_traitsIcEENS4_9allocatorIcEEEENS4_17basic_string_viewIcS7_EERKT_DpRKT0_:
   25|      1|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|      1|   size_t i = 0;
   27|       |
   28|      2|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 2, False: 0]
  ------------------
   29|      2|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 1, False: 1]
  |  Branch (29:30): [True: 1, False: 0]
  |  Branch (29:59): [True: 1, False: 0]
  ------------------
   30|      1|         oss << val;
   31|      1|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|      1|      } else {
   33|      1|         oss << format[i];
   34|      1|      }
   35|       |
   36|      1|      i += 1;
   37|      1|   }
   38|      1|}
_ZN5Botan10fmt_detail6do_fmtERNSt3__119basic_ostringstreamIcNS1_11char_traitsIcEENS1_9allocatorIcEEEENS1_17basic_string_viewIcS4_EE:
   20|      1|inline void do_fmt(std::ostringstream& oss, std::string_view format) {
   21|      1|   oss << format;
   22|      1|}

_ZN5Botan11checked_mulITkNSt3__117unsigned_integralEmEENS1_8optionalIT_EES3_S3_:
   46|   262k|constexpr inline std::optional<T> checked_mul(T a, T b) {
   47|       |   // Multiplication by 1U is a hack to work around C's insane
   48|       |   // integer promotion rules.
   49|       |   // https://stackoverflow.com/questions/24795651
   50|   262k|   const T r = (1U * a) * b;
   51|       |   // If a == 0 then the multiply certainly did not overflow
   52|       |   // Otherwise r / a == b unless overflow occurred
   53|   262k|   if(a != 0 && r / a != b) {
  ------------------
  |  Branch (53:7): [True: 262k, False: 0]
  |  Branch (53:17): [True: 0, False: 262k]
  ------------------
   54|      0|      return {};
   55|      0|   }
   56|   262k|   return r;
   57|   262k|}

_ZN5Botan8store_beINS_6detail10AutoDetectEJRKmPhEEEDaDpOT0_:
  745|      4|inline constexpr auto store_be(ParamTs&&... params) {
  746|      4|   return detail::store_any<std::endian::big, ModifierT>(std::forward<ParamTs>(params)...);
  747|      4|}
_ZN5Botan6detail9store_anyILNSt3__16endianE64206ENS0_10AutoDetectETkNS0_20unsigned_integralishEmQoosr3stdE7same_asIS4_T0_Esr3stdE7same_asIT1_S5_EEEvS6_Ph:
  711|      4|inline constexpr void store_any(T in, uint8_t out[]) {
  712|       |   // asserts that *out points to enough bytes to write into
  713|      4|   store_any<endianness, InT>(in, std::span<uint8_t, sizeof(T)>(out, sizeof(T)));
  714|      4|}
_ZN5Botan6detail9store_anyILNSt3__16endianE64206ENS0_10AutoDetectETkNS0_20unsigned_integralishEmTkNS_6ranges23contiguous_output_rangeIhEENS2_4spanIhLm8EEEQsr3stdE7same_asIS4_T0_EEEvT1_OT2_:
  646|      4|inline constexpr void store_any(T in, OutR&& out_range) {
  647|      4|   store_any<endianness, T>(in, std::forward<OutR>(out_range));
  648|      4|}
_ZN5Botan6detail9store_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEmTkNS_6ranges23contiguous_output_rangeIhEENS2_4spanIhLm8EEEQnt15custom_storableINS0_19wrapped_type_helperIu14__remove_cvrefIT0_EE4typeEEEEvS9_OT1_:
  525|      4|inline constexpr void store_any(WrappedInT wrapped_in, OutR&& out_range) {
  526|      4|   const auto in = detail::unwrap_strong_type_or_enum(wrapped_in);
  527|      4|   using InT = decltype(in);
  528|      4|   ranges::assert_exact_byte_length<sizeof(in)>(out_range);
  529|      4|   const std::span out{out_range};
  530|       |
  531|       |   // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  532|       |   // internally to copy ranges on a byte-by-byte basis, which is not allowed
  533|       |   // in a `constexpr` context.
  534|      4|   if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  ------------------
  |  Branch (534:7): [Folded, False: 4]
  ------------------
  535|      0|      return fallback_store_any<endianness, InT>(in, std::forward<OutR>(out_range));
  536|      4|   } else {
  537|       |      if constexpr(sizeof(InT) == 1) {
  538|       |         out[0] = static_cast<uint8_t>(in);
  539|       |      } else if constexpr(endianness == std::endian::native) {
  540|       |         typecast_copy(out, in);
  541|      4|      } else {
  542|      4|         static_assert(opposite(endianness) == std::endian::native);
  543|      4|         typecast_copy(out, reverse_bytes(in));
  544|      4|      }
  545|      4|   }
  546|      4|}
_ZN5Botan6detail26unwrap_strong_type_or_enumITkNS0_20unsigned_integralishEmEEDaT_:
  190|      4|constexpr auto unwrap_strong_type_or_enum(InT t) {
  191|       |   if constexpr(std::is_enum_v<InT>) {
  192|       |      // TODO: C++23: use std::to_underlying(in) instead
  193|       |      return static_cast<std::underlying_type_t<InT>>(t);
  194|      4|   } else {
  195|      4|      return Botan::unwrap_strong_type(t);
  196|      4|   }
  197|      4|}
_ZN5Botan7load_beImJNSt3__14spanIKhLm8EEEEEEDaDpOT0_:
  504|  1.45k|inline constexpr auto load_be(ParamTs&&... params) {
  505|  1.45k|   return detail::load_any<std::endian::big, OutT>(std::forward<ParamTs>(params)...);
  506|  1.45k|}
_ZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEmTkNS_6ranges16contiguous_rangeIhEENS2_4spanIKhLm8EEEQnt15custom_loadableINS0_19wrapped_type_helperIu14__remove_cvrefIT0_EE4typeEEEESA_OT1_:
  278|  1.45k|inline constexpr WrappedOutT load_any(InR&& in_range) {
  279|  1.45k|   using OutT = detail::wrapped_type<WrappedOutT>;
  280|  1.45k|   ranges::assert_exact_byte_length<sizeof(OutT)>(in_range);
  281|       |
  282|  1.45k|   return detail::wrap_strong_type_or_enum<WrappedOutT>([&]() -> OutT {
  283|       |      // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  284|       |      // internally to copy ranges on a byte-by-byte basis, which is not allowed
  285|       |      // in a `constexpr` context.
  286|  1.45k|      if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  287|  1.45k|         return fallback_load_any<endianness, OutT>(std::forward<InR>(in_range));
  288|  1.45k|      } else {
  289|  1.45k|         const std::span in{in_range};
  290|  1.45k|         if constexpr(sizeof(OutT) == 1) {
  291|  1.45k|            return static_cast<OutT>(in[0]);
  292|  1.45k|         } else if constexpr(endianness == std::endian::native) {
  293|  1.45k|            return typecast_copy<OutT>(in);
  294|  1.45k|         } else {
  295|  1.45k|            static_assert(opposite(endianness) == std::endian::native);
  296|  1.45k|            return reverse_bytes(typecast_copy<OutT>(in));
  297|  1.45k|         }
  298|  1.45k|      }
  299|  1.45k|   }());
  300|  1.45k|}
_ZN5Botan6detail24wrap_strong_type_or_enumITkNS0_20unsigned_integralishEmTkNSt3__117unsigned_integralEmEEDaT0_:
  200|  2.37k|constexpr auto wrap_strong_type_or_enum(T t) {
  201|       |   if constexpr(std::is_enum_v<OutT>) {
  202|       |      return static_cast<OutT>(t);
  203|  2.37k|   } else {
  204|  2.37k|      return Botan::wrap_strong_type<OutT>(t);
  205|  2.37k|   }
  206|  2.37k|}
_ZZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEmTkNS_6ranges16contiguous_rangeIhEENS2_4spanIKhLm8EEEQnt15custom_loadableINS0_19wrapped_type_helperIu14__remove_cvrefIT0_EE4typeEEEESA_OT1_ENKUlvE_clEv:
  282|  1.45k|   return detail::wrap_strong_type_or_enum<WrappedOutT>([&]() -> OutT {
  283|       |      // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  284|       |      // internally to copy ranges on a byte-by-byte basis, which is not allowed
  285|       |      // in a `constexpr` context.
  286|  1.45k|      if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  ------------------
  |  Branch (286:10): [Folded, False: 1.45k]
  ------------------
  287|      0|         return fallback_load_any<endianness, OutT>(std::forward<InR>(in_range));
  288|  1.45k|      } else {
  289|  1.45k|         const std::span in{in_range};
  290|       |         if constexpr(sizeof(OutT) == 1) {
  291|       |            return static_cast<OutT>(in[0]);
  292|       |         } else if constexpr(endianness == std::endian::native) {
  293|       |            return typecast_copy<OutT>(in);
  294|  1.45k|         } else {
  295|  1.45k|            static_assert(opposite(endianness) == std::endian::native);
  296|  1.45k|            return reverse_bytes(typecast_copy<OutT>(in));
  297|  1.45k|         }
  298|  1.45k|      }
  299|  1.45k|   }());
_ZN5Botan7load_beImJRNSt3__15arrayIhLm8EEEEEEDaDpOT0_:
  504|    913|inline constexpr auto load_be(ParamTs&&... params) {
  505|    913|   return detail::load_any<std::endian::big, OutT>(std::forward<ParamTs>(params)...);
  506|    913|}
_ZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEmTkNS_6ranges16contiguous_rangeIhEERNS2_5arrayIhLm8EEEQnt15custom_loadableINS0_19wrapped_type_helperIu14__remove_cvrefIT0_EE4typeEEEESA_OT1_:
  278|    913|inline constexpr WrappedOutT load_any(InR&& in_range) {
  279|    913|   using OutT = detail::wrapped_type<WrappedOutT>;
  280|    913|   ranges::assert_exact_byte_length<sizeof(OutT)>(in_range);
  281|       |
  282|    913|   return detail::wrap_strong_type_or_enum<WrappedOutT>([&]() -> OutT {
  283|       |      // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  284|       |      // internally to copy ranges on a byte-by-byte basis, which is not allowed
  285|       |      // in a `constexpr` context.
  286|    913|      if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  287|    913|         return fallback_load_any<endianness, OutT>(std::forward<InR>(in_range));
  288|    913|      } else {
  289|    913|         const std::span in{in_range};
  290|    913|         if constexpr(sizeof(OutT) == 1) {
  291|    913|            return static_cast<OutT>(in[0]);
  292|    913|         } else if constexpr(endianness == std::endian::native) {
  293|    913|            return typecast_copy<OutT>(in);
  294|    913|         } else {
  295|    913|            static_assert(opposite(endianness) == std::endian::native);
  296|    913|            return reverse_bytes(typecast_copy<OutT>(in));
  297|    913|         }
  298|    913|      }
  299|    913|   }());
  300|    913|}
_ZZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEmTkNS_6ranges16contiguous_rangeIhEERNS2_5arrayIhLm8EEEQnt15custom_loadableINS0_19wrapped_type_helperIu14__remove_cvrefIT0_EE4typeEEEESA_OT1_ENKUlvE_clEv:
  282|    913|   return detail::wrap_strong_type_or_enum<WrappedOutT>([&]() -> OutT {
  283|       |      // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  284|       |      // internally to copy ranges on a byte-by-byte basis, which is not allowed
  285|       |      // in a `constexpr` context.
  286|    913|      if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  ------------------
  |  Branch (286:10): [Folded, False: 913]
  ------------------
  287|      0|         return fallback_load_any<endianness, OutT>(std::forward<InR>(in_range));
  288|    913|      } else {
  289|    913|         const std::span in{in_range};
  290|       |         if constexpr(sizeof(OutT) == 1) {
  291|       |            return static_cast<OutT>(in[0]);
  292|       |         } else if constexpr(endianness == std::endian::native) {
  293|       |            return typecast_copy<OutT>(in);
  294|    913|         } else {
  295|    913|            static_assert(opposite(endianness) == std::endian::native);
  296|    913|            return reverse_bytes(typecast_copy<OutT>(in));
  297|    913|         }
  298|    913|      }
  299|    913|   }());
_ZN5Botan6detail9store_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEjTkNS_6ranges23contiguous_output_rangeIhEENS2_4spanIhLm4EEEQnt15custom_storableINS0_19wrapped_type_helperIu14__remove_cvrefIT0_EE4typeEEEEvS9_OT1_:
  525|     32|inline constexpr void store_any(WrappedInT wrapped_in, OutR&& out_range) {
  526|     32|   const auto in = detail::unwrap_strong_type_or_enum(wrapped_in);
  527|     32|   using InT = decltype(in);
  528|     32|   ranges::assert_exact_byte_length<sizeof(in)>(out_range);
  529|     32|   const std::span out{out_range};
  530|       |
  531|       |   // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  532|       |   // internally to copy ranges on a byte-by-byte basis, which is not allowed
  533|       |   // in a `constexpr` context.
  534|     32|   if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  ------------------
  |  Branch (534:7): [Folded, False: 32]
  ------------------
  535|      0|      return fallback_store_any<endianness, InT>(in, std::forward<OutR>(out_range));
  536|     32|   } else {
  537|       |      if constexpr(sizeof(InT) == 1) {
  538|       |         out[0] = static_cast<uint8_t>(in);
  539|       |      } else if constexpr(endianness == std::endian::native) {
  540|       |         typecast_copy(out, in);
  541|     32|      } else {
  542|     32|         static_assert(opposite(endianness) == std::endian::native);
  543|     32|         typecast_copy(out, reverse_bytes(in));
  544|     32|      }
  545|     32|   }
  546|     32|}
_ZN5Botan6detail26unwrap_strong_type_or_enumITkNS0_20unsigned_integralishEjEEDaT_:
  190|     32|constexpr auto unwrap_strong_type_or_enum(InT t) {
  191|       |   if constexpr(std::is_enum_v<InT>) {
  192|       |      // TODO: C++23: use std::to_underlying(in) instead
  193|       |      return static_cast<std::underlying_type_t<InT>>(t);
  194|     32|   } else {
  195|     32|      return Botan::unwrap_strong_type(t);
  196|     32|   }
  197|     32|}
_ZN5Botan11copy_out_beITkNS_6ranges14spanable_rangeENSt3__16vectorIjNS_16secure_allocatorIjEEEEEEvNS2_4spanIhLm18446744073709551615EEERKT_:
  773|      4|inline void copy_out_be(std::span<uint8_t> out, const InR& in) {
  774|      4|   using T = std::ranges::range_value_t<InR>;
  775|      4|   std::span<const T> in_s{in};
  776|      4|   const auto remaining_bytes = detail::copy_out_any_word_aligned_portion<std::endian::big>(out, in_s);
  777|       |
  778|       |   // copy remaining bytes as a partial word
  779|      4|   for(size_t i = 0; i < remaining_bytes; ++i) {
  ------------------
  |  Branch (779:22): [True: 0, False: 4]
  ------------------
  780|      0|      out[i] = get_byte_var(i, in_s.front());
  781|      0|   }
  782|      4|}
_ZN5Botan6detail33copy_out_any_word_aligned_portionILNSt3__16endianE64206ETkNS0_20unsigned_integralishEjEEmRNS2_4spanIhLm18446744073709551615EEERNS4_IKT0_Lm18446744073709551615EEE:
  752|      4|inline size_t copy_out_any_word_aligned_portion(std::span<uint8_t>& out, std::span<const T>& in) {
  753|      4|   const size_t full_words = out.size() / sizeof(T);
  754|      4|   const size_t full_word_bytes = full_words * sizeof(T);
  755|      4|   const size_t remaining_bytes = out.size() - full_word_bytes;
  756|      4|   BOTAN_ASSERT_NOMSG(in.size_bytes() >= full_word_bytes + remaining_bytes);
  ------------------
  |  |   77|      4|   do {                                                                     \
  |  |   78|      4|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|      4|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 4]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|      4|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 4]
  |  |  ------------------
  ------------------
  757|       |
  758|       |   // copy full words
  759|      4|   store_any<endianness, T>(out.first(full_word_bytes), in.first(full_words));
  760|      4|   out = out.subspan(full_word_bytes);
  761|      4|   in = in.subspan(full_words);
  762|       |
  763|      4|   return remaining_bytes;
  764|      4|}
_ZN5Botan6detail9store_anyILNSt3__16endianE64206EjTkNS_6ranges23contiguous_output_rangeIhEENS2_4spanIhLm18446744073709551615EEETkNS4_14spanable_rangeENS6_IKjLm18446744073709551615EEEQoosr3stdE7same_asINS0_10AutoDetectET0_Esr3stdE7same_asISB_NS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT2_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISJ_EESK_E4type10value_typeEEEEvOT1_RKSG_:
  603|      4|inline constexpr void store_any(OutR&& out /* NOLINT(*-std-forward) */, const InR& in) {
  604|      4|   ranges::assert_equal_byte_lengths(out, in);
  605|      4|   using element_type = std::ranges::range_value_t<InR>;
  606|       |
  607|      4|   auto store_elementwise = [&] {
  608|      4|      constexpr size_t bytes_per_element = sizeof(element_type);
  609|      4|      std::span<uint8_t> out_s(out);
  610|      4|      for(auto in_elem : in) {
  611|      4|         store_any<endianness, element_type>(out_s.template first<bytes_per_element>(), in_elem);
  612|      4|         out_s = out_s.subspan(bytes_per_element);
  613|      4|      }
  614|      4|   };
  615|       |
  616|       |   // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  617|       |   // internally to copy ranges on a byte-by-byte basis, which is not allowed
  618|       |   // in a `constexpr` context.
  619|      4|   if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  ------------------
  |  Branch (619:7): [Folded, False: 4]
  ------------------
  620|      0|      store_elementwise();
  621|      4|   } else {
  622|       |      if constexpr(endianness == std::endian::native && !custom_storable<element_type>) {
  623|       |         typecast_copy(out, in);
  624|      4|      } else {
  625|      4|         store_elementwise();
  626|      4|      }
  627|      4|   }
  628|      4|}
_ZZN5Botan6detail9store_anyILNSt3__16endianE64206EjTkNS_6ranges23contiguous_output_rangeIhEENS2_4spanIhLm18446744073709551615EEETkNS4_14spanable_rangeENS6_IKjLm18446744073709551615EEEQoosr3stdE7same_asINS0_10AutoDetectET0_Esr3stdE7same_asISB_NS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT2_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISJ_EESK_E4type10value_typeEEEEvOT1_RKSG_ENKUlvE_clEv:
  607|      4|   auto store_elementwise = [&] {
  608|      4|      constexpr size_t bytes_per_element = sizeof(element_type);
  609|      4|      std::span<uint8_t> out_s(out);
  610|     32|      for(auto in_elem : in) {
  ------------------
  |  Branch (610:24): [True: 32, False: 4]
  ------------------
  611|     32|         store_any<endianness, element_type>(out_s.template first<bytes_per_element>(), in_elem);
  612|     32|         out_s = out_s.subspan(bytes_per_element);
  613|     32|      }
  614|      4|   };
_ZN5Botan6detail9store_anyILNSt3__16endianE64206EjTkNS_6ranges23contiguous_output_rangeIhEENS2_4spanIhLm4EEETpTkNS0_20unsigned_integralishEJjEQaagtsZT2_Li0Eooaasr3stdE7same_asINS0_10AutoDetectET0_E10all_same_vIDpT2_Eaa20unsigned_integralishIS9_E10all_same_vIS9_SB_EEEvOT1_SB_:
  582|     32|inline constexpr void store_any(OutR&& out /* NOLINT(*-std-forward) */, Ts... ins) {
  583|     32|   ranges::assert_exact_byte_length<(sizeof(Ts) + ...)>(out);
  584|     32|   auto store_one = [off = 0]<typename T>(auto o, T i) mutable {
  585|     32|      store_any<endianness, T>(i, o.subspan(off).template first<sizeof(T)>());
  586|     32|      off += sizeof(T);
  587|     32|   };
  588|       |
  589|     32|   (store_one(std::span{out}, ins), ...);
  590|     32|}
_ZZN5Botan6detail9store_anyILNSt3__16endianE64206EjTkNS_6ranges23contiguous_output_rangeIhEENS2_4spanIhLm4EEETpTkNS0_20unsigned_integralishEJjEQaagtsZT2_Li0Eooaasr3stdE7same_asINS0_10AutoDetectET0_E10all_same_vIDpT2_Eaa20unsigned_integralishIS9_E10all_same_vIS9_SB_EEEvOT1_SB_ENUlTyS9_T_E_clIjS7_EEDaS9_SE_:
  584|     32|   auto store_one = [off = 0]<typename T>(auto o, T i) mutable {
  585|     32|      store_any<endianness, T>(i, o.subspan(off).template first<sizeof(T)>());
  586|     32|      off += sizeof(T);
  587|     32|   };
_ZN5Botan7load_leIjJPjPKhmEEEDaDpOT0_:
  495|      2|inline constexpr auto load_le(ParamTs&&... params) {
  496|      2|   return detail::load_any<std::endian::little, OutT>(std::forward<ParamTs>(params)...);
  497|      2|}
_ZN5Botan6detail8load_anyILNSt3__16endianE57005EjTkNS0_20unsigned_integralishEjQoosr3stdE7same_asINS0_10AutoDetectET0_Esr3stdE7same_asIT1_S5_EEEvPS6_PKhm:
  483|      2|inline constexpr void load_any(T out[], const uint8_t in[], size_t count) {
  484|       |   // asserts that *in and *out point to the correct amount of memory
  485|      2|   load_any<endianness, OutT>(std::span<T>(out, count), std::span<const uint8_t>(in, count * sizeof(T)));
  486|      2|}
_ZN5Botan6detail8load_anyILNSt3__16endianE57005EjTkNS_6ranges23contiguous_output_rangeENS2_4spanIjLm18446744073709551615EEETkNS4_16contiguous_rangeIhEENS5_IKhLm18446744073709551615EEEQaa20unsigned_integralishINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT1_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISH_EESI_E4type10value_typeEEoosr3stdE7same_asINS0_10AutoDetectET0_Esr3stdE7same_asISP_SN_EEEvOSE_RKT2_:
  355|      2|inline constexpr void load_any(OutR&& out /* NOLINT(*-std-forward) */, const InR& in) {
  356|      2|   ranges::assert_equal_byte_lengths(out, in);
  357|      2|   using element_type = std::ranges::range_value_t<OutR>;
  358|       |
  359|      2|   auto load_elementwise = [&] {
  360|      2|      constexpr size_t bytes_per_element = sizeof(element_type);
  361|      2|      std::span<const uint8_t> in_s(in);
  362|      2|      for(auto& out_elem : out) {
  363|      2|         out_elem = load_any<endianness, element_type>(in_s.template first<bytes_per_element>());
  364|      2|         in_s = in_s.subspan(bytes_per_element);
  365|      2|      }
  366|      2|   };
  367|       |
  368|       |   // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  369|       |   // internally to copy ranges on a byte-by-byte basis, which is not allowed
  370|       |   // in a `constexpr` context.
  371|      2|   if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  ------------------
  |  Branch (371:7): [Folded, False: 2]
  ------------------
  372|      0|      load_elementwise();
  373|      2|   } else {
  374|      2|      if constexpr(endianness == std::endian::native && !custom_loadable<element_type>) {
  375|      2|         typecast_copy(out, in);
  376|       |      } else {
  377|       |         load_elementwise();
  378|       |      }
  379|      2|   }
  380|      2|}

_ZN5Botan18MerkleDamgard_HashINS_7SHA_256EEC2Ev:
   42|      1|      MerkleDamgard_Hash() { clear(); }
_ZN5Botan18MerkleDamgard_HashINS_7SHA_256EE5clearEv:
   70|      7|      void clear() {
   71|      7|         MD::init(m_digest);
   72|      7|         m_buffer.clear();
   73|      7|         m_count = 0;
   74|      7|      }
_ZN5Botan18MerkleDamgard_HashINS_7SHA_256EE6updateENSt3__14spanIKhLm18446744073709551615EEE:
   44|      9|      void update(std::span<const uint8_t> input) {
   45|      9|         BufferSlicer in(input);
   46|       |
   47|     18|         while(!in.empty()) {
  ------------------
  |  Branch (47:16): [True: 9, False: 9]
  ------------------
   48|      9|            if(const auto one_block = m_buffer.handle_unaligned_data(in)) {
  ------------------
  |  Branch (48:27): [True: 0, False: 9]
  ------------------
   49|      0|               MD::compress_n(m_digest, one_block.value(), 1);
   50|      0|            }
   51|       |
   52|      9|            if(m_buffer.in_alignment()) {
  ------------------
  |  Branch (52:16): [True: 6, False: 3]
  ------------------
   53|      6|               const auto [aligned_data, full_blocks] = m_buffer.aligned_data_to_process(in);
   54|      6|               if(full_blocks > 0) {
  ------------------
  |  Branch (54:19): [True: 6, False: 0]
  ------------------
   55|      6|                  MD::compress_n(m_digest, aligned_data, full_blocks);
   56|      6|               }
   57|      6|            }
   58|      9|         }
   59|       |
   60|      9|         m_count += input.size();
   61|      9|      }
_ZN5Botan18MerkleDamgard_HashINS_7SHA_256EE5finalENSt3__14spanIhLm18446744073709551615EEE:
   63|      4|      void final(std::span<uint8_t> output) {
   64|      4|         append_padding_bit();
   65|      4|         append_counter_and_finalize();
   66|      4|         copy_output(output);
   67|      4|         clear();
   68|      4|      }
_ZN5Botan18MerkleDamgard_HashINS_7SHA_256EE18append_padding_bitEv:
   77|      4|      void append_padding_bit() {
   78|      4|         BOTAN_ASSERT_NOMSG(!m_buffer.ready_to_consume());
  ------------------
  |  |   77|      4|   do {                                                                     \
  |  |   78|      4|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|      4|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 4]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|      4|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 4]
  |  |  ------------------
  ------------------
   79|      4|         if constexpr(MD::bit_endianness == MD_Endian::Big) {
   80|      4|            const uint8_t final_byte = 0x80;
   81|      4|            m_buffer.append({&final_byte, 1});
   82|       |         } else {
   83|       |            const uint8_t final_byte = 0x01;
   84|       |            m_buffer.append({&final_byte, 1});
   85|       |         }
   86|      4|      }
_ZN5Botan18MerkleDamgard_HashINS_7SHA_256EE27append_counter_and_finalizeEv:
   88|      4|      void append_counter_and_finalize() {
   89|       |         // Compress the remaining data if the final data block does not provide
   90|       |         // enough space for the counter bytes.
   91|      4|         if(m_buffer.elements_until_alignment() < MD::ctr_bytes) {
  ------------------
  |  Branch (91:13): [True: 0, False: 4]
  ------------------
   92|      0|            m_buffer.fill_up_with_zeros();
   93|      0|            MD::compress_n(m_digest, m_buffer.consume(), 1);
   94|      0|         }
   95|       |
   96|       |         // Make sure that any remaining bytes in the very last block are zero.
   97|      4|         BOTAN_ASSERT_NOMSG(m_buffer.elements_until_alignment() >= MD::ctr_bytes);
  ------------------
  |  |   77|      4|   do {                                                                     \
  |  |   78|      4|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|      4|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 4]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|      4|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 4]
  |  |  ------------------
  ------------------
   98|      4|         m_buffer.fill_up_with_zeros();
   99|       |
  100|       |         // Replace a bunch of the right-most zero-padding with the counter bytes.
  101|      4|         const uint64_t bit_count = m_count * 8;
  102|      4|         auto last_bytes = m_buffer.directly_modify_last(sizeof(bit_count));
  103|      4|         if constexpr(MD::byte_endianness == MD_Endian::Big) {
  104|      4|            store_be(bit_count, last_bytes.data());
  105|       |         } else {
  106|       |            store_le(bit_count, last_bytes.data());
  107|       |         }
  108|       |
  109|       |         // Compress the very last block.
  110|      4|         MD::compress_n(m_digest, m_buffer.consume(), 1);
  111|      4|      }
_ZN5Botan18MerkleDamgard_HashINS_7SHA_256EE11copy_outputENSt3__14spanIhLm18446744073709551615EEE:
  113|      4|      void copy_output(std::span<uint8_t> output) {
  114|      4|         BOTAN_ASSERT_NOMSG(output.size() >= MD::output_bytes);
  ------------------
  |  |   77|      4|   do {                                                                     \
  |  |   78|      4|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|      4|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 4]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|      4|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 4]
  |  |  ------------------
  ------------------
  115|       |
  116|      4|         if constexpr(MD::byte_endianness == MD_Endian::Big) {
  117|      4|            copy_out_be(output.first(MD::output_bytes), m_digest);
  118|       |         } else {
  119|       |            copy_out_le(output.first(MD::output_bytes), m_digest);
  120|       |         }
  121|      4|      }

_ZN5Botan14zeroize_bufferITkNSt3__117unsigned_integralEmEEvPT_m:
   37|  1.05M|inline void zeroize_buffer(T buf[], size_t n) {
   38|  1.05M|   if(n > 0) {
  ------------------
  |  Branch (38:7): [True: 965k, False: 88.6k]
  ------------------
   39|   965k|      std::memset(buf, 0, sizeof(T) * n);
   40|   965k|   }
   41|  1.05M|}
_ZN5Botan21unchecked_copy_memoryITkNSt3__117unsigned_integralEmEEvPT_PKS2_m:
   44|   117k|inline void unchecked_copy_memory(T* out, const T* in, size_t n) {
   45|   117k|   if(in != nullptr && out != nullptr && n > 0) {
  ------------------
  |  Branch (45:7): [True: 117k, False: 0]
  |  Branch (45:24): [True: 117k, False: 0]
  |  Branch (45:42): [True: 117k, False: 0]
  ------------------
   46|   117k|      std::memmove(out, in, sizeof(T) * n);
   47|   117k|   }
   48|   117k|}
_ZN5Botan14zeroize_bufferITkNSt3__117unsigned_integralEhEEvPT_m:
   37|     11|inline void zeroize_buffer(T buf[], size_t n) {
   38|     11|   if(n > 0) {
  ------------------
  |  Branch (38:7): [True: 11, False: 0]
  ------------------
   39|     11|      std::memset(buf, 0, sizeof(T) * n);
   40|     11|   }
   41|     11|}

_ZNK5Botan17Montgomery_Params1pEv:
   41|   451k|      const BigInt& p() const { return m_data->p(); }
_ZNK5Botan17Montgomery_Params2R1Ev:
   43|  2.38k|      const BigInt& R1() const { return m_data->r1(); }
_ZNK5Botan17Montgomery_Params2R2Ev:
   45|  2.38k|      const BigInt& R2() const { return m_data->r2(); }
_ZNK5Botan17Montgomery_Params6p_dashEv:
   49|   443k|      word p_dash() const { return m_data->p_dash(); }
_ZNK5Botan17Montgomery_Params7p_wordsEv:
   51|   233k|      size_t p_words() const { return m_data->p_size(); }
_ZNK5Botan17Montgomery_Params4Data1pEv:
   76|   451k|            const BigInt& p() const { return m_p; }
_ZNK5Botan17Montgomery_Params4Data2r1Ev:
   78|  2.38k|            const BigInt& r1() const { return m_r1; }
_ZNK5Botan17Montgomery_Params4Data2r2Ev:
   80|  2.38k|            const BigInt& r2() const { return m_r2; }
_ZNK5Botan17Montgomery_Params4Data6p_dashEv:
   84|   443k|            word p_dash() const { return m_p_dash; }
_ZNK5Botan17Montgomery_Params4Data6p_sizeEv:
   86|   233k|            size_t p_size() const { return m_p_words; }
_ZNK5Botan14Montgomery_Int4reprEv:
  143|  44.0k|      const secure_vector<word>& repr() const { return m_v; }
_ZNK5Botan14Montgomery_Int18_const_time_poisonEv:
  159|    688|      void _const_time_poison() const { CT::poison(m_v); }
_ZNK5Botan14Montgomery_Int20_const_time_unpoisonEv:
  161|  2.38k|      void _const_time_unpoison() const { CT::unpoison(m_v); }
_ZNK5Botan14Montgomery_Int7_paramsEv:
  163|  2.38k|      const Montgomery_Params& _params() const { return m_params; }

_ZN5Botan17monty_exp_vartimeERKNS_17Montgomery_ParamsERKNS_6BigIntES5_:
   54|  2.33k|inline Montgomery_Int monty_exp_vartime(const Montgomery_Params& params_p, const BigInt& g, const BigInt& k) {
   55|  2.33k|   auto precomputed = monty_precompute(params_p, g, 4, false);
   56|  2.33k|   return monty_execute_vartime(*precomputed, k);
   57|  2.33k|}

_ZN5Botan8word_addITkNS_8WordTypeEmEET_S1_S1_PS1_:
  231|  18.5k|inline constexpr auto word_add(W x, W y, W* carry) -> W {
  232|  18.5k|#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_addc)
  233|  18.5k|   if(!std::is_constant_evaluated()) {
  ------------------
  |  Branch (233:7): [True: 18.5k, Folded]
  ------------------
  234|       |      if constexpr(std::same_as<W, unsigned int>) {
  235|       |         return __builtin_addc(x, y, *carry & 1, carry);
  236|  18.5k|      } else if constexpr(std::same_as<W, unsigned long>) {
  237|  18.5k|         return __builtin_addcl(x, y, *carry & 1, carry);
  238|       |      } else if constexpr(std::same_as<W, unsigned long long>) {
  239|       |         return __builtin_addcll(x, y, *carry & 1, carry);
  240|       |      }
  241|  18.5k|   }
  242|      0|#endif
  243|       |
  244|       |   if constexpr(WordInfo<W>::dword_is_native && use_dword_for_word_add) {
  245|       |      /*
  246|       |      TODO(Botan4) this is largely a performance hack for GCCs that don't
  247|       |      support __builtin_addc, if we increase the minimum supported version of
  248|       |      GCC to GCC 14 then we can remove this and not worry about it
  249|       |      */
  250|       |      const W cb = *carry & 1;
  251|       |      const auto s = typename WordInfo<W>::dword(x) + y + cb;
  252|       |      *carry = static_cast<W>(s >> WordInfo<W>::bits);
  253|       |      return static_cast<W>(s);
  254|  18.5k|   } else {
  255|  18.5k|      const W cb = *carry & 1;
  256|  18.5k|      W z = x + y;
  257|  18.5k|      W c1 = (z < x);
  258|  18.5k|      z += cb;
  259|  18.5k|      *carry = c1 | (z < cb);
  260|  18.5k|      return z;
  261|  18.5k|   }
  262|  18.5k|}
_ZN5Botan10word8_sub2ITkNS_8WordTypeEmEET_PS1_PKS1_S1_:
  345|  1.35k|inline constexpr auto word8_sub2(W x[8], const W y[8], W carry) -> W {
  346|  1.35k|#if defined(BOTAN_MP_USE_X86_64_ASM)
  347|  1.35k|   if(std::same_as<W, uint64_t> && !std::is_constant_evaluated()) {
  ------------------
  |  Branch (347:7): [True: 0, Folded]
  |  Branch (347:36): [True: 0, Folded]
  ------------------
  348|  1.35k|      asm volatile(ADD_OR_SUBTRACT(DO_8_TIMES(ADDSUB2_OP, "sbbq"))
  349|  1.35k|                   : [carry] "=r"(carry)
  350|  1.35k|                   : [x] "r"(x), [y] "r"(y), "0"(carry)
  351|  1.35k|                   : "cc", "memory");
  352|  1.35k|      return carry;
  353|  1.35k|   }
  354|      0|#endif
  355|       |
  356|      0|   x[0] = word_sub(x[0], y[0], &carry);
  357|      0|   x[1] = word_sub(x[1], y[1], &carry);
  358|      0|   x[2] = word_sub(x[2], y[2], &carry);
  359|      0|   x[3] = word_sub(x[3], y[3], &carry);
  360|      0|   x[4] = word_sub(x[4], y[4], &carry);
  361|      0|   x[5] = word_sub(x[5], y[5], &carry);
  362|      0|   x[6] = word_sub(x[6], y[6], &carry);
  363|      0|   x[7] = word_sub(x[7], y[7], &carry);
  364|      0|   return carry;
  365|  1.35k|}
_ZN5Botan8word_subITkNS_8WordTypeEmEET_S1_S1_PS1_:
  320|  2.27M|inline constexpr auto word_sub(W x, W y, W* carry) -> W {
  321|  2.27M|#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_subc)
  322|  2.27M|   if(!std::is_constant_evaluated()) {
  ------------------
  |  Branch (322:7): [True: 2.27M, Folded]
  ------------------
  323|       |      if constexpr(std::same_as<W, unsigned int>) {
  324|       |         return __builtin_subc(x, y, *carry & 1, carry);
  325|  2.27M|      } else if constexpr(std::same_as<W, unsigned long>) {
  326|  2.27M|         return __builtin_subcl(x, y, *carry & 1, carry);
  327|       |      } else if constexpr(std::same_as<W, unsigned long long>) {
  328|       |         return __builtin_subcll(x, y, *carry & 1, carry);
  329|       |      }
  330|  2.27M|   }
  331|      0|#endif
  332|       |
  333|      0|   const W cb = *carry & 1;
  334|  2.27M|   W t0 = x - y;
  335|  2.27M|   W c1 = (t0 > x);
  336|  2.27M|   W z = t0 - cb;
  337|  2.27M|   *carry = c1 | (z > t0);
  338|  2.27M|   return z;
  339|  2.27M|}
_ZN5Botan10word8_sub3ITkNS_8WordTypeEmEET_PS1_PKS1_S4_S1_:
  371|    675|inline constexpr auto word8_sub3(W z[8], const W x[8], const W y[8], W carry) -> W {
  372|    675|#if defined(BOTAN_MP_USE_X86_64_ASM)
  373|    675|   if(std::same_as<W, uint64_t> && !std::is_constant_evaluated()) {
  ------------------
  |  Branch (373:7): [True: 0, Folded]
  |  Branch (373:36): [True: 0, Folded]
  ------------------
  374|    675|      asm volatile(ADD_OR_SUBTRACT(DO_8_TIMES(ADDSUB3_OP, "sbbq"))
  375|    675|                   : [carry] "=r"(carry)
  376|    675|                   : [x] "r"(x), [y] "r"(y), [z] "r"(z), "0"(carry)
  377|    675|                   : "cc", "memory");
  378|    675|      return carry;
  379|    675|   }
  380|      0|#endif
  381|       |
  382|      0|   z[0] = word_sub(x[0], y[0], &carry);
  383|      0|   z[1] = word_sub(x[1], y[1], &carry);
  384|      0|   z[2] = word_sub(x[2], y[2], &carry);
  385|      0|   z[3] = word_sub(x[3], y[3], &carry);
  386|      0|   z[4] = word_sub(x[4], y[4], &carry);
  387|      0|   z[5] = word_sub(x[5], y[5], &carry);
  388|      0|   z[6] = word_sub(x[6], y[6], &carry);
  389|      0|   z[7] = word_sub(x[7], y[7], &carry);
  390|      0|   return carry;
  391|    675|}
_ZN5Botan10word_madd2ITkNS_8WordTypeEmEET_S1_S1_PS1_:
   90|   111k|inline constexpr auto word_madd2(W a, W b, W* c) -> W {
   91|   111k|#if defined(BOTAN_MP_USE_X86_64_ASM)
   92|   111k|   if(std::same_as<W, uint64_t> && !std::is_constant_evaluated()) {
  ------------------
  |  Branch (92:7): [True: 0, Folded]
  |  Branch (92:36): [True: 0, Folded]
  ------------------
   93|   111k|      asm(R"(
   94|   111k|         mulq %[b]
   95|   111k|         addq %[c],%[a]
   96|   111k|         adcq $0,%[carry]
   97|   111k|         )"
   98|   111k|          : [a] "=a"(a), [b] "=rm"(b), [carry] "=&d"(*c)
   99|   111k|          : "0"(a), "1"(b), [c] "g"(*c)
  100|   111k|          : "cc");
  101|       |
  102|   111k|      return a;
  103|   111k|   }
  104|       |#elif defined(BOTAN_MP_USE_AARCH64_ASM)
  105|       |   if(std::same_as<W, uint64_t> && !std::is_constant_evaluated()) {
  106|       |      W lo = 0;
  107|       |      W hi = 0;
  108|       |      asm(R"(
  109|       |         mul  %[lo], %[a], %[b]
  110|       |         umulh %[hi], %[a], %[b]
  111|       |         adds %[lo], %[lo], %[c]
  112|       |         adc  %[hi], %[hi], xzr
  113|       |         )"
  114|       |          : [lo] "=&r"(lo), [hi] "=&r"(hi)
  115|       |          : [a] "r"(a), [b] "r"(b), [c] "r"(*c)
  116|       |          : "cc");
  117|       |
  118|       |      *c = hi;
  119|       |      return lo;
  120|       |   }
  121|       |#endif
  122|       |
  123|      0|   typedef typename WordInfo<W>::dword dword;
  124|      0|   const dword s = dword(a) * b + *c;
  125|      0|   *c = static_cast<W>(s >> WordInfo<W>::bits);
  126|      0|   return static_cast<W>(s);
  127|   111k|}
_ZN5Botan5word3ImEC2Ev:
  458|   922k|      constexpr word3() : m_w(0) {}
_ZN5Botan5word3ImE3mulEmm:
  460|  11.0M|      inline constexpr void mul(W x, W y) { m_w += static_cast<W3>(x) * y; }
_ZN5Botan5word3ImE7extractEv:
  466|  6.15M|      inline constexpr W extract() {
  467|  6.15M|         W r = static_cast<W>(m_w);
  468|  6.15M|         m_w >>= WordInfo<W>::bits;
  469|  6.15M|         return r;
  470|  6.15M|      }
_ZN5Botan5word3ImE6mul_x2Emm:
  462|  2.10M|      inline constexpr void mul_x2(W x, W y) { m_w += static_cast<W3>(x) * y * 2; }
_ZN5Botan5word3ImE3addEm:
  464|  3.55M|      inline constexpr void add(W x) { m_w += x; }
_ZN5Botan5word3ImE10monty_stepEmm:
  472|  1.77M|      inline constexpr W monty_step(W p0, W p_dash) {
  473|  1.77M|         const W w0 = static_cast<W>(m_w);
  474|  1.77M|         const W r = w0 * p_dash;
  475|  1.77M|         mul(r, p0);
  476|  1.77M|         m_w >>= WordInfo<W>::bits;
  477|  1.77M|         return r;
  478|  1.77M|      }

_ZN5Botan17bigint_monty_redcEPmPKmS2_mmS0_m:
  924|   443k|   word r[], const word z[], const word p[], size_t p_size, word p_dash, word ws[], size_t ws_size) {
  925|   443k|   const size_t z_size = 2 * p_size;
  926|       |
  927|   443k|   BOTAN_ARG_CHECK(ws_size >= p_size, "Montgomery reduction workspace too small");
  ------------------
  |  |   35|   443k|   do {                                                          \
  |  |   36|   443k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|   443k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 443k]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|   443k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 443k]
  |  |  ------------------
  ------------------
  928|       |
  929|   443k|   if(p_size == 4) {
  ------------------
  |  Branch (929:7): [True: 443k, False: 0]
  ------------------
  930|   443k|      bigint_monty_redc_4(r, z, p, p_dash, ws);
  931|   443k|   } else if(p_size == 6) {
  ------------------
  |  Branch (931:14): [True: 0, False: 0]
  ------------------
  932|      0|      bigint_monty_redc_6(r, z, p, p_dash, ws);
  933|      0|   } else if(p_size == 8) {
  ------------------
  |  Branch (933:14): [True: 0, False: 0]
  ------------------
  934|      0|      bigint_monty_redc_8(r, z, p, p_dash, ws);
  935|      0|   } else if(p_size == 12) {
  ------------------
  |  Branch (935:14): [True: 0, False: 0]
  ------------------
  936|      0|      bigint_monty_redc_12(r, z, p, p_dash, ws);
  937|      0|   } else if(p_size == 16) {
  ------------------
  |  Branch (937:14): [True: 0, False: 0]
  ------------------
  938|      0|      bigint_monty_redc_16(r, z, p, p_dash, ws);
  939|      0|   } else if(p_size == 24) {
  ------------------
  |  Branch (939:14): [True: 0, False: 0]
  ------------------
  940|      0|      bigint_monty_redc_24(r, z, p, p_dash, ws);
  941|      0|   } else if(p_size == 32) {
  ------------------
  |  Branch (941:14): [True: 0, False: 0]
  ------------------
  942|      0|      bigint_monty_redc_32(r, z, p, p_dash, ws);
  943|      0|   } else {
  944|      0|      bigint_monty_redc_generic(r, z, z_size, p, p_size, p_dash, ws);
  945|      0|   }
  946|   443k|}
_ZN5Botan25bigint_monty_redc_inplaceEPmPKmmmS0_m:
  948|   443k|inline void bigint_monty_redc_inplace(word z[], const word p[], size_t p_size, word p_dash, word ws[], size_t ws_size) {
  949|   443k|   bigint_monty_redc(z, z, p, p_size, p_dash, ws, ws_size);
  950|   443k|   zeroize_buffer(z + p_size, p_size);
  951|   443k|}
_ZN5Botan11bigint_add2ITkNS_8WordTypeEmEET_PS1_mPKS1_m:
   94|    101|inline constexpr auto bigint_add2(W x[], size_t x_size, const W y[], size_t y_size) -> W {
   95|    101|   W carry = 0;
   96|       |
   97|    101|   BOTAN_ASSERT(x_size >= y_size, "Expected sizes");
  ------------------
  |  |   64|    101|   do {                                                                                 \
  |  |   65|    101|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                                     \
  |  |   66|    101|      if(!(expr)) {                                                                     \
  |  |  ------------------
  |  |  |  Branch (66:10): [True: 0, False: 101]
  |  |  ------------------
  |  |   67|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                            \
  |  |   68|      0|         Botan::assertion_failure(#expr, assertion_made, __func__, __FILE__, __LINE__); \
  |  |   69|      0|      }                                                                                 \
  |  |   70|    101|   } while(0)
  |  |  ------------------
  |  |  |  Branch (70:12): [Folded, False: 101]
  |  |  ------------------
  ------------------
   98|       |
   99|    101|   const size_t blocks = y_size - (y_size % 8);
  100|       |
  101|    101|   for(size_t i = 0; i != blocks; i += 8) {
  ------------------
  |  Branch (101:22): [True: 0, False: 101]
  ------------------
  102|      0|      carry = word8_add2(x + i, y + i, carry);
  103|      0|   }
  104|       |
  105|    202|   for(size_t i = blocks; i != y_size; ++i) {
  ------------------
  |  Branch (105:27): [True: 101, False: 101]
  ------------------
  106|    101|      x[i] = word_add(x[i], y[i], &carry);
  107|    101|   }
  108|       |
  109|    707|   for(size_t i = y_size; i != x_size; ++i) {
  ------------------
  |  Branch (109:27): [True: 606, False: 101]
  ------------------
  110|    606|      x[i] = word_add(x[i], static_cast<W>(0), &carry);
  111|    606|   }
  112|       |
  113|    101|   return carry;
  114|    101|}
_ZN5Botan10bigint_cmpITkNS_8WordTypeEmEEiPKT_mS3_m:
  439|  95.6k|inline constexpr int32_t bigint_cmp(const W x[], size_t x_size, const W y[], size_t y_size) {
  440|  95.6k|   static_assert(sizeof(W) >= sizeof(uint32_t), "Size assumption");
  441|       |
  442|  95.6k|   const W LT = static_cast<W>(-1);
  443|  95.6k|   const W EQ = 0;
  444|  95.6k|   const W GT = 1;
  445|       |
  446|  95.6k|   const size_t common_elems = std::min(x_size, y_size);
  447|       |
  448|  95.6k|   W result = EQ;  // until found otherwise
  449|       |
  450|   309k|   for(size_t i = 0; i != common_elems; i++) {
  ------------------
  |  Branch (450:22): [True: 214k, False: 95.6k]
  ------------------
  451|   214k|      const auto is_eq = CT::Mask<W>::is_equal(x[i], y[i]);
  452|   214k|      const auto is_lt = CT::Mask<W>::is_lt(x[i], y[i]);
  453|       |
  454|   214k|      result = is_eq.select(result, is_lt.select(LT, GT));
  455|   214k|   }
  456|       |
  457|  95.6k|   if(x_size < y_size) {
  ------------------
  |  Branch (457:7): [True: 70, False: 95.5k]
  ------------------
  458|     70|      W mask = 0;
  459|    144|      for(size_t i = x_size; i != y_size; i++) {
  ------------------
  |  Branch (459:30): [True: 74, False: 70]
  ------------------
  460|     74|         mask |= y[i];
  461|     74|      }
  462|       |
  463|       |      // If any bits were set in high part of y, then x < y
  464|     70|      result = CT::Mask<W>::is_zero(mask).select(result, LT);
  465|  95.5k|   } else if(y_size < x_size) {
  ------------------
  |  Branch (465:14): [True: 3.63k, False: 91.9k]
  ------------------
  466|  3.63k|      W mask = 0;
  467|  10.7k|      for(size_t i = y_size; i != x_size; i++) {
  ------------------
  |  Branch (467:30): [True: 7.16k, False: 3.63k]
  ------------------
  468|  7.16k|         mask |= x[i];
  469|  7.16k|      }
  470|       |
  471|       |      // If any bits were set in high part of x, then x > y
  472|  3.63k|      result = CT::Mask<W>::is_zero(mask).select(result, GT);
  473|  3.63k|   }
  474|       |
  475|  95.6k|   CT::unpoison(result);
  476|  95.6k|   BOTAN_DEBUG_ASSERT(result == LT || result == GT || result == EQ);
  ------------------
  |  |  130|  95.6k|      do { /* NOLINT(*-avoid-do-while) */ \
  |  |  131|  95.6k|      } while(0)
  |  |  ------------------
  |  |  |  Branch (131:15): [Folded, False: 95.6k]
  |  |  ------------------
  ------------------
  477|  95.6k|   return static_cast<int32_t>(result);
  478|  95.6k|}
_ZN5Botan11bigint_sub2ITkNS_8WordTypeEmEET_PS1_mPKS1_m:
  148|  30.0k|inline constexpr auto bigint_sub2(W x[], size_t x_size, const W y[], size_t y_size) -> W {
  149|  30.0k|   W borrow = 0;
  150|       |
  151|  30.0k|   BOTAN_ASSERT(x_size >= y_size, "Expected sizes");
  ------------------
  |  |   64|  30.0k|   do {                                                                                 \
  |  |   65|  30.0k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                                     \
  |  |   66|  30.0k|      if(!(expr)) {                                                                     \
  |  |  ------------------
  |  |  |  Branch (66:10): [True: 0, False: 30.0k]
  |  |  ------------------
  |  |   67|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                            \
  |  |   68|      0|         Botan::assertion_failure(#expr, assertion_made, __func__, __FILE__, __LINE__); \
  |  |   69|      0|      }                                                                                 \
  |  |   70|  30.0k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (70:12): [Folded, False: 30.0k]
  |  |  ------------------
  ------------------
  152|       |
  153|  30.0k|   const size_t blocks = y_size - (y_size % 8);
  154|       |
  155|  31.3k|   for(size_t i = 0; i != blocks; i += 8) {
  ------------------
  |  Branch (155:22): [True: 1.35k, False: 30.0k]
  ------------------
  156|  1.35k|      borrow = word8_sub2(x + i, y + i, borrow);
  157|  1.35k|   }
  158|       |
  159|   164k|   for(size_t i = blocks; i != y_size; ++i) {
  ------------------
  |  Branch (159:27): [True: 134k, False: 30.0k]
  ------------------
  160|   134k|      x[i] = word_sub(x[i], y[i], &borrow);
  161|   134k|   }
  162|       |
  163|  34.1k|   for(size_t i = y_size; i != x_size; ++i) {
  ------------------
  |  Branch (163:27): [True: 4.12k, False: 30.0k]
  ------------------
  164|  4.12k|      x[i] = word_sub(x[i], static_cast<W>(0), &borrow);
  165|  4.12k|   }
  166|       |
  167|  30.0k|   return borrow;
  168|  30.0k|}
_ZN5Botan15bigint_sub2_revITkNS_8WordTypeEmEEvPT_PKS1_m:
  174|     14|inline constexpr void bigint_sub2_rev(W x[], const W y[], size_t y_size) {
  175|     14|   W borrow = 0;
  176|       |
  177|     68|   for(size_t i = 0; i != y_size; ++i) {
  ------------------
  |  Branch (177:22): [True: 54, False: 14]
  ------------------
  178|     54|      x[i] = word_sub(y[i], x[i], &borrow);
  179|     54|   }
  180|       |
  181|     14|   BOTAN_ASSERT(borrow == 0, "y must be greater than x");
  ------------------
  |  |   64|     14|   do {                                                                                 \
  |  |   65|     14|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                                     \
  |  |   66|     14|      if(!(expr)) {                                                                     \
  |  |  ------------------
  |  |  |  Branch (66:10): [True: 0, False: 14]
  |  |  ------------------
  |  |   67|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                            \
  |  |   68|      0|         Botan::assertion_failure(#expr, assertion_made, __func__, __FILE__, __LINE__); \
  |  |   69|      0|      }                                                                                 \
  |  |   70|     14|   } while(0)
  |  |  ------------------
  |  |  |  Branch (70:12): [Folded, False: 14]
  |  |  ------------------
  ------------------
  182|     14|}
_ZN5Botan11bigint_sub3ITkNS_8WordTypeEmEET_PS1_PKS1_mS4_m:
  192|  46.2k|inline constexpr auto bigint_sub3(W z[], const W x[], size_t x_size, const W y[], size_t y_size) -> W {
  193|  46.2k|   W borrow = 0;
  194|       |
  195|  46.2k|   BOTAN_ASSERT(x_size >= y_size, "Expected sizes");
  ------------------
  |  |   64|  46.2k|   do {                                                                                 \
  |  |   65|  46.2k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                                     \
  |  |   66|  46.2k|      if(!(expr)) {                                                                     \
  |  |  ------------------
  |  |  |  Branch (66:10): [True: 0, False: 46.2k]
  |  |  ------------------
  |  |   67|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                            \
  |  |   68|      0|         Botan::assertion_failure(#expr, assertion_made, __func__, __FILE__, __LINE__); \
  |  |   69|      0|      }                                                                                 \
  |  |   70|  46.2k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (70:12): [Folded, False: 46.2k]
  |  |  ------------------
  ------------------
  196|       |
  197|  46.2k|   const size_t blocks = y_size - (y_size % 8);
  198|       |
  199|  46.8k|   for(size_t i = 0; i != blocks; i += 8) {
  ------------------
  |  Branch (199:22): [True: 675, False: 46.2k]
  ------------------
  200|    675|      borrow = word8_sub3(z + i, x + i, y + i, borrow);
  201|    675|   }
  202|       |
  203|   214k|   for(size_t i = blocks; i != y_size; ++i) {
  ------------------
  |  Branch (203:27): [True: 168k, False: 46.2k]
  ------------------
  204|   168k|      z[i] = word_sub(x[i], y[i], &borrow);
  205|   168k|   }
  206|       |
  207|   105k|   for(size_t i = y_size; i != x_size; ++i) {
  ------------------
  |  Branch (207:27): [True: 59.3k, False: 46.2k]
  ------------------
  208|  59.3k|      z[i] = word_sub(x[i], static_cast<W>(0), &borrow);
  209|  59.3k|   }
  210|       |
  211|  46.2k|   return borrow;
  212|  46.2k|}
_ZN5Botan11bigint_add3ITkNS_8WordTypeEmEET_PS1_PKS1_mS4_m:
  120|  1.46k|inline constexpr auto bigint_add3(W z[], const W x[], size_t x_size, const W y[], size_t y_size) -> W {
  121|  1.46k|   if(x_size < y_size) {
  ------------------
  |  Branch (121:7): [True: 46, False: 1.41k]
  ------------------
  122|     46|      return bigint_add3(z, y, y_size, x, x_size);
  123|     46|   }
  124|       |
  125|  1.41k|   W carry = 0;
  126|       |
  127|  1.41k|   const size_t blocks = y_size - (y_size % 8);
  128|       |
  129|  1.41k|   for(size_t i = 0; i != blocks; i += 8) {
  ------------------
  |  Branch (129:22): [True: 0, False: 1.41k]
  ------------------
  130|      0|      carry = word8_add3(z + i, x + i, y + i, carry);
  131|      0|   }
  132|       |
  133|  5.07k|   for(size_t i = blocks; i != y_size; ++i) {
  ------------------
  |  Branch (133:27): [True: 3.65k, False: 1.41k]
  ------------------
  134|  3.65k|      z[i] = word_add(x[i], y[i], &carry);
  135|  3.65k|   }
  136|       |
  137|  3.38k|   for(size_t i = y_size; i != x_size; ++i) {
  ------------------
  |  Branch (137:27): [True: 1.96k, False: 1.41k]
  ------------------
  138|  1.96k|      z[i] = word_add(x[i], static_cast<W>(0), &carry);
  139|  1.96k|   }
  140|       |
  141|  1.41k|   return carry;
  142|  1.46k|}
_ZN5Botan14bigint_linmul3ITkNS_8WordTypeEmEEvPT_PKS1_mS1_:
  416|  15.6k|inline constexpr void bigint_linmul3(W z[], const W x[], size_t x_size, W y) {
  417|  15.6k|   const size_t blocks = x_size - (x_size % 8);
  418|       |
  419|  15.6k|   W carry = 0;
  420|       |
  421|  15.6k|   for(size_t i = 0; i != blocks; i += 8) {
  ------------------
  |  Branch (421:22): [True: 0, False: 15.6k]
  ------------------
  422|      0|      carry = word8_linmul3(z + i, x + i, y, carry);
  423|      0|   }
  424|       |
  425|  61.6k|   for(size_t i = blocks; i != x_size; ++i) {
  ------------------
  |  Branch (425:27): [True: 46.0k, False: 15.6k]
  ------------------
  426|  46.0k|      z[i] = word_madd2(x[i], y, &carry);
  427|  46.0k|   }
  428|       |
  429|  15.6k|   z[x_size] = carry;
  430|  15.6k|}
_ZN5Botan14divide_precompImEC2Em:
  574|  39.7k|      explicit constexpr divide_precomp(W divisor) : m_divisor(divisor) {
  575|  39.7k|         BOTAN_ARG_CHECK(m_divisor != 0, "Division by zero");
  ------------------
  |  |   35|  39.7k|   do {                                                          \
  |  |   36|  39.7k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  39.7k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 39.7k]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|  39.7k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 39.7k]
  |  |  ------------------
  ------------------
  576|  39.7k|      }
_ZNK5Botan14divide_precompImE16vartime_mod_2to1Emm:
  644|  29.7k|      inline constexpr W vartime_mod_2to1(W n1, W n0) const {
  645|  29.7k|         BOTAN_ASSERT_NOMSG(n1 < m_divisor);
  ------------------
  |  |   77|  29.7k|   do {                                                                     \
  |  |   78|  29.7k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|  29.7k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 29.7k]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|  29.7k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 29.7k]
  |  |  ------------------
  ------------------
  646|  29.7k|         W q = this->vartime_div_2to1(n1, n0);
  647|  29.7k|         W carry = 0;
  648|  29.7k|         q = word_madd2(q, m_divisor, &carry);
  649|  29.7k|         return (n0 - q);
  650|  29.7k|      }
_ZNK5Botan14divide_precompImE16vartime_div_2to1Emm:
  581|  45.9k|      inline constexpr W vartime_div_2to1(W n1, W n0) const {
  582|  45.9k|         BOTAN_ASSERT_NOMSG(n1 < m_divisor);
  ------------------
  |  |   77|  45.9k|   do {                                                                     \
  |  |   78|  45.9k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|  45.9k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 45.9k]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|  45.9k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 45.9k]
  |  |  ------------------
  ------------------
  583|       |
  584|  45.9k|         if(m_divisor == WordInfo<W>::max) {
  ------------------
  |  Branch (584:13): [True: 448, False: 45.5k]
  ------------------
  585|    448|            return vartime_div_2to1_max_d(n1, n0);
  586|    448|         }
  587|       |
  588|  45.5k|         if(m_divisor == WordInfo<W>::top_bit) {
  ------------------
  |  Branch (588:13): [True: 6, False: 45.4k]
  ------------------
  589|       |            // Simply a shift by N-1 bits
  590|      6|            return (n1 << 1) | (n0 >> (WordInfo<W>::bits - 1));
  591|      6|         }
  592|       |
  593|  45.4k|         if(!std::is_constant_evaluated()) {
  ------------------
  |  Branch (593:13): [True: 45.4k, Folded]
  ------------------
  594|  45.4k|#if defined(BOTAN_MP_USE_X86_64_ASM)
  595|  45.4k|            if constexpr(std::same_as<W, uint64_t>) {
  596|  45.4k|               W quotient = 0;
  597|  45.4k|               W remainder = 0;
  598|       |               // NOLINTNEXTLINE(*-no-assembler)
  599|  45.4k|               asm("divq %[v]" : "=a"(quotient), "=d"(remainder) : [v] "r"(m_divisor), "a"(n0), "d"(n1) : "cc");
  600|  45.4k|               return quotient;
  601|  45.4k|            }
  602|      0|#endif
  603|       |
  604|      0|#if !defined(BOTAN_BUILD_COMPILER_IS_CLANGCL)
  605|       |
  606|       |            /* clang-cl has a bug where on encountering a 128/64 division it emits
  607|       |            * a call to __udivti3() but then fails to link the relevant builtin into
  608|       |            * the binary, causing a link failure. Work around this by simply omitting
  609|       |            * such code for clang-cl
  610|       |            *
  611|       |            * See https://github.com/llvm/llvm-project/issues/25679
  612|       |            */
  613|  45.4k|            if constexpr(WordInfo<W>::dword_is_native) {
  614|  45.4k|               typename WordInfo<W>::dword n = n1;
  615|  45.4k|               n <<= WordInfo<W>::bits;
  616|  45.4k|               n |= n0;
  617|  45.4k|               return static_cast<W>(n / m_divisor);
  618|  45.4k|            }
  619|  45.4k|#endif
  620|  45.4k|         }
  621|       |
  622|      0|         W high = n1;
  623|  45.4k|         W quotient = 0;
  624|       |
  625|  45.4k|         for(size_t i = 0; i != WordInfo<W>::bits; ++i) {
  ------------------
  |  Branch (625:28): [True: 0, False: 45.4k]
  ------------------
  626|      0|            const W high_top_bit = high >> (WordInfo<W>::bits - 1);
  627|       |
  628|      0|            high <<= 1;
  629|      0|            high |= (n0 >> (WordInfo<W>::bits - 1 - i)) & 1;
  630|      0|            quotient <<= 1;
  631|       |
  632|      0|            if(high_top_bit || high >= m_divisor) {
  ------------------
  |  Branch (632:16): [True: 0, False: 0]
  |  Branch (632:32): [True: 0, False: 0]
  ------------------
  633|      0|               high -= m_divisor;
  634|      0|               quotient |= 1;
  635|      0|            }
  636|      0|         }
  637|       |
  638|  45.4k|         return quotient;
  639|  45.5k|      }
_ZN5Botan14divide_precompImE22vartime_div_2to1_max_dEmm:
  657|    448|      static inline constexpr W vartime_div_2to1_max_d(W n1, W n0) {
  658|       |         /*
  659|       |         Use k to refer to WordInfo<W>::bits
  660|       |
  661|       |         We are dividing n = (n1 * 2^k) + n0 by 2^k - 1
  662|       |
  663|       |         Recall that 2^k = 1 (mod 2^k - 1)
  664|       |
  665|       |         Rewrite n = n1*2^k + n0 as n1*(2^k - 1) + n1 + n0
  666|       |
  667|       |         The result of dividing n by (2^k - 1) will be equal to
  668|       |         (n1*(2^k-1) + n1 + n0) / (2^k-1) =
  669|       |         n1 + ((n1 + n0) / (2^k-1)
  670|       |
  671|       |         Use c to refer to ((n1 + n0) / (2^k-1))
  672|       |
  673|       |         If (n1 + n0) < (2^k - 1) then c is 0
  674|       |         If (n1 + n0) >= (2^k - 1) then c is 1
  675|       |
  676|       |         Since n1 < 2^k - 1 [*] and n0 <= 2^k - 1 it is impossible for (n1 + n0) / (2^k -1)
  677|       |         to be greater than 1.
  678|       |
  679|       |         [*] We require n1 be strictly less than the divisor to ensure that the
  680|       |         output fits in a single word; this is checked at the start of vartime_div_2to1.
  681|       |         */
  682|       |
  683|    448|         const W s = n0 + n1;
  684|       |         // did n0 + n1 overflow? or does (n0 + n1) == 2^k - 1? if either, c == 1
  685|    448|         if(s < n0 || s == WordInfo<W>::max) {
  ------------------
  |  Branch (685:13): [True: 93, False: 355]
  |  Branch (685:23): [True: 1, False: 354]
  ------------------
  686|     94|            n1 += 1;
  687|     94|         }
  688|       |
  689|    448|         return n1;
  690|    448|      }
_ZN5Botan11bigint_shl1ITkNS_8WordTypeEmEEvPT_mmm:
  309|  29.8k|inline constexpr void bigint_shl1(W x[], size_t x_size, size_t x_words, size_t shift) {
  310|  29.8k|   const size_t word_shift = shift / WordInfo<W>::bits;
  311|  29.8k|   const size_t bit_shift = shift % WordInfo<W>::bits;
  312|       |
  313|  29.8k|   BOTAN_ASSERT_NOMSG(word_shift <= x_size);
  ------------------
  |  |   77|  29.8k|   do {                                                                     \
  |  |   78|  29.8k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|  29.8k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 29.8k]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|  29.8k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 29.8k]
  |  |  ------------------
  ------------------
  314|  29.8k|   BOTAN_ASSERT_NOMSG(x_words <= x_size - word_shift);
  ------------------
  |  |   77|  29.8k|   do {                                                                     \
  |  |   78|  29.8k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|  29.8k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 29.8k]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|  29.8k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 29.8k]
  |  |  ------------------
  ------------------
  315|       |
  316|  29.8k|   unchecked_copy_memory(x + word_shift, x, x_words);
  317|  29.8k|   zeroize_buffer(x, word_shift);
  318|       |
  319|  29.8k|   const auto carry_mask = CT::Mask<W>::expand(bit_shift);
  320|  29.8k|   const W carry_shift = carry_mask.if_set_return(WordInfo<W>::bits - bit_shift);
  321|       |
  322|  29.8k|   W carry = 0;
  323|   147k|   for(size_t i = word_shift; i != x_size; ++i) {
  ------------------
  |  Branch (323:31): [True: 117k, False: 29.8k]
  ------------------
  324|   117k|      const W w = x[i];
  325|   117k|      x[i] = (w << bit_shift) | carry;
  326|   117k|      carry = carry_mask.if_set_return(w >> carry_shift);
  327|   117k|   }
  328|  29.8k|}
_ZN5Botan11bigint_shr1ITkNS_8WordTypeEmEEvPT_mm:
  331|  72.2k|inline constexpr void bigint_shr1(W x[], size_t x_size, size_t shift) {
  332|  72.2k|   const size_t word_shift = shift / WordInfo<W>::bits;
  333|  72.2k|   const size_t bit_shift = shift % WordInfo<W>::bits;
  334|       |
  335|  72.2k|   const size_t top = x_size >= word_shift ? (x_size - word_shift) : 0;
  ------------------
  |  Branch (335:23): [True: 72.2k, False: 0]
  ------------------
  336|       |
  337|  72.2k|   if(top > 0) {
  ------------------
  |  Branch (337:7): [True: 72.2k, False: 0]
  ------------------
  338|  72.2k|      unchecked_copy_memory(x, x + word_shift, top);
  339|  72.2k|   }
  340|  72.2k|   zeroize_buffer(x + top, std::min(word_shift, x_size));
  341|       |
  342|  72.2k|   const auto carry_mask = CT::Mask<W>::expand(bit_shift);
  343|  72.2k|   const W carry_shift = carry_mask.if_set_return(WordInfo<W>::bits - bit_shift);
  344|       |
  345|  72.2k|   W carry = 0;
  346|       |
  347|   647k|   for(size_t i = 0; i != top; ++i) {
  ------------------
  |  Branch (347:22): [True: 575k, False: 72.2k]
  ------------------
  348|   575k|      const W w = x[top - i - 1];
  349|   575k|      x[top - i - 1] = (w >> bit_shift) | carry;
  350|   575k|      carry = carry_mask.if_set_return(w << carry_shift);
  351|   575k|   }
  352|  72.2k|}
_ZN5Botan11bigint_shl2ITkNS_8WordTypeEmEEvPT_mPKS1_mm:
  355|  14.4k|inline constexpr void bigint_shl2(W y[], size_t y_size, const W x[], size_t x_size, size_t shift) {
  356|  14.4k|   const size_t word_shift = shift / WordInfo<W>::bits;
  357|  14.4k|   const size_t bit_shift = shift % WordInfo<W>::bits;
  358|       |
  359|  14.4k|   BOTAN_ASSERT_NOMSG(word_shift <= y_size);
  ------------------
  |  |   77|  14.4k|   do {                                                                     \
  |  |   78|  14.4k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|  14.4k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 14.4k]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|  14.4k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 14.4k]
  |  |  ------------------
  ------------------
  360|  14.4k|   BOTAN_ASSERT_NOMSG(x_size < y_size - word_shift);
  ------------------
  |  |   77|  14.4k|   do {                                                                     \
  |  |   78|  14.4k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|  14.4k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 14.4k]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|  14.4k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 14.4k]
  |  |  ------------------
  ------------------
  361|       |
  362|  14.4k|   unchecked_copy_memory(y + word_shift, x, x_size);
  363|  14.4k|   zeroize_buffer(y, word_shift);
  364|  14.4k|   zeroize_buffer(y + word_shift + x_size, y_size - word_shift - x_size);
  365|       |
  366|  14.4k|   const auto carry_mask = CT::Mask<W>::expand(bit_shift);
  367|  14.4k|   const W carry_shift = carry_mask.if_set_return(WordInfo<W>::bits - bit_shift);
  368|       |
  369|  14.4k|   W carry = 0;
  370|  63.8k|   for(size_t i = word_shift; i != x_size + word_shift + 1; ++i) {
  ------------------
  |  Branch (370:31): [True: 49.4k, False: 14.4k]
  ------------------
  371|  49.4k|      const W w = y[i];
  372|  49.4k|      y[i] = (w << bit_shift) | carry;
  373|  49.4k|      carry = carry_mask.if_set_return(w >> carry_shift);
  374|  49.4k|   }
  375|  14.4k|}
_ZN5Botan11bigint_shr2ITkNS_8WordTypeEmEEvPT_mPKS1_mm:
  378|    717|inline constexpr void bigint_shr2(W y[], size_t y_size, const W x[], size_t x_size, size_t shift) {
  379|    717|   const size_t word_shift = shift / WordInfo<W>::bits;
  380|    717|   const size_t bit_shift = shift % WordInfo<W>::bits;
  381|    717|   const size_t new_size = x_size < word_shift ? 0 : (x_size - word_shift);
  ------------------
  |  Branch (381:28): [True: 0, False: 717]
  ------------------
  382|       |
  383|    717|   BOTAN_ASSERT_NOMSG(new_size <= y_size);
  ------------------
  |  |   77|    717|   do {                                                                     \
  |  |   78|    717|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|    717|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 717]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|    717|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 717]
  |  |  ------------------
  ------------------
  384|       |
  385|    717|   if(new_size > 0) {
  ------------------
  |  Branch (385:7): [True: 717, False: 0]
  ------------------
  386|    717|      unchecked_copy_memory(y, x + word_shift, new_size);
  387|    717|   }
  388|    717|   zeroize_buffer(y + new_size, y_size - new_size);
  389|       |
  390|    717|   const auto carry_mask = CT::Mask<W>::expand(bit_shift);
  391|    717|   const W carry_shift = carry_mask.if_set_return(WordInfo<W>::bits - bit_shift);
  392|       |
  393|    717|   W carry = 0;
  394|  3.58k|   for(size_t i = new_size; i > 0; --i) {
  ------------------
  |  Branch (394:29): [True: 2.86k, False: 717]
  ------------------
  395|  2.86k|      W w = y[i - 1];
  396|  2.86k|      y[i - 1] = (w >> bit_shift) | carry;
  397|  2.86k|      carry = carry_mask.if_set_return(w << carry_shift);
  398|  2.86k|   }
  399|    717|}
_ZN5Botan15bigint_ct_is_eqITkNS_8WordTypeEmEENS_2CT4MaskIT_EEPKS3_mS6_m:
  519|    804|inline constexpr auto bigint_ct_is_eq(const W x[], size_t x_size, const W y[], size_t y_size) -> CT::Mask<W> {
  520|    804|   const size_t common_elems = std::min(x_size, y_size);
  521|       |
  522|    804|   W diff = 0;
  523|       |
  524|  9.93k|   for(size_t i = 0; i != common_elems; i++) {
  ------------------
  |  Branch (524:22): [True: 9.13k, False: 804]
  ------------------
  525|  9.13k|      diff |= (x[i] ^ y[i]);
  526|  9.13k|   }
  527|       |
  528|       |   // If any bits were set in high part of x/y, then they are not equal
  529|    804|   if(x_size < y_size) {
  ------------------
  |  Branch (529:7): [True: 0, False: 804]
  ------------------
  530|      0|      for(size_t i = x_size; i != y_size; i++) {
  ------------------
  |  Branch (530:30): [True: 0, False: 0]
  ------------------
  531|      0|         diff |= y[i];
  532|      0|      }
  533|    804|   } else if(y_size < x_size) {
  ------------------
  |  Branch (533:14): [True: 89, False: 715]
  ------------------
  534|    445|      for(size_t i = y_size; i != x_size; i++) {
  ------------------
  |  Branch (534:30): [True: 356, False: 89]
  ------------------
  535|    356|         diff |= x[i];
  536|    356|      }
  537|     89|   }
  538|       |
  539|    804|   return CT::Mask<W>::is_zero(diff);
  540|    804|}
_ZN5Botan15bigint_ct_is_ltITkNS_8WordTypeEmEENS_2CT4MaskIT_EEPKS3_mS6_mb:
  487|  63.0k|   -> CT::Mask<W> {
  488|  63.0k|   const size_t common_elems = std::min(x_size, y_size);
  489|       |
  490|  63.0k|   auto is_lt = CT::Mask<W>::expand(lt_or_equal);
  491|       |
  492|   486k|   for(size_t i = 0; i != common_elems; i++) {
  ------------------
  |  Branch (492:22): [True: 423k, False: 63.0k]
  ------------------
  493|   423k|      const auto eq = CT::Mask<W>::is_equal(x[i], y[i]);
  494|   423k|      const auto lt = CT::Mask<W>::is_lt(x[i], y[i]);
  495|   423k|      is_lt = eq.select_mask(is_lt, lt);
  496|   423k|   }
  497|       |
  498|  63.0k|   if(x_size < y_size) {
  ------------------
  |  Branch (498:7): [True: 2.07k, False: 60.9k]
  ------------------
  499|  2.07k|      W mask = 0;
  500|  11.1k|      for(size_t i = x_size; i != y_size; i++) {
  ------------------
  |  Branch (500:30): [True: 9.04k, False: 2.07k]
  ------------------
  501|  9.04k|         mask |= y[i];
  502|  9.04k|      }
  503|       |      // If any bits were set in high part of y, then is_lt should be forced true
  504|  2.07k|      is_lt |= CT::Mask<W>::expand(mask);
  505|  60.9k|   } else if(y_size < x_size) {
  ------------------
  |  Branch (505:14): [True: 20.9k, False: 39.9k]
  ------------------
  506|  20.9k|      W mask = 0;
  507|   150k|      for(size_t i = y_size; i != x_size; i++) {
  ------------------
  |  Branch (507:30): [True: 129k, False: 20.9k]
  ------------------
  508|   129k|         mask |= x[i];
  509|   129k|      }
  510|       |
  511|       |      // If any bits were set in high part of x, then is_lt should be false
  512|  20.9k|      is_lt &= CT::Mask<W>::is_zero(mask);
  513|  20.9k|   }
  514|       |
  515|  63.0k|   return is_lt;
  516|  63.0k|}
_ZN5Botan15bigint_cnd_swapITkNS_8WordTypeEmEEvT_PS1_S2_m:
   29|  3.87k|inline constexpr void bigint_cnd_swap(W cnd, W x[], W y[], size_t size) {
   30|  3.87k|   const auto mask = CT::Mask<W>::expand(cnd);
   31|       |
   32|  23.2k|   for(size_t i = 0; i != size; ++i) {
  ------------------
  |  Branch (32:22): [True: 19.3k, False: 3.87k]
  ------------------
   33|  19.3k|      const W a = x[i];
   34|  19.3k|      const W b = y[i];
   35|  19.3k|      x[i] = mask.select(b, a);
   36|  19.3k|      y[i] = mask.select(a, b);
   37|  19.3k|   }
   38|  3.87k|}
_ZN5Botan14bigint_sub_absITkNS_8WordTypeEmEENS_2CT4MaskIT_EEPS3_PKS3_S7_mS5_:
  279|  13.0k|inline constexpr auto bigint_sub_abs(W z[], const W x[], const W y[], size_t N, W ws[]) -> CT::Mask<W> {
  280|       |   // Subtract in both direction then conditional copy out the result
  281|       |
  282|  13.0k|   W* ws0 = ws;
  283|  13.0k|   W* ws1 = ws + N;
  284|       |
  285|  13.0k|   W borrow0 = 0;
  286|  13.0k|   W borrow1 = 0;
  287|       |
  288|  13.0k|   const size_t blocks = N - (N % 8);
  289|       |
  290|  13.0k|   for(size_t i = 0; i != blocks; i += 8) {
  ------------------
  |  Branch (290:22): [True: 0, False: 13.0k]
  ------------------
  291|      0|      borrow0 = word8_sub3(ws0 + i, x + i, y + i, borrow0);
  292|      0|      borrow1 = word8_sub3(ws1 + i, y + i, x + i, borrow1);
  293|      0|   }
  294|       |
  295|  78.5k|   for(size_t i = blocks; i != N; ++i) {
  ------------------
  |  Branch (295:27): [True: 65.4k, False: 13.0k]
  ------------------
  296|  65.4k|      ws0[i] = word_sub(x[i], y[i], &borrow0);
  297|  65.4k|      ws1[i] = word_sub(y[i], x[i], &borrow1);
  298|  65.4k|   }
  299|       |
  300|  13.0k|   return CT::conditional_copy_mem(borrow0, z, ws1, ws0, N);
  301|  13.0k|}
_ZN5Botan13monty_inverseITkNS_8WordTypeEmEET_S1_:
  703|    689|inline constexpr auto monty_inverse(W a) -> W {
  704|    689|   BOTAN_ARG_CHECK(a % 2 == 1, "Cannot compute Montgomery inverse of an even integer");
  ------------------
  |  |   35|    689|   do {                                                          \
  |  |   36|    689|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|    689|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 689]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|    689|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 689]
  |  |  ------------------
  ------------------
  705|       |
  706|       |   // Newton's Method, following https://lemire.me/blog/2017/09/18/computing-the-inverse-of-odd-integers/
  707|       |
  708|    689|   constexpr size_t iter = WordInfo<W>::bits == 64 ? 4 : 3;
  ------------------
  |  Branch (708:28): [True: 0, Folded]
  ------------------
  709|       |
  710|       |   // Initial guess provides 5 bits of accuracy
  711|    689|   W r = (3 * a) ^ 2;
  712|       |
  713|       |   // Each iteration doubles the accuracy
  714|  3.44k|   for(size_t i = 0; i != iter; ++i) {
  ------------------
  |  Branch (714:22): [True: 2.75k, False: 689]
  ------------------
  715|  2.75k|      r = r * (2 - r * a);
  716|  2.75k|   }
  717|       |
  718|       |   // Now invert in addition space
  719|    689|   r = (WordInfo<W>::max - r) + 1;
  720|       |
  721|    689|   return r;
  722|    689|}
_ZN5Botan22bigint_monty_maybe_subILm4ETkNS_8WordTypeEmEEvPT0_S1_PKS1_S4_:
  254|   443k|inline constexpr void bigint_monty_maybe_sub(W z[N], W x0, const W x[N], const W y[N]) {
  255|   443k|   W borrow = 0;
  256|       |
  257|  2.21M|   for(size_t i = 0; i != N; ++i) {
  ------------------
  |  Branch (257:22): [True: 1.77M, False: 443k]
  ------------------
  258|  1.77M|      z[i] = word_sub(x[i], y[i], &borrow);
  259|  1.77M|   }
  260|       |
  261|   443k|   borrow = (x0 - borrow) > x0;
  262|       |
  263|   443k|   CT::conditional_assign_mem(borrow, z, x, N);
  264|   443k|}

_ZN5Botan4rotrILm2ETkNSt3__117unsigned_integralEjEET0_S2_QaagtT_Li0EltT_mlLi8EstS2_:
   37|    640|{
   38|    640|   return static_cast<T>((input >> ROT) | (input << (8 * sizeof(T) - ROT)));
   39|    640|}
_ZN5Botan4rotrILm22ETkNSt3__117unsigned_integralEjEET0_S2_QaagtT_Li0EltT_mlLi8EstS2_:
   37|    640|{
   38|    640|   return static_cast<T>((input >> ROT) | (input << (8 * sizeof(T) - ROT)));
   39|    640|}
_ZN5Botan4rotrILm13ETkNSt3__117unsigned_integralEjEET0_S2_QaagtT_Li0EltT_mlLi8EstS2_:
   37|    640|{
   38|    640|   return static_cast<T>((input >> ROT) | (input << (8 * sizeof(T) - ROT)));
   39|    640|}
_ZN5Botan3rhoILm2ELm13ELm22ETkNSt3__117unsigned_integralEjEET2_S2_:
   53|    640|BOTAN_FORCE_INLINE constexpr T rho(T x) {
   54|    640|   return rotr<R1>(x) ^ rotr<R2>(x) ^ rotr<R3>(x);
   55|    640|}
_ZN5Botan3rhoILm6ELm11ELm25ETkNSt3__117unsigned_integralEjEET2_S2_:
   53|    640|BOTAN_FORCE_INLINE constexpr T rho(T x) {
   54|    640|   return rotr<R1>(x) ^ rotr<R2>(x) ^ rotr<R3>(x);
   55|    640|}
_ZN5Botan4rotrILm6ETkNSt3__117unsigned_integralEjEET0_S2_QaagtT_Li0EltT_mlLi8EstS2_:
   37|    640|{
   38|    640|   return static_cast<T>((input >> ROT) | (input << (8 * sizeof(T) - ROT)));
   39|    640|}
_ZN5Botan4rotrILm11ETkNSt3__117unsigned_integralEjEET0_S2_QaagtT_Li0EltT_mlLi8EstS2_:
   37|    640|{
   38|    640|   return static_cast<T>((input >> ROT) | (input << (8 * sizeof(T) - ROT)));
   39|    640|}
_ZN5Botan4rotrILm25ETkNSt3__117unsigned_integralEjEET0_S2_QaagtT_Li0EltT_mlLi8EstS2_:
   37|    640|{
   38|    640|   return static_cast<T>((input >> ROT) | (input << (8 * sizeof(T) - ROT)));
   39|    640|}

_ZN5Botan8round_upEmm:
   26|  1.30k|constexpr inline size_t round_up(size_t n, size_t align_to) {
   27|       |   // Arguably returning n in this case would also be sensible
   28|  1.30k|   BOTAN_ARG_CHECK(align_to != 0, "align_to must not be 0");
  ------------------
  |  |   35|  1.30k|   do {                                                          \
  |  |   36|  1.30k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  1.30k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 1.30k]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|  1.30k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 1.30k]
  |  |  ------------------
  ------------------
   29|       |
   30|  1.30k|   if(n % align_to > 0) {
  ------------------
  |  Branch (30:7): [True: 1.24k, False: 53]
  ------------------
   31|  1.24k|      const size_t adj = align_to - (n % align_to);
   32|  1.24k|      BOTAN_ARG_CHECK(n + adj >= n, "Integer overflow during rounding");
  ------------------
  |  |   35|  1.24k|   do {                                                          \
  |  |   36|  1.24k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  1.24k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 1.24k]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|  1.24k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 1.24k]
  |  |  ------------------
  ------------------
   33|  1.24k|      n += adj;
   34|  1.24k|   }
   35|  1.30k|   return n;
   36|  1.30k|}

_ZNK5Botan9SCAN_Name9algo_nameEv:
   38|      7|      const std::string& algo_name() const { return m_alg_name; }
_ZNK5Botan9SCAN_Name9arg_countEv:
   43|      3|      size_t arg_count() const { return m_args.size(); }

_ZNK5Botan7SHA_25613output_lengthEv:
   75|      9|      size_t output_length() const override { return output_bytes; }
_ZNK5Botan7SHA_25615hash_block_sizeEv:
   77|      1|      size_t hash_block_size() const override { return block_bytes; }
_ZN5Botan7SHA_2565clearEv:
   83|      2|      void clear() override { m_md.clear(); }

_ZN5Botan9SHA2_32_FEjjjRjjjjS0_j:
   42|    640|   uint32_t A, uint32_t B, uint32_t C, uint32_t& D, uint32_t E, uint32_t F, uint32_t G, uint32_t& H, uint32_t M) {
   43|    640|   H += rho<6, 11, 25>(E) + choose(E, F, G) + M;
   44|    640|   D += H;
   45|    640|   H += rho<2, 13, 22>(A) + majority(A, B, C);
   46|    640|}

_ZN5Botan9SIMD_4x32C2Ev:
   86|     40|      BOTAN_FN_ISA_SIMD_4X32 SIMD_4x32() noexcept {
   87|     40|#if defined(BOTAN_SIMD_USE_SSSE3)
   88|     40|         m_simd = _mm_setzero_si128();
   89|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
   90|       |         m_simd = vec_splat_u32(0);
   91|       |#elif defined(BOTAN_SIMD_USE_NEON)
   92|       |         m_simd = vdupq_n_u32(0);
   93|       |#elif defined(BOTAN_SIMD_USE_LSX)
   94|       |         m_simd = __lsx_vldi(0);
   95|       |#elif defined(BOTAN_SIMD_USE_SIMD128)
   96|       |         m_simd = wasm_u32x4_const_splat(0);
   97|       |#endif
   98|     40|      }
_ZN5Botan9SIMD_4x3212byte_shuffleERKS0_S2_:
  825|    240|      static inline SIMD_4x32 BOTAN_FN_ISA_SIMD_4X32 byte_shuffle(const SIMD_4x32& tbl, const SIMD_4x32& idx) {
  826|    240|#if defined(BOTAN_SIMD_USE_SSSE3)
  827|    240|         return SIMD_4x32(_mm_shuffle_epi8(tbl.raw(), idx.raw()));
  828|       |#elif defined(BOTAN_SIMD_USE_NEON)
  829|       |         const uint8x16_t tbl8 = vreinterpretq_u8_u32(tbl.raw());
  830|       |         const uint8x16_t idx8 = vreinterpretq_u8_u32(idx.raw());
  831|       |
  832|       |   #if defined(BOTAN_TARGET_ARCH_IS_ARM32)
  833|       |         const uint8x8x2_t tbl2 = {vget_low_u8(tbl8), vget_high_u8(tbl8)};
  834|       |
  835|       |         return SIMD_4x32(
  836|       |            vreinterpretq_u32_u8(vcombine_u8(vtbl2_u8(tbl2, vget_low_u8(idx8)), vtbl2_u8(tbl2, vget_high_u8(idx8)))));
  837|       |   #else
  838|       |         return SIMD_4x32(vreinterpretq_u32_u8(vqtbl1q_u8(tbl8, idx8)));
  839|       |   #endif
  840|       |
  841|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  842|       |         const auto r = vec_perm(reinterpret_cast<__vector signed char>(tbl.raw()),
  843|       |                                 reinterpret_cast<__vector signed char>(tbl.raw()),
  844|       |                                 reinterpret_cast<__vector unsigned char>(idx.raw()));
  845|       |         return SIMD_4x32(reinterpret_cast<__vector unsigned int>(r));
  846|       |#elif defined(BOTAN_SIMD_USE_LSX)
  847|       |         return SIMD_4x32(__lsx_vshuf_b(tbl.raw(), tbl.raw(), idx.raw()));
  848|       |#elif defined(BOTAN_SIMD_USE_SIMD128)
  849|       |         return SIMD_4x32(wasm_i8x16_swizzle(tbl.raw(), idx.raw()));
  850|       |#endif
  851|    240|      }
_ZNK5Botan9SIMD_4x323rawEv:
  996|  1.88k|      native_simd_type BOTAN_FN_ISA_SIMD_4X32 raw() const noexcept { return m_simd; }
_ZN5Botan9SIMD_4x32C2EDv2_x:
  998|  2.28k|      explicit BOTAN_FN_ISA_SIMD_4X32 SIMD_4x32(native_simd_type x) noexcept : m_simd(x) {}
_ZN5Botan9SIMD_4x327load_leEPKv:
  162|    200|      static SIMD_4x32 BOTAN_FN_ISA_SIMD_4X32 load_le(const void* in) noexcept {
  163|    200|#if defined(BOTAN_SIMD_USE_SSSE3)
  164|    200|         return SIMD_4x32(_mm_loadu_si128(reinterpret_cast<const __m128i*>(in)));
  165|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  166|       |         uint32_t R0 = Botan::load_le<uint32_t>(reinterpret_cast<const uint8_t*>(in), 0);
  167|       |         uint32_t R1 = Botan::load_le<uint32_t>(reinterpret_cast<const uint8_t*>(in), 1);
  168|       |         uint32_t R2 = Botan::load_le<uint32_t>(reinterpret_cast<const uint8_t*>(in), 2);
  169|       |         uint32_t R3 = Botan::load_le<uint32_t>(reinterpret_cast<const uint8_t*>(in), 3);
  170|       |         __vector unsigned int val = {R0, R1, R2, R3};
  171|       |         return SIMD_4x32(val);
  172|       |#elif defined(BOTAN_SIMD_USE_NEON)
  173|       |         SIMD_4x32 l(vld1q_u32(static_cast<const uint32_t*>(in)));
  174|       |         if constexpr(std::endian::native == std::endian::big) {
  175|       |            return l.bswap();
  176|       |         } else {
  177|       |            return l;
  178|       |         }
  179|       |#elif defined(BOTAN_SIMD_USE_LSX)
  180|       |         return SIMD_4x32(__lsx_vld(in, 0));
  181|       |#elif defined(BOTAN_SIMD_USE_SIMD128)
  182|       |         return SIMD_4x32(wasm_v128_load(in));
  183|       |#endif
  184|    200|      }
_ZN5Botan9SIMD_4x32C2Ejjjj:
  103|    240|      BOTAN_FN_ISA_SIMD_4X32 SIMD_4x32(uint32_t B0, uint32_t B1, uint32_t B2, uint32_t B3) noexcept {
  104|    240|#if defined(BOTAN_SIMD_USE_SSSE3)
  105|    240|         m_simd = _mm_set_epi32(B3, B2, B1, B0);
  106|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  107|       |         __vector unsigned int val = {B0, B1, B2, B3};
  108|       |         m_simd = val;
  109|       |#elif defined(BOTAN_SIMD_USE_NEON)
  110|       |         // Better way to do this?
  111|       |         const uint32_t B[4] = {B0, B1, B2, B3};
  112|       |         m_simd = vld1q_u32(B);
  113|       |#elif defined(BOTAN_SIMD_USE_LSX)
  114|       |         // Better way to do this?
  115|       |         const uint32_t B[4] = {B0, B1, B2, B3};
  116|       |         m_simd = __lsx_vld(B, 0);
  117|       |#elif defined(BOTAN_SIMD_USE_SIMD128)
  118|       |         m_simd = wasm_u32x4_make(B0, B1, B2, B3);
  119|       |#endif
  120|    240|      }
_ZNK5Botan9SIMD_4x32eoERKS0_:
  403|    600|      SIMD_4x32 BOTAN_FN_ISA_SIMD_4X32 operator^(const SIMD_4x32& other) const noexcept {
  404|    600|         SIMD_4x32 retval(*this);
  405|    600|         retval ^= other;
  406|    600|         return retval;
  407|    600|      }
_ZN5Botan9SIMD_4x32eOERKS0_:
  455|    960|      void BOTAN_FN_ISA_SIMD_4X32 operator^=(const SIMD_4x32& other) noexcept {
  456|    960|#if defined(BOTAN_SIMD_USE_SSSE3)
  457|    960|         m_simd = _mm_xor_si128(m_simd, other.m_simd);
  458|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  459|       |         m_simd = vec_xor(m_simd, other.m_simd);
  460|       |#elif defined(BOTAN_SIMD_USE_NEON)
  461|       |         m_simd = veorq_u32(m_simd, other.m_simd);
  462|       |#elif defined(BOTAN_SIMD_USE_LSX)
  463|       |         m_simd = __lsx_vxor_v(m_simd, other.m_simd);
  464|       |#elif defined(BOTAN_SIMD_USE_SIMD128)
  465|       |         m_simd = wasm_v128_xor(m_simd, other.m_simd);
  466|       |#endif
  467|    960|      }
_ZNK5Botan9SIMD_4x328store_leEPh:
  234|    160|      void BOTAN_FN_ISA_SIMD_4X32 store_le(uint8_t out[]) const noexcept {
  235|    160|#if defined(BOTAN_SIMD_USE_SSSE3)
  236|       |
  237|    160|         _mm_storeu_si128(reinterpret_cast<__m128i*>(out), raw());
  238|       |
  239|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  240|       |
  241|       |         union {
  242|       |               __vector unsigned int V;
  243|       |               uint32_t R[4];
  244|       |         } vec{};
  245|       |
  246|       |         // NOLINTNEXTLINE(*-union-access)
  247|       |         vec.V = raw();
  248|       |         // NOLINTNEXTLINE(*-union-access)
  249|       |         Botan::store_le(out, vec.R[0], vec.R[1], vec.R[2], vec.R[3]);
  250|       |
  251|       |#elif defined(BOTAN_SIMD_USE_NEON)
  252|       |         if constexpr(std::endian::native == std::endian::little) {
  253|       |            vst1q_u8(out, vreinterpretq_u8_u32(m_simd));
  254|       |         } else {
  255|       |            vst1q_u8(out, vreinterpretq_u8_u32(bswap().m_simd));
  256|       |         }
  257|       |#elif defined(BOTAN_SIMD_USE_LSX)
  258|       |         __lsx_vst(raw(), out, 0);
  259|       |#elif defined(BOTAN_SIMD_USE_SIMD128)
  260|       |         wasm_v128_store(out, m_simd);
  261|       |#endif
  262|    160|      }
_ZN5Botan9SIMD_4x327load_beEPKv:
  189|     40|      static SIMD_4x32 BOTAN_FN_ISA_SIMD_4X32 load_be(const void* in) noexcept {
  190|     40|#if defined(BOTAN_SIMD_USE_SSSE3) || defined(BOTAN_SIMD_USE_LSX) || defined(BOTAN_SIMD_USE_SIMD128)
  191|     40|         return load_le(in).bswap();
  192|       |
  193|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  194|       |         uint32_t R0 = Botan::load_be<uint32_t>(reinterpret_cast<const uint8_t*>(in), 0);
  195|       |         uint32_t R1 = Botan::load_be<uint32_t>(reinterpret_cast<const uint8_t*>(in), 1);
  196|       |         uint32_t R2 = Botan::load_be<uint32_t>(reinterpret_cast<const uint8_t*>(in), 2);
  197|       |         uint32_t R3 = Botan::load_be<uint32_t>(reinterpret_cast<const uint8_t*>(in), 3);
  198|       |         __vector unsigned int val = {R0, R1, R2, R3};
  199|       |         return SIMD_4x32(val);
  200|       |
  201|       |#elif defined(BOTAN_SIMD_USE_NEON)
  202|       |         SIMD_4x32 l(vld1q_u32(static_cast<const uint32_t*>(in)));
  203|       |         if constexpr(std::endian::native == std::endian::little) {
  204|       |            return l.bswap();
  205|       |         } else {
  206|       |            return l;
  207|       |         }
  208|       |#endif
  209|     40|      }
_ZNK5Botan9SIMD_4x328store_leEPj:
  219|    160|      void BOTAN_FN_ISA_SIMD_4X32 store_le(uint32_t out[4]) const noexcept {
  220|    160|         this->store_le(reinterpret_cast<uint8_t*>(out));
  221|    160|      }
_ZNK5Botan9SIMD_4x32plERKS0_:
  385|    160|      SIMD_4x32 BOTAN_FN_ISA_SIMD_4X32 operator+(const SIMD_4x32& other) const noexcept {
  386|    160|         SIMD_4x32 retval(*this);
  387|    160|         retval += other;
  388|    160|         return retval;
  389|    160|      }
_ZN5Botan9SIMD_4x32pLERKS0_:
  427|    640|      void BOTAN_FN_ISA_SIMD_4X32 operator+=(const SIMD_4x32& other) noexcept {
  428|    640|#if defined(BOTAN_SIMD_USE_SSSE3)
  429|    640|         m_simd = _mm_add_epi32(m_simd, other.m_simd);
  430|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  431|       |         m_simd = vec_add(m_simd, other.m_simd);
  432|       |#elif defined(BOTAN_SIMD_USE_NEON)
  433|       |         m_simd = vaddq_u32(m_simd, other.m_simd);
  434|       |#elif defined(BOTAN_SIMD_USE_LSX)
  435|       |         m_simd = __lsx_vadd_w(m_simd, other.m_simd);
  436|       |#elif defined(BOTAN_SIMD_USE_SIMD128)
  437|       |         m_simd = wasm_i32x4_add(m_simd, other.m_simd);
  438|       |#endif
  439|    640|      }
_ZNK5Botan9SIMD_4x325bswapEv:
  576|     40|      BOTAN_FN_ISA_SIMD_4X32 SIMD_4x32 bswap() const noexcept {
  577|     40|#if defined(BOTAN_SIMD_USE_SSSE3)
  578|     40|         const auto idx = _mm_set_epi8(12, 13, 14, 15, 8, 9, 10, 11, 4, 5, 6, 7, 0, 1, 2, 3);
  579|       |
  580|     40|         return SIMD_4x32(_mm_shuffle_epi8(raw(), idx));
  581|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  582|       |   #ifdef BOTAN_SIMD_USE_VSX
  583|       |         return SIMD_4x32(vec_revb(m_simd));
  584|       |   #else
  585|       |         const __vector unsigned char rev[1] = {
  586|       |            {3, 2, 1, 0, 7, 6, 5, 4, 11, 10, 9, 8, 15, 14, 13, 12},
  587|       |         };
  588|       |
  589|       |         return SIMD_4x32(vec_perm(m_simd, m_simd, rev[0]));
  590|       |   #endif
  591|       |
  592|       |#elif defined(BOTAN_SIMD_USE_NEON)
  593|       |         return SIMD_4x32(vreinterpretq_u32_u8(vrev32q_u8(vreinterpretq_u8_u32(m_simd))));
  594|       |#elif defined(BOTAN_SIMD_USE_LSX)
  595|       |         return SIMD_4x32(__lsx_vshuf4i_b(m_simd, 0b00011011));
  596|       |#elif defined(BOTAN_SIMD_USE_SIMD128)
  597|       |         return SIMD_4x32(wasm_i8x16_shuffle(m_simd, m_simd, 3, 2, 1, 0, 7, 6, 5, 4, 11, 10, 9, 8, 15, 14, 13, 12));
  598|       |#endif
  599|     40|      }
_ZNK5Botan9SIMD_4x323shlILi14EEES0_vQaagtT_Li0EltT_Li32E:
  502|    120|      {
  503|    120|#if defined(BOTAN_SIMD_USE_SSSE3)
  504|    120|         return SIMD_4x32(_mm_slli_epi32(m_simd, SHIFT));
  505|       |
  506|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  507|       |         const unsigned int s = static_cast<unsigned int>(SHIFT);
  508|       |         const __vector unsigned int shifts = {s, s, s, s};
  509|       |         return SIMD_4x32(vec_sl(m_simd, shifts));
  510|       |#elif defined(BOTAN_SIMD_USE_NEON)
  511|       |         return SIMD_4x32(vshlq_n_u32(m_simd, SHIFT));
  512|       |#elif defined(BOTAN_SIMD_USE_LSX)
  513|       |         return SIMD_4x32(__lsx_vslli_w(m_simd, SHIFT));
  514|       |#elif defined(BOTAN_SIMD_USE_SIMD128)
  515|       |         return SIMD_4x32(wasm_i32x4_shl(m_simd, SHIFT));
  516|       |#endif
  517|    120|      }
_ZNK5Botan9SIMD_4x323shrILi7EEES0_v:
  520|    120|      SIMD_4x32 BOTAN_FN_ISA_SIMD_4X32 shr() const noexcept {
  521|    120|#if defined(BOTAN_SIMD_USE_SSSE3)
  522|    120|         return SIMD_4x32(_mm_srli_epi32(m_simd, SHIFT));
  523|       |
  524|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  525|       |         const unsigned int s = static_cast<unsigned int>(SHIFT);
  526|       |         const __vector unsigned int shifts = {s, s, s, s};
  527|       |         return SIMD_4x32(vec_sr(m_simd, shifts));
  528|       |#elif defined(BOTAN_SIMD_USE_NEON)
  529|       |         return SIMD_4x32(vshrq_n_u32(m_simd, SHIFT));
  530|       |#elif defined(BOTAN_SIMD_USE_LSX)
  531|       |         return SIMD_4x32(__lsx_vsrli_w(m_simd, SHIFT));
  532|       |#elif defined(BOTAN_SIMD_USE_SIMD128)
  533|       |         return SIMD_4x32(wasm_u32x4_shr(m_simd, SHIFT));
  534|       |#endif
  535|    120|      }
_ZNK5Botan9SIMD_4x323shrILi3EEES0_v:
  520|    120|      SIMD_4x32 BOTAN_FN_ISA_SIMD_4X32 shr() const noexcept {
  521|    120|#if defined(BOTAN_SIMD_USE_SSSE3)
  522|    120|         return SIMD_4x32(_mm_srli_epi32(m_simd, SHIFT));
  523|       |
  524|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  525|       |         const unsigned int s = static_cast<unsigned int>(SHIFT);
  526|       |         const __vector unsigned int shifts = {s, s, s, s};
  527|       |         return SIMD_4x32(vec_sr(m_simd, shifts));
  528|       |#elif defined(BOTAN_SIMD_USE_NEON)
  529|       |         return SIMD_4x32(vshrq_n_u32(m_simd, SHIFT));
  530|       |#elif defined(BOTAN_SIMD_USE_LSX)
  531|       |         return SIMD_4x32(__lsx_vsrli_w(m_simd, SHIFT));
  532|       |#elif defined(BOTAN_SIMD_USE_SIMD128)
  533|       |         return SIMD_4x32(wasm_u32x4_shr(m_simd, SHIFT));
  534|       |#endif
  535|    120|      }
_ZNK5Botan9SIMD_4x323shrILi11EEES0_v:
  520|    120|      SIMD_4x32 BOTAN_FN_ISA_SIMD_4X32 shr() const noexcept {
  521|    120|#if defined(BOTAN_SIMD_USE_SSSE3)
  522|    120|         return SIMD_4x32(_mm_srli_epi32(m_simd, SHIFT));
  523|       |
  524|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  525|       |         const unsigned int s = static_cast<unsigned int>(SHIFT);
  526|       |         const __vector unsigned int shifts = {s, s, s, s};
  527|       |         return SIMD_4x32(vec_sr(m_simd, shifts));
  528|       |#elif defined(BOTAN_SIMD_USE_NEON)
  529|       |         return SIMD_4x32(vshrq_n_u32(m_simd, SHIFT));
  530|       |#elif defined(BOTAN_SIMD_USE_LSX)
  531|       |         return SIMD_4x32(__lsx_vsrli_w(m_simd, SHIFT));
  532|       |#elif defined(BOTAN_SIMD_USE_SIMD128)
  533|       |         return SIMD_4x32(wasm_u32x4_shr(m_simd, SHIFT));
  534|       |#endif
  535|    120|      }
_ZNK5Botan9SIMD_4x323shlILi11EEES0_vQaagtT_Li0EltT_Li32E:
  502|    120|      {
  503|    120|#if defined(BOTAN_SIMD_USE_SSSE3)
  504|    120|         return SIMD_4x32(_mm_slli_epi32(m_simd, SHIFT));
  505|       |
  506|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  507|       |         const unsigned int s = static_cast<unsigned int>(SHIFT);
  508|       |         const __vector unsigned int shifts = {s, s, s, s};
  509|       |         return SIMD_4x32(vec_sl(m_simd, shifts));
  510|       |#elif defined(BOTAN_SIMD_USE_NEON)
  511|       |         return SIMD_4x32(vshlq_n_u32(m_simd, SHIFT));
  512|       |#elif defined(BOTAN_SIMD_USE_LSX)
  513|       |         return SIMD_4x32(__lsx_vslli_w(m_simd, SHIFT));
  514|       |#elif defined(BOTAN_SIMD_USE_SIMD128)
  515|       |         return SIMD_4x32(wasm_i32x4_shl(m_simd, SHIFT));
  516|       |#endif
  517|    120|      }
_ZNK5Botan9SIMD_4x323shrILi10EEES0_v:
  520|    240|      SIMD_4x32 BOTAN_FN_ISA_SIMD_4X32 shr() const noexcept {
  521|    240|#if defined(BOTAN_SIMD_USE_SSSE3)
  522|    240|         return SIMD_4x32(_mm_srli_epi32(m_simd, SHIFT));
  523|       |
  524|       |#elif defined(BOTAN_SIMD_USE_ALTIVEC)
  525|       |         const unsigned int s = static_cast<unsigned int>(SHIFT);
  526|       |         const __vector unsigned int shifts = {s, s, s, s};
  527|       |         return SIMD_4x32(vec_sr(m_simd, shifts));
  528|       |#elif defined(BOTAN_SIMD_USE_NEON)
  529|       |         return SIMD_4x32(vshrq_n_u32(m_simd, SHIFT));
  530|       |#elif defined(BOTAN_SIMD_USE_LSX)
  531|       |         return SIMD_4x32(__lsx_vsrli_w(m_simd, SHIFT));
  532|       |#elif defined(BOTAN_SIMD_USE_SIMD128)
  533|       |         return SIMD_4x32(wasm_u32x4_shr(m_simd, SHIFT));
  534|       |#endif
  535|    240|      }

_ZN5Botan9SIMD_8x32C2Ejjjjjjjj:
   46|      5|                         uint32_t B7) noexcept {
   47|       |         // NOLINTNEXTLINE(*-prefer-member-initializer)
   48|      5|         m_avx2 = _mm256_set_epi32(B7, B6, B5, B4, B3, B2, B1, B0);
   49|      5|      }
_ZN5Botan9SIMD_8x325splatEj:
   58|    155|      static SIMD_8x32 splat(uint32_t B) noexcept { return SIMD_8x32(_mm256_set1_epi32(B)); }
_ZNK5Botan9SIMD_8x328store_leEPh:
   84|     80|      void store_le(uint8_t out[]) const noexcept { _mm256_storeu_si256(reinterpret_cast<__m256i*>(out), m_avx2); }
_ZNK5Botan9SIMD_8x32plERKS0_:
  164|      5|      SIMD_8x32 operator+(const SIMD_8x32& other) const noexcept {
  165|      5|         SIMD_8x32 retval(*this);
  166|      5|         retval += other;
  167|      5|         return retval;
  168|      5|      }
_ZNK5Botan9SIMD_8x32miERKS0_:
  171|      5|      SIMD_8x32 operator-(const SIMD_8x32& other) const noexcept {
  172|      5|         SIMD_8x32 retval(*this);
  173|      5|         retval -= other;
  174|      5|         return retval;
  175|      5|      }
_ZN5Botan9SIMD_8x32pLERKS0_:
  199|  1.68k|      void operator+=(const SIMD_8x32& other) { m_avx2 = _mm256_add_epi32(m_avx2, other.m_avx2); }
_ZN5Botan9SIMD_8x32mIERKS0_:
  202|      5|      void operator-=(const SIMD_8x32& other) { m_avx2 = _mm256_sub_epi32(m_avx2, other.m_avx2); }
_ZN5Botan9SIMD_8x32eOERKS0_:
  205|  1.60k|      void operator^=(const SIMD_8x32& other) { m_avx2 = _mm256_xor_si256(m_avx2, other.m_avx2); }
_ZN5Botan9SIMD_8x329transposeERS0_S1_S1_S1_:
  264|     20|      static void transpose(SIMD_8x32& B0, SIMD_8x32& B1, SIMD_8x32& B2, SIMD_8x32& B3) noexcept {
  265|     20|         const __m256i T0 = _mm256_unpacklo_epi32(B0.m_avx2, B1.m_avx2);
  266|     20|         const __m256i T1 = _mm256_unpacklo_epi32(B2.m_avx2, B3.m_avx2);
  267|     20|         const __m256i T2 = _mm256_unpackhi_epi32(B0.m_avx2, B1.m_avx2);
  268|     20|         const __m256i T3 = _mm256_unpackhi_epi32(B2.m_avx2, B3.m_avx2);
  269|       |
  270|     20|         B0.m_avx2 = _mm256_unpacklo_epi64(T0, T1);
  271|     20|         B1.m_avx2 = _mm256_unpackhi_epi64(T0, T1);
  272|     20|         B2.m_avx2 = _mm256_unpacklo_epi64(T2, T3);
  273|     20|         B3.m_avx2 = _mm256_unpackhi_epi64(T2, T3);
  274|     20|      }
_ZN5Botan9SIMD_8x329transposeERS0_S1_S1_S1_S1_S1_S1_S1_:
  302|     10|                            SIMD_8x32& B7) noexcept {
  303|     10|         transpose(B0, B1, B2, B3);
  304|     10|         transpose(B4, B5, B6, B7);
  305|       |
  306|     10|         swap_tops(B0, B4);
  307|     10|         swap_tops(B1, B5);
  308|     10|         swap_tops(B2, B6);
  309|     10|         swap_tops(B3, B7);
  310|     10|      }
_ZNK5Botan9SIMD_8x3211unsigned_ltERKS0_:
  317|      5|      SIMD_8x32 BOTAN_FN_ISA_AVX2 unsigned_lt(const SIMD_8x32& other) const noexcept {
  318|       |         // No unsigned comparison before AVX-512; bias into the signed domain
  319|      5|         const __m256i bias = _mm256_set1_epi32(static_cast<int32_t>(0x80000000));
  320|      5|         return SIMD_8x32(_mm256_cmpgt_epi32(_mm256_xor_si256(other.raw(), bias), _mm256_xor_si256(raw(), bias)));
  321|      5|      }
_ZN5Botan9SIMD_8x3215reset_registersEv:
  346|      5|      static void reset_registers() noexcept { _mm256_zeroupper(); }
_ZN5Botan9SIMD_8x3214zero_registersEv:
  349|      5|      static void zero_registers() noexcept { _mm256_zeroall(); }
_ZNK5Botan9SIMD_8x323rawEv:
  351|    170|      __m256i BOTAN_FN_ISA_AVX2 raw() const noexcept { return m_avx2; }
_ZN5Botan9SIMD_8x32C2EDv4_x:
  354|  1.84k|      explicit SIMD_8x32(__m256i x) noexcept : m_avx2(x) {}
_ZN5Botan9SIMD_8x329swap_topsERS0_S1_:
  358|     40|      static void swap_tops(SIMD_8x32& A, SIMD_8x32& B) {
  359|     40|         auto T0 = SIMD_8x32(_mm256_permute2x128_si256(A.raw(), B.raw(), 0 + (2 << 4)));
  360|       |         auto T1 = SIMD_8x32(_mm256_permute2x128_si256(A.raw(), B.raw(), 1 + (3 << 4)));
  361|     40|         A = T0;
  362|     40|         B = T1;
  363|     40|      }
_ZNK5Botan9SIMD_8x324rotlILm7EEES0_vQaagtT_Li0EltT_Li32E:
  118|    400|      {
  119|       |#if defined(__AVX512VL__)
  120|       |         return SIMD_8x32(_mm256_rol_epi32(m_avx2, ROT));
  121|       |#else
  122|       |         if constexpr(ROT == 8) {
  123|       |            const __m256i shuf_rotl_8 =
  124|       |               _mm256_set_epi64x(0x0e0d0c0f'0a09080b, 0x06050407'02010003, 0x0e0d0c0f'0a09080b, 0x06050407'02010003);
  125|       |
  126|       |            return SIMD_8x32(_mm256_shuffle_epi8(m_avx2, shuf_rotl_8));
  127|       |         } else if constexpr(ROT == 16) {
  128|       |            const __m256i shuf_rotl_16 =
  129|       |               _mm256_set_epi64x(0x0d0c0f0e'09080b0a, 0x05040706'01000302, 0x0d0c0f0e'09080b0a, 0x05040706'01000302);
  130|       |
  131|       |            return SIMD_8x32(_mm256_shuffle_epi8(m_avx2, shuf_rotl_16));
  132|       |         } else if constexpr(ROT == 24) {
  133|       |            const __m256i shuf_rotl_24 =
  134|       |               _mm256_set_epi64x(0x0c0f0e0d'080b0a09, 0x04070605'00030201, 0x0c0f0e0d'080b0a09, 0x04070605'00030201);
  135|       |
  136|       |            return SIMD_8x32(_mm256_shuffle_epi8(m_avx2, shuf_rotl_24));
  137|    400|         } else {
  138|    400|            return SIMD_8x32(_mm256_xor_si256(_mm256_slli_epi32(m_avx2, static_cast<int>(ROT)),
  139|    400|                                              _mm256_srli_epi32(m_avx2, static_cast<int>(32 - ROT))));
  140|    400|         }
  141|    400|#endif
  142|    400|      }
_ZNK5Botan9SIMD_8x324rotlILm16EEES0_vQaagtT_Li0EltT_Li32E:
  118|    400|      {
  119|       |#if defined(__AVX512VL__)
  120|       |         return SIMD_8x32(_mm256_rol_epi32(m_avx2, ROT));
  121|       |#else
  122|       |         if constexpr(ROT == 8) {
  123|       |            const __m256i shuf_rotl_8 =
  124|       |               _mm256_set_epi64x(0x0e0d0c0f'0a09080b, 0x06050407'02010003, 0x0e0d0c0f'0a09080b, 0x06050407'02010003);
  125|       |
  126|       |            return SIMD_8x32(_mm256_shuffle_epi8(m_avx2, shuf_rotl_8));
  127|    400|         } else if constexpr(ROT == 16) {
  128|    400|            const __m256i shuf_rotl_16 =
  129|    400|               _mm256_set_epi64x(0x0d0c0f0e'09080b0a, 0x05040706'01000302, 0x0d0c0f0e'09080b0a, 0x05040706'01000302);
  130|       |
  131|    400|            return SIMD_8x32(_mm256_shuffle_epi8(m_avx2, shuf_rotl_16));
  132|       |         } else if constexpr(ROT == 24) {
  133|       |            const __m256i shuf_rotl_24 =
  134|       |               _mm256_set_epi64x(0x0c0f0e0d'080b0a09, 0x04070605'00030201, 0x0c0f0e0d'080b0a09, 0x04070605'00030201);
  135|       |
  136|       |            return SIMD_8x32(_mm256_shuffle_epi8(m_avx2, shuf_rotl_24));
  137|       |         } else {
  138|       |            return SIMD_8x32(_mm256_xor_si256(_mm256_slli_epi32(m_avx2, static_cast<int>(ROT)),
  139|       |                                              _mm256_srli_epi32(m_avx2, static_cast<int>(32 - ROT))));
  140|       |         }
  141|    400|#endif
  142|    400|      }
_ZNK5Botan9SIMD_8x324rotlILm12EEES0_vQaagtT_Li0EltT_Li32E:
  118|    400|      {
  119|       |#if defined(__AVX512VL__)
  120|       |         return SIMD_8x32(_mm256_rol_epi32(m_avx2, ROT));
  121|       |#else
  122|       |         if constexpr(ROT == 8) {
  123|       |            const __m256i shuf_rotl_8 =
  124|       |               _mm256_set_epi64x(0x0e0d0c0f'0a09080b, 0x06050407'02010003, 0x0e0d0c0f'0a09080b, 0x06050407'02010003);
  125|       |
  126|       |            return SIMD_8x32(_mm256_shuffle_epi8(m_avx2, shuf_rotl_8));
  127|       |         } else if constexpr(ROT == 16) {
  128|       |            const __m256i shuf_rotl_16 =
  129|       |               _mm256_set_epi64x(0x0d0c0f0e'09080b0a, 0x05040706'01000302, 0x0d0c0f0e'09080b0a, 0x05040706'01000302);
  130|       |
  131|       |            return SIMD_8x32(_mm256_shuffle_epi8(m_avx2, shuf_rotl_16));
  132|       |         } else if constexpr(ROT == 24) {
  133|       |            const __m256i shuf_rotl_24 =
  134|       |               _mm256_set_epi64x(0x0c0f0e0d'080b0a09, 0x04070605'00030201, 0x0c0f0e0d'080b0a09, 0x04070605'00030201);
  135|       |
  136|       |            return SIMD_8x32(_mm256_shuffle_epi8(m_avx2, shuf_rotl_24));
  137|    400|         } else {
  138|    400|            return SIMD_8x32(_mm256_xor_si256(_mm256_slli_epi32(m_avx2, static_cast<int>(ROT)),
  139|    400|                                              _mm256_srli_epi32(m_avx2, static_cast<int>(32 - ROT))));
  140|    400|         }
  141|    400|#endif
  142|    400|      }
_ZNK5Botan9SIMD_8x324rotlILm8EEES0_vQaagtT_Li0EltT_Li32E:
  118|    400|      {
  119|       |#if defined(__AVX512VL__)
  120|       |         return SIMD_8x32(_mm256_rol_epi32(m_avx2, ROT));
  121|       |#else
  122|    400|         if constexpr(ROT == 8) {
  123|    400|            const __m256i shuf_rotl_8 =
  124|    400|               _mm256_set_epi64x(0x0e0d0c0f'0a09080b, 0x06050407'02010003, 0x0e0d0c0f'0a09080b, 0x06050407'02010003);
  125|       |
  126|    400|            return SIMD_8x32(_mm256_shuffle_epi8(m_avx2, shuf_rotl_8));
  127|       |         } else if constexpr(ROT == 16) {
  128|       |            const __m256i shuf_rotl_16 =
  129|       |               _mm256_set_epi64x(0x0d0c0f0e'09080b0a, 0x05040706'01000302, 0x0d0c0f0e'09080b0a, 0x05040706'01000302);
  130|       |
  131|       |            return SIMD_8x32(_mm256_shuffle_epi8(m_avx2, shuf_rotl_16));
  132|       |         } else if constexpr(ROT == 24) {
  133|       |            const __m256i shuf_rotl_24 =
  134|       |               _mm256_set_epi64x(0x0c0f0e0d'080b0a09, 0x04070605'00030201, 0x0c0f0e0d'080b0a09, 0x04070605'00030201);
  135|       |
  136|       |            return SIMD_8x32(_mm256_shuffle_epi8(m_avx2, shuf_rotl_24));
  137|       |         } else {
  138|       |            return SIMD_8x32(_mm256_xor_si256(_mm256_slli_epi32(m_avx2, static_cast<int>(ROT)),
  139|       |                                              _mm256_srli_epi32(m_avx2, static_cast<int>(32 - ROT))));
  140|       |         }
  141|    400|#endif
  142|    400|      }

_ZN5Botan2CT13value_barrierITkNSt3__117unsigned_integralEmQntsr3stdE7same_asIbT_EEES3_S3_:
   43|  16.2M|constexpr inline T value_barrier(T x) {
   44|  16.2M|   if(std::is_constant_evaluated()) {
  ------------------
  |  Branch (44:7): [Folded, False: 16.2M]
  ------------------
   45|      0|      return x;
   46|  16.2M|   } else {
   47|  16.2M|#if defined(BOTAN_CT_VALUE_BARRIER_USE_ASM)
   48|       |      /*
   49|       |      * We may want a "stronger" statement such as
   50|       |      *     asm volatile("" : "+r,m"(x) : : "memory);
   51|       |      * (see https://theunixzoo.co.uk/blog/2021-10-14-preventing-optimisations.html)
   52|       |      * however the current approach seems sufficient with current compilers,
   53|       |      * and is minimally damaging with regards to degrading code generation.
   54|       |      */
   55|  16.2M|      asm("" : "+r"(x) : /* no input */);  // NOLINT(*-no-assembler)
   56|  16.2M|      return x;
   57|       |#elif defined(BOTAN_CT_VALUE_BARRIER_USE_VOLATILE)
   58|       |      volatile T vx = x;
   59|       |      return vx;
   60|       |#else
   61|       |      return x;
   62|       |#endif
   63|  16.2M|   }
   64|  16.2M|}
_ZN5Botan2CT13value_barrierITkNSt3__117unsigned_integralEhQntsr3stdE7same_asIbT_EEES3_S3_:
   43|  68.1k|constexpr inline T value_barrier(T x) {
   44|  68.1k|   if(std::is_constant_evaluated()) {
  ------------------
  |  Branch (44:7): [Folded, False: 68.1k]
  ------------------
   45|      0|      return x;
   46|  68.1k|   } else {
   47|  68.1k|#if defined(BOTAN_CT_VALUE_BARRIER_USE_ASM)
   48|       |      /*
   49|       |      * We may want a "stronger" statement such as
   50|       |      *     asm volatile("" : "+r,m"(x) : : "memory);
   51|       |      * (see https://theunixzoo.co.uk/blog/2021-10-14-preventing-optimisations.html)
   52|       |      * however the current approach seems sufficient with current compilers,
   53|       |      * and is minimally damaging with regards to degrading code generation.
   54|       |      */
   55|  68.1k|      asm("" : "+r"(x) : /* no input */);  // NOLINT(*-no-assembler)
   56|  68.1k|      return x;
   57|       |#elif defined(BOTAN_CT_VALUE_BARRIER_USE_VOLATILE)
   58|       |      volatile T vx = x;
   59|       |      return vx;
   60|       |#else
   61|       |      return x;
   62|       |#endif
   63|  68.1k|   }
   64|  68.1k|}

_ZN5Botan13ignore_paramsIJPKmmEEEvDpRKT_:
  142|   635k|constexpr void ignore_params([[maybe_unused]] const T&... args) {}

_ZN5Botan6BigIntD2Ev:
  185|   195k|      ~BigInt() { _const_time_unpoison(); }
_ZN5BotangtERKNS_6BigIntEm:
 1423|  4.19k|inline bool operator>(const BigInt& a, word b) {
 1424|  4.19k|   return (a.cmp_word(b) > 0);
 1425|  4.19k|}
_ZN5BotanneERKNS_6BigIntES2_:
 1323|    675|inline bool operator!=(const BigInt& a, const BigInt& b) {
 1324|    675|   return !a.is_equal(b);
 1325|    675|}
_ZN5Botan6BigInt4zeroEv:
   50|  13.8k|      static BigInt zero() { return BigInt(); }
_ZN5Botan6BigInt3oneEv:
   55|      2|      static BigInt one() { return BigInt::from_u64(1); }
_ZN5Botan6BigIntC2EOS0_:
  183|  40.3k|      BigInt(BigInt&& other) noexcept { this->swap(other); }
_ZN5Botan6BigIntaSEOS0_:
  190|   127k|      BigInt& operator=(BigInt&& other) noexcept {
  191|   127k|         if(this != &other) {
  ------------------
  |  Branch (191:13): [True: 127k, False: 0]
  ------------------
  192|   127k|            this->swap(other);
  193|   127k|         }
  194|       |
  195|   127k|         return (*this);
  196|   127k|      }
_ZN5Botan6BigInt4swapERS0_:
  207|   167k|      void swap(BigInt& other) noexcept {
  208|   167k|         m_data.swap(other.m_data);
  209|   167k|         std::swap(m_signedness, other.m_signedness);
  210|   167k|      }
_ZN5Botan6BigInt8swap_regERNSt3__16vectorImNS_16secure_allocatorImEEEE:
  218|  1.59k|      BOTAN_DEPRECATED("Deprecated no replacement") void swap_reg(secure_vector<word>& reg) {
  219|  1.59k|         m_data.swap(reg);
  220|       |         // sign left unchanged
  221|  1.59k|      }
_ZN5Botan6BigIntpLEm:
  233|    101|      BigInt& operator+=(word y) { return add(&y, 1, Positive); }
_ZN5Botan6BigIntmIEm:
  245|    676|      BigInt& operator-=(word y) { return sub(&y, 1, Positive); }
_ZN5Botan6BigInt3subEPKmmNS0_4SignE:
  358|  16.9k|      BigInt& sub(const word y[], size_t y_words, Sign sign) {
  359|  16.9k|         return add(y, y_words, sign == Positive ? Negative : Positive);
  ------------------
  |  Branch (359:33): [True: 16.9k, False: 0]
  ------------------
  360|  16.9k|      }
_ZN5Botan6BigInt5clearEv:
  441|  1.24k|      void clear() {
  442|  1.24k|         m_data.set_to_zero();
  443|  1.24k|         m_signedness = Positive;
  444|  1.24k|      }
_ZNK5Botan6BigInt7is_evenEv:
  481|    763|      bool is_even() const { return !get_bit(0); }
_ZNK5Botan6BigInt6is_oddEv:
  487|  43.4k|      bool is_odd() const { return get_bit(0); }
_ZNK5Botan6BigInt6signumEv:
  493|   553k|      int signum() const {
  494|   553k|         if(sig_words() == 0) {
  ------------------
  |  Branch (494:13): [True: 398, False: 552k]
  ------------------
  495|    398|            return 0;
  496|    398|         }
  497|   552k|         return (sign() == Negative) ? -1 : 1;
  ------------------
  |  Branch (497:17): [True: 534, False: 552k]
  ------------------
  498|   553k|      }
_ZNK5Botan6BigInt7is_zeroEv:
  510|  67.1k|      bool is_zero() const { return sig_words() == 0; }
_ZN5Botan6BigInt7set_bitEm:
  516|  2.43k|      void set_bit(size_t n) { conditionally_set_bit(n, true); }
_ZN5Botan6BigInt21conditionally_set_bitEmb:
  526|  6.30k|      void conditionally_set_bit(size_t n, bool set_it) {
  527|  6.30k|         const size_t which = n / (sizeof(word) * 8);
  528|  6.30k|         const word mask = static_cast<word>(set_it) << (n % (sizeof(word) * 8));
  529|  6.30k|         m_data.set_word_at(which, word_at(which) | mask);
  530|  6.30k|      }
_ZNK5Botan6BigInt7get_bitEm:
  549|   109k|      bool get_bit(size_t n) const { return ((word_at(n / (sizeof(word) * 8)) >> (n % (sizeof(word) * 8))) & 1) == 1; }
_ZNK5Botan6BigInt7word_atEm:
  601|   761k|      word word_at(size_t n) const { return m_data.get_word_at(n); }
_ZN5Botan6BigInt11set_word_atEmm:
  608|  35.9k|      BOTAN_DEPRECATED("Deprecated no replacement") void set_word_at(size_t i, word w) { m_data.set_word_at(i, w); }
_ZNK5Botan6BigInt4signEv:
  641|   711k|      Sign sign() const { return (m_signedness); }
_ZNK5Botan6BigInt12reverse_signEv:
  647|    567|      Sign reverse_sign() const {
  648|    567|         if(sign() == Positive) {
  ------------------
  |  Branch (648:13): [True: 565, False: 2]
  ------------------
  649|    565|            return Negative;
  650|    565|         }
  651|      2|         return Positive;
  652|    567|      }
_ZN5Botan6BigInt9flip_signEv:
  657|    522|      BOTAN_DEPRECATED("Deprecated no replacement") void flip_sign() { set_sign(reverse_sign()); }
_ZN5Botan6BigInt8set_signENS0_4SignE:
  663|  73.4k|      void set_sign(Sign sign) {
  664|  73.4k|         if(sign == Negative && is_zero()) {
  ------------------
  |  Branch (664:13): [True: 530, False: 72.8k]
  |  Branch (664:33): [True: 2, False: 528]
  ------------------
  665|      2|            sign = Positive;
  666|      2|         }
  667|       |
  668|  73.4k|         m_signedness = sign;
  669|  73.4k|      }
_ZNK5Botan6BigInt4sizeEv:
  681|   583k|      size_t size() const { return m_data.size(); }
_ZNK5Botan6BigInt9sig_wordsEv:
  687|  1.06M|      size_t sig_words() const { return m_data.sig_words(); }
_ZN5Botan6BigInt12mutable_dataEv:
  712|  81.5k|      BOTAN_DEPRECATED("Deprecated no replacement") word* mutable_data() { return m_data.mutable_data(); }
_ZNK5Botan6BigInt4dataEv:
  718|  1.52k|      BOTAN_DEPRECATED("Deprecated no replacement") const word* data() const { return m_data.const_data(); }
_ZNK5Botan6BigInt7grow_toEm:
  738|  69.8k|      BOTAN_DEPRECATED("Deprecated no replacement") void grow_to(size_t n) const { m_data.grow_to(n); }
_ZN5Botan6BigInt10power_of_2Em:
  906|  1.74k|      static BigInt power_of_2(size_t n) {
  907|  1.74k|         BigInt b;
  908|  1.74k|         b.set_bit(n);
  909|  1.74k|         return b;
  910|  1.74k|      }
_ZNK5Botan6BigInt8_as_spanEv:
 1023|  9.52k|      std::span<const word> _as_span() const { return m_data.const_span(); }
_ZNK5Botan6BigInt5_dataEv:
 1033|   812k|      const word* _data() const { return m_data.const_data(); }
_ZN5Botan6BigInt11_from_wordsERNSt3__16vectorImNS_16secure_allocatorImEEEE:
 1052|  15.4k|      static BigInt _from_words(secure_vector<word>& words) {
 1053|  15.4k|         BigInt bn;
 1054|  15.4k|         bn.m_data.swap(words);
 1055|  15.4k|         return bn;
 1056|  15.4k|      }
_ZN5Botan6BigInt4Data12mutable_dataEv:
 1083|   179k|            word* mutable_data() {
 1084|   179k|               invalidate_sig_words();
 1085|   179k|               return m_reg.data();
 1086|   179k|            }
_ZNK5Botan6BigInt4Data10const_dataEv:
 1088|  1.00M|            const word* const_data() const { return m_reg.data(); }
_ZNK5Botan6BigInt4Data10const_spanEv:
 1090|  9.52k|            std::span<const word> const_span() const { return std::span{m_reg}; }
_ZNK5Botan6BigInt4Data11get_word_atEm:
 1099|   761k|            word get_word_at(size_t n) const {
 1100|   761k|               if(n < m_reg.size()) {
  ------------------
  |  Branch (1100:19): [True: 758k, False: 2.41k]
  ------------------
 1101|   758k|                  return m_reg[n];
 1102|   758k|               }
 1103|  2.41k|               return 0;
 1104|   761k|            }
_ZN5Botan6BigInt4Data11set_word_atEmm:
 1106|  42.7k|            void set_word_at(size_t i, word w) {
 1107|  42.7k|               invalidate_sig_words();
 1108|  42.7k|               if(i >= m_reg.size()) {
  ------------------
  |  Branch (1108:19): [True: 30.7k, False: 12.0k]
  ------------------
 1109|  30.7k|                  if(w == 0) {
  ------------------
  |  Branch (1109:22): [True: 1, False: 30.7k]
  ------------------
 1110|      1|                     return;
 1111|      1|                  }
 1112|  30.7k|                  grow_to(i + 1);
 1113|  30.7k|               }
 1114|  42.7k|               m_reg[i] = w;
 1115|  42.7k|            }
_ZNK5Botan6BigInt4Data7grow_toEm:
 1126|   126k|            void grow_to(size_t n) const {
 1127|   126k|               if(n > size()) {
  ------------------
  |  Branch (1127:19): [True: 81.1k, False: 45.4k]
  ------------------
 1128|  81.1k|                  if(n <= m_reg.capacity()) {
  ------------------
  |  Branch (1128:22): [True: 508, False: 80.6k]
  ------------------
 1129|    508|                     m_reg.resize(n);
 1130|  80.6k|                  } else {
 1131|  80.6k|                     m_reg.resize(n + (8 - (n % 8)));
 1132|  80.6k|                  }
 1133|  81.1k|               }
 1134|   126k|            }
_ZNK5Botan6BigInt4Data4sizeEv:
 1136|   978k|            size_t size() const { return m_reg.size(); }
_ZN5Botan6BigInt4Data4swapERS1_:
 1151|   167k|            void swap(Data& other) noexcept {
 1152|   167k|               m_reg.swap(other.m_reg);
 1153|   167k|               std::swap(m_sig_words, other.m_sig_words);
 1154|   167k|            }
_ZN5Botan6BigInt4Data4swapERNSt3__16vectorImNS_16secure_allocatorImEEEE:
 1156|  18.3k|            void swap(secure_vector<word>& reg) noexcept {
 1157|  18.3k|               m_reg.swap(reg);
 1158|  18.3k|               invalidate_sig_words();
 1159|  18.3k|            }
_ZNK5Botan6BigInt4Data20invalidate_sig_wordsEv:
 1161|   240k|            void invalidate_sig_words() const noexcept { m_sig_words = sig_words_npos; }
_ZNK5Botan6BigInt4Data9sig_wordsEv:
 1163|  1.06M|            size_t sig_words() const {
 1164|  1.06M|               if(m_sig_words == sig_words_npos) {
  ------------------
  |  Branch (1164:19): [True: 193k, False: 867k]
  ------------------
 1165|   193k|                  m_sig_words = calc_sig_words();
 1166|   193k|               }
 1167|  1.06M|               return m_sig_words;
 1168|  1.06M|            }
_ZN5BotanplERKNS_6BigIntES2_:
 1189|    808|inline BigInt operator+(const BigInt& x, const BigInt& y) {
 1190|    808|   return BigInt::add2(x, y._data(), y.sig_words(), y.sign());
 1191|    808|}
_ZN5BotanplERKNS_6BigIntEm:
 1199|    609|inline BigInt operator+(const BigInt& x, word y) {
 1200|    609|   return BigInt::add2(x, &y, 1, BigInt::Positive);
 1201|    609|}
_ZN5BotanmiERKNS_6BigIntES2_:
 1219|     45|inline BigInt operator-(const BigInt& x, const BigInt& y) {
 1220|     45|   return BigInt::add2(x, y._data(), y.sig_words(), y.reverse_sign());
 1221|     45|}
_ZN5BotanmiERKNS_6BigIntEm:
 1229|    717|inline BigInt operator-(const BigInt& x, word y) {
 1230|    717|   return BigInt::add2(x, &y, 1, BigInt::Negative);
 1231|    717|}
_ZN5BotanmlEmRKNS_6BigIntE:
 1255|  15.6k|inline BigInt operator*(word x, const BigInt& y) {
 1256|  15.6k|   return y * x;
 1257|  15.6k|}
_ZN5BotaneqERKNS_6BigIntES2_:
 1313|    129|inline bool operator==(const BigInt& a, const BigInt& b) {
 1314|    129|   return a.is_equal(b);
 1315|    129|}
_ZN5BotanleERKNS_6BigIntES2_:
 1333|     86|inline bool operator<=(const BigInt& a, const BigInt& b) {
 1334|     86|   return (a.cmp(b) <= 0);
 1335|     86|}
_ZN5BotangeERKNS_6BigIntES2_:
 1343|  2.46k|inline bool operator>=(const BigInt& a, const BigInt& b) {
 1344|  2.46k|   return (a.cmp(b) >= 0);
 1345|  2.46k|}
_ZN5BotanltERKNS_6BigIntES2_:
 1353|  47.4k|inline bool operator<(const BigInt& a, const BigInt& b) {
 1354|  47.4k|   return a.is_less_than(b);
 1355|  47.4k|}
_ZN5BotaneqERKNS_6BigIntEm:
 1373|  87.3k|inline bool operator==(const BigInt& a, word b) {
 1374|  87.3k|   return (a.cmp_word(b) == 0);
 1375|  87.3k|}
_ZN5BotanneERKNS_6BigIntEm:
 1383|  3.16k|inline bool operator!=(const BigInt& a, word b) {
 1384|  3.16k|   return (a.cmp_word(b) != 0);
 1385|  3.16k|}
_ZN5BotanleERKNS_6BigIntEm:
 1393|  1.19k|inline bool operator<=(const BigInt& a, word b) {
 1394|  1.19k|   return (a.cmp_word(b) <= 0);
 1395|  1.19k|}
_ZN5BotangeERKNS_6BigIntEm:
 1403|  3.60k|inline bool operator>=(const BigInt& a, word b) {
 1404|  3.60k|   return (a.cmp_word(b) >= 0);
 1405|  3.60k|}
_ZN5BotanltERKNS_6BigIntEm:
 1413|  3.16k|inline bool operator<(const BigInt& a, word b) {
 1414|  3.16k|   return (a.cmp_word(b) < 0);
 1415|  3.16k|}
_ZN5Botan6BigIntC2ERKS0_:
   88|  31.7k|      BigInt(const BigInt& other) = default;
_ZN5Botan6BigIntC2Ev:
   45|   122k|      BigInt() = default;
_ZN5Botan6BigIntaSERKS0_:
  201|  28.5k|      BigInt& operator=(const BigInt&) = default;

_ZN5Botan20Buffered_Computation6updateENSt3__14spanIKhLm18446744073709551615EEE:
   41|     10|      void update(std::span<const uint8_t> in) { add_data(in); }
_ZN5Botan20Buffered_Computation5finalITkNS_8concepts21resizable_byte_bufferENSt3__16vectorIhNS_16secure_allocatorIhEEEEEET_v:
  104|      2|      T final() {
  105|      2|         T output(output_length());
  106|      2|         final_result(output);
  107|      2|         return output;
  108|      2|      }
_ZN5Botan20Buffered_ComputationD2Ev:
  169|      2|      virtual ~Buffered_Computation() = default;

_ZNK5Botan10ChaCha_RNG31max_number_of_bytes_per_requestEv:
  120|     53|      size_t max_number_of_bytes_per_request() const override { return 0; }

_ZN5Botan11clear_bytesEPvm:
  101|  44.0k|inline constexpr void clear_bytes(void* ptr, size_t bytes) {
  102|  44.0k|   if(bytes > 0) {
  ------------------
  |  Branch (102:7): [True: 42.7k, False: 1.24k]
  ------------------
  103|  42.7k|      std::memset(ptr, 0, bytes);
  104|  42.7k|   }
  105|  44.0k|}
_ZN5Botan9clear_memImEEvPT_m:
  118|  30.8k|inline constexpr void clear_mem(T* ptr, size_t n) {
  119|  30.8k|   clear_bytes(ptr, sizeof(T) * n);
  120|  30.8k|}
_ZN5Botan8copy_memImQsr3stdE12is_trivial_vIu7__decayIT_EEEEvPS1_PKS1_m:
  144|  13.0k|inline constexpr void copy_mem(T* out, const T* in, size_t n) {
  145|  13.0k|   BOTAN_ASSERT_IMPLICATION(n > 0, in != nullptr && out != nullptr, "If n > 0 then args are not null");
  ------------------
  |  |  103|  13.0k|   do {                                                                                          \
  |  |  104|  13.0k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                                              \
  |  |  105|  26.1k|      if((expr1) && !(expr2)) {                                                                  \
  |  |  ------------------
  |  |  |  Branch (105:10): [True: 13.0k, False: 0]
  |  |  |  Branch (105:23): [True: 13.0k, False: 0]
  |  |  |  Branch (105:23): [True: 13.0k, False: 0]
  |  |  ------------------
  |  |  106|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                                     \
  |  |  107|      0|         Botan::assertion_failure(#expr1 " implies " #expr2, msg, __func__, __FILE__, __LINE__); \
  |  |  108|      0|      }                                                                                          \
  |  |  109|  13.0k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (109:12): [Folded, False: 13.0k]
  |  |  ------------------
  ------------------
  146|       |
  147|  13.0k|   if(in != nullptr && out != nullptr && n > 0) {
  ------------------
  |  Branch (147:7): [True: 13.0k, False: 0]
  |  Branch (147:24): [True: 13.0k, False: 0]
  |  Branch (147:42): [True: 13.0k, False: 0]
  ------------------
  148|  13.0k|      std::memmove(out, in, sizeof(T) * n);
  149|  13.0k|   }
  150|  13.0k|}
_ZN5Botan13typecast_copyITkNS_6ranges23contiguous_output_rangeERKNSt3__14spanIhLm8EEEmQaaaasr3stdE23is_trivially_copyable_vIT0_Entsr3std6rangesE5rangeIS7_Esr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISF_EESG_E4type10value_typeEEEEvOSC_RKS7_:
  199|      4|inline constexpr void typecast_copy(ToR&& out /* NOLINT(*-std-forward) */, const FromT& in) {
  200|      4|   typecast_copy(out, std::span<const FromT, 1>(&in, 1));
  201|      4|}
_ZN5Botan13typecast_copyITkNS_6ranges23contiguous_output_rangeERKNSt3__14spanIhLm8EEETkNS1_16contiguous_rangeENS3_IKmLm1EEEQaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISG_EESH_E4type10value_typeEEsr3stdE23is_trivially_copyable_vINS9_IXsr21__is_primary_templateINSA_Iu14__remove_cvrefIDTclL_ZNSC_5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENSI_ISQ_EESR_E4type10value_typeEEEEvOSN_RKSD_:
  176|      4|inline constexpr void typecast_copy(ToR&& out /* NOLINT(*-std-forward) */, const FromR& in) {
  177|      4|   ranges::assert_equal_byte_lengths(out, in);
  178|      4|   std::memcpy(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  179|      4|}
_ZN5Botan13typecast_copyImTkNS_6ranges16contiguous_rangeENSt3__14spanIKhLm8EEEQaaaasr3stdE26is_default_constructible_vIT_Esr3stdE23is_trivially_copyable_vIS6_Esr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISE_EESF_E4type10value_typeEEEES6_RKSB_:
  210|  1.45k|inline constexpr ToT typecast_copy(const FromR& src) {
  211|  1.45k|   ToT dst;  // NOLINT(*-member-init)
  212|  1.45k|   typecast_copy(dst, src);
  213|  1.45k|   return dst;
  214|  1.45k|}
_ZN5Botan13typecast_copyImTkNS_6ranges16contiguous_rangeENSt3__14spanIKhLm8EEEQaaaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISD_EESE_E4type10value_typeEEsr3stdE23is_trivially_copyable_vIT_Entsr3std6rangesE5rangeISK_EEEvRSK_RKSA_:
  188|  1.45k|inline constexpr void typecast_copy(ToT& out, const FromR& in) {
  189|  1.45k|   typecast_copy(std::span<ToT, 1>(&out, 1), in);
  190|  1.45k|}
_ZN5Botan13typecast_copyITkNS_6ranges23contiguous_output_rangeENSt3__14spanImLm1EEETkNS1_16contiguous_rangeENS3_IKhLm8EEEQaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISE_EESF_E4type10value_typeEEsr3stdE23is_trivially_copyable_vINS7_IXsr21__is_primary_templateINS8_Iu14__remove_cvrefIDTclL_ZNSA_5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENSG_ISO_EESP_E4type10value_typeEEEEvOSL_RKSB_:
  176|  1.45k|inline constexpr void typecast_copy(ToR&& out /* NOLINT(*-std-forward) */, const FromR& in) {
  177|  1.45k|   ranges::assert_equal_byte_lengths(out, in);
  178|  1.45k|   std::memcpy(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  179|  1.45k|}
_ZN5Botan8copy_memITkNS_6ranges23contiguous_output_rangeENSt3__14spanIhLm18446744073709551615EEETkNS1_16contiguous_rangeENS3_IKhLm18446744073709551615EEEQaasr3stdE9is_same_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISE_EESF_E4type10value_typeENS7_IXsr21__is_primary_templateINS8_Iu14__remove_cvrefIDTclL_ZNSA_5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENSG_ISO_EESP_E4type10value_typeEEsr3stdE23is_trivially_copyable_vIST_EEEvOSB_RKSL_:
  160|    915|inline constexpr void copy_mem(OutR&& out /* NOLINT(*-std-forward) */, const InR& in) {
  161|    915|   ranges::assert_equal_byte_lengths(out, in);
  162|    915|   if(std::is_constant_evaluated()) {
  ------------------
  |  Branch (162:7): [Folded, False: 915]
  ------------------
  163|      0|      std::copy(std::ranges::begin(in), std::ranges::end(in), std::ranges::begin(out));
  164|    915|   } else if(ranges::size_bytes(out) > 0) {
  ------------------
  |  Branch (164:14): [True: 915, False: 0]
  ------------------
  165|    915|      std::memmove(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  166|    915|   }
  167|    915|}
_ZN5Botan13typecast_copyImTkNS_6ranges16contiguous_rangeENSt3__14spanIhLm8EEEQaaaasr3stdE26is_default_constructible_vIT_Esr3stdE23is_trivially_copyable_vIS5_Esr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISD_EESE_E4type10value_typeEEEES5_RKSA_:
  210|    913|inline constexpr ToT typecast_copy(const FromR& src) {
  211|    913|   ToT dst;  // NOLINT(*-member-init)
  212|    913|   typecast_copy(dst, src);
  213|    913|   return dst;
  214|    913|}
_ZN5Botan13typecast_copyImTkNS_6ranges16contiguous_rangeENSt3__14spanIhLm8EEEQaaaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISC_EESD_E4type10value_typeEEsr3stdE23is_trivially_copyable_vIT_Entsr3std6rangesE5rangeISJ_EEEvRSJ_RKS9_:
  188|    913|inline constexpr void typecast_copy(ToT& out, const FromR& in) {
  189|    913|   typecast_copy(std::span<ToT, 1>(&out, 1), in);
  190|    913|}
_ZN5Botan13typecast_copyITkNS_6ranges23contiguous_output_rangeENSt3__14spanImLm1EEETkNS1_16contiguous_rangeENS3_IhLm8EEEQaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISD_EESE_E4type10value_typeEEsr3stdE23is_trivially_copyable_vINS6_IXsr21__is_primary_templateINS7_Iu14__remove_cvrefIDTclL_ZNS9_5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENSF_ISN_EESO_E4type10value_typeEEEEvOSK_RKSA_:
  176|    913|inline constexpr void typecast_copy(ToR&& out /* NOLINT(*-std-forward) */, const FromR& in) {
  177|    913|   ranges::assert_equal_byte_lengths(out, in);
  178|    913|   std::memcpy(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  179|    913|}
_ZN5Botan9clear_memITkNS_6ranges23contiguous_output_rangeENSt3__14spanImLm18446744073709551615EEEEEvOT_Qsr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRS5_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISD_EESE_E4type10value_typeEE:
  132|  13.0k|{
  133|  13.0k|   clear_bytes(std::ranges::data(mem), ranges::size_bytes(mem));
  134|  13.0k|}
_ZN5Botan8copy_memITkNS_6ranges23contiguous_output_rangeENSt3__14spanImLm18446744073709551615EEETkNS1_16contiguous_rangeENS3_IKmLm18446744073709551615EEEQaasr3stdE9is_same_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISE_EESF_E4type10value_typeENS7_IXsr21__is_primary_templateINS8_Iu14__remove_cvrefIDTclL_ZNSA_5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENSG_ISO_EESP_E4type10value_typeEEsr3stdE23is_trivially_copyable_vIST_EEEvOSB_RKSL_:
  160|  4.76k|inline constexpr void copy_mem(OutR&& out /* NOLINT(*-std-forward) */, const InR& in) {
  161|  4.76k|   ranges::assert_equal_byte_lengths(out, in);
  162|  4.76k|   if(std::is_constant_evaluated()) {
  ------------------
  |  Branch (162:7): [Folded, False: 4.76k]
  ------------------
  163|      0|      std::copy(std::ranges::begin(in), std::ranges::end(in), std::ranges::begin(out));
  164|  4.76k|   } else if(ranges::size_bytes(out) > 0) {
  ------------------
  |  Branch (164:14): [True: 4.76k, False: 0]
  ------------------
  165|  4.76k|      std::memmove(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  166|  4.76k|   }
  167|  4.76k|}
_ZN5Botan8copy_memITkNS_6ranges23contiguous_output_rangeERNSt3__16vectorImNS_16secure_allocatorImEEEETkNS1_16contiguous_rangeENS2_4spanImLm18446744073709551615EEEQaasr3stdE9is_same_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISH_EESI_E4type10value_typeENSA_IXsr21__is_primary_templateINSB_Iu14__remove_cvrefIDTclL_ZNSD_5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENSJ_ISR_EESS_E4type10value_typeEEsr3stdE23is_trivially_copyable_vISW_EEEvOSE_RKSO_:
  160|   424k|inline constexpr void copy_mem(OutR&& out /* NOLINT(*-std-forward) */, const InR& in) {
  161|   424k|   ranges::assert_equal_byte_lengths(out, in);
  162|   424k|   if(std::is_constant_evaluated()) {
  ------------------
  |  Branch (162:7): [Folded, False: 424k]
  ------------------
  163|      0|      std::copy(std::ranges::begin(in), std::ranges::end(in), std::ranges::begin(out));
  164|   424k|   } else if(ranges::size_bytes(out) > 0) {
  ------------------
  |  Branch (164:14): [True: 424k, False: 0]
  ------------------
  165|   424k|      std::memmove(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  166|   424k|   }
  167|   424k|}
_ZN5Botan9clear_memIhEEvPT_m:
  118|      4|inline constexpr void clear_mem(T* ptr, size_t n) {
  119|      4|   clear_bytes(ptr, sizeof(T) * n);
  120|      4|}
_ZN5Botan13typecast_copyITkNS_6ranges23contiguous_output_rangeERKNSt3__14spanIhLm4EEEjQaaaasr3stdE23is_trivially_copyable_vIT0_Entsr3std6rangesE5rangeIS7_Esr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISF_EESG_E4type10value_typeEEEEvOSC_RKS7_:
  199|     32|inline constexpr void typecast_copy(ToR&& out /* NOLINT(*-std-forward) */, const FromT& in) {
  200|     32|   typecast_copy(out, std::span<const FromT, 1>(&in, 1));
  201|     32|}
_ZN5Botan13typecast_copyITkNS_6ranges23contiguous_output_rangeERKNSt3__14spanIhLm4EEETkNS1_16contiguous_rangeENS3_IKjLm1EEEQaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISG_EESH_E4type10value_typeEEsr3stdE23is_trivially_copyable_vINS9_IXsr21__is_primary_templateINSA_Iu14__remove_cvrefIDTclL_ZNSC_5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENSI_ISQ_EESR_E4type10value_typeEEEEvOSN_RKSD_:
  176|     32|inline constexpr void typecast_copy(ToR&& out /* NOLINT(*-std-forward) */, const FromR& in) {
  177|     32|   ranges::assert_equal_byte_lengths(out, in);
  178|     32|   std::memcpy(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  179|     32|}
_ZN5Botan8copy_memIhQsr3stdE12is_trivial_vIu7__decayIT_EEEEvPS1_PKS1_m:
  144|     57|inline constexpr void copy_mem(T* out, const T* in, size_t n) {
  145|     57|   BOTAN_ASSERT_IMPLICATION(n > 0, in != nullptr && out != nullptr, "If n > 0 then args are not null");
  ------------------
  |  |  103|     57|   do {                                                                                          \
  |  |  104|     57|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                                              \
  |  |  105|    108|      if((expr1) && !(expr2)) {                                                                  \
  |  |  ------------------
  |  |  |  Branch (105:10): [True: 54, False: 3]
  |  |  |  Branch (105:23): [True: 54, False: 0]
  |  |  |  Branch (105:23): [True: 54, False: 0]
  |  |  ------------------
  |  |  106|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                                     \
  |  |  107|      0|         Botan::assertion_failure(#expr1 " implies " #expr2, msg, __func__, __FILE__, __LINE__); \
  |  |  108|      0|      }                                                                                          \
  |  |  109|     57|   } while(0)
  |  |  ------------------
  |  |  |  Branch (109:12): [Folded, False: 57]
  |  |  ------------------
  ------------------
  146|       |
  147|     57|   if(in != nullptr && out != nullptr && n > 0) {
  ------------------
  |  Branch (147:7): [True: 57, False: 0]
  |  Branch (147:24): [True: 57, False: 0]
  |  Branch (147:42): [True: 54, False: 3]
  ------------------
  148|     54|      std::memmove(out, in, sizeof(T) * n);
  149|     54|   }
  150|     57|}
_ZN5Botan9clear_memIjEEvPT_m:
  118|      6|inline constexpr void clear_mem(T* ptr, size_t n) {
  119|      6|   clear_bytes(ptr, sizeof(T) * n);
  120|      6|}
_ZN5Botan13typecast_copyITkNS_6ranges23contiguous_output_rangeERNSt3__14spanIjLm18446744073709551615EEETkNS1_16contiguous_rangeENS3_IKhLm18446744073709551615EEEQaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISF_EESG_E4type10value_typeEEsr3stdE23is_trivially_copyable_vINS8_IXsr21__is_primary_templateINS9_Iu14__remove_cvrefIDTclL_ZNSB_5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENSH_ISP_EESQ_E4type10value_typeEEEEvOSM_RKSC_:
  176|      2|inline constexpr void typecast_copy(ToR&& out /* NOLINT(*-std-forward) */, const FromR& in) {
  177|      2|   ranges::assert_equal_byte_lengths(out, in);
  178|      2|   std::memcpy(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  179|      2|}

_ZN5Botan6ranges25assert_equal_byte_lengthsITkNS0_14spanable_rangeENSt3__14spanIhLm18446744073709551615EEETpTkNS0_14spanable_rangeEJNS3_IKhLm18446744073709551615EEEEEEvRKT_DpRKT0_QgtsZT0_Li0E:
  100|    915|{
  101|    915|   const std::span s0{r0};
  102|       |
  103|       |   if constexpr(statically_spanable_range<R0>) {
  104|       |      constexpr size_t expected_size = s0.size_bytes();
  105|       |      (assert_exact_byte_length<expected_size>(rs), ...);
  106|    915|   } else {
  107|    915|      const size_t expected_size = s0.size_bytes();
  108|    915|      const bool correct_size =
  109|    915|         ((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...);
  110|       |
  111|    915|      if(!correct_size) {
  ------------------
  |  Branch (111:10): [True: 0, False: 915]
  ------------------
  112|      0|         memory_region_size_violation();
  113|      0|      }
  114|    915|   }
  115|    915|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm8ETkNS0_14spanable_rangeENSt3__14spanIhLm8EEEEEvRKT0_:
   77|    917|inline constexpr void assert_exact_byte_length(const R& r) {
   78|    917|   const std::span s{r};
   79|    917|   if constexpr(statically_spanable_range<R>) {
   80|    917|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   81|       |   } else {
   82|       |      if(s.size_bytes() != expected) {
   83|       |         memory_region_size_violation();
   84|       |      }
   85|       |   }
   86|    917|}
_ZN5Botan6ranges25assert_equal_byte_lengthsITkNS0_14spanable_rangeENSt3__14spanIhLm8EEETpTkNS0_14spanable_rangeEJNS3_IKmLm1EEEEEEvRKT_DpRKT0_QgtsZT0_Li0E:
  100|      4|{
  101|      4|   const std::span s0{r0};
  102|       |
  103|      4|   if constexpr(statically_spanable_range<R0>) {
  104|      4|      constexpr size_t expected_size = s0.size_bytes();
  105|      4|      (assert_exact_byte_length<expected_size>(rs), ...);
  106|       |   } else {
  107|       |      const size_t expected_size = s0.size_bytes();
  108|       |      const bool correct_size =
  109|       |         ((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...);
  110|       |
  111|       |      if(!correct_size) {
  112|       |         memory_region_size_violation();
  113|       |      }
  114|       |   }
  115|      4|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm8ETkNS0_14spanable_rangeENSt3__14spanIKmLm1EEEEEvRKT0_:
   77|      4|inline constexpr void assert_exact_byte_length(const R& r) {
   78|      4|   const std::span s{r};
   79|      4|   if constexpr(statically_spanable_range<R>) {
   80|      4|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   81|       |   } else {
   82|       |      if(s.size_bytes() != expected) {
   83|       |         memory_region_size_violation();
   84|       |      }
   85|       |   }
   86|      4|}
_ZN5Botan6ranges10size_bytesITkNS0_14spanable_rangeENSt3__14spanIhLm8EEEEEmRKT_:
   59|      4|inline constexpr size_t size_bytes(const spanable_range auto& r) {
   60|      4|   return std::span{r}.size_bytes();
   61|      4|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm8ETkNS0_14spanable_rangeENSt3__14spanIKhLm8EEEEEvRKT0_:
   77|  2.91k|inline constexpr void assert_exact_byte_length(const R& r) {
   78|  2.91k|   const std::span s{r};
   79|  2.91k|   if constexpr(statically_spanable_range<R>) {
   80|  2.91k|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   81|       |   } else {
   82|       |      if(s.size_bytes() != expected) {
   83|       |         memory_region_size_violation();
   84|       |      }
   85|       |   }
   86|  2.91k|}
_ZN5Botan6ranges25assert_equal_byte_lengthsITkNS0_14spanable_rangeENSt3__14spanImLm1EEETpTkNS0_14spanable_rangeEJNS3_IKhLm8EEEEEEvRKT_DpRKT0_QgtsZT0_Li0E:
  100|  1.45k|{
  101|  1.45k|   const std::span s0{r0};
  102|       |
  103|  1.45k|   if constexpr(statically_spanable_range<R0>) {
  104|  1.45k|      constexpr size_t expected_size = s0.size_bytes();
  105|  1.45k|      (assert_exact_byte_length<expected_size>(rs), ...);
  106|       |   } else {
  107|       |      const size_t expected_size = s0.size_bytes();
  108|       |      const bool correct_size =
  109|       |         ((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...);
  110|       |
  111|       |      if(!correct_size) {
  112|       |         memory_region_size_violation();
  113|       |      }
  114|       |   }
  115|  1.45k|}
_ZN5Botan6ranges10size_bytesITkNS0_14spanable_rangeENSt3__14spanImLm1EEEEEmRKT_:
   59|  2.37k|inline constexpr size_t size_bytes(const spanable_range auto& r) {
   60|  2.37k|   return std::span{r}.size_bytes();
   61|  2.37k|}
_ZN5Botan6ranges10size_bytesITkNS0_14spanable_rangeENSt3__14spanIhLm18446744073709551615EEEEEmRKT_:
   59|  1.83k|inline constexpr size_t size_bytes(const spanable_range auto& r) {
   60|  1.83k|   return std::span{r}.size_bytes();
   61|  1.83k|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm8ETkNS0_14spanable_rangeENSt3__15arrayIhLm8EEEEEvRKT0_:
   77|    913|inline constexpr void assert_exact_byte_length(const R& r) {
   78|    913|   const std::span s{r};
   79|    913|   if constexpr(statically_spanable_range<R>) {
   80|    913|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   81|       |   } else {
   82|       |      if(s.size_bytes() != expected) {
   83|       |         memory_region_size_violation();
   84|       |      }
   85|       |   }
   86|    913|}
_ZN5Botan6ranges25assert_equal_byte_lengthsITkNS0_14spanable_rangeENSt3__14spanImLm1EEETpTkNS0_14spanable_rangeEJNS3_IhLm8EEEEEEvRKT_DpRKT0_QgtsZT0_Li0E:
  100|    913|{
  101|    913|   const std::span s0{r0};
  102|       |
  103|    913|   if constexpr(statically_spanable_range<R0>) {
  104|    913|      constexpr size_t expected_size = s0.size_bytes();
  105|    913|      (assert_exact_byte_length<expected_size>(rs), ...);
  106|       |   } else {
  107|       |      const size_t expected_size = s0.size_bytes();
  108|       |      const bool correct_size =
  109|       |         ((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...);
  110|       |
  111|       |      if(!correct_size) {
  112|       |         memory_region_size_violation();
  113|       |      }
  114|       |   }
  115|    913|}
_ZN5Botan6ranges10size_bytesITkNS0_14spanable_rangeENSt3__14spanImLm18446744073709551615EEEEEmRKT_:
   59|  22.6k|inline constexpr size_t size_bytes(const spanable_range auto& r) {
   60|  22.6k|   return std::span{r}.size_bytes();
   61|  22.6k|}
_ZN5Botan6ranges25assert_equal_byte_lengthsITkNS0_14spanable_rangeENSt3__14spanImLm18446744073709551615EEETpTkNS0_14spanable_rangeEJNS3_IKmLm18446744073709551615EEEEEEvRKT_DpRKT0_QgtsZT0_Li0E:
  100|  4.76k|{
  101|  4.76k|   const std::span s0{r0};
  102|       |
  103|       |   if constexpr(statically_spanable_range<R0>) {
  104|       |      constexpr size_t expected_size = s0.size_bytes();
  105|       |      (assert_exact_byte_length<expected_size>(rs), ...);
  106|  4.76k|   } else {
  107|  4.76k|      const size_t expected_size = s0.size_bytes();
  108|  4.76k|      const bool correct_size =
  109|  4.76k|         ((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...);
  110|       |
  111|  4.76k|      if(!correct_size) {
  ------------------
  |  Branch (111:10): [True: 0, False: 4.76k]
  ------------------
  112|      0|         memory_region_size_violation();
  113|      0|      }
  114|  4.76k|   }
  115|  4.76k|}
_ZN5Botan6ranges25assert_equal_byte_lengthsITkNS0_14spanable_rangeENSt3__16vectorImNS_16secure_allocatorImEEEETpTkNS0_14spanable_rangeEJNS2_4spanImLm18446744073709551615EEEEEEvRKT_DpRKT0_QgtsZT0_Li0E:
  100|   424k|{
  101|   424k|   const std::span s0{r0};
  102|       |
  103|       |   if constexpr(statically_spanable_range<R0>) {
  104|       |      constexpr size_t expected_size = s0.size_bytes();
  105|       |      (assert_exact_byte_length<expected_size>(rs), ...);
  106|   424k|   } else {
  107|   424k|      const size_t expected_size = s0.size_bytes();
  108|   424k|      const bool correct_size =
  109|   424k|         ((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...);
  110|       |
  111|   424k|      if(!correct_size) {
  ------------------
  |  Branch (111:10): [True: 0, False: 424k]
  ------------------
  112|      0|         memory_region_size_violation();
  113|      0|      }
  114|   424k|   }
  115|   424k|}
_ZN5Botan6ranges10size_bytesITkNS0_14spanable_rangeENSt3__16vectorImNS_16secure_allocatorImEEEEEEmRKT_:
   59|   849k|inline constexpr size_t size_bytes(const spanable_range auto& r) {
   60|   849k|   return std::span{r}.size_bytes();
   61|   849k|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm4ETkNS0_14spanable_rangeENSt3__14spanIhLm4EEEEEvRKT0_:
   77|     64|inline constexpr void assert_exact_byte_length(const R& r) {
   78|     64|   const std::span s{r};
   79|     64|   if constexpr(statically_spanable_range<R>) {
   80|     64|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   81|       |   } else {
   82|       |      if(s.size_bytes() != expected) {
   83|       |         memory_region_size_violation();
   84|       |      }
   85|       |   }
   86|     64|}
_ZN5Botan6ranges25assert_equal_byte_lengthsITkNS0_14spanable_rangeENSt3__14spanIhLm4EEETpTkNS0_14spanable_rangeEJNS3_IKjLm1EEEEEEvRKT_DpRKT0_QgtsZT0_Li0E:
  100|     32|{
  101|     32|   const std::span s0{r0};
  102|       |
  103|     32|   if constexpr(statically_spanable_range<R0>) {
  104|     32|      constexpr size_t expected_size = s0.size_bytes();
  105|     32|      (assert_exact_byte_length<expected_size>(rs), ...);
  106|       |   } else {
  107|       |      const size_t expected_size = s0.size_bytes();
  108|       |      const bool correct_size =
  109|       |         ((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...);
  110|       |
  111|       |      if(!correct_size) {
  112|       |         memory_region_size_violation();
  113|       |      }
  114|       |   }
  115|     32|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm4ETkNS0_14spanable_rangeENSt3__14spanIKjLm1EEEEEvRKT0_:
   77|     32|inline constexpr void assert_exact_byte_length(const R& r) {
   78|     32|   const std::span s{r};
   79|     32|   if constexpr(statically_spanable_range<R>) {
   80|     32|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   81|       |   } else {
   82|       |      if(s.size_bytes() != expected) {
   83|       |         memory_region_size_violation();
   84|       |      }
   85|       |   }
   86|     32|}
_ZN5Botan6ranges10size_bytesITkNS0_14spanable_rangeENSt3__14spanIhLm4EEEEEmRKT_:
   59|     32|inline constexpr size_t size_bytes(const spanable_range auto& r) {
   60|     32|   return std::span{r}.size_bytes();
   61|     32|}
_ZN5Botan6ranges25assert_equal_byte_lengthsITkNS0_14spanable_rangeENSt3__14spanIjLm18446744073709551615EEETpTkNS0_14spanable_rangeEJNS3_IKhLm18446744073709551615EEEEEEvRKT_DpRKT0_QgtsZT0_Li0E:
  100|      4|{
  101|      4|   const std::span s0{r0};
  102|       |
  103|       |   if constexpr(statically_spanable_range<R0>) {
  104|       |      constexpr size_t expected_size = s0.size_bytes();
  105|       |      (assert_exact_byte_length<expected_size>(rs), ...);
  106|      4|   } else {
  107|      4|      const size_t expected_size = s0.size_bytes();
  108|      4|      const bool correct_size =
  109|      4|         ((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...);
  110|       |
  111|      4|      if(!correct_size) {
  ------------------
  |  Branch (111:10): [True: 0, False: 4]
  ------------------
  112|      0|         memory_region_size_violation();
  113|      0|      }
  114|      4|   }
  115|      4|}
_ZN5Botan6ranges25assert_equal_byte_lengthsITkNS0_14spanable_rangeENSt3__14spanIhLm18446744073709551615EEETpTkNS0_14spanable_rangeEJNS3_IKjLm18446744073709551615EEEEEEvRKT_DpRKT0_QgtsZT0_Li0E:
  100|      4|{
  101|      4|   const std::span s0{r0};
  102|       |
  103|       |   if constexpr(statically_spanable_range<R0>) {
  104|       |      constexpr size_t expected_size = s0.size_bytes();
  105|       |      (assert_exact_byte_length<expected_size>(rs), ...);
  106|      4|   } else {
  107|      4|      const size_t expected_size = s0.size_bytes();
  108|      4|      const bool correct_size =
  109|      4|         ((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...);
  110|       |
  111|      4|      if(!correct_size) {
  ------------------
  |  Branch (111:10): [True: 0, False: 4]
  ------------------
  112|      0|         memory_region_size_violation();
  113|      0|      }
  114|      4|   }
  115|      4|}
_ZN5Botan6ranges10size_bytesITkNS0_14spanable_rangeENSt3__14spanIjLm18446744073709551615EEEEEmRKT_:
   59|      2|inline constexpr size_t size_bytes(const spanable_range auto& r) {
   60|      2|   return std::span{r}.size_bytes();
   61|      2|}

_ZN5Botan21RandomNumberGeneratorD2Ev:
   52|      1|      virtual ~RandomNumberGenerator() = default;
_ZN5Botan21RandomNumberGenerator9randomizeENSt3__14spanIhLm18446744073709551615EEE:
   86|     53|      void randomize(std::span<uint8_t> output) { this->fill_bytes_with_input(output, {}); }
_ZN5Botan21RandomNumberGenerator11add_entropyENSt3__14spanIKhLm18446744073709551615EEE:
  114|      1|      void add_entropy(std::span<const uint8_t> input) { this->fill_bytes_with_input({}, input); }
_ZN5Botan21RandomNumberGenerator10random_vecENSt3__14spanIhLm18446744073709551615EEE:
  244|     53|      void random_vec(std::span<uint8_t> v) { this->randomize(v); }
_ZN5Botan21RandomNumberGeneratorC2Ev:
   57|      1|      RandomNumberGenerator() = default;
_ZN5Botan21RandomNumberGenerator10random_vecITkNS_8concepts21resizable_byte_bufferENSt3__16vectorIhNS_16secure_allocatorIhEEEEQsr3stdE21default_initializableIT_EEES8_m:
  270|     53|      T random_vec(size_t bytes) {
  271|     53|         T result;
  272|     53|         random_vec(result, bytes);
  273|     53|         return result;
  274|     53|      }
_ZN5Botan21RandomNumberGenerator10random_vecITkNS_8concepts21resizable_byte_bufferENSt3__16vectorIhNS_16secure_allocatorIhEEEEEEvRT_m:
  255|     53|      void random_vec(T& v, size_t bytes) {
  256|     53|         v.resize(bytes);
  257|     53|         random_vec(v);
  258|     53|      }

_ZN5Botan16secure_allocatorIhE8allocateEm:
   95|     60|      T* allocate(std::size_t n) { return static_cast<T*>(allocate_memory(n, sizeof(T))); }
_ZN5Botan16secure_allocatorIhE10deallocateEPhm:
  102|     60|      void deallocate(T* p, std::size_t n) { deallocate_memory(p, n, sizeof(T)); }
_ZN5Botan16secure_allocatorImE10deallocateEPmm:
  102|   262k|      void deallocate(T* p, std::size_t n) { deallocate_memory(p, n, sizeof(T)); }
_ZN5Botan16secure_allocatorImE8allocateEm:
   95|   262k|      T* allocate(std::size_t n) { return static_cast<T*>(allocate_memory(n, sizeof(T))); }
_ZN5Botan16secure_allocatorIjE10deallocateEPjm:
  102|      3|      void deallocate(T* p, std::size_t n) { deallocate_memory(p, n, sizeof(T)); }
_ZN5Botan16secure_allocatorIjE8allocateEm:
   95|      3|      T* allocate(std::size_t n) { return static_cast<T*>(allocate_memory(n, sizeof(T))); }

_ZN5Botan12Stateful_RNGC2Ev:
   64|      1|      Stateful_RNG() : m_reseed_interval(0) {}

_ZN5Botan12StreamCipher15write_keystreamENSt3__14spanIhLm18446744073709551615EEE:
   88|     54|      void write_keystream(std::span<uint8_t> out) { generate_keystream(out.data(), out.size()); }
_ZN5Botan12StreamCipher6set_ivEPKhm:
  168|      2|      void set_iv(const uint8_t iv[], size_t iv_len) { set_iv_bytes(iv, iv_len); }
_ZN5Botan12StreamCipher15keystream_bytesITkNS_8concepts21resizable_byte_bufferENSt3__16vectorIhNS_16secure_allocatorIhEEEEEET_m:
   98|      1|      T keystream_bytes(size_t bytes) {
   99|      1|         T out(bytes);
  100|      1|         write_keystream(out);
  101|      1|         return out;
  102|      1|      }

_ZN5Botan18unwrap_strong_typeIRmEEDcOT_:
  328|      4|[[nodiscard]] constexpr decltype(auto) unwrap_strong_type(T&& t) {
  329|      4|   if constexpr(!concepts::strong_type<std::remove_cvref_t<T>>) {
  330|       |      // If the parameter type isn't a strong type, return it as is.
  331|      4|      return std::forward<T>(t);
  332|       |   } else {
  333|       |      // Unwrap the strong type and return the underlying value.
  334|       |      return std::forward<T>(t).get();
  335|       |   }
  336|      4|}
_ZN5Botan16wrap_strong_typeImRmQoosr3stdE18constructible_fromIT_T0_Eaasr8conceptsE11strong_typeIS2_Esr3stdE18constructible_fromINS2_12wrapped_typeES3_EEEDcOS3_:
  353|  2.37k|[[nodiscard]] constexpr decltype(auto) wrap_strong_type(ParamT&& t) {
  354|  2.37k|   if constexpr(std::same_as<std::remove_cvref_t<ParamT>, T>) {
  355|       |      // Noop, if the parameter type already is the desired return type.
  356|  2.37k|      return std::forward<ParamT>(t);
  357|       |   } else if constexpr(std::constructible_from<T, ParamT>) {
  358|       |      // Implicit conversion from the parameter type to the return type.
  359|       |      return T{std::forward<ParamT>(t)};
  360|       |   } else {
  361|       |      // Explicitly calling the wrapped type's constructor to support
  362|       |      // implicit conversions on types that mark their constructors as explicit.
  363|       |      static_assert(concepts::strong_type<T> && std::constructible_from<typename T::wrapped_type, ParamT>);
  364|       |      return T{typename T::wrapped_type{std::forward<ParamT>(t)}};
  365|       |   }
  366|  2.37k|}
_ZN5Botan18unwrap_strong_typeIRjEEDcOT_:
  328|     32|[[nodiscard]] constexpr decltype(auto) unwrap_strong_type(T&& t) {
  329|     32|   if constexpr(!concepts::strong_type<std::remove_cvref_t<T>>) {
  330|       |      // If the parameter type isn't a strong type, return it as is.
  331|     32|      return std::forward<T>(t);
  332|       |   } else {
  333|       |      // Unwrap the strong type and return the underlying value.
  334|       |      return std::forward<T>(t).get();
  335|       |   }
  336|     32|}

_ZN5Botan24Key_Length_SpecificationC2Emmm:
   37|      4|            m_min_keylen(min_k), m_max_keylen(max_k > 0 ? max_k : min_k), m_keylen_mod(k_mod) {}
  ------------------
  |  Branch (37:47): [True: 4, False: 0]
  ------------------
_ZNK5Botan24Key_Length_Specification15valid_keylengthEm:
   44|      4|      bool valid_keylength(size_t length) const {
   45|      4|         return ((length >= m_min_keylen) && (length <= m_max_keylen) && (length % m_keylen_mod == 0));
  ------------------
  |  Branch (45:18): [True: 4, False: 0]
  |  Branch (45:46): [True: 4, False: 0]
  |  Branch (45:74): [True: 4, False: 0]
  ------------------
   46|      4|      }
_ZNK5Botan18SymmetricAlgorithm15valid_keylengthEm:
  143|      4|      bool valid_keylength(size_t length) const { return key_spec().valid_keylength(length); }
_ZNK5Botan18SymmetricAlgorithm23assert_key_material_setEv:
  180|     59|      void assert_key_material_set() const { assert_key_material_set(has_keying_material()); }
_ZNK5Botan18SymmetricAlgorithm23assert_key_material_setEb:
  186|     59|      void assert_key_material_set(bool predicate) const {
  187|     59|         if(!predicate) {
  ------------------
  |  Branch (187:13): [True: 0, False: 59]
  ------------------
  188|      0|            throw_key_not_set_error();
  189|      0|         }
  190|     59|      }
_ZN5Botan18SymmetricAlgorithmD2Ev:
   90|      2|      virtual ~SymmetricAlgorithm() = default;
_ZN5Botan18SymmetricAlgorithmC2Ev:
   88|      2|      SymmetricAlgorithm() = default;

LLVMFuzzerInitialize:
   28|      2|extern "C" int LLVMFuzzerInitialize(int* /*argc*/, char*** /*argv*/) {
   29|       |   /*
   30|       |   * This disables the mlock pool, as overwrites within the pool are
   31|       |   * opaque to ASan or other instrumentation.
   32|       |   */
   33|      2|   ::setenv("BOTAN_MLOCK_POOL_SIZE", "0", 1);
   34|      2|   return 0;
   35|      2|}
LLVMFuzzerTestOneInput:
   39|  1.23k|extern "C" int LLVMFuzzerTestOneInput(const uint8_t in[], size_t len) {
   40|  1.23k|   if(len <= max_fuzzer_input_size) {
  ------------------
  |  Branch (40:7): [True: 1.22k, False: 10]
  ------------------
   41|  1.22k|      try {
   42|  1.22k|         fuzz(std::span<const uint8_t>(in, len));
   43|  1.22k|      } catch(const std::exception& e) {
   44|      0|         std::cerr << "Uncaught exception from fuzzer driver " << e.what() << "\n";
   45|      0|         abort();
   46|      0|      } catch(...) {
   47|      0|         std::cerr << "Uncaught exception from fuzzer driver (unknown type)\n";
   48|      0|         abort();
   49|      0|      }
   50|  1.22k|   }
   51|  1.23k|   return 0;
   52|  1.23k|}
_Z10fuzzer_rngv:
   62|      1|inline Botan::RandomNumberGenerator& fuzzer_rng() {
   63|      1|   return *fuzzer_rng_as_shared();
   64|      1|}
_Z20fuzzer_rng_as_sharedv:
   56|      1|inline std::shared_ptr<Botan::RandomNumberGenerator> fuzzer_rng_as_shared() {
   57|      1|   static const std::shared_ptr<Botan::ChaCha_RNG> rng =
   58|      1|      std::make_shared<Botan::ChaCha_RNG>(Botan::secure_vector<uint8_t>(32));
   59|      1|   return rng;
   60|      1|}

_Z4fuzzNSt3__14spanIKhLm18446744073709551615EEE:
   12|  1.22k|void fuzz(std::span<const uint8_t> in) {
   13|       |   // Ressol is mostly used for ECC point decompression so best to test smaller sizes
   14|  1.22k|   static const size_t p_bits = 256;
   15|       |   // Use p == 1 mod 4 since sqrt modulo p == 3 mod 4 is a fast case
   16|  1.22k|   static const Botan::BigInt p = random_prime(fuzzer_rng(), p_bits, 0, 1, 4);
   17|  1.22k|   static auto mod_p = Botan::Barrett_Reduction::for_public_modulus(p);
   18|       |
   19|  1.22k|   if(in.size() > p_bits / 8) {
  ------------------
  |  Branch (19:7): [True: 25, False: 1.19k]
  ------------------
   20|     25|      return;
   21|     25|   }
   22|       |
   23|  1.19k|   try {
   24|  1.19k|      const Botan::BigInt a = Botan::BigInt::from_bytes(in);
   25|  1.19k|      const Botan::BigInt a_sqrt = Botan::sqrt_modulo_prime(a, p);
   26|       |
   27|  1.19k|      if(a_sqrt > 0) {
  ------------------
  |  Branch (27:10): [True: 675, False: 520]
  ------------------
   28|    675|         const Botan::BigInt a_redc = mod_p.reduce(a);
   29|    675|         const Botan::BigInt z = mod_p.square(a_sqrt);
   30|       |
   31|    675|         if(z != a_redc) {
  ------------------
  |  Branch (31:13): [True: 0, False: 675]
  ------------------
   32|      0|            FUZZER_WRITE_AND_CRASH("A = " << a.to_hex_string() << "\n"
  ------------------
  |  |   70|      0|   do {                                                                                                       \
  |  |   71|      0|      std::cerr << expr << " @ Line " << __LINE__ << " in " << __FILE__ << "\n"; /* NOLINT(*-macro-paren*) */ \
  |  |   72|      0|      abort();                                                                                                \
  |  |   73|      0|   } while(0)
  |  |  ------------------
  |  |  |  Branch (73:12): [Folded, False: 0]
  |  |  ------------------
  ------------------
   33|      0|                                          << "P = " << p.to_hex_string() << "\n"
   34|      0|                                          << "R = " << a_sqrt.to_hex_string() << "\n"
   35|      0|                                          << "Z = " << z.to_hex_string() << "\n");
   36|      0|         }
   37|    675|      }
   38|  1.19k|   } catch(const Botan::Exception& e) {}
   39|  1.19k|}

_ZN5Botan20Buffered_Computation5finalENSt3__14spanIhLm18446744073709551615EEE:
   54|      4|void Buffered_Computation::final(std::span<uint8_t> out) {
   55|      4|   BOTAN_ARG_CHECK(out.size() >= output_length(), "Output buffer has insufficient capacity");
  ------------------
  |  |   35|      4|   do {                                                          \
  |  |   36|      4|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|      4|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 4]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|      4|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 4]
  |  |  ------------------
  ------------------
   56|       |   // Pass exactly output_length() bytes so that an oversized buffer has the
   57|       |   // result written to its leading bytes with the remainder left untouched.
   58|      4|   final_result(out.first(output_length()));
   59|      4|}

_ZN5Botan18SymmetricAlgorithm7set_keyENSt3__14spanIKhLm18446744073709551615EEE:
   22|      4|void SymmetricAlgorithm::set_key(std::span<const uint8_t> key) {
   23|      4|   if(!valid_keylength(key.size())) {
  ------------------
  |  Branch (23:7): [True: 0, False: 4]
  ------------------
   24|      0|      throw Invalid_Key_Length(name(), key.size());
   25|      0|   }
   26|      4|   key_schedule(key);
   27|      4|}

_ZN5Botan12HashFunction6createENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEES5_:
  111|      1|std::unique_ptr<HashFunction> HashFunction::create(std::string_view algo_spec, std::string_view provider) {
  112|       |#if defined(BOTAN_HAS_COMMONCRYPTO)
  113|       |   if(provider.empty() || provider == "commoncrypto") {
  114|       |      if(auto hash = make_commoncrypto_hash(algo_spec))
  115|       |         return hash;
  116|       |
  117|       |      if(!provider.empty())
  118|       |         return nullptr;
  119|       |   }
  120|       |#endif
  121|       |
  122|      1|   if(provider.empty() == false && provider != "base") {
  ------------------
  |  Branch (122:7): [True: 0, False: 1]
  |  Branch (122:36): [True: 0, False: 0]
  ------------------
  123|      0|      return nullptr;  // unknown provider
  124|      0|   }
  125|       |
  126|      1|#if defined(BOTAN_HAS_SHA1)
  127|      1|   if(algo_spec == "SHA-1") {
  ------------------
  |  Branch (127:7): [True: 0, False: 1]
  ------------------
  128|      0|      return std::make_unique<SHA_1>();
  129|      0|   }
  130|      1|#endif
  131|       |
  132|      1|#if defined(BOTAN_HAS_SHA2_32)
  133|      1|   if(algo_spec == "SHA-224") {
  ------------------
  |  Branch (133:7): [True: 0, False: 1]
  ------------------
  134|      0|      return std::make_unique<SHA_224>();
  135|      0|   }
  136|       |
  137|      1|   if(algo_spec == "SHA-256") {
  ------------------
  |  Branch (137:7): [True: 1, False: 0]
  ------------------
  138|      1|      return std::make_unique<SHA_256>();
  139|      1|   }
  140|      0|#endif
  141|       |
  142|      0|#if defined(BOTAN_HAS_SHA2_64)
  143|      0|   if(algo_spec == "SHA-384") {
  ------------------
  |  Branch (143:7): [True: 0, False: 0]
  ------------------
  144|      0|      return std::make_unique<SHA_384>();
  145|      0|   }
  146|       |
  147|      0|   if(algo_spec == "SHA-512") {
  ------------------
  |  Branch (147:7): [True: 0, False: 0]
  ------------------
  148|      0|      return std::make_unique<SHA_512>();
  149|      0|   }
  150|       |
  151|      0|   if(algo_spec == "SHA-512-256") {
  ------------------
  |  Branch (151:7): [True: 0, False: 0]
  ------------------
  152|      0|      return std::make_unique<SHA_512_256>();
  153|      0|   }
  154|      0|#endif
  155|       |
  156|      0|#if defined(BOTAN_HAS_RIPEMD_160)
  157|      0|   if(algo_spec == "RIPEMD-160") {
  ------------------
  |  Branch (157:7): [True: 0, False: 0]
  ------------------
  158|      0|      return std::make_unique<RIPEMD_160>();
  159|      0|   }
  160|      0|#endif
  161|       |
  162|      0|#if defined(BOTAN_HAS_WHIRLPOOL)
  163|      0|   if(algo_spec == "Whirlpool") {
  ------------------
  |  Branch (163:7): [True: 0, False: 0]
  ------------------
  164|      0|      return std::make_unique<Whirlpool>();
  165|      0|   }
  166|      0|#endif
  167|       |
  168|      0|#if defined(BOTAN_HAS_MD5)
  169|      0|   if(algo_spec == "MD5") {
  ------------------
  |  Branch (169:7): [True: 0, False: 0]
  ------------------
  170|      0|      return std::make_unique<MD5>();
  171|      0|   }
  172|      0|#endif
  173|       |
  174|      0|#if defined(BOTAN_HAS_MD4)
  175|      0|   if(algo_spec == "MD4") {
  ------------------
  |  Branch (175:7): [True: 0, False: 0]
  ------------------
  176|      0|      return std::make_unique<MD4>();
  177|      0|   }
  178|      0|#endif
  179|       |
  180|      0|#if defined(BOTAN_HAS_GOST_34_11)
  181|      0|   if(algo_spec == "GOST-R-34.11-94" || algo_spec == "GOST-34.11") {
  ------------------
  |  Branch (181:7): [True: 0, False: 0]
  |  Branch (181:41): [True: 0, False: 0]
  ------------------
  182|      0|      return std::make_unique<GOST_34_11>();
  183|      0|   }
  184|      0|#endif
  185|       |
  186|      0|#if defined(BOTAN_HAS_ADLER32)
  187|      0|   if(algo_spec == "Adler32") {
  ------------------
  |  Branch (187:7): [True: 0, False: 0]
  ------------------
  188|      0|      return std::make_unique<Adler32>();
  189|      0|   }
  190|      0|#endif
  191|       |
  192|      0|#if defined(BOTAN_HAS_ASCON_HASH256)
  193|      0|   if(algo_spec == "Ascon-Hash256") {
  ------------------
  |  Branch (193:7): [True: 0, False: 0]
  ------------------
  194|      0|      return std::make_unique<Ascon_Hash256>();
  195|      0|   }
  196|      0|#endif
  197|       |
  198|      0|#if defined(BOTAN_HAS_CRC24)
  199|      0|   if(algo_spec == "CRC24") {
  ------------------
  |  Branch (199:7): [True: 0, False: 0]
  ------------------
  200|      0|      return std::make_unique<CRC24>();
  201|      0|   }
  202|      0|#endif
  203|       |
  204|      0|#if defined(BOTAN_HAS_CRC32)
  205|      0|   if(algo_spec == "CRC32") {
  ------------------
  |  Branch (205:7): [True: 0, False: 0]
  ------------------
  206|      0|      return std::make_unique<CRC32>();
  207|      0|   }
  208|      0|#endif
  209|       |
  210|      0|#if defined(BOTAN_HAS_STREEBOG)
  211|      0|   if(algo_spec == "Streebog-256") {
  ------------------
  |  Branch (211:7): [True: 0, False: 0]
  ------------------
  212|      0|      return std::make_unique<Streebog>(256);
  213|      0|   }
  214|      0|   if(algo_spec == "Streebog-512") {
  ------------------
  |  Branch (214:7): [True: 0, False: 0]
  ------------------
  215|      0|      return std::make_unique<Streebog>(512);
  216|      0|   }
  217|      0|#endif
  218|       |
  219|      0|#if defined(BOTAN_HAS_SM3)
  220|      0|   if(algo_spec == "SM3") {
  ------------------
  |  Branch (220:7): [True: 0, False: 0]
  ------------------
  221|      0|      return std::make_unique<SM3>();
  222|      0|   }
  223|      0|#endif
  224|       |
  225|      0|   const SCAN_Name req(algo_spec);
  226|       |
  227|      0|#if defined(BOTAN_HAS_SKEIN_512)
  228|      0|   if(req.algo_name() == "Skein-512") {
  ------------------
  |  Branch (228:7): [True: 0, False: 0]
  ------------------
  229|      0|      return std::make_unique<Skein_512>(req.arg_as_integer(0, 512), req.arg(1, ""));
  230|      0|   }
  231|      0|#endif
  232|       |
  233|      0|#if defined(BOTAN_HAS_BLAKE2B)
  234|      0|   if(req.algo_name() == "Blake2b" || req.algo_name() == "BLAKE2b") {
  ------------------
  |  Branch (234:7): [True: 0, False: 0]
  |  Branch (234:39): [True: 0, False: 0]
  ------------------
  235|      0|      return std::make_unique<BLAKE2b>(req.arg_as_integer(0, 512));
  236|      0|   }
  237|      0|#endif
  238|       |
  239|      0|#if defined(BOTAN_HAS_BLAKE2S)
  240|      0|   if(req.algo_name() == "Blake2s" || req.algo_name() == "BLAKE2s") {
  ------------------
  |  Branch (240:7): [True: 0, False: 0]
  |  Branch (240:39): [True: 0, False: 0]
  ------------------
  241|      0|      return std::make_unique<BLAKE2s>(req.arg_as_integer(0, 256));
  242|      0|   }
  243|      0|#endif
  244|       |
  245|      0|#if defined(BOTAN_HAS_KECCAK)
  246|      0|   if(req.algo_name() == "Keccak-1600") {
  ------------------
  |  Branch (246:7): [True: 0, False: 0]
  ------------------
  247|      0|      return std::make_unique<Keccak_1600>(req.arg_as_integer(0, 512));
  248|      0|   }
  249|      0|#endif
  250|       |
  251|      0|#if defined(BOTAN_HAS_SHA3)
  252|      0|   if(req.algo_name() == "SHA-3") {
  ------------------
  |  Branch (252:7): [True: 0, False: 0]
  ------------------
  253|      0|      return std::make_unique<SHA_3>(req.arg_as_integer(0, 512));
  254|      0|   }
  255|      0|#endif
  256|       |
  257|      0|#if defined(BOTAN_HAS_SHAKE)
  258|      0|   if(req.algo_name() == "SHAKE-128" && req.arg_count() == 1) {
  ------------------
  |  Branch (258:7): [True: 0, False: 0]
  |  Branch (258:41): [True: 0, False: 0]
  ------------------
  259|      0|      return std::make_unique<SHAKE_128>(req.arg_as_integer(0));
  260|      0|   }
  261|      0|   if(req.algo_name() == "SHAKE-256" && req.arg_count() == 1) {
  ------------------
  |  Branch (261:7): [True: 0, False: 0]
  |  Branch (261:41): [True: 0, False: 0]
  ------------------
  262|      0|      return std::make_unique<SHAKE_256>(req.arg_as_integer(0));
  263|      0|   }
  264|      0|#endif
  265|       |
  266|      0|#if defined(BOTAN_HAS_PARALLEL_HASH)
  267|      0|   if(req.algo_name() == "Parallel") {
  ------------------
  |  Branch (267:7): [True: 0, False: 0]
  ------------------
  268|      0|      std::vector<std::unique_ptr<HashFunction>> hashes;
  269|       |
  270|      0|      for(size_t i = 0; i != req.arg_count(); ++i) {
  ------------------
  |  Branch (270:25): [True: 0, False: 0]
  ------------------
  271|      0|         auto h = HashFunction::create(req.arg(i));
  272|      0|         if(!h) {
  ------------------
  |  Branch (272:13): [True: 0, False: 0]
  ------------------
  273|      0|            return nullptr;
  274|      0|         }
  275|      0|         hashes.push_back(std::move(h));
  276|      0|      }
  277|       |
  278|      0|      return std::make_unique<Parallel>(hashes);
  279|      0|   }
  280|      0|#endif
  281|       |
  282|      0|#if defined(BOTAN_HAS_TRUNCATED_HASH)
  283|      0|   if(req.algo_name() == "Truncated" && req.arg_count() == 2) {
  ------------------
  |  Branch (283:7): [True: 0, False: 0]
  |  Branch (283:41): [True: 0, False: 0]
  ------------------
  284|      0|      auto hash = HashFunction::create(req.arg(0));
  285|      0|      if(!hash) {
  ------------------
  |  Branch (285:10): [True: 0, False: 0]
  ------------------
  286|      0|         return nullptr;
  287|      0|      }
  288|       |
  289|      0|      return std::make_unique<Truncated_Hash>(std::move(hash), req.arg_as_integer(1));
  290|      0|   }
  291|      0|#endif
  292|       |
  293|      0|#if defined(BOTAN_HAS_COMB4P)
  294|      0|   if(req.algo_name() == "Comb4P" && req.arg_count() == 2) {
  ------------------
  |  Branch (294:7): [True: 0, False: 0]
  |  Branch (294:38): [True: 0, False: 0]
  ------------------
  295|      0|      auto h1 = HashFunction::create(req.arg(0));
  296|      0|      auto h2 = HashFunction::create(req.arg(1));
  297|       |
  298|      0|      if(h1 && h2) {
  ------------------
  |  Branch (298:10): [True: 0, False: 0]
  |  Branch (298:16): [True: 0, False: 0]
  ------------------
  299|      0|         return std::make_unique<Comb4P>(std::move(h1), std::move(h2));
  300|      0|      }
  301|      0|   }
  302|      0|#endif
  303|       |
  304|      0|   return nullptr;
  305|      0|}

_ZN5Botan7SHA_25615compress_digestERNSt3__16vectorIjNS_16secure_allocatorIjEEEENS1_4spanIKhLm18446744073709551615EEEm:
   59|     10|                                                             size_t blocks) {
   60|     10|#if defined(BOTAN_HAS_SHA2_32_X86)
   61|     10|   if(CPUID::has(CPUID::Feature::SHA)) {
  ------------------
  |  Branch (61:7): [True: 0, False: 10]
  ------------------
   62|      0|      return SHA_256::compress_digest_x86(digest, input, blocks);
   63|      0|   }
   64|     10|#endif
   65|       |
   66|       |#if defined(BOTAN_HAS_SHA2_32_ARMV8)
   67|       |   if(CPUID::has(CPUID::Feature::SHA2)) {
   68|       |      return SHA_256::compress_digest_armv8(digest, input, blocks);
   69|       |   }
   70|       |#endif
   71|       |
   72|     10|#if defined(BOTAN_HAS_SHA2_32_X86_AVX2)
   73|     10|   if(CPUID::has(CPUID::Feature::AVX2, CPUID::Feature::BMI)) {
  ------------------
  |  Branch (73:7): [True: 10, False: 0]
  ------------------
   74|     10|      return SHA_256::compress_digest_x86_avx2(digest, input, blocks);
   75|     10|   }
   76|      0|#endif
   77|       |
   78|      0|#if defined(BOTAN_HAS_SHA2_32_SIMD)
   79|      0|   if(CPUID::has(CPUID::Feature::SIMD_4X32)) {
  ------------------
  |  Branch (79:7): [True: 0, False: 0]
  ------------------
   80|      0|      return SHA_256::compress_digest_x86_simd(digest, input, blocks);
   81|      0|   }
   82|      0|#endif
   83|       |
   84|      0|   uint32_t A = digest[0];
   85|      0|   uint32_t B = digest[1];
   86|      0|   uint32_t C = digest[2];
   87|      0|   uint32_t D = digest[3];
   88|      0|   uint32_t E = digest[4];
   89|      0|   uint32_t F = digest[5];
   90|      0|   uint32_t G = digest[6];
   91|      0|   uint32_t H = digest[7];
   92|       |
   93|      0|   std::array<uint32_t, 16> W{};
   94|       |
   95|      0|   BufferSlicer in(input);
   96|       |
   97|      0|   for(size_t i = 0; i != blocks; ++i) {
  ------------------
  |  Branch (97:22): [True: 0, False: 0]
  ------------------
   98|      0|      load_be(W, in.take<block_bytes>());
   99|       |
  100|       |      // clang-format off
  101|       |
  102|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W[ 0], W[14], W[ 9], W[ 1], 0x428A2F98);
  103|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W[ 1], W[15], W[10], W[ 2], 0x71374491);
  104|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W[ 2], W[ 0], W[11], W[ 3], 0xB5C0FBCF);
  105|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W[ 3], W[ 1], W[12], W[ 4], 0xE9B5DBA5);
  106|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W[ 4], W[ 2], W[13], W[ 5], 0x3956C25B);
  107|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W[ 5], W[ 3], W[14], W[ 6], 0x59F111F1);
  108|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W[ 6], W[ 4], W[15], W[ 7], 0x923F82A4);
  109|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W[ 7], W[ 5], W[ 0], W[ 8], 0xAB1C5ED5);
  110|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W[ 8], W[ 6], W[ 1], W[ 9], 0xD807AA98);
  111|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W[ 9], W[ 7], W[ 2], W[10], 0x12835B01);
  112|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W[10], W[ 8], W[ 3], W[11], 0x243185BE);
  113|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W[11], W[ 9], W[ 4], W[12], 0x550C7DC3);
  114|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W[12], W[10], W[ 5], W[13], 0x72BE5D74);
  115|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W[13], W[11], W[ 6], W[14], 0x80DEB1FE);
  116|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W[14], W[12], W[ 7], W[15], 0x9BDC06A7);
  117|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W[15], W[13], W[ 8], W[ 0], 0xC19BF174);
  118|       |
  119|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W[ 0], W[14], W[ 9], W[ 1], 0xE49B69C1);
  120|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W[ 1], W[15], W[10], W[ 2], 0xEFBE4786);
  121|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W[ 2], W[ 0], W[11], W[ 3], 0x0FC19DC6);
  122|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W[ 3], W[ 1], W[12], W[ 4], 0x240CA1CC);
  123|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W[ 4], W[ 2], W[13], W[ 5], 0x2DE92C6F);
  124|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W[ 5], W[ 3], W[14], W[ 6], 0x4A7484AA);
  125|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W[ 6], W[ 4], W[15], W[ 7], 0x5CB0A9DC);
  126|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W[ 7], W[ 5], W[ 0], W[ 8], 0x76F988DA);
  127|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W[ 8], W[ 6], W[ 1], W[ 9], 0x983E5152);
  128|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W[ 9], W[ 7], W[ 2], W[10], 0xA831C66D);
  129|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W[10], W[ 8], W[ 3], W[11], 0xB00327C8);
  130|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W[11], W[ 9], W[ 4], W[12], 0xBF597FC7);
  131|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W[12], W[10], W[ 5], W[13], 0xC6E00BF3);
  132|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W[13], W[11], W[ 6], W[14], 0xD5A79147);
  133|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W[14], W[12], W[ 7], W[15], 0x06CA6351);
  134|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W[15], W[13], W[ 8], W[ 0], 0x14292967);
  135|       |
  136|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W[ 0], W[14], W[ 9], W[ 1], 0x27B70A85);
  137|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W[ 1], W[15], W[10], W[ 2], 0x2E1B2138);
  138|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W[ 2], W[ 0], W[11], W[ 3], 0x4D2C6DFC);
  139|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W[ 3], W[ 1], W[12], W[ 4], 0x53380D13);
  140|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W[ 4], W[ 2], W[13], W[ 5], 0x650A7354);
  141|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W[ 5], W[ 3], W[14], W[ 6], 0x766A0ABB);
  142|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W[ 6], W[ 4], W[15], W[ 7], 0x81C2C92E);
  143|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W[ 7], W[ 5], W[ 0], W[ 8], 0x92722C85);
  144|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W[ 8], W[ 6], W[ 1], W[ 9], 0xA2BFE8A1);
  145|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W[ 9], W[ 7], W[ 2], W[10], 0xA81A664B);
  146|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W[10], W[ 8], W[ 3], W[11], 0xC24B8B70);
  147|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W[11], W[ 9], W[ 4], W[12], 0xC76C51A3);
  148|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W[12], W[10], W[ 5], W[13], 0xD192E819);
  149|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W[13], W[11], W[ 6], W[14], 0xD6990624);
  150|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W[14], W[12], W[ 7], W[15], 0xF40E3585);
  151|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W[15], W[13], W[ 8], W[ 0], 0x106AA070);
  152|       |
  153|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W[ 0], W[14], W[ 9], W[ 1], 0x19A4C116);
  154|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W[ 1], W[15], W[10], W[ 2], 0x1E376C08);
  155|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W[ 2], W[ 0], W[11], W[ 3], 0x2748774C);
  156|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W[ 3], W[ 1], W[12], W[ 4], 0x34B0BCB5);
  157|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W[ 4], W[ 2], W[13], W[ 5], 0x391C0CB3);
  158|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W[ 5], W[ 3], W[14], W[ 6], 0x4ED8AA4A);
  159|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W[ 6], W[ 4], W[15], W[ 7], 0x5B9CCA4F);
  160|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W[ 7], W[ 5], W[ 0], W[ 8], 0x682E6FF3);
  161|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W[ 8], W[ 6], W[ 1], W[ 9], 0x748F82EE);
  162|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W[ 9], W[ 7], W[ 2], W[10], 0x78A5636F);
  163|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W[10], W[ 8], W[ 3], W[11], 0x84C87814);
  164|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W[11], W[ 9], W[ 4], W[12], 0x8CC70208);
  165|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W[12], W[10], W[ 5], W[13], 0x90BEFFFA);
  166|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W[13], W[11], W[ 6], W[14], 0xA4506CEB);
  167|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W[14], W[12], W[ 7], W[15], 0xBEF9A3F7);
  168|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W[15], W[13], W[ 8], W[ 0], 0xC67178F2);
  169|       |
  170|       |      // clang-format on
  171|       |
  172|      0|      A = (digest[0] += A);
  173|      0|      B = (digest[1] += B);
  174|      0|      C = (digest[2] += C);
  175|      0|      D = (digest[3] += D);
  176|      0|      E = (digest[4] += E);
  177|      0|      F = (digest[5] += F);
  178|      0|      G = (digest[6] += G);
  179|      0|      H = (digest[7] += H);
  180|      0|   }
  181|      0|}
_ZN5Botan7SHA_25610compress_nERNSt3__16vectorIjNS_16secure_allocatorIjEEEENS1_4spanIKhLm18446744073709551615EEEm:
  215|     10|void SHA_256::compress_n(digest_type& digest, std::span<const uint8_t> input, size_t blocks) {
  216|     10|   SHA_256::compress_digest(digest, input, blocks);
  217|     10|}
_ZN5Botan7SHA_2564initERNSt3__16vectorIjNS_16secure_allocatorIjEEEE:
  219|      7|void SHA_256::init(digest_type& digest) {
  220|      7|   digest.assign({0x6A09E667, 0xBB67AE85, 0x3C6EF372, 0xA54FF53A, 0x510E527F, 0x9B05688C, 0x1F83D9AB, 0x5BE0CD19});
  221|      7|}
_ZN5Botan7SHA_2568add_dataENSt3__14spanIKhLm18446744073709551615EEE:
  231|      9|void SHA_256::add_data(std::span<const uint8_t> input) {
  232|      9|   m_md.update(input);
  233|      9|}
_ZN5Botan7SHA_25612final_resultENSt3__14spanIhLm18446744073709551615EEE:
  235|      4|void SHA_256::final_result(std::span<uint8_t> output) {
  236|      4|   m_md.final(output);
  237|      4|}

_ZN5Botan7SHA_25624compress_digest_x86_avx2ERNSt3__16vectorIjNS_16secure_allocatorIjEEEENS1_4spanIKhLm18446744073709551615EEEm:
  100|     10|   digest_type& digest, std::span<const uint8_t> input, size_t blocks) {
  101|       |   // clang-format off
  102|       |
  103|     10|   alignas(64) const uint32_t K[64] = {
  104|     10|      0x428A2F98, 0x71374491, 0xB5C0FBCF, 0xE9B5DBA5, 0x3956C25B, 0x59F111F1, 0x923F82A4, 0xAB1C5ED5,
  105|     10|      0xD807AA98, 0x12835B01, 0x243185BE, 0x550C7DC3, 0x72BE5D74, 0x80DEB1FE, 0x9BDC06A7, 0xC19BF174,
  106|     10|      0xE49B69C1, 0xEFBE4786, 0x0FC19DC6, 0x240CA1CC, 0x2DE92C6F, 0x4A7484AA, 0x5CB0A9DC, 0x76F988DA,
  107|     10|      0x983E5152, 0xA831C66D, 0xB00327C8, 0xBF597FC7, 0xC6E00BF3, 0xD5A79147, 0x06CA6351, 0x14292967,
  108|     10|      0x27B70A85, 0x2E1B2138, 0x4D2C6DFC, 0x53380D13, 0x650A7354, 0x766A0ABB, 0x81C2C92E, 0x92722C85,
  109|     10|      0xA2BFE8A1, 0xA81A664B, 0xC24B8B70, 0xC76C51A3, 0xD192E819, 0xD6990624, 0xF40E3585, 0x106AA070,
  110|     10|      0x19A4C116, 0x1E376C08, 0x2748774C, 0x34B0BCB5, 0x391C0CB3, 0x4ED8AA4A, 0x5B9CCA4F, 0x682E6FF3,
  111|     10|      0x748F82EE, 0x78A5636F, 0x84C87814, 0x8CC70208, 0x90BEFFFA, 0xA4506CEB, 0xBEF9A3F7, 0xC67178F2};
  112|       |
  113|       |   // clang-format on
  114|       |
  115|     10|   alignas(64) uint32_t W[16];
  116|     10|   alignas(64) uint32_t W2[64];
  117|       |
  118|     10|   uint32_t A = digest[0];
  119|     10|   uint32_t B = digest[1];
  120|     10|   uint32_t C = digest[2];
  121|     10|   uint32_t D = digest[3];
  122|     10|   uint32_t E = digest[4];
  123|     10|   uint32_t F = digest[5];
  124|     10|   uint32_t G = digest[6];
  125|     10|   uint32_t H = digest[7];
  126|       |
  127|     10|   const uint8_t* data = input.data();
  128|       |
  129|     10|   while(blocks >= 2) {
  ------------------
  |  Branch (129:10): [True: 0, False: 10]
  ------------------
  130|      0|      SIMD_8x32 WS[4];
  131|       |
  132|      0|      for(size_t i = 0; i < 4; i++) {
  ------------------
  |  Branch (132:25): [True: 0, False: 0]
  ------------------
  133|      0|         WS[i] = SIMD_8x32::load_be128(&data[16 * i], &data[64 + 16 * i]);
  134|      0|         auto WK = WS[i] + SIMD_8x32::load_le128(&K[4 * i]);
  135|      0|         WK.store_le128(&W[4 * i], &W2[4 * i]);
  136|      0|      }
  137|       |
  138|      0|      data += 2 * 64;
  139|      0|      blocks -= 2;
  140|       |
  141|      0|      for(size_t r = 0; r != 48; r += 16) {
  ------------------
  |  Branch (141:25): [True: 0, False: 0]
  ------------------
  142|      0|         auto w = next_w(WS) + SIMD_8x32::load_le128(&K[r + 16]);
  143|       |
  144|      0|         SHA2_32_F(A, B, C, D, E, F, G, H, W[0]);
  145|      0|         SHA2_32_F(H, A, B, C, D, E, F, G, W[1]);
  146|      0|         SHA2_32_F(G, H, A, B, C, D, E, F, W[2]);
  147|      0|         SHA2_32_F(F, G, H, A, B, C, D, E, W[3]);
  148|       |
  149|      0|         w.store_le128(&W[0], &W2[r + 16]);
  150|       |
  151|      0|         w = next_w(WS) + SIMD_8x32::load_le128(&K[r + 20]);
  152|       |
  153|      0|         SHA2_32_F(E, F, G, H, A, B, C, D, W[4]);
  154|      0|         SHA2_32_F(D, E, F, G, H, A, B, C, W[5]);
  155|      0|         SHA2_32_F(C, D, E, F, G, H, A, B, W[6]);
  156|      0|         SHA2_32_F(B, C, D, E, F, G, H, A, W[7]);
  157|       |
  158|      0|         w.store_le128(&W[4], &W2[r + 20]);
  159|       |
  160|      0|         w = next_w(WS) + SIMD_8x32::load_le128(&K[r + 24]);
  161|       |
  162|      0|         SHA2_32_F(A, B, C, D, E, F, G, H, W[8]);
  163|      0|         SHA2_32_F(H, A, B, C, D, E, F, G, W[9]);
  164|      0|         SHA2_32_F(G, H, A, B, C, D, E, F, W[10]);
  165|      0|         SHA2_32_F(F, G, H, A, B, C, D, E, W[11]);
  166|       |
  167|      0|         w.store_le128(&W[8], &W2[r + 24]);
  168|       |
  169|      0|         w = next_w(WS) + SIMD_8x32::load_le128(&K[r + 28]);
  170|       |
  171|      0|         SHA2_32_F(E, F, G, H, A, B, C, D, W[12]);
  172|      0|         SHA2_32_F(D, E, F, G, H, A, B, C, W[13]);
  173|      0|         SHA2_32_F(C, D, E, F, G, H, A, B, W[14]);
  174|      0|         SHA2_32_F(B, C, D, E, F, G, H, A, W[15]);
  175|       |
  176|      0|         w.store_le128(&W[12], &W2[r + 28]);
  177|      0|      }
  178|       |
  179|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W[0]);
  180|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W[1]);
  181|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W[2]);
  182|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W[3]);
  183|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W[4]);
  184|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W[5]);
  185|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W[6]);
  186|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W[7]);
  187|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W[8]);
  188|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W[9]);
  189|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W[10]);
  190|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W[11]);
  191|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W[12]);
  192|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W[13]);
  193|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W[14]);
  194|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W[15]);
  195|       |
  196|      0|      A = (digest[0] += A);
  197|      0|      B = (digest[1] += B);
  198|      0|      C = (digest[2] += C);
  199|      0|      D = (digest[3] += D);
  200|      0|      E = (digest[4] += E);
  201|      0|      F = (digest[5] += F);
  202|      0|      G = (digest[6] += G);
  203|      0|      H = (digest[7] += H);
  204|       |
  205|       |      // Now the second block, with already expanded message
  206|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W2[0]);
  207|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W2[1]);
  208|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W2[2]);
  209|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W2[3]);
  210|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W2[4]);
  211|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W2[5]);
  212|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W2[6]);
  213|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W2[7]);
  214|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W2[8]);
  215|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W2[9]);
  216|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W2[10]);
  217|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W2[11]);
  218|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W2[12]);
  219|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W2[13]);
  220|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W2[14]);
  221|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W2[15]);
  222|       |
  223|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W2[16]);
  224|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W2[17]);
  225|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W2[18]);
  226|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W2[19]);
  227|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W2[20]);
  228|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W2[21]);
  229|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W2[22]);
  230|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W2[23]);
  231|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W2[24]);
  232|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W2[25]);
  233|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W2[26]);
  234|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W2[27]);
  235|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W2[28]);
  236|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W2[29]);
  237|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W2[30]);
  238|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W2[31]);
  239|       |
  240|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W2[32]);
  241|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W2[33]);
  242|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W2[34]);
  243|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W2[35]);
  244|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W2[36]);
  245|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W2[37]);
  246|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W2[38]);
  247|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W2[39]);
  248|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W2[40]);
  249|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W2[41]);
  250|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W2[42]);
  251|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W2[43]);
  252|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W2[44]);
  253|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W2[45]);
  254|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W2[46]);
  255|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W2[47]);
  256|       |
  257|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W2[48]);
  258|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W2[49]);
  259|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W2[50]);
  260|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W2[51]);
  261|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W2[52]);
  262|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W2[53]);
  263|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W2[54]);
  264|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W2[55]);
  265|      0|      SHA2_32_F(A, B, C, D, E, F, G, H, W2[56]);
  266|      0|      SHA2_32_F(H, A, B, C, D, E, F, G, W2[57]);
  267|      0|      SHA2_32_F(G, H, A, B, C, D, E, F, W2[58]);
  268|      0|      SHA2_32_F(F, G, H, A, B, C, D, E, W2[59]);
  269|      0|      SHA2_32_F(E, F, G, H, A, B, C, D, W2[60]);
  270|      0|      SHA2_32_F(D, E, F, G, H, A, B, C, W2[61]);
  271|      0|      SHA2_32_F(C, D, E, F, G, H, A, B, W2[62]);
  272|      0|      SHA2_32_F(B, C, D, E, F, G, H, A, W2[63]);
  273|       |
  274|      0|      A = (digest[0] += A);
  275|      0|      B = (digest[1] += B);
  276|      0|      C = (digest[2] += C);
  277|      0|      D = (digest[3] += D);
  278|      0|      E = (digest[4] += E);
  279|      0|      F = (digest[5] += F);
  280|      0|      G = (digest[6] += G);
  281|      0|      H = (digest[7] += H);
  282|      0|   }
  283|       |
  284|     20|   while(blocks > 0) {
  ------------------
  |  Branch (284:10): [True: 10, False: 10]
  ------------------
  285|     10|      SIMD_4x32 WS[4];
  286|       |
  287|     50|      for(size_t i = 0; i < 4; i++) {
  ------------------
  |  Branch (287:25): [True: 40, False: 10]
  ------------------
  288|     40|         WS[i] = SIMD_4x32::load_be(&data[16 * i]);
  289|     40|         auto WK = WS[i] + SIMD_4x32::load_le(&K[4 * i]);
  290|     40|         WK.store_le(&W[4 * i]);
  291|     40|      }
  292|       |
  293|     10|      data += 64;
  294|     10|      blocks -= 1;
  295|       |
  296|     40|      for(size_t r = 0; r != 48; r += 16) {
  ------------------
  |  Branch (296:25): [True: 30, False: 10]
  ------------------
  297|     30|         auto w = next_w(WS) + SIMD_4x32::load_le(&K[r + 16]);
  298|       |
  299|     30|         SHA2_32_F(A, B, C, D, E, F, G, H, W[0]);
  300|     30|         SHA2_32_F(H, A, B, C, D, E, F, G, W[1]);
  301|     30|         SHA2_32_F(G, H, A, B, C, D, E, F, W[2]);
  302|     30|         SHA2_32_F(F, G, H, A, B, C, D, E, W[3]);
  303|       |
  304|     30|         w.store_le(&W[0]);
  305|       |
  306|     30|         w = next_w(WS) + SIMD_4x32::load_le(&K[r + 20]);
  307|       |
  308|     30|         SHA2_32_F(E, F, G, H, A, B, C, D, W[4]);
  309|     30|         SHA2_32_F(D, E, F, G, H, A, B, C, W[5]);
  310|     30|         SHA2_32_F(C, D, E, F, G, H, A, B, W[6]);
  311|     30|         SHA2_32_F(B, C, D, E, F, G, H, A, W[7]);
  312|       |
  313|     30|         w.store_le(&W[4]);
  314|       |
  315|     30|         w = next_w(WS) + SIMD_4x32::load_le(&K[r + 24]);
  316|       |
  317|     30|         SHA2_32_F(A, B, C, D, E, F, G, H, W[8]);
  318|     30|         SHA2_32_F(H, A, B, C, D, E, F, G, W[9]);
  319|     30|         SHA2_32_F(G, H, A, B, C, D, E, F, W[10]);
  320|     30|         SHA2_32_F(F, G, H, A, B, C, D, E, W[11]);
  321|       |
  322|     30|         w.store_le(&W[8]);
  323|       |
  324|     30|         w = next_w(WS) + SIMD_4x32::load_le(&K[r + 28]);
  325|       |
  326|     30|         SHA2_32_F(E, F, G, H, A, B, C, D, W[12]);
  327|     30|         SHA2_32_F(D, E, F, G, H, A, B, C, W[13]);
  328|     30|         SHA2_32_F(C, D, E, F, G, H, A, B, W[14]);
  329|     30|         SHA2_32_F(B, C, D, E, F, G, H, A, W[15]);
  330|       |
  331|     30|         w.store_le(&W[12]);
  332|     30|      }
  333|       |
  334|     10|      SHA2_32_F(A, B, C, D, E, F, G, H, W[0]);
  335|     10|      SHA2_32_F(H, A, B, C, D, E, F, G, W[1]);
  336|     10|      SHA2_32_F(G, H, A, B, C, D, E, F, W[2]);
  337|     10|      SHA2_32_F(F, G, H, A, B, C, D, E, W[3]);
  338|     10|      SHA2_32_F(E, F, G, H, A, B, C, D, W[4]);
  339|     10|      SHA2_32_F(D, E, F, G, H, A, B, C, W[5]);
  340|     10|      SHA2_32_F(C, D, E, F, G, H, A, B, W[6]);
  341|     10|      SHA2_32_F(B, C, D, E, F, G, H, A, W[7]);
  342|     10|      SHA2_32_F(A, B, C, D, E, F, G, H, W[8]);
  343|     10|      SHA2_32_F(H, A, B, C, D, E, F, G, W[9]);
  344|     10|      SHA2_32_F(G, H, A, B, C, D, E, F, W[10]);
  345|     10|      SHA2_32_F(F, G, H, A, B, C, D, E, W[11]);
  346|     10|      SHA2_32_F(E, F, G, H, A, B, C, D, W[12]);
  347|     10|      SHA2_32_F(D, E, F, G, H, A, B, C, W[13]);
  348|     10|      SHA2_32_F(C, D, E, F, G, H, A, B, W[14]);
  349|     10|      SHA2_32_F(B, C, D, E, F, G, H, A, W[15]);
  350|       |
  351|     10|      A = (digest[0] += A);
  352|     10|      B = (digest[1] += B);
  353|     10|      C = (digest[2] += C);
  354|     10|      D = (digest[3] += D);
  355|     10|      E = (digest[4] += E);
  356|     10|      F = (digest[5] += F);
  357|     10|      G = (digest[6] += G);
  358|     10|      H = (digest[7] += H);
  359|     10|   }
  360|     10|}
sha2_32_avx2.cpp:_ZN5Botan12_GLOBAL__N_16next_wINS_9SIMD_4x32EEET_PS3_:
   50|    120|BOTAN_FN_ISA_AVX2_BMI2 BOTAN_FORCE_INLINE SIMD_T next_w(SIMD_T x[4]) {
   51|    120|   constexpr size_t sigma0_0 = 7;
   52|    120|   constexpr size_t sigma0_1 = 18;
   53|    120|   constexpr size_t sigma0_2 = 3;
   54|    120|   constexpr size_t sigma1_0 = 17;
   55|    120|   constexpr size_t sigma1_1 = 19;
   56|    120|   constexpr size_t sigma1_2 = 10;
   57|       |
   58|    120|   const SIMD_T lo_mask = SIMD_T(0x03020100, 0x0b0a0908, 0x80808080, 0x80808080);
   59|    120|   const SIMD_T hi_mask = SIMD_T(0x80808080, 0x80808080, 0x03020100, 0x0b0a0908);
   60|       |
   61|    120|   auto t0 = alignr4(x[1], x[0]);
   62|    120|   x[0] += alignr4(x[3], x[2]);
   63|       |
   64|    120|   auto t1 = t0.template shl<32 - sigma0_1>();
   65|    120|   auto t2 = t0.template shr<sigma0_0>();
   66|    120|   auto t3 = t0.template shr<sigma0_2>();
   67|    120|   t0 = t3 ^ t2;
   68|       |
   69|    120|   t3 = shuffle_32<0b11111010>(x[3]);
   70|    120|   t2 = t2.template shr<sigma0_1 - sigma0_0>();
   71|    120|   t0 ^= t1 ^ t2;
   72|    120|   t1 = t1.template shl<sigma0_1 - sigma0_0>();
   73|    120|   t2 = t3.template shr<sigma1_2>();
   74|    120|   t3 = shr64<sigma1_0>(t3);
   75|    120|   x[0] += t0 ^ t1;
   76|       |
   77|    120|   t2 ^= t3;
   78|    120|   t3 = shr64<sigma1_1 - sigma1_0>(t3);
   79|    120|   x[0] += SIMD_T::byte_shuffle(t2 ^ t3, lo_mask);
   80|       |
   81|    120|   t3 = shuffle_32<0b01010000>(x[0]);
   82|    120|   t2 = t3.template shr<sigma1_2>();
   83|    120|   t3 = shr64<sigma1_0>(t3);
   84|    120|   t2 ^= t3;
   85|    120|   t3 = shr64<sigma1_1 - sigma1_0>(t3);
   86|    120|   x[0] += SIMD_T::byte_shuffle(t2 ^ t3, hi_mask);
   87|       |
   88|    120|   const auto tmp = x[0];
   89|    120|   x[0] = x[1];
   90|    120|   x[1] = x[2];
   91|    120|   x[2] = x[3];
   92|    120|   x[3] = tmp;
   93|       |
   94|    120|   return x[3];
   95|    120|}
sha2_32_avx2.cpp:_ZN5Botan12_GLOBAL__N_17alignr4ERKNS_9SIMD_4x32ES3_:
   21|    240|BOTAN_FN_ISA_AVX2_BMI2 inline SIMD_4x32 alignr4(const SIMD_4x32& a, const SIMD_4x32& b) {
   22|       |   return SIMD_4x32(_mm_alignr_epi8(a.raw(), b.raw(), 4));
   23|    240|}
sha2_32_avx2.cpp:_ZN5Botan12_GLOBAL__N_110shuffle_32ILh250EEENS_9SIMD_4x32ERKS2_:
   31|    120|BOTAN_FN_ISA_AVX2_BMI2 inline SIMD_4x32 shuffle_32(const SIMD_4x32& a) {
   32|       |   return SIMD_4x32(_mm_shuffle_epi32(a.raw(), S));
   33|    120|}
sha2_32_avx2.cpp:_ZN5Botan12_GLOBAL__N_15shr64ILm17EEENS_9SIMD_4x32ERKS2_:
   26|    240|BOTAN_FN_ISA_AVX2_BMI2 inline SIMD_4x32 shr64(const SIMD_4x32& a) {
   27|    240|   return SIMD_4x32(_mm_srli_epi64(a.raw(), S));
   28|    240|}
sha2_32_avx2.cpp:_ZN5Botan12_GLOBAL__N_15shr64ILm2EEENS_9SIMD_4x32ERKS2_:
   26|    240|BOTAN_FN_ISA_AVX2_BMI2 inline SIMD_4x32 shr64(const SIMD_4x32& a) {
   27|    240|   return SIMD_4x32(_mm_srli_epi64(a.raw(), S));
   28|    240|}
sha2_32_avx2.cpp:_ZN5Botan12_GLOBAL__N_110shuffle_32ILh80EEENS_9SIMD_4x32ERKS2_:
   31|    120|BOTAN_FN_ISA_AVX2_BMI2 inline SIMD_4x32 shuffle_32(const SIMD_4x32& a) {
   32|       |   return SIMD_4x32(_mm_shuffle_epi32(a.raw(), S));
   33|    120|}

_ZN5Botan4HMAC8add_dataENSt3__14spanIKhLm18446744073709551615EEE:
   21|      1|void HMAC::add_data(std::span<const uint8_t> input) {
   22|      1|   assert_key_material_set();
   23|      1|   m_hash->update(input);
   24|      1|}
_ZN5Botan4HMAC12final_resultENSt3__14spanIhLm18446744073709551615EEE:
   29|      2|void HMAC::final_result(std::span<uint8_t> mac) {
   30|      2|   assert_key_material_set();
   31|      2|   m_hash->final(mac);
   32|      2|   m_hash->update(m_okey);
   33|      2|   m_hash->update(mac.first(m_hash_output_length));
   34|      2|   m_hash->final(mac);
   35|      2|   m_hash->update(m_ikey);
   36|      2|}
_ZNK5Botan4HMAC8key_specEv:
   48|      2|Key_Length_Specification HMAC::key_spec() const {
   49|       |   // Support very long lengths for things like PBKDF2 and the TLS PRF
   50|      2|   return Key_Length_Specification(0, 8192);
   51|      2|}
_ZNK5Botan4HMAC13output_lengthEv:
   53|      4|size_t HMAC::output_length() const {
   54|      4|   return m_hash_output_length;
   55|      4|}
_ZNK5Botan4HMAC19has_keying_materialEv:
   57|      3|bool HMAC::has_keying_material() const {
   58|      3|   return !m_okey.empty();
   59|      3|}
_ZN5Botan4HMAC12key_scheduleENSt3__14spanIKhLm18446744073709551615EEE:
   64|      2|void HMAC::key_schedule(std::span<const uint8_t> key) {
   65|      2|   const uint8_t ipad = 0x36;
   66|      2|   const uint8_t opad = 0x5C;
   67|       |
   68|      2|   m_hash->clear();
   69|       |
   70|      2|   m_ikey.resize(m_hash_block_size);
   71|      2|   m_okey.resize(m_hash_block_size);
   72|       |
   73|      2|   clear_mem(m_ikey.data(), m_ikey.size());
   74|      2|   clear_mem(m_okey.data(), m_okey.size());
   75|       |
   76|       |   /*
   77|       |   * Sometimes the HMAC key length itself is sensitive, as with PBKDF2 where it
   78|       |   * reveals the length of the passphrase. Make some attempt to hide this to
   79|       |   * side channels. Clearly if the secret is longer than the block size then the
   80|       |   * branch to hash first reveals that. In addition, counting the number of
   81|       |   * compression functions executed reveals the size at the granularity of the
   82|       |   * hash function's block size.
   83|       |   *
   84|       |   * The greater concern is for smaller keys; being able to detect when a
   85|       |   * passphrase is say 4 bytes may assist choosing weaker targets. Even though
   86|       |   * the loop bounds are constant, we can only actually read key[0..length] so
   87|       |   * it doesn't seem possible to make this computation truly constant time.
   88|       |   *
   89|       |   * We don't mind leaking if the length is exactly zero since that's
   90|       |   * trivial to simply check.
   91|       |   */
   92|       |
   93|      2|   if(key.size() > m_hash_block_size) {
  ------------------
  |  Branch (93:7): [True: 0, False: 2]
  ------------------
   94|      0|      m_hash->update(key);
   95|      0|      m_hash->final(m_ikey.data());
   96|      2|   } else if(key.size() >= 20) {
  ------------------
  |  Branch (96:14): [True: 2, False: 0]
  ------------------
   97|       |      // For long keys we just leak the length either it is a cryptovariable
   98|       |      // or a long enough password that just the length is not a useful signal
   99|      2|      copy_mem(std::span{m_ikey}.first(key.size()), key);
  100|      2|   } else if(!key.empty()) {
  ------------------
  |  Branch (100:14): [True: 0, False: 0]
  ------------------
  101|      0|      for(size_t i = 0, i_mod_length = 0; i != m_hash_block_size; ++i) {
  ------------------
  |  Branch (101:43): [True: 0, False: 0]
  ------------------
  102|       |         /*
  103|       |         access key[i % length] but avoiding division due to variable
  104|       |         time computation on some processors.
  105|       |         */
  106|      0|         auto needs_reduction = CT::Mask<size_t>::is_lte(key.size(), i_mod_length);
  107|      0|         i_mod_length = needs_reduction.select(0, i_mod_length);
  108|      0|         const uint8_t kb = key[i_mod_length];
  109|       |
  110|      0|         auto in_range = CT::Mask<size_t>::is_lt(i, key.size());
  111|      0|         m_ikey[i] = static_cast<uint8_t>(in_range.if_set_return(kb));
  112|      0|         i_mod_length += 1;
  113|      0|      }
  114|      0|   }
  115|       |
  116|    130|   for(size_t i = 0; i != m_hash_block_size; ++i) {
  ------------------
  |  Branch (116:22): [True: 128, False: 2]
  ------------------
  117|    128|      m_ikey[i] ^= ipad;
  118|    128|      m_okey[i] = m_ikey[i] ^ ipad ^ opad;
  119|    128|   }
  120|       |
  121|      2|   m_hash->update(m_ikey);
  122|      2|}
_ZN5Botan4HMACC2ENSt3__110unique_ptrINS_12HashFunctionENS1_14default_deleteIS3_EEEE:
  151|      1|      m_hash(std::move(hash)),
  152|      1|      m_hash_output_length(m_hash->output_length()),
  153|      1|      m_hash_block_size(m_hash->hash_block_size()) {
  154|      1|   BOTAN_ARG_CHECK(m_hash_output_length >= 8, "HMAC is not compatible with this hash function");
  ------------------
  |  |   35|      1|   do {                                                          \
  |  |   36|      1|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|      1|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 1]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|      1|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 1]
  |  |  ------------------
  ------------------
  155|      1|   BOTAN_ARG_CHECK(m_hash_block_size >= m_hash_output_length, "HMAC is not compatible with this hash function");
  ------------------
  |  |   35|      1|   do {                                                          \
  |  |   36|      1|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|      1|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 1]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|      1|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 1]
  |  |  ------------------
  ------------------
  156|      1|}

_ZN5Botan25MessageAuthenticationCode6createENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEES5_:
   51|      1|                                                                             std::string_view provider) {
   52|      1|   const SCAN_Name req(algo_spec);
   53|       |
   54|      1|#if defined(BOTAN_HAS_BLAKE2BMAC)
   55|      1|   if(req.algo_name() == "Blake2b" || req.algo_name() == "BLAKE2b") {
  ------------------
  |  Branch (55:7): [True: 0, False: 1]
  |  Branch (55:39): [True: 0, False: 1]
  ------------------
   56|      0|      if(provider.empty() || provider == "base") {
  ------------------
  |  Branch (56:10): [True: 0, False: 0]
  |  Branch (56:30): [True: 0, False: 0]
  ------------------
   57|      0|         return std::make_unique<BLAKE2bMAC>(req.arg_as_integer(0, 512));
   58|      0|      }
   59|      0|   }
   60|      1|#endif
   61|       |
   62|      1|#if defined(BOTAN_HAS_GMAC)
   63|      1|   if(req.algo_name() == "GMAC" && req.arg_count() == 1) {
  ------------------
  |  Branch (63:7): [True: 0, False: 1]
  |  Branch (63:36): [True: 0, False: 0]
  ------------------
   64|      0|      if(provider.empty() || provider == "base") {
  ------------------
  |  Branch (64:10): [True: 0, False: 0]
  |  Branch (64:30): [True: 0, False: 0]
  ------------------
   65|      0|         if(auto bc = BlockCipher::create(req.arg(0))) {
  ------------------
  |  Branch (65:18): [True: 0, False: 0]
  ------------------
   66|      0|            return std::make_unique<GMAC>(std::move(bc));
   67|      0|         }
   68|      0|      }
   69|      0|   }
   70|      1|#endif
   71|       |
   72|      1|#if defined(BOTAN_HAS_HMAC)
   73|      1|   if(req.algo_name() == "HMAC" && req.arg_count() == 1) {
  ------------------
  |  Branch (73:7): [True: 1, False: 0]
  |  Branch (73:36): [True: 1, False: 0]
  ------------------
   74|      1|      if(provider.empty() || provider == "base") {
  ------------------
  |  Branch (74:10): [True: 1, False: 0]
  |  Branch (74:30): [True: 0, False: 0]
  ------------------
   75|      1|         if(auto hash = HashFunction::create(req.arg(0))) {
  ------------------
  |  Branch (75:18): [True: 1, False: 0]
  ------------------
   76|      1|            return std::make_unique<HMAC>(std::move(hash));
   77|      1|         }
   78|      1|      }
   79|      1|   }
   80|      0|#endif
   81|       |
   82|      0|#if defined(BOTAN_HAS_POLY1305)
   83|      0|   if(req.algo_name() == "Poly1305" && req.arg_count() == 0) {
  ------------------
  |  Branch (83:7): [True: 0, False: 0]
  |  Branch (83:40): [True: 0, False: 0]
  ------------------
   84|      0|      if(provider.empty() || provider == "base") {
  ------------------
  |  Branch (84:10): [True: 0, False: 0]
  |  Branch (84:30): [True: 0, False: 0]
  ------------------
   85|      0|         return std::make_unique<Poly1305>();
   86|      0|      }
   87|      0|   }
   88|      0|#endif
   89|       |
   90|      0|#if defined(BOTAN_HAS_SIPHASH)
   91|      0|   if(req.algo_name() == "SipHash") {
  ------------------
  |  Branch (91:7): [True: 0, False: 0]
  ------------------
   92|      0|      if(provider.empty() || provider == "base") {
  ------------------
  |  Branch (92:10): [True: 0, False: 0]
  |  Branch (92:30): [True: 0, False: 0]
  ------------------
   93|      0|         return std::make_unique<SipHash>(req.arg_as_integer(0, 2), req.arg_as_integer(1, 4));
   94|      0|      }
   95|      0|   }
   96|      0|#endif
   97|       |
   98|      0|#if defined(BOTAN_HAS_CMAC)
   99|      0|   if((req.algo_name() == "CMAC" || req.algo_name() == "OMAC") && req.arg_count() == 1) {
  ------------------
  |  Branch (99:8): [True: 0, False: 0]
  |  Branch (99:37): [True: 0, False: 0]
  |  Branch (99:67): [True: 0, False: 0]
  ------------------
  100|      0|      if(provider.empty() || provider == "base") {
  ------------------
  |  Branch (100:10): [True: 0, False: 0]
  |  Branch (100:30): [True: 0, False: 0]
  ------------------
  101|      0|         if(auto bc = BlockCipher::create(req.arg(0))) {
  ------------------
  |  Branch (101:18): [True: 0, False: 0]
  ------------------
  102|      0|            return std::make_unique<CMAC>(std::move(bc));
  103|      0|         }
  104|      0|      }
  105|      0|   }
  106|      0|#endif
  107|       |
  108|      0|#if defined(BOTAN_HAS_ANSI_X919_MAC)
  109|      0|   if(req.algo_name() == "X9.19-MAC") {
  ------------------
  |  Branch (109:7): [True: 0, False: 0]
  ------------------
  110|      0|      if(provider.empty() || provider == "base") {
  ------------------
  |  Branch (110:10): [True: 0, False: 0]
  |  Branch (110:30): [True: 0, False: 0]
  ------------------
  111|      0|         return std::make_unique<ANSI_X919_MAC>();
  112|      0|      }
  113|      0|   }
  114|      0|#endif
  115|       |
  116|      0|#if defined(BOTAN_HAS_KMAC)
  117|      0|   if(req.algo_name() == "KMAC-128") {
  ------------------
  |  Branch (117:7): [True: 0, False: 0]
  ------------------
  118|      0|      if(provider.empty() || provider == "base") {
  ------------------
  |  Branch (118:10): [True: 0, False: 0]
  |  Branch (118:30): [True: 0, False: 0]
  ------------------
  119|      0|         if(req.arg_count() != 1) {
  ------------------
  |  Branch (119:13): [True: 0, False: 0]
  ------------------
  120|      0|            throw Invalid_Argument(
  121|      0|               "invalid algorithm specification for KMAC-128: need exactly one argument for output bit length");
  122|      0|         }
  123|      0|         return std::make_unique<KMAC128>(req.arg_as_integer(0));
  124|      0|      }
  125|      0|   }
  126|       |
  127|      0|   if(req.algo_name() == "KMAC-256") {
  ------------------
  |  Branch (127:7): [True: 0, False: 0]
  ------------------
  128|      0|      if(provider.empty() || provider == "base") {
  ------------------
  |  Branch (128:10): [True: 0, False: 0]
  |  Branch (128:30): [True: 0, False: 0]
  ------------------
  129|      0|         if(req.arg_count() != 1) {
  ------------------
  |  Branch (129:13): [True: 0, False: 0]
  ------------------
  130|      0|            throw Invalid_Argument(
  131|      0|               "invalid algorithm specification for KMAC-256: need exactly one argument for output bit length");
  132|      0|         }
  133|      0|         return std::make_unique<KMAC256>(req.arg_as_integer(0));
  134|      0|      }
  135|      0|   }
  136|      0|#endif
  137|       |
  138|      0|   BOTAN_UNUSED(req);
  ------------------
  |  |  144|      0|#define BOTAN_UNUSED Botan::ignore_params
  ------------------
  139|      0|   BOTAN_UNUSED(provider);
  ------------------
  |  |  144|      0|#define BOTAN_UNUSED Botan::ignore_params
  ------------------
  140|       |
  141|      0|   return nullptr;
  142|      0|}
_ZN5Botan25MessageAuthenticationCode15create_or_throwENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEES5_:
  150|      1|                                                                                      std::string_view provider) {
  151|      1|   if(auto mac = MessageAuthenticationCode::create(algo, provider)) {
  ------------------
  |  Branch (151:12): [True: 1, False: 0]
  ------------------
  152|      1|      return mac;
  153|      1|   }
  154|      0|   throw Lookup_Error("MAC", algo, provider);
  155|      1|}

_ZN5Botan6BigIntpLERKS0_:
   16|      6|BigInt& BigInt::operator+=(const BigInt& y) {
   17|      6|   if(&y == this) {
  ------------------
  |  Branch (17:7): [True: 0, False: 6]
  ------------------
   18|      0|      return *this <<= 1;
   19|      0|   }
   20|      6|   return add(y._data(), y.sig_words(), y.sign());
   21|      6|}
_ZN5Botan6BigIntmIERKS0_:
   23|  16.2k|BigInt& BigInt::operator-=(const BigInt& y) {
   24|  16.2k|   if(&y == this) {
  ------------------
  |  Branch (24:7): [True: 0, False: 16.2k]
  ------------------
   25|      0|      this->clear();
   26|      0|      this->set_sign(Positive);
   27|      0|      return *this;
   28|      0|   }
   29|  16.2k|   return sub(y._data(), y.sig_words(), y.sign());
   30|  16.2k|}
_ZN5Botan6BigInt3addEPKmmNS0_4SignE:
   32|  17.0k|BigInt& BigInt::add(const word y[], size_t y_words, Sign y_sign) {
   33|  17.0k|   const size_t x_sw = sig_words();
   34|       |
   35|  17.0k|   grow_to(std::max(x_sw, y_words) + 1);
   36|       |
   37|  17.0k|   if(sign() == y_sign) {
  ------------------
  |  Branch (37:7): [True: 101, False: 16.9k]
  ------------------
   38|    101|      const word carry = bigint_add2(mutable_data(), size() - 1, y, y_words);
   39|    101|      mutable_data()[size() - 1] += carry;
   40|  16.9k|   } else {
   41|  16.9k|      const int32_t relative_size = bigint_cmp(_data(), x_sw, y, y_words);
   42|       |
   43|  16.9k|      if(relative_size >= 0) {
  ------------------
  |  Branch (43:10): [True: 16.9k, False: 14]
  ------------------
   44|       |         // *this >= y
   45|  16.9k|         bigint_sub2(mutable_data(), x_sw, y, y_words);
   46|  16.9k|      } else {
   47|       |         // *this < y: compute *this = y - *this
   48|     14|         bigint_sub2_rev(mutable_data(), y, y_words);
   49|     14|      }
   50|       |
   51|  16.9k|      if(relative_size < 0) {
  ------------------
  |  Branch (51:10): [True: 14, False: 16.9k]
  ------------------
   52|     14|         set_sign(y_sign);
   53|  16.9k|      } else if(relative_size == 0) {
  ------------------
  |  Branch (53:17): [True: 0, False: 16.9k]
  ------------------
   54|      0|         set_sign(Positive);
   55|      0|      }
   56|  16.9k|   }
   57|       |
   58|  17.0k|   return (*this);
   59|  17.0k|}
_ZN5Botan6BigIntrMERKS0_:
  232|  39.0k|BigInt& BigInt::operator%=(const BigInt& mod) {
  233|  39.0k|   return (*this = (*this) % mod);
  234|  39.0k|}
_ZN5Botan6BigIntlSEm:
  269|  26.0k|BigInt& BigInt::operator<<=(size_t shift) {
  270|  26.0k|   if(shift >= 65536) {
  ------------------
  |  Branch (270:7): [True: 0, False: 26.0k]
  ------------------
  271|      0|      throw Invalid_Argument("BigInt left shift count too large");
  272|      0|   }
  273|       |
  274|  26.0k|   const size_t sw = sig_words();
  275|  26.0k|   const size_t new_size = sw + (shift + WordInfo<word>::bits - 1) / WordInfo<word>::bits;
  276|       |
  277|  26.0k|   m_data.grow_to(new_size);
  278|       |
  279|  26.0k|   bigint_shl1(m_data.mutable_data(), new_size, sw, shift);
  280|       |
  281|  26.0k|   return (*this);
  282|  26.0k|}
_ZN5Botan6BigIntrSEm:
  287|  72.2k|BigInt& BigInt::operator>>=(size_t shift) {
  288|  72.2k|   bigint_shr1(m_data.mutable_data(), m_data.size(), shift);
  289|       |
  290|  72.2k|   if(sig_words() == 0 && m_signedness == Negative) {
  ------------------
  |  Branch (290:7): [True: 1, False: 72.1k]
  |  Branch (290:27): [True: 0, False: 1]
  ------------------
  291|      0|      m_signedness = Positive;
  292|      0|   }
  293|       |
  294|  72.2k|   return (*this);
  295|  72.2k|}

_ZN5Botan6BigInt4add2ERKS0_PKmmNS0_4SignE:
   20|  2.17k|BigInt BigInt::add2(const BigInt& x, const word y[], size_t y_size, BigInt::Sign y_sign) {
   21|  2.17k|   const size_t x_sw = x.sig_words();
   22|       |
   23|  2.17k|   BigInt z = BigInt::with_capacity(std::max(x_sw, y_size) + 1);
   24|       |
   25|  2.17k|   if(x.sign() == y_sign) {
  ------------------
  |  Branch (25:7): [True: 1.41k, False: 762]
  ------------------
   26|  1.41k|      const word carry = bigint_add3(z.mutable_data(), x._data(), x_sw, y, y_size);
   27|  1.41k|      z.mutable_data()[std::max(x_sw, y_size)] += carry;
   28|  1.41k|      z.set_sign(x.sign());
   29|  1.41k|   } else {
   30|    762|      const int32_t relative_size = bigint_cmp(x.data(), x_sw, y, y_size);
   31|       |
   32|    762|      if(relative_size < 0) {
  ------------------
  |  Branch (32:10): [True: 0, False: 762]
  ------------------
   33|       |         // x < y so z = abs(y - x)
   34|       |         // NOLINTNEXTLINE(*-suspicious-call-argument) intentionally swapping x and y here
   35|      0|         bigint_sub3(z.mutable_data(), y, y_size, x.data(), x_sw);
   36|      0|         z.set_sign(y_sign);
   37|    762|      } else if(relative_size == 0) {
  ------------------
  |  Branch (37:17): [True: 0, False: 762]
  ------------------
   38|       |         // Positive zero (nothing to do in this case)
   39|    762|      } else {
   40|       |         /*
   41|       |         * We know at this point that x >= y so if y_size is larger than
   42|       |         * x_sw, we are guaranteed they are just leading zeros which can
   43|       |         * be ignored
   44|       |         */
   45|    762|         y_size = std::min(x_sw, y_size);
   46|    762|         bigint_sub3(z.mutable_data(), x.data(), x_sw, y, y_size);
   47|    762|         z.set_sign(x.sign());
   48|    762|      }
   49|    762|   }
   50|       |
   51|  2.17k|   return z;
   52|  2.17k|}
_ZN5BotanmlERKNS_6BigIntEm:
   90|  15.6k|BigInt operator*(const BigInt& x, word y) {
   91|  15.6k|   const size_t x_sw = x.sig_words();
   92|       |
   93|  15.6k|   BigInt z = BigInt::with_capacity(x_sw + 1);
   94|       |
   95|  15.6k|   if(x_sw > 0 && y > 0) {
  ------------------
  |  Branch (95:7): [True: 15.6k, False: 0]
  |  Branch (95:19): [True: 15.6k, False: 0]
  ------------------
   96|  15.6k|      bigint_linmul3(z.mutable_data(), x._data(), x_sw, y);
   97|  15.6k|      z.set_sign(x.sign());
   98|  15.6k|   }
   99|       |
  100|  15.6k|   return z;
  101|  15.6k|}
_ZN5BotanrmERKNS_6BigIntES2_:
  134|  39.0k|BigInt operator%(const BigInt& n, const BigInt& mod) {
  135|  39.0k|   if(mod.is_zero()) {
  ------------------
  |  Branch (135:7): [True: 0, False: 39.0k]
  ------------------
  136|      0|      throw Invalid_Argument("BigInt::operator% divide by zero");
  137|      0|   }
  138|  39.0k|   if(mod.signum() < 0) {
  ------------------
  |  Branch (138:7): [True: 0, False: 39.0k]
  ------------------
  139|      0|      throw Invalid_Argument("BigInt::operator% modulus must be > 0");
  140|      0|   }
  141|  39.0k|   if(n.signum() >= 0 && mod.signum() >= 0 && n < mod) {
  ------------------
  |  Branch (141:7): [True: 39.0k, False: 2]
  |  Branch (141:26): [True: 39.0k, False: 0]
  |  Branch (141:47): [True: 0, False: 39.0k]
  ------------------
  142|      0|      return n;
  143|      0|   }
  144|       |
  145|  39.0k|   if(mod.sig_words() == 1) {
  ------------------
  |  Branch (145:7): [True: 25.9k, False: 13.1k]
  ------------------
  146|  25.9k|      return BigInt::from_word(n % mod.word_at(0));
  147|  25.9k|   }
  148|       |
  149|  13.1k|   BigInt q;
  150|  13.1k|   BigInt r;
  151|  13.1k|   vartime_divide(n, mod, q, r);
  152|  13.1k|   return r;
  153|  39.0k|}
_ZN5BotanrmERKNS_6BigIntEm:
  158|  46.6k|word operator%(const BigInt& n, word mod) {
  159|  46.6k|   if(mod == 0) {
  ------------------
  |  Branch (159:7): [True: 0, False: 46.6k]
  ------------------
  160|      0|      throw Invalid_Argument("BigInt::operator% divide by zero");
  161|      0|   }
  162|       |
  163|  46.6k|   if(mod == 1) {
  ------------------
  |  Branch (163:7): [True: 0, False: 46.6k]
  ------------------
  164|      0|      return 0;
  165|      0|   }
  166|       |
  167|  46.6k|   word remainder = 0;
  168|       |
  169|  46.6k|   if(n.signum() >= 0 && is_power_of_2(mod)) {
  ------------------
  |  Branch (169:7): [True: 46.6k, False: 0]
  |  Branch (169:26): [True: 20.7k, False: 25.9k]
  ------------------
  170|  20.7k|      remainder = (n.word_at(0) & (mod - 1));
  171|  25.9k|   } else {
  172|  25.9k|      const divide_precomp redc_mod(mod);
  173|  25.9k|      const size_t sw = n.sig_words();
  174|  55.6k|      for(size_t i = sw; i > 0; --i) {
  ------------------
  |  Branch (174:26): [True: 29.7k, False: 25.9k]
  ------------------
  175|  29.7k|         remainder = redc_mod.vartime_mod_2to1(remainder, n.word_at(i - 1));
  176|  29.7k|      }
  177|  25.9k|   }
  178|       |
  179|  46.6k|   if(remainder != 0 && n.sign() == BigInt::Negative) {
  ------------------
  |  Branch (179:7): [True: 46.6k, False: 0]
  |  Branch (179:25): [True: 0, False: 46.6k]
  ------------------
  180|      0|      return mod - remainder;
  181|      0|   }
  182|  46.6k|   return remainder;
  183|  46.6k|}
_ZN5BotanlsERKNS_6BigIntEm:
  188|  14.4k|BigInt operator<<(const BigInt& x, size_t shift) {
  189|  14.4k|   if(shift >= 65536) {
  ------------------
  |  Branch (189:7): [True: 0, False: 14.4k]
  ------------------
  190|      0|      throw Invalid_Argument("BigInt left shift count too large");
  191|      0|   }
  192|       |
  193|  14.4k|   if(x.is_zero()) {
  ------------------
  |  Branch (193:7): [True: 0, False: 14.4k]
  ------------------
  194|      0|      return BigInt::zero();
  195|      0|   }
  196|       |
  197|  14.4k|   const size_t x_sw = x.sig_words();
  198|       |
  199|  14.4k|   const size_t new_size = x_sw + shift / WordInfo<word>::bits + 1;
  200|  14.4k|   BigInt y = BigInt::with_capacity(new_size);
  201|  14.4k|   bigint_shl2(y.mutable_data(), new_size, x._data(), x_sw, shift);
  202|  14.4k|   y.set_sign(x.sign());
  203|  14.4k|   return y;
  204|  14.4k|}
_ZN5BotanrsERKNS_6BigIntEm:
  209|    717|BigInt operator>>(const BigInt& x, size_t shift) {
  210|    717|   const size_t shift_words = shift / WordInfo<word>::bits;
  211|    717|   const size_t x_sw = x.sig_words();
  212|       |
  213|    717|   if(shift_words >= x_sw) {
  ------------------
  |  Branch (213:7): [True: 0, False: 717]
  ------------------
  214|      0|      return BigInt::zero();
  215|      0|   }
  216|       |
  217|    717|   const size_t new_size = x_sw - shift_words;
  218|    717|   BigInt y = BigInt::with_capacity(new_size);
  219|    717|   bigint_shr2(y.mutable_data(), new_size, x._data(), x_sw, shift);
  220|       |
  221|    717|   if(x.signum() < 0 && y.is_zero()) {
  ------------------
  |  Branch (221:7): [True: 0, False: 717]
  |  Branch (221:25): [True: 0, False: 0]
  ------------------
  222|      0|      y.set_sign(BigInt::Positive);
  223|    717|   } else {
  224|    717|      y.set_sign(x.sign());
  225|    717|   }
  226|       |
  227|    717|   return y;
  228|    717|}

_ZN5Botan6BigInt9randomizeERNS_21RandomNumberGeneratorEmb:
   19|     53|void BigInt::randomize(RandomNumberGenerator& rng, size_t bitsize, bool set_high_bit) {
   20|     53|   set_sign(Positive);
   21|       |
   22|     53|   if(bitsize == 0) {
  ------------------
  |  Branch (22:7): [True: 0, False: 53]
  ------------------
   23|      0|      clear();
   24|     53|   } else {
   25|     53|      secure_vector<uint8_t> array = rng.random_vec(round_up(bitsize, 8) / 8);
   26|       |
   27|       |      // Always cut unwanted bits
   28|     53|      if(bitsize % 8 > 0) {
  ------------------
  |  Branch (28:10): [True: 0, False: 53]
  ------------------
   29|      0|         array[0] &= 0xFF >> (8 - (bitsize % 8));
   30|      0|      }
   31|       |
   32|       |      // Set the highest bit if wanted
   33|     53|      if(set_high_bit) {
  ------------------
  |  Branch (33:10): [True: 1, False: 52]
  ------------------
   34|      1|         array[0] |= 0x80 >> ((bitsize % 8) > 0 ? (8 - bitsize % 8) : 0);
  ------------------
  |  Branch (34:31): [True: 0, False: 1]
  ------------------
   35|      1|      }
   36|       |
   37|     53|      assign_from_bytes(array);
   38|     53|   }
   39|     53|}
_ZN5Botan6BigInt14random_integerERNS_21RandomNumberGeneratorERKS0_S4_:
   44|     86|BigInt BigInt::random_integer(RandomNumberGenerator& rng, const BigInt& min, const BigInt& max) {
   45|     86|   if(min.signum() < 0 || max.signum() < 0 || max <= min) {
  ------------------
  |  Branch (45:7): [True: 0, False: 86]
  |  Branch (45:27): [True: 0, False: 86]
  |  Branch (45:47): [True: 0, False: 86]
  ------------------
   46|      0|      throw Invalid_Argument("BigInt::random_integer invalid range");
   47|      0|   }
   48|       |
   49|       |   /*
   50|       |   If min is > 1 then we generate a random number `r` in [0,max-min)
   51|       |   and return min + r.
   52|       |
   53|       |   This same logic could also be reasonably chosen for min == 1, but
   54|       |   that breaks certain tests which expect stability of this function
   55|       |   when generating within [1,n)
   56|       |   */
   57|     86|   if(min > 1) {
  ------------------
  |  Branch (57:7): [True: 43, False: 43]
  ------------------
   58|     43|      const BigInt diff = max - min;
   59|       |      // This call is recursive, but will not recurse further
   60|     43|      return min + BigInt::random_integer(rng, BigInt::zero(), diff);
   61|     43|   }
   62|       |
   63|     43|   BOTAN_DEBUG_ASSERT(min <= 1);
  ------------------
  |  |  130|     43|      do { /* NOLINT(*-avoid-do-while) */ \
  |  |  131|     43|      } while(0)
  |  |  ------------------
  |  |  |  Branch (131:15): [Folded, False: 43]
  |  |  ------------------
  ------------------
   64|       |
   65|     43|   const size_t bits = max.bits();
   66|       |
   67|     52|   for(;;) {
   68|     52|      BigInt r;
   69|     52|      r.randomize(rng, bits, false);
   70|     52|      if(r >= min && r < max) {
  ------------------
  |  Branch (70:10): [True: 52, False: 0]
  |  Branch (70:22): [True: 43, False: 9]
  ------------------
   71|     43|         return r;
   72|     43|      }
   73|     52|   }
   74|     43|}

_ZN5Botan6BigIntC2Em:
   20|    521|BigInt::BigInt(uint64_t n) {
   21|    521|   if constexpr(sizeof(word) == 8) {
   22|    521|      m_data.set_word_at(0, static_cast<word>(n));
   23|       |   } else {
   24|       |      m_data.set_word_at(1, static_cast<word>(n >> 32));
   25|       |      m_data.set_word_at(0, static_cast<word>(n));
   26|       |   }
   27|    521|}
_ZN5Botan6BigInt8from_u64Em:
   30|    520|BigInt BigInt::from_u64(uint64_t n) {
   31|    520|   return BigInt(n);
   32|    520|}
_ZN5Botan6BigInt9from_wordEm:
   35|  27.7k|BigInt BigInt::from_word(word n) {
   36|  27.7k|   BigInt bn;
   37|  27.7k|   bn.set_word_at(0, n);
   38|  27.7k|   return bn;
   39|  27.7k|}
_ZN5Botan6BigInt8from_s32Ei:
   42|    518|BigInt BigInt::from_s32(int32_t n) {
   43|    518|   if(n >= 0) {
  ------------------
  |  Branch (43:7): [True: 0, False: 518]
  ------------------
   44|      0|      return BigInt::from_u64(static_cast<uint64_t>(n));
   45|    518|   } else {
   46|    518|      return -BigInt::from_u64(static_cast<uint64_t>(-static_cast<int64_t>(n)));
   47|    518|   }
   48|    518|}
_ZN5Botan6BigInt13with_capacityEm:
   51|  32.9k|BigInt BigInt::with_capacity(size_t size) {
   52|  32.9k|   BigInt bn;
   53|  32.9k|   bn.grow_to(size);
   54|  32.9k|   return bn;
   55|  32.9k|}
_ZN5Botan6BigInt10from_bytesENSt3__14spanIKhLm18446744073709551615EEE:
   83|  1.19k|BigInt BigInt::from_bytes(std::span<const uint8_t> input) {
   84|  1.19k|   BigInt r;
   85|  1.19k|   r.assign_from_bytes(input);
   86|  1.19k|   return r;
   87|  1.19k|}
_ZN5Botan6BigIntC2ERNS_21RandomNumberGeneratorEmb:
  114|      1|BigInt::BigInt(RandomNumberGenerator& rng, size_t bits, bool set_high_bit) {
  115|      1|   randomize(rng, bits, set_high_bit);
  116|      1|}
_ZNK5Botan6BigInt8cmp_wordEm:
  122|   102k|int32_t BigInt::cmp_word(word other) const {
  123|   102k|   if(signum() < 0) {
  ------------------
  |  Branch (123:7): [True: 522, False: 102k]
  ------------------
  124|    522|      return -1;  // other is positive ...
  125|    522|   }
  126|       |
  127|   102k|   const size_t sw = this->sig_words();
  128|   102k|   if(sw > 1) {
  ------------------
  |  Branch (128:7): [True: 39.8k, False: 62.2k]
  ------------------
  129|  39.8k|      return 1;  // must be larger since other is just one word ...
  130|  39.8k|   }
  131|       |
  132|  62.2k|   return bigint_cmp(this->_data(), sw, &other, 1);
  133|   102k|}
_ZNK5Botan6BigInt3cmpERKS0_b:
  138|  2.54k|int32_t BigInt::cmp(const BigInt& other, bool check_signs) const {
  139|  2.54k|   if(check_signs) {
  ------------------
  |  Branch (139:7): [True: 2.54k, False: 0]
  ------------------
  140|  2.54k|      if(other.signum() >= 0 && this->signum() < 0) {
  ------------------
  |  Branch (140:10): [True: 2.54k, False: 0]
  |  Branch (140:33): [True: 0, False: 2.54k]
  ------------------
  141|      0|         return -1;
  142|      0|      }
  143|       |
  144|  2.54k|      if(other.signum() < 0 && this->signum() >= 0) {
  ------------------
  |  Branch (144:10): [True: 0, False: 2.54k]
  |  Branch (144:32): [True: 0, False: 0]
  ------------------
  145|      0|         return 1;
  146|      0|      }
  147|       |
  148|  2.54k|      if(other.signum() < 0 && this->signum() < 0) {
  ------------------
  |  Branch (148:10): [True: 0, False: 2.54k]
  |  Branch (148:32): [True: 0, False: 0]
  ------------------
  149|      0|         return (-bigint_cmp(this->_data(), this->size(), other._data(), other.size()));
  150|      0|      }
  151|  2.54k|   }
  152|       |
  153|  2.54k|   return bigint_cmp(this->_data(), this->size(), other._data(), other.size());
  154|  2.54k|}
_ZNK5Botan6BigInt8is_equalERKS0_:
  156|    804|bool BigInt::is_equal(const BigInt& other) const {
  157|    804|   if(this->sign() != other.sign()) {
  ------------------
  |  Branch (157:7): [True: 0, False: 804]
  ------------------
  158|      0|      return false;
  159|      0|   }
  160|       |
  161|    804|   return bigint_ct_is_eq(this->_data(), this->size(), other._data(), other.size()).as_bool();
  162|    804|}
_ZNK5Botan6BigInt12is_less_thanERKS0_:
  164|  47.4k|bool BigInt::is_less_than(const BigInt& other) const {
  165|  47.4k|   if(this->signum() < 0 && other.signum() >= 0) {
  ------------------
  |  Branch (165:7): [True: 0, False: 47.4k]
  |  Branch (165:29): [True: 0, False: 0]
  ------------------
  166|      0|      return true;
  167|      0|   }
  168|       |
  169|  47.4k|   if(this->signum() >= 0 && other.signum() < 0) {
  ------------------
  |  Branch (169:7): [True: 47.4k, False: 0]
  |  Branch (169:30): [True: 0, False: 47.4k]
  ------------------
  170|      0|      return false;
  171|      0|   }
  172|       |
  173|  47.4k|   if(other.signum() < 0 && this->signum() < 0) {
  ------------------
  |  Branch (173:7): [True: 0, False: 47.4k]
  |  Branch (173:29): [True: 0, False: 0]
  ------------------
  174|      0|      return bigint_ct_is_lt(other._data(), other.size(), this->_data(), this->size()).as_bool();
  175|      0|   }
  176|       |
  177|  47.4k|   return bigint_ct_is_lt(this->_data(), this->size(), other._data(), other.size()).as_bool();
  178|  47.4k|}
_ZN5Botan6BigInt4Data11set_to_zeroEv:
  191|  1.24k|void BigInt::Data::set_to_zero() {
  192|  1.24k|   m_reg.resize(m_reg.capacity());
  193|  1.24k|   clear_mem(m_reg.data(), m_reg.size());
  194|  1.24k|   m_sig_words = 0;
  195|  1.24k|}
_ZNK5Botan6BigInt4Data14calc_sig_wordsEv:
  215|   193k|size_t BigInt::Data::calc_sig_words() const {
  216|   193k|   const size_t sz = m_reg.size();
  217|   193k|   size_t sig = sz;
  218|       |
  219|   193k|   word sub = 1;
  220|       |
  221|  1.83M|   for(size_t i = 0; i != sz; ++i) {
  ------------------
  |  Branch (221:22): [True: 1.64M, False: 193k]
  ------------------
  222|  1.64M|      const word w = m_reg[sz - i - 1];
  223|  1.64M|      sub &= ct_is_zero(w);
  224|  1.64M|      sig -= sub;
  225|  1.64M|   }
  226|       |
  227|       |   /*
  228|       |   * This depends on the data so is poisoned, but unpoison it here as
  229|       |   * later conditionals are made on the size.
  230|       |   */
  231|   193k|   CT::unpoison(sig);
  232|       |
  233|   193k|   return sig;
  234|   193k|}
_ZNK5Botan6BigInt13get_substringEmm:
  239|  84.5k|uint32_t BigInt::get_substring(size_t offset, size_t length) const {
  240|  84.5k|   if(length == 0 || length > 32) {
  ------------------
  |  Branch (240:7): [True: 0, False: 84.5k]
  |  Branch (240:22): [True: 0, False: 84.5k]
  ------------------
  241|      0|      throw Invalid_Argument("BigInt::get_substring invalid substring length");
  242|      0|   }
  243|       |
  244|  84.5k|   const uint32_t mask = 0xFFFFFFFF >> (32 - length);
  245|       |
  246|  84.5k|   const size_t word_offset = offset / WordInfo<word>::bits;
  247|  84.5k|   const size_t wshift = (offset % WordInfo<word>::bits);
  248|       |
  249|       |   /*
  250|       |   * The substring is contained within one or at most two words. The
  251|       |   * offset and length are not secret, so we can perform conditional
  252|       |   * operations on those values.
  253|       |   */
  254|  84.5k|   const word w0 = word_at(word_offset);
  255|       |
  256|  84.5k|   if(wshift == 0 || (offset + length) / WordInfo<word>::bits == word_offset) {
  ------------------
  |  Branch (256:7): [True: 6.35k, False: 78.2k]
  |  Branch (256:22): [True: 74.2k, False: 4.01k]
  ------------------
  257|  80.5k|      return static_cast<uint32_t>(w0 >> wshift) & mask;
  258|  80.5k|   } else {
  259|  4.01k|      const word w1 = word_at(word_offset + 1);
  260|  4.01k|      return static_cast<uint32_t>((w0 >> wshift) | (w1 << (WordInfo<word>::bits - wshift))) & mask;
  261|  4.01k|   }
  262|  84.5k|}
_ZNK5Botan6BigInt13top_bits_freeEv:
  298|  17.2k|size_t BigInt::top_bits_free() const {
  299|  17.2k|   const size_t words = sig_words();
  300|       |
  301|  17.2k|   const word top_word = word_at(words - 1);
  302|  17.2k|   const size_t bits_used = high_bit(CT::value_barrier(top_word));
  303|  17.2k|   CT::unpoison(bits_used);
  304|  17.2k|   return WordInfo<word>::bits - bits_used;
  305|  17.2k|}
_ZNK5Botan6BigInt4bitsEv:
  307|  3.40k|size_t BigInt::bits() const {
  308|  3.40k|   const size_t words = sig_words();
  309|       |
  310|  3.40k|   if(words == 0) {
  ------------------
  |  Branch (310:7): [True: 1, False: 3.40k]
  ------------------
  311|      1|      return 0;
  312|      1|   }
  313|       |
  314|  3.40k|   const size_t full_words = (words - 1) * WordInfo<word>::bits;
  315|  3.40k|   const size_t top_bits = WordInfo<word>::bits - top_bits_free();
  316|       |
  317|  3.40k|   return full_words + top_bits;
  318|  3.40k|}
_ZNK5Botan6BigIntngEv:
  323|    518|BigInt BigInt::operator-() const {
  324|    518|   BigInt x = (*this);
  325|    518|   x.flip_sign();
  326|    518|   return x;
  327|    518|}
_ZN5Botan6BigInt12reduce_belowERKS0_RNSt3__16vectorImNS_16secure_allocatorImEEEE:
  329|  13.8k|size_t BigInt::reduce_below(const BigInt& p, secure_vector<word>& ws) {
  330|  13.8k|   if(p.signum() < 0 || this->signum() < 0) {
  ------------------
  |  Branch (330:7): [True: 0, False: 13.8k]
  |  Branch (330:25): [True: 0, False: 13.8k]
  ------------------
  331|      0|      throw Invalid_Argument("BigInt::reduce_below both values must be positive");
  332|      0|   }
  333|       |
  334|  13.8k|   const size_t p_words = p.sig_words();
  335|       |
  336|  13.8k|   if(size() < p_words + 1) {
  ------------------
  |  Branch (336:7): [True: 1.02k, False: 12.7k]
  ------------------
  337|  1.02k|      grow_to(p_words + 1);
  338|  1.02k|   }
  339|       |
  340|  13.8k|   if(ws.size() < p_words + 1) {
  ------------------
  |  Branch (340:7): [True: 13.8k, False: 0]
  ------------------
  341|  13.8k|      ws.resize(p_words + 1);
  342|  13.8k|   }
  343|       |
  344|  13.8k|   clear_mem(ws.data(), ws.size());
  345|       |
  346|  13.8k|   size_t reductions = 0;
  347|       |
  348|  15.4k|   for(;;) {
  349|  15.4k|      const word borrow = bigint_sub3(ws.data(), _data(), p_words + 1, p._data(), p_words);
  350|  15.4k|      if(borrow > 0) {
  ------------------
  |  Branch (350:10): [True: 13.8k, False: 1.59k]
  ------------------
  351|  13.8k|         break;
  352|  13.8k|      }
  353|       |
  354|  1.59k|      ++reductions;
  355|  1.59k|      swap_reg(ws);
  356|  1.59k|   }
  357|       |
  358|  13.8k|   return reductions;
  359|  13.8k|}
_ZNK5Botan6BigInt3absEv:
  386|      2|BigInt BigInt::abs() const {
  387|      2|   BigInt x = (*this);
  388|      2|   x.set_sign(Positive);
  389|      2|   return x;
  390|      2|}
_ZN5Botan6BigInt17assign_from_bytesENSt3__14spanIKhLm18446744073709551615EEE:
  425|  1.24k|void BigInt::assign_from_bytes(std::span<const uint8_t> bytes) {
  426|  1.24k|   clear();
  427|       |
  428|  1.24k|   const size_t length = bytes.size();
  429|  1.24k|   const size_t full_words = length / sizeof(word);
  430|  1.24k|   const size_t extra_bytes = length % sizeof(word);
  431|       |
  432|  1.24k|   secure_vector<word> reg((round_up(full_words + (extra_bytes > 0 ? 1 : 0), 8)));
  ------------------
  |  Branch (432:52): [True: 913, False: 335]
  ------------------
  433|       |
  434|  2.70k|   for(size_t i = 0; i != full_words; ++i) {
  ------------------
  |  Branch (434:22): [True: 1.45k, False: 1.24k]
  ------------------
  435|  1.45k|      reg[i] = load_be<word>(bytes.last<sizeof(word)>());
  436|  1.45k|      bytes = bytes.first(bytes.size() - sizeof(word));
  437|  1.45k|   }
  438|       |
  439|  1.24k|   if(!bytes.empty()) {
  ------------------
  |  Branch (439:7): [True: 913, False: 335]
  ------------------
  440|    913|      BOTAN_ASSERT_NOMSG(extra_bytes == bytes.size());
  ------------------
  |  |   77|    913|   do {                                                                     \
  |  |   78|    913|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|    913|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 913]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|    913|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 913]
  |  |  ------------------
  ------------------
  441|    913|      std::array<uint8_t, sizeof(word)> last_partial_word = {0};
  442|    913|      copy_mem(std::span{last_partial_word}.last(extra_bytes), bytes);
  443|    913|      reg[full_words] = load_be<word>(last_partial_word);
  444|    913|   }
  445|       |
  446|  1.24k|   m_data.swap(reg);
  447|  1.24k|}
_ZN5Botan6BigInt11ct_cond_addEbRKS0_:
  449|    765|void BigInt::ct_cond_add(bool predicate, const BigInt& value) {
  450|    765|   if(this->signum() < 0 || value.signum() < 0) {
  ------------------
  |  Branch (450:7): [True: 0, False: 765]
  |  Branch (450:29): [True: 0, False: 765]
  ------------------
  451|      0|      throw Invalid_Argument("BigInt::ct_cond_add requires both values to be positive");
  452|      0|   }
  453|    765|   const size_t v_words = value.sig_words();
  454|       |
  455|       |   // The carry can propagate through every existing word of *this, so the
  456|       |   // output needs one slot above whichever input is wider.
  457|    765|   this->grow_to(std::max(this->size(), v_words) + 1);
  458|       |
  459|    765|   const auto mask = CT::Mask<word>::expand(static_cast<word>(predicate)).value();
  460|       |
  461|    765|   word carry = 0;
  462|       |
  463|    765|   word* x = this->mutable_data();
  464|    765|   const word* y = value._data();
  465|       |
  466|  3.82k|   for(size_t i = 0; i != v_words; ++i) {
  ------------------
  |  Branch (466:22): [True: 3.06k, False: 765]
  ------------------
  467|  3.06k|      x[i] = word_add(x[i], y[i] & mask, &carry);
  468|  3.06k|   }
  469|       |
  470|  9.94k|   for(size_t i = v_words; i != size(); ++i) {
  ------------------
  |  Branch (470:28): [True: 9.18k, False: 765]
  ------------------
  471|  9.18k|      x[i] = word_add(x[i], static_cast<word>(0), &carry);
  472|  9.18k|   }
  473|    765|}
_ZN5Botan6BigInt14cond_flip_signEb:
  521|  13.6k|void BigInt::cond_flip_sign(bool predicate) {
  522|       |   // This code is assuming Negative == 0, Positive == 1
  523|       |
  524|  13.6k|   const auto mask = CT::Mask<uint8_t>::expand_bool(predicate);
  525|       |
  526|  13.6k|   const uint8_t current_sign = static_cast<uint8_t>(sign());
  527|       |
  528|  13.6k|   const uint8_t new_sign = mask.select(current_sign ^ 1, current_sign);
  529|       |
  530|  13.6k|   set_sign(static_cast<Sign>(new_sign));
  531|  13.6k|}
_ZN5Botan6BigInt14ct_cond_assignEbRKS0_:
  533|    510|void BigInt::ct_cond_assign(bool predicate, const BigInt& other) {
  534|    510|   const size_t t_words = size();
  535|    510|   const size_t o_words = other.size();
  536|       |
  537|    510|   if(t_words < o_words) {
  ------------------
  |  Branch (537:7): [True: 510, False: 0]
  ------------------
  538|    510|      grow_to(o_words);
  539|    510|   }
  540|       |
  541|    510|   const size_t r_words = std::max(t_words, o_words);
  542|       |
  543|    510|   const auto mask = CT::Mask<word>::expand_bool(predicate);
  544|       |
  545|  8.67k|   for(size_t i = 0; i != r_words; ++i) {
  ------------------
  |  Branch (545:22): [True: 8.16k, False: 510]
  ------------------
  546|  8.16k|      const word o_word = other.word_at(i);
  547|  8.16k|      const word t_word = this->word_at(i);
  548|  8.16k|      this->set_word_at(i, mask.select(o_word, t_word));
  549|  8.16k|   }
  550|       |
  551|    510|   const auto same_sign = CT::Mask<word>::is_equal(sign(), other.sign()).as_choice();
  552|    510|   cond_flip_sign((mask.as_choice() && !same_sign).as_bool());
  553|    510|}
_ZNK5Botan6BigInt20_const_time_unpoisonEv:
  559|   195k|void BigInt::_const_time_unpoison() const {
  560|   195k|   CT::unpoison(m_data.const_data(), m_data.size());
  561|   195k|}

_ZN5Botan15ct_divide_pow2kEmRKNS_6BigIntE:
   89|     15|BigInt ct_divide_pow2k(size_t k, const BigInt& y) {
   90|     15|   BOTAN_ARG_CHECK(y.signum() != 0, "Cannot divide by zero");
  ------------------
  |  |   35|     15|   do {                                                          \
  |  |   36|     15|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|     15|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 15]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|     15|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 15]
  |  |  ------------------
  ------------------
   91|     15|   BOTAN_ARG_CHECK(y.signum() >= 0, "Negative divisor not supported");
  ------------------
  |  |   35|     15|   do {                                                          \
  |  |   36|     15|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|     15|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 15]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|     15|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 15]
  |  |  ------------------
  ------------------
   92|     15|   BOTAN_ARG_CHECK(k > 1, "Invalid k");
  ------------------
  |  |   35|     15|   do {                                                          \
  |  |   36|     15|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|     15|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 15]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|     15|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 15]
  |  |  ------------------
  ------------------
   93|       |
   94|     15|   const size_t x_bits = k + 1;
   95|     15|   const size_t y_bits = y.bits();
   96|       |
   97|     15|   if(x_bits < y_bits) {
  ------------------
  |  Branch (97:7): [True: 0, False: 15]
  ------------------
   98|      0|      return BigInt::zero();
   99|      0|   }
  100|       |
  101|     15|   BOTAN_ASSERT_NOMSG(y_bits >= 1);
  ------------------
  |  |   77|     15|   do {                                                                     \
  |  |   78|     15|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|     15|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 15]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|     15|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 15]
  |  |  ------------------
  ------------------
  102|     15|   const size_t x_words = (x_bits + WordInfo<word>::bits - 1) / WordInfo<word>::bits;
  103|     15|   const size_t y_words = y.sig_words();
  104|       |
  105|     15|   BigInt q = BigInt::with_capacity(x_words);
  106|     15|   BigInt r = BigInt::with_capacity(y_words + 1);
  107|     15|   BigInt t = BigInt::with_capacity(y_words + 1);  // a temporary
  108|       |
  109|     15|   r.set_bit(y_bits - 1);
  110|  3.88k|   for(size_t i = y_bits - 1; i != x_bits; ++i) {
  ------------------
  |  Branch (110:31): [True: 3.87k, False: 15]
  ------------------
  111|  3.87k|      const size_t b = x_bits - 1 - i;
  112|       |
  113|  3.87k|      if(i >= y_bits) {
  ------------------
  |  Branch (113:10): [True: 3.85k, False: 15]
  ------------------
  114|  3.85k|         bigint_shl1(r.mutable_data(), r.size(), r.size(), 1);
  115|  3.85k|      }
  116|       |
  117|  3.87k|      const bool r_gte_y = bigint_sub3(t.mutable_data(), r._data(), r.size(), y._data(), y_words) == 0;
  118|       |
  119|  3.87k|      q.conditionally_set_bit(b, r_gte_y);
  120|       |
  121|  3.87k|      bigint_cnd_swap(static_cast<word>(r_gte_y), r.mutable_data(), t.mutable_data(), y_words + 1);
  122|  3.87k|   }
  123|       |
  124|       |   // No need for sign fixup
  125|       |
  126|     15|   return q;
  127|     15|}
_ZN5Botan11ct_mod_wordERKNS_6BigIntEm:
  174|    256|word ct_mod_word(const BigInt& x, word y) {
  175|    256|   BOTAN_ARG_CHECK(x.signum() >= 0, "The argument x must be non-negative");
  ------------------
  |  |   35|    256|   do {                                                          \
  |  |   36|    256|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|    256|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 256]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|    256|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 256]
  |  |  ------------------
  ------------------
  176|    256|   BOTAN_ARG_CHECK(y != 0, "Cannot divide by zero");
  ------------------
  |  |   35|    256|   do {                                                          \
  |  |   36|    256|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|    256|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 256]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|    256|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 256]
  |  |  ------------------
  ------------------
  177|       |
  178|    256|   const size_t x_bits = x.bits();
  179|       |
  180|    256|   word r = 0;
  181|       |
  182|  65.7k|   for(size_t i = 0; i != x_bits; ++i) {
  ------------------
  |  Branch (182:22): [True: 65.5k, False: 256]
  ------------------
  183|  65.5k|      const size_t b = x_bits - 1 - i;
  184|  65.5k|      const bool x_b = x.get_bit(b);
  185|       |
  186|  65.5k|      const auto r_carry = CT::Mask<word>::expand_top_bit(r);
  187|       |
  188|  65.5k|      r <<= 1;
  189|  65.5k|      r += static_cast<word>(x_b);
  190|       |
  191|  65.5k|      const auto r_gte_y = CT::Mask<word>::is_gte(r, y) | r_carry;
  192|  65.5k|      r = r_gte_y.select(r - y, r);
  193|  65.5k|   }
  194|       |
  195|    256|   return r;
  196|    256|}
_ZN5Botan20vartime_divide_pow2kEmRKNS_6BigIntE:
  232|    675|BigInt vartime_divide_pow2k(size_t k, const BigInt& y_arg) {
  233|    675|   constexpr size_t WB = WordInfo<word>::bits;
  234|       |
  235|    675|   BOTAN_ARG_CHECK(y_arg.signum() != 0, "Cannot divide by zero");
  ------------------
  |  |   35|    675|   do {                                                          \
  |  |   36|    675|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|    675|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 675]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|    675|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 675]
  |  |  ------------------
  ------------------
  236|    675|   BOTAN_ARG_CHECK(y_arg.signum() >= 0, "Negative divisor not supported");
  ------------------
  |  |   35|    675|   do {                                                          \
  |  |   36|    675|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|    675|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 675]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|    675|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 675]
  |  |  ------------------
  ------------------
  237|    675|   BOTAN_ARG_CHECK(k > 1, "Invalid k");
  ------------------
  |  |   35|    675|   do {                                                          \
  |  |   36|    675|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|    675|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 675]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|    675|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 675]
  |  |  ------------------
  ------------------
  238|       |
  239|    675|   BigInt y = y_arg;
  240|       |
  241|    675|   const size_t y_words = y.sig_words();
  242|       |
  243|    675|   BOTAN_ASSERT_NOMSG(y_words > 0);
  ------------------
  |  |   77|    675|   do {                                                                     \
  |  |   78|    675|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|    675|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 675]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|    675|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 675]
  |  |  ------------------
  ------------------
  244|       |
  245|       |   // Calculate shifts needed to normalize y with high bit set
  246|    675|   const size_t shifts = y.top_bits_free();
  247|       |
  248|    675|   if(shifts > 0) {
  ------------------
  |  Branch (248:7): [True: 0, False: 675]
  ------------------
  249|      0|      y <<= shifts;
  250|      0|   }
  251|       |
  252|    675|   BigInt r;
  253|    675|   r.set_bit(k + shifts);  // (2^k) << shifts
  254|       |
  255|       |   // we know y has not changed size, since we only shifted up to set high bit
  256|    675|   const size_t t = y_words - 1;
  257|    675|   const size_t n = std::max(y_words, r.sig_words()) - 1;
  258|       |
  259|    675|   BOTAN_ASSERT_NOMSG(n >= t);
  ------------------
  |  |   77|    675|   do {                                                                     \
  |  |   78|    675|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|    675|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 675]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|    675|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 675]
  |  |  ------------------
  ------------------
  260|       |
  261|    675|   BigInt q = BigInt::zero();
  262|    675|   q.grow_to(n - t + 1);
  263|       |
  264|    675|   word* q_words = q.mutable_data();
  265|       |
  266|    675|   BigInt shifted_y = y << (WB * (n - t));
  267|       |
  268|       |   // Set q_{n-t} to number of times r > shifted_y
  269|    675|   secure_vector<word> ws;
  270|    675|   q_words[n - t] = r.reduce_below(shifted_y, ws);
  271|       |
  272|    675|   const word y_t0 = y.word_at(t);
  273|    675|   const word y_t1 = y.word_at(t - 1);
  274|    675|   BOTAN_DEBUG_ASSERT((y_t0 >> (WB - 1)) == 1);
  ------------------
  |  |  130|    675|      do { /* NOLINT(*-avoid-do-while) */ \
  |  |  131|    675|      } while(0)
  |  |  ------------------
  |  |  |  Branch (131:15): [Folded, False: 675]
  |  |  ------------------
  ------------------
  275|       |
  276|    675|   const divide_precomp div_y_t0(y_t0);
  277|       |
  278|  4.05k|   for(size_t i = n; i != t; --i) {
  ------------------
  |  Branch (278:22): [True: 3.37k, False: 675]
  ------------------
  279|  3.37k|      const word x_i0 = r.word_at(i);
  280|  3.37k|      const word x_i1 = r.word_at(i - 1);
  281|  3.37k|      const word x_i2 = r.word_at(i - 2);
  282|       |
  283|  3.37k|      word qit = (x_i0 == y_t0) ? WordInfo<word>::max : div_y_t0.vartime_div_2to1(x_i0, x_i1);
  ------------------
  |  Branch (283:18): [True: 0, False: 3.37k]
  ------------------
  284|       |
  285|       |      // Per HAC 14.23, this operation is required at most twice
  286|  4.05k|      for(size_t j = 0; j != 2; ++j) {
  ------------------
  |  Branch (286:25): [True: 4.05k, False: 0]
  ------------------
  287|  4.05k|         if(division_check_vartime(qit, y_t0, y_t1, x_i0, x_i1, x_i2)) {
  ------------------
  |  Branch (287:13): [True: 675, False: 3.37k]
  ------------------
  288|    675|            BOTAN_ASSERT_NOMSG(qit > 0);
  ------------------
  |  |   77|    675|   do {                                                                     \
  |  |   78|    675|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|    675|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 675]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|    675|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 675]
  |  |  ------------------
  ------------------
  289|    675|            qit--;
  290|  3.37k|         } else {
  291|  3.37k|            break;
  292|  3.37k|         }
  293|  4.05k|      }
  294|       |
  295|  3.37k|      shifted_y >>= WB;
  296|       |      // Now shifted_y == y << (WB * (i-t-1))
  297|       |
  298|       |      /*
  299|       |      * Special case qit == 0 and qit == 1 which occurs relatively often here due to a
  300|       |      * combination of the fixed 2^k and in many cases the typical structure of
  301|       |      * public moduli (as this function is called by Barrett_Reduction::for_public_modulus).
  302|       |      *
  303|       |      * Over the test suite, about 5% of loop iterations have qit == 1 and 10% have qit == 0
  304|       |      */
  305|       |
  306|  3.37k|      if(qit != 0) {
  ------------------
  |  Branch (306:10): [True: 3.37k, False: 0]
  ------------------
  307|  3.37k|         if(qit == 1) {
  ------------------
  |  Branch (307:13): [True: 675, False: 2.70k]
  ------------------
  308|    675|            r -= shifted_y;
  309|  2.70k|         } else {
  310|  2.70k|            r -= qit * shifted_y;
  311|  2.70k|         }
  312|       |
  313|  3.37k|         if(r.signum() < 0) {
  ------------------
  |  Branch (313:13): [True: 0, False: 3.37k]
  ------------------
  314|      0|            BOTAN_ASSERT_NOMSG(qit > 0);
  ------------------
  |  |   77|      0|   do {                                                                     \
  |  |   78|      0|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|      0|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 0]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|      0|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 0]
  |  |  ------------------
  ------------------
  315|      0|            qit--;
  316|      0|            r += shifted_y;
  317|      0|            BOTAN_ASSERT_NOMSG(r.signum() >= 0);
  ------------------
  |  |   77|      0|   do {                                                                     \
  |  |   78|      0|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|      0|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 0]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|      0|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 0]
  |  |  ------------------
  ------------------
  318|      0|         }
  319|  3.37k|      }
  320|       |
  321|  3.37k|      q_words[i - t - 1] = qit;
  322|  3.37k|   }
  323|       |
  324|    675|   return q;
  325|    675|}
_ZN5Botan14vartime_divideERKNS_6BigIntES2_RS0_S3_:
  332|  13.1k|void vartime_divide(const BigInt& x, const BigInt& y_arg, BigInt& q_out, BigInt& r_out) {
  333|  13.1k|   constexpr size_t WB = WordInfo<word>::bits;
  334|       |
  335|  13.1k|   if(y_arg.is_zero()) {
  ------------------
  |  Branch (335:7): [True: 0, False: 13.1k]
  ------------------
  336|      0|      throw Invalid_Argument("vartime_divide: cannot divide by zero");
  337|      0|   }
  338|       |
  339|  13.1k|   const size_t y_words = y_arg.sig_words();
  340|       |
  341|  13.1k|   BOTAN_ASSERT_NOMSG(y_words > 0);
  ------------------
  |  |   77|  13.1k|   do {                                                                     \
  |  |   78|  13.1k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|  13.1k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 13.1k]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|  13.1k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 13.1k]
  |  |  ------------------
  ------------------
  342|       |
  343|  13.1k|   BigInt y = y_arg;
  344|       |
  345|  13.1k|   BigInt r = x;
  346|  13.1k|   BigInt q = BigInt::zero();
  347|  13.1k|   secure_vector<word> ws;
  348|       |
  349|  13.1k|   r.set_sign(BigInt::Positive);
  350|  13.1k|   y.set_sign(BigInt::Positive);
  351|       |
  352|       |   // Calculate shifts needed to normalize y with high bit set
  353|  13.1k|   const size_t shifts = y.top_bits_free();
  354|       |
  355|  13.1k|   if(shifts > 0) {
  ------------------
  |  Branch (355:7): [True: 13.0k, False: 115]
  ------------------
  356|  13.0k|      y <<= shifts;
  357|  13.0k|      r <<= shifts;
  358|  13.0k|   }
  359|       |
  360|       |   // we know y has not changed size, since we only shifted up to set high bit
  361|  13.1k|   const size_t t = y_words - 1;
  362|  13.1k|   const size_t n = std::max(y_words, r.sig_words()) - 1;  // r may have changed size however
  363|       |
  364|  13.1k|   BOTAN_ASSERT_NOMSG(n >= t);
  ------------------
  |  |   77|  13.1k|   do {                                                                     \
  |  |   78|  13.1k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|  13.1k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 13.1k]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|  13.1k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 13.1k]
  |  |  ------------------
  ------------------
  365|       |
  366|  13.1k|   q.grow_to(n - t + 1);
  367|       |
  368|  13.1k|   word* q_words = q.mutable_data();
  369|       |
  370|  13.1k|   BigInt shifted_y = y << (WB * (n - t));
  371|       |
  372|       |   // Set q_{n-t} to number of times r > shifted_y
  373|  13.1k|   q_words[n - t] = r.reduce_below(shifted_y, ws);
  374|       |
  375|  13.1k|   const word y_t0 = y.word_at(t);
  376|  13.1k|   const word y_t1 = y.word_at(t - 1);
  377|  13.1k|   BOTAN_DEBUG_ASSERT((y_t0 >> (WB - 1)) == 1);
  ------------------
  |  |  130|  13.1k|      do { /* NOLINT(*-avoid-do-while) */ \
  |  |  131|  13.1k|      } while(0)
  |  |  ------------------
  |  |  |  Branch (131:15): [Folded, False: 13.1k]
  |  |  ------------------
  ------------------
  378|       |
  379|  13.1k|   const divide_precomp div_y_t0(y_t0);
  380|       |
  381|  26.0k|   for(size_t i = n; i != t; --i) {
  ------------------
  |  Branch (381:22): [True: 12.9k, False: 13.1k]
  ------------------
  382|  12.9k|      const word x_i0 = r.word_at(i);
  383|  12.9k|      const word x_i1 = r.word_at(i - 1);
  384|  12.9k|      const word x_i2 = r.word_at(i - 2);
  385|       |
  386|  12.9k|      word qit = (x_i0 == y_t0) ? WordInfo<word>::max : div_y_t0.vartime_div_2to1(x_i0, x_i1);
  ------------------
  |  Branch (386:18): [True: 83, False: 12.8k]
  ------------------
  387|       |
  388|       |      // Per HAC 14.23, this operation is required at most twice
  389|  13.5k|      for(size_t j = 0; j != 2; ++j) {
  ------------------
  |  Branch (389:25): [True: 13.5k, False: 20]
  ------------------
  390|  13.5k|         if(division_check_vartime(qit, y_t0, y_t1, x_i0, x_i1, x_i2)) {
  ------------------
  |  Branch (390:13): [True: 668, False: 12.9k]
  ------------------
  391|    668|            BOTAN_ASSERT_NOMSG(qit > 0);
  ------------------
  |  |   77|    668|   do {                                                                     \
  |  |   78|    668|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|    668|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 668]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|    668|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 668]
  |  |  ------------------
  ------------------
  392|    668|            qit--;
  393|  12.9k|         } else {
  394|  12.9k|            break;
  395|  12.9k|         }
  396|  13.5k|      }
  397|       |
  398|  12.9k|      shifted_y >>= WB;
  399|       |      // Now shifted_y == y << (WB * (i-t-1))
  400|       |
  401|  12.9k|      if(qit != 0) {
  ------------------
  |  Branch (401:10): [True: 12.9k, False: 17]
  ------------------
  402|  12.9k|         r -= qit * shifted_y;
  403|  12.9k|         if(r.signum() < 0) {
  ------------------
  |  Branch (403:13): [True: 6, False: 12.9k]
  ------------------
  404|      6|            BOTAN_ASSERT_NOMSG(qit > 0);
  ------------------
  |  |   77|      6|   do {                                                                     \
  |  |   78|      6|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|      6|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 6]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|      6|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 6]
  |  |  ------------------
  ------------------
  405|      6|            qit--;
  406|      6|            r += shifted_y;
  407|      6|            BOTAN_ASSERT_NOMSG(r.signum() >= 0);
  ------------------
  |  |   77|      6|   do {                                                                     \
  |  |   78|      6|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|      6|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 6]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|      6|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 6]
  |  |  ------------------
  ------------------
  408|      6|         }
  409|  12.9k|      }
  410|       |
  411|  12.9k|      q_words[i - t - 1] = qit;
  412|  12.9k|   }
  413|       |
  414|  13.1k|   if(shifts > 0) {
  ------------------
  |  Branch (414:7): [True: 13.0k, False: 115]
  ------------------
  415|  13.0k|      r >>= shifts;
  416|  13.0k|   }
  417|       |
  418|  13.1k|   sign_fixup(x, y_arg, q, r);
  419|       |
  420|  13.1k|   r_out = r;
  421|  13.1k|   q_out = q;
  422|  13.1k|}
divide.cpp:_ZN5Botan12_GLOBAL__N_110sign_fixupERKNS_6BigIntES3_RS1_S4_:
   21|  13.1k|void sign_fixup(const BigInt& x, const BigInt& y, BigInt& q, BigInt& r) {
   22|  13.1k|   q.cond_flip_sign(x.sign() != y.sign());
   23|       |
   24|  13.1k|   if(x.signum() < 0 && r.signum() != 0) {
  ------------------
  |  Branch (24:7): [True: 2, False: 13.1k]
  |  Branch (24:25): [True: 2, False: 0]
  ------------------
   25|      2|      if(y.signum() > 0) {
  ------------------
  |  Branch (25:10): [True: 2, False: 0]
  ------------------
   26|      2|         q -= 1;
   27|      2|      } else {
   28|      0|         q += 1;
   29|      0|      }
   30|      2|      r = y.abs() - r;
   31|      2|   }
   32|  13.1k|}
divide.cpp:_ZN5Botan12_GLOBAL__N_122division_check_vartimeEmmmmmm:
   34|  17.6k|inline bool division_check_vartime(word q, word y2, word y1, word x3, word x2, word x1) {
   35|       |   /*
   36|       |   Compute (y3,y2,y1) = (y2,y1) * q
   37|       |   and return true if (y3,y2,y1) > (x3,x2,x1)
   38|       |   */
   39|       |
   40|  17.6k|   word y3 = 0;
   41|  17.6k|   y1 = word_madd2(q, y1, &y3);
   42|  17.6k|   y2 = word_madd2(q, y2, &y3);
   43|       |
   44|  17.6k|   if(x3 != y3) {
  ------------------
  |  Branch (44:7): [True: 7.93k, False: 9.68k]
  ------------------
   45|  7.93k|      return (y3 > x3);
   46|  7.93k|   }
   47|  9.68k|   if(x2 != y2) {
  ------------------
  |  Branch (47:7): [True: 9.57k, False: 116]
  ------------------
   48|  9.57k|      return (y2 > x2);
   49|  9.57k|   }
   50|    116|   return (y1 > x1);
   51|  9.68k|}

_ZN5Botan17bigint_comba_sqr4EPmPKm:
   17|   351k|void bigint_comba_sqr4(word z[8], const word x[4]) {
   18|   351k|   word3<word> accum;
   19|       |
   20|   351k|   accum.mul(x[0], x[0]);
   21|   351k|   z[0] = accum.extract();
   22|   351k|   accum.mul_x2(x[0], x[1]);
   23|   351k|   z[1] = accum.extract();
   24|   351k|   accum.mul_x2(x[0], x[2]);
   25|   351k|   accum.mul(x[1], x[1]);
   26|   351k|   z[2] = accum.extract();
   27|   351k|   accum.mul_x2(x[0], x[3]);
   28|   351k|   accum.mul_x2(x[1], x[2]);
   29|   351k|   z[3] = accum.extract();
   30|   351k|   accum.mul_x2(x[1], x[3]);
   31|   351k|   accum.mul(x[2], x[2]);
   32|   351k|   z[4] = accum.extract();
   33|   351k|   accum.mul_x2(x[2], x[3]);
   34|   351k|   z[5] = accum.extract();
   35|   351k|   accum.mul(x[3], x[3]);
   36|   351k|   z[6] = accum.extract();
   37|   351k|   z[7] = accum.extract();
   38|   351k|}
_ZN5Botan17bigint_comba_mul4EPmPKmS2_:
   43|   101k|void bigint_comba_mul4(word z[8], const word x[4], const word y[4]) {
   44|   101k|   word3<word> accum;
   45|       |
   46|   101k|   accum.mul(x[0], y[0]);
   47|   101k|   z[0] = accum.extract();
   48|   101k|   accum.mul(x[0], y[1]);
   49|   101k|   accum.mul(x[1], y[0]);
   50|   101k|   z[1] = accum.extract();
   51|   101k|   accum.mul(x[0], y[2]);
   52|   101k|   accum.mul(x[1], y[1]);
   53|   101k|   accum.mul(x[2], y[0]);
   54|   101k|   z[2] = accum.extract();
   55|   101k|   accum.mul(x[0], y[3]);
   56|   101k|   accum.mul(x[1], y[2]);
   57|   101k|   accum.mul(x[2], y[1]);
   58|   101k|   accum.mul(x[3], y[0]);
   59|   101k|   z[3] = accum.extract();
   60|   101k|   accum.mul(x[1], y[3]);
   61|   101k|   accum.mul(x[2], y[2]);
   62|   101k|   accum.mul(x[3], y[1]);
   63|   101k|   z[4] = accum.extract();
   64|   101k|   accum.mul(x[2], y[3]);
   65|   101k|   accum.mul(x[3], y[2]);
   66|   101k|   z[5] = accum.extract();
   67|   101k|   accum.mul(x[3], y[3]);
   68|   101k|   z[6] = accum.extract();
   69|   101k|   z[7] = accum.extract();
   70|   101k|}
_ZN5Botan17bigint_comba_mul6EPmPKmS2_:
  116|  26.1k|void bigint_comba_mul6(word z[12], const word x[6], const word y[6]) {
  117|  26.1k|   word3<word> accum;
  118|       |
  119|  26.1k|   accum.mul(x[0], y[0]);
  120|  26.1k|   z[0] = accum.extract();
  121|  26.1k|   accum.mul(x[0], y[1]);
  122|  26.1k|   accum.mul(x[1], y[0]);
  123|  26.1k|   z[1] = accum.extract();
  124|  26.1k|   accum.mul(x[0], y[2]);
  125|  26.1k|   accum.mul(x[1], y[1]);
  126|  26.1k|   accum.mul(x[2], y[0]);
  127|  26.1k|   z[2] = accum.extract();
  128|  26.1k|   accum.mul(x[0], y[3]);
  129|  26.1k|   accum.mul(x[1], y[2]);
  130|  26.1k|   accum.mul(x[2], y[1]);
  131|  26.1k|   accum.mul(x[3], y[0]);
  132|  26.1k|   z[3] = accum.extract();
  133|  26.1k|   accum.mul(x[0], y[4]);
  134|  26.1k|   accum.mul(x[1], y[3]);
  135|  26.1k|   accum.mul(x[2], y[2]);
  136|  26.1k|   accum.mul(x[3], y[1]);
  137|  26.1k|   accum.mul(x[4], y[0]);
  138|  26.1k|   z[4] = accum.extract();
  139|  26.1k|   accum.mul(x[0], y[5]);
  140|  26.1k|   accum.mul(x[1], y[4]);
  141|  26.1k|   accum.mul(x[2], y[3]);
  142|  26.1k|   accum.mul(x[3], y[2]);
  143|  26.1k|   accum.mul(x[4], y[1]);
  144|  26.1k|   accum.mul(x[5], y[0]);
  145|  26.1k|   z[5] = accum.extract();
  146|  26.1k|   accum.mul(x[1], y[5]);
  147|  26.1k|   accum.mul(x[2], y[4]);
  148|  26.1k|   accum.mul(x[3], y[3]);
  149|  26.1k|   accum.mul(x[4], y[2]);
  150|  26.1k|   accum.mul(x[5], y[1]);
  151|  26.1k|   z[6] = accum.extract();
  152|  26.1k|   accum.mul(x[2], y[5]);
  153|  26.1k|   accum.mul(x[3], y[4]);
  154|  26.1k|   accum.mul(x[4], y[3]);
  155|  26.1k|   accum.mul(x[5], y[2]);
  156|  26.1k|   z[7] = accum.extract();
  157|  26.1k|   accum.mul(x[3], y[5]);
  158|  26.1k|   accum.mul(x[4], y[4]);
  159|  26.1k|   accum.mul(x[5], y[3]);
  160|  26.1k|   z[8] = accum.extract();
  161|  26.1k|   accum.mul(x[4], y[5]);
  162|  26.1k|   accum.mul(x[5], y[4]);
  163|  26.1k|   z[9] = accum.extract();
  164|  26.1k|   accum.mul(x[5], y[5]);
  165|  26.1k|   z[10] = accum.extract();
  166|  26.1k|   z[11] = accum.extract();
  167|  26.1k|}

_ZN5Botan10bigint_mulEPmmPKmmmS2_mmS0_m:
  292|   127k|                size_t ws_size) {
  293|   127k|   zeroize_buffer(z, z_size);
  294|       |
  295|   127k|   if(x_sw == 1) {
  ------------------
  |  Branch (295:7): [True: 0, False: 127k]
  ------------------
  296|      0|      bigint_linmul3(z, y, y_sw, x[0]);
  297|   127k|   } else if(y_sw == 1) {
  ------------------
  |  Branch (297:14): [True: 0, False: 127k]
  ------------------
  298|      0|      bigint_linmul3(z, x, x_sw, y[0]);
  299|   127k|   } else if(sized_for_comba_mul<4>(x_sw, x_size, y_sw, y_size, z_size)) {
  ------------------
  |  Branch (299:14): [True: 101k, False: 26.1k]
  ------------------
  300|   101k|      bigint_comba_mul4(z, x, y);
  301|   101k|   } else if(sized_for_comba_mul<6>(x_sw, x_size, y_sw, y_size, z_size)) {
  ------------------
  |  Branch (301:14): [True: 26.1k, False: 0]
  ------------------
  302|  26.1k|      bigint_comba_mul6(z, x, y);
  303|  26.1k|   } else if(sized_for_comba_mul<8>(x_sw, x_size, y_sw, y_size, z_size)) {
  ------------------
  |  Branch (303:14): [True: 0, False: 0]
  ------------------
  304|      0|      bigint_comba_mul8(z, x, y);
  305|      0|   } else if(sized_for_comba_mul<9>(x_sw, x_size, y_sw, y_size, z_size)) {
  ------------------
  |  Branch (305:14): [True: 0, False: 0]
  ------------------
  306|      0|      bigint_comba_mul9(z, x, y);
  307|      0|   } else if(sized_for_comba_mul<16>(x_sw, x_size, y_sw, y_size, z_size)) {
  ------------------
  |  Branch (307:14): [True: 0, False: 0]
  ------------------
  308|      0|      bigint_comba_mul16(z, x, y);
  309|      0|   } else if(sized_for_comba_mul<24>(x_sw, x_size, y_sw, y_size, z_size)) {
  ------------------
  |  Branch (309:14): [True: 0, False: 0]
  ------------------
  310|      0|      bigint_comba_mul24(z, x, y);
  311|      0|   } else if(x_sw < KARATSUBA_MULTIPLY_THRESHOLD || y_sw < KARATSUBA_MULTIPLY_THRESHOLD || workspace == nullptr) {
  ------------------
  |  Branch (311:14): [True: 0, False: 0]
  |  Branch (311:53): [True: 0, False: 0]
  |  Branch (311:92): [True: 0, False: 0]
  ------------------
  312|      0|      basecase_mul(z, z_size, x, x_sw, y, y_sw);
  313|      0|   } else {
  314|      0|      const size_t N = karatsuba_size(z_size, x_size, x_sw, y_size, y_sw);
  315|       |
  316|      0|      if(N > 0 && z_size >= 2 * N && ws_size >= 2 * N) {
  ------------------
  |  Branch (316:10): [True: 0, False: 0]
  |  Branch (316:19): [True: 0, False: 0]
  |  Branch (316:38): [True: 0, False: 0]
  ------------------
  317|      0|         karatsuba_mul(z, x, y, N, workspace);
  318|      0|      } else {
  319|      0|         basecase_mul(z, z_size, x, x_sw, y, y_sw);
  320|      0|      }
  321|      0|   }
  322|   127k|}
_ZN5Botan10bigint_sqrEPmmPKmmmS0_m:
  327|   351k|void bigint_sqr(word z[], size_t z_size, const word x[], size_t x_size, size_t x_sw, word workspace[], size_t ws_size) {
  328|   351k|   zeroize_buffer(z, z_size);
  329|       |
  330|   351k|   BOTAN_ASSERT(z_size / 2 >= x_sw, "Output size is sufficient");
  ------------------
  |  |   64|   351k|   do {                                                                                 \
  |  |   65|   351k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                                     \
  |  |   66|   351k|      if(!(expr)) {                                                                     \
  |  |  ------------------
  |  |  |  Branch (66:10): [True: 0, False: 351k]
  |  |  ------------------
  |  |   67|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                            \
  |  |   68|      0|         Botan::assertion_failure(#expr, assertion_made, __func__, __FILE__, __LINE__); \
  |  |   69|      0|      }                                                                                 \
  |  |   70|   351k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (70:12): [Folded, False: 351k]
  |  |  ------------------
  ------------------
  331|       |
  332|   351k|   if(x_sw == 1) {
  ------------------
  |  Branch (332:7): [True: 0, False: 351k]
  ------------------
  333|      0|      bigint_linmul3(z, x, x_sw, x[0]);
  334|   351k|   } else if(sized_for_comba_sqr<4>(x_sw, x_size, z_size)) {
  ------------------
  |  Branch (334:14): [True: 351k, False: 0]
  ------------------
  335|   351k|      bigint_comba_sqr4(z, x);
  336|   351k|   } else if(sized_for_comba_sqr<6>(x_sw, x_size, z_size)) {
  ------------------
  |  Branch (336:14): [True: 0, False: 0]
  ------------------
  337|      0|      bigint_comba_sqr6(z, x);
  338|      0|   } else if(sized_for_comba_sqr<8>(x_sw, x_size, z_size)) {
  ------------------
  |  Branch (338:14): [True: 0, False: 0]
  ------------------
  339|      0|      bigint_comba_sqr8(z, x);
  340|      0|   } else if(sized_for_comba_sqr<9>(x_sw, x_size, z_size)) {
  ------------------
  |  Branch (340:14): [True: 0, False: 0]
  ------------------
  341|      0|      bigint_comba_sqr9(z, x);
  342|      0|   } else if(sized_for_comba_sqr<16>(x_sw, x_size, z_size)) {
  ------------------
  |  Branch (342:14): [True: 0, False: 0]
  ------------------
  343|      0|      bigint_comba_sqr16(z, x);
  344|      0|   } else if(sized_for_comba_sqr<24>(x_sw, x_size, z_size)) {
  ------------------
  |  Branch (344:14): [True: 0, False: 0]
  ------------------
  345|      0|      bigint_comba_sqr24(z, x);
  346|      0|   } else if(x_size < KARATSUBA_SQUARE_THRESHOLD || workspace == nullptr) {
  ------------------
  |  Branch (346:14): [True: 0, False: 0]
  |  Branch (346:53): [True: 0, False: 0]
  ------------------
  347|      0|      basecase_sqr(z, z_size, x, x_sw);
  348|      0|   } else {
  349|      0|      const size_t N = karatsuba_size(z_size, x_size, x_sw);
  350|       |
  351|      0|      if(N > 0 && z_size >= 2 * N && ws_size >= 2 * N) {
  ------------------
  |  Branch (351:10): [True: 0, False: 0]
  |  Branch (351:19): [True: 0, False: 0]
  |  Branch (351:38): [True: 0, False: 0]
  ------------------
  352|      0|         karatsuba_sqr(z, x, N, workspace);
  353|      0|      } else {
  354|      0|         basecase_sqr(z, z_size, x, x_sw);
  355|      0|      }
  356|      0|   }
  357|   351k|}
mp_karat.cpp:_ZN5Botan12_GLOBAL__N_119sized_for_comba_mulILm4EEEbmmmmm:
  272|   127k|inline bool sized_for_comba_mul(size_t x_sw, size_t x_size, size_t y_sw, size_t y_size, size_t z_size) {
  273|   127k|   return (x_sw <= SZ && x_size >= SZ && y_sw <= SZ && y_size >= SZ && z_size >= 2 * SZ);
  ------------------
  |  Branch (273:12): [True: 101k, False: 26.1k]
  |  Branch (273:26): [True: 101k, False: 0]
  |  Branch (273:42): [True: 101k, False: 0]
  |  Branch (273:56): [True: 101k, False: 0]
  |  Branch (273:72): [True: 101k, False: 0]
  ------------------
  274|   127k|}
mp_karat.cpp:_ZN5Botan12_GLOBAL__N_119sized_for_comba_mulILm6EEEbmmmmm:
  272|  26.1k|inline bool sized_for_comba_mul(size_t x_sw, size_t x_size, size_t y_sw, size_t y_size, size_t z_size) {
  273|  26.1k|   return (x_sw <= SZ && x_size >= SZ && y_sw <= SZ && y_size >= SZ && z_size >= 2 * SZ);
  ------------------
  |  Branch (273:12): [True: 26.1k, False: 0]
  |  Branch (273:26): [True: 26.1k, False: 0]
  |  Branch (273:42): [True: 26.1k, False: 0]
  |  Branch (273:56): [True: 26.1k, False: 0]
  |  Branch (273:72): [True: 26.1k, False: 0]
  ------------------
  274|  26.1k|}
mp_karat.cpp:_ZN5Botan12_GLOBAL__N_119sized_for_comba_sqrILm4EEEbmmm:
  277|   351k|inline bool sized_for_comba_sqr(size_t x_sw, size_t x_size, size_t z_size) {
  278|   351k|   return (x_sw <= SZ && x_size >= SZ && z_size >= 2 * SZ);
  ------------------
  |  Branch (278:12): [True: 351k, False: 0]
  |  Branch (278:26): [True: 351k, False: 0]
  |  Branch (278:42): [True: 351k, False: 0]
  ------------------
  279|   351k|}

_ZN5Botan19bigint_monty_redc_4EPmPKmS2_mS0_:
   12|   443k|void bigint_monty_redc_4(word r[4], const word z[8], const word p[4], word p_dash, word ws[4]) {
   13|   443k|   word3<word> accum;
   14|   443k|   accum.add(z[0]);
   15|   443k|   ws[0] = accum.monty_step(p[0], p_dash);
   16|   443k|   accum.mul(ws[0], p[1]);
   17|   443k|   accum.add(z[1]);
   18|   443k|   ws[1] = accum.monty_step(p[0], p_dash);
   19|   443k|   accum.mul(ws[0], p[2]);
   20|   443k|   accum.mul(ws[1], p[1]);
   21|   443k|   accum.add(z[2]);
   22|   443k|   ws[2] = accum.monty_step(p[0], p_dash);
   23|   443k|   accum.mul(ws[0], p[3]);
   24|   443k|   accum.mul(ws[1], p[2]);
   25|   443k|   accum.mul(ws[2], p[1]);
   26|   443k|   accum.add(z[3]);
   27|   443k|   ws[3] = accum.monty_step(p[0], p_dash);
   28|   443k|   accum.mul(ws[1], p[3]);
   29|   443k|   accum.mul(ws[2], p[2]);
   30|   443k|   accum.mul(ws[3], p[1]);
   31|   443k|   accum.add(z[4]);
   32|   443k|   ws[0] = accum.extract();
   33|   443k|   accum.mul(ws[2], p[3]);
   34|   443k|   accum.mul(ws[3], p[2]);
   35|   443k|   accum.add(z[5]);
   36|   443k|   ws[1] = accum.extract();
   37|   443k|   accum.mul(ws[3], p[3]);
   38|   443k|   accum.add(z[6]);
   39|   443k|   ws[2] = accum.extract();
   40|   443k|   accum.add(z[7]);
   41|   443k|   ws[3] = accum.extract();
   42|   443k|   const word w1 = accum.extract();
   43|   443k|   bigint_monty_maybe_sub<4>(r, w1, ws, p);
   44|   443k|}

_ZN5Botan17Barrett_ReductionC2ERKNS_6BigIntES1_m:
   17|    690|      m_modulus(m), m_mu(std::move(mu)), m_mod_words(mw), m_modulus_bits(m.bits()) {
   18|       |   // Give some extra space for Karatsuba
   19|    690|   m_modulus.grow_to(m_mod_words + 8);
   20|    690|   m_mu.grow_to(m_mod_words + 8);
   21|    690|}
_ZN5Botan17Barrett_Reduction18for_secret_modulusERKNS_6BigIntE:
   23|     15|Barrett_Reduction Barrett_Reduction::for_secret_modulus(const BigInt& mod) {
   24|     15|   BOTAN_ARG_CHECK(mod.signum() > 0, "Modulus must be positive");
  ------------------
  |  |   35|     15|   do {                                                          \
  |  |   36|     15|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|     15|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 15]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|     15|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 15]
  |  |  ------------------
  ------------------
   25|       |
   26|     15|   const size_t mod_words = mod.sig_words();
   27|       |
   28|       |   // Compute mu = floor(2^{2k} / m)
   29|     15|   const size_t mu_bits = 2 * WordInfo<word>::bits * mod_words;
   30|     15|   return Barrett_Reduction(mod, ct_divide_pow2k(mu_bits, mod), mod_words);
   31|     15|}
_ZN5Botan17Barrett_Reduction18for_public_modulusERKNS_6BigIntE:
   33|    675|Barrett_Reduction Barrett_Reduction::for_public_modulus(const BigInt& mod) {
   34|    675|   BOTAN_ARG_CHECK(mod.signum() > 0, "Modulus must be positive");
  ------------------
  |  |   35|    675|   do {                                                          \
  |  |   36|    675|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|    675|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 675]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|    675|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 675]
  |  |  ------------------
  ------------------
   35|       |
   36|    675|   const size_t mod_words = mod.sig_words();
   37|       |
   38|       |   // Compute mu = floor(2^{2k} / m)
   39|    675|   const size_t mu_bits = 2 * WordInfo<word>::bits * mod_words;
   40|    675|   return Barrett_Reduction(mod, vartime_divide_pow2k(mu_bits, mod), mod_words);
   41|    675|}
_ZNK5Botan17Barrett_Reduction8multiplyERKNS_6BigIntES3_:
  159|  4.91k|BigInt Barrett_Reduction::multiply(const BigInt& x, const BigInt& y) const {
  160|  4.91k|   BOTAN_ARG_CHECK(acceptable_barrett_input(x, m_modulus).as_bool(), "Invalid x param for Barrett multiply");
  ------------------
  |  |   35|  4.91k|   do {                                                          \
  |  |   36|  4.91k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  4.91k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 4.91k]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|  4.91k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 4.91k]
  |  |  ------------------
  ------------------
  161|  4.91k|   BOTAN_ARG_CHECK(acceptable_barrett_input(y, m_modulus).as_bool(), "Invalid y param for Barrett multiply");
  ------------------
  |  |   35|  4.91k|   do {                                                          \
  |  |   36|  4.91k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  4.91k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 4.91k]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|  4.91k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 4.91k]
  |  |  ------------------
  ------------------
  162|       |
  163|  4.91k|   secure_vector<word> ws(2 * (m_mod_words + 2));
  164|  4.91k|   secure_vector<word> xy(2 * m_mod_words);
  165|       |
  166|  4.91k|   bigint_mul(xy.data(),
  167|  4.91k|              xy.size(),
  168|  4.91k|              x._data(),
  169|  4.91k|              x.size(),
  170|  4.91k|              std::min(x.size(), m_mod_words),
  171|  4.91k|              y._data(),
  172|  4.91k|              y.size(),
  173|  4.91k|              std::min(y.size(), m_mod_words),
  174|  4.91k|              ws.data(),
  175|  4.91k|              ws.size());
  176|       |
  177|  4.91k|   return barrett_reduce(m_mod_words, m_modulus, m_mu, xy, ws);
  178|  4.91k|}
_ZNK5Botan17Barrett_Reduction6squareERKNS_6BigIntE:
  180|  5.79k|BigInt Barrett_Reduction::square(const BigInt& x) const {
  181|  5.79k|   BOTAN_ARG_CHECK(acceptable_barrett_input(x, m_modulus).as_bool(), "Invalid x param for Barrett square");
  ------------------
  |  |   35|  5.79k|   do {                                                          \
  |  |   36|  5.79k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  5.79k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 5.79k]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|  5.79k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 5.79k]
  |  |  ------------------
  ------------------
  182|       |
  183|  5.79k|   secure_vector<word> ws(2 * (m_mod_words + 2));
  184|  5.79k|   secure_vector<word> x2(2 * m_mod_words);
  185|       |
  186|  5.79k|   bigint_sqr(x2.data(), x2.size(), x._data(), x.size(), std::min(x.size(), m_mod_words), ws.data(), ws.size());
  187|       |
  188|  5.79k|   return barrett_reduce(m_mod_words, m_modulus, m_mu, x2, ws);
  189|  5.79k|}
_ZNK5Botan17Barrett_Reduction6reduceERKNS_6BigIntE:
  191|  2.38k|BigInt Barrett_Reduction::reduce(const BigInt& x) const {
  192|  2.38k|   BOTAN_ARG_CHECK(x.signum() >= 0, "Argument must be non-negative");
  ------------------
  |  |   35|  2.38k|   do {                                                          \
  |  |   36|  2.38k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  2.38k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 2.38k]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|  2.38k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 2.38k]
  |  |  ------------------
  ------------------
  193|       |
  194|  2.38k|   const size_t x_sw = x.sig_words();
  195|  2.38k|   BOTAN_ARG_CHECK(x_sw <= 2 * m_mod_words, "Argument is too large for Barrett reduction");
  ------------------
  |  |   35|  2.38k|   do {                                                          \
  |  |   36|  2.38k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  2.38k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 2.38k]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|  2.38k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 2.38k]
  |  |  ------------------
  ------------------
  196|       |
  197|  2.38k|   x.grow_to(2 * m_mod_words);
  198|       |
  199|  2.38k|   secure_vector<word> ws;
  200|  2.38k|   return barrett_reduce(m_mod_words, m_modulus, m_mu, x._as_span(), ws);
  201|  2.38k|}
barrett.cpp:_ZN5Botan12_GLOBAL__N_124acceptable_barrett_inputERKNS_6BigIntES3_:
  151|  15.6k|CT::Choice acceptable_barrett_input(const BigInt& x, const BigInt& modulus) {
  152|  15.6k|   auto x_is_positive = CT::Choice::from_int(static_cast<uint32_t>(x.signum() >= 0));
  153|  15.6k|   auto x_lt_mod = bigint_ct_is_lt(x._data(), x.size(), modulus._data(), modulus.sig_words()).as_choice();
  154|  15.6k|   return x_is_positive && x_lt_mod;
  155|  15.6k|}
barrett.cpp:_ZN5Botan12_GLOBAL__N_114barrett_reduceEmRKNS_6BigIntES3_NSt3__14spanIKmLm18446744073709551615EEERNS4_6vectorImNS_16secure_allocatorImEEEE:
   54|  13.0k|   size_t mod_words, const BigInt& modulus, const BigInt& mu, std::span<const word> x_words, secure_vector<word>& ws) {
   55|  13.0k|   BOTAN_ASSERT_NOMSG(modulus.sig_words() == mod_words);
  ------------------
  |  |   77|  13.0k|   do {                                                                     \
  |  |   78|  13.0k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|  13.0k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 13.0k]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|  13.0k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 13.0k]
  |  |  ------------------
  ------------------
   56|       |
   57|       |   // Caller must expand input to be at least this size
   58|  13.0k|   BOTAN_ASSERT_NOMSG(x_words.size() >= 2 * mod_words);
  ------------------
  |  |   77|  13.0k|   do {                                                                     \
  |  |   78|  13.0k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|  13.0k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 13.0k]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|  13.0k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 13.0k]
  |  |  ------------------
  ------------------
   59|       |
   60|       |   // Normally mod_words + 1 but can be + 2 if the modulus is a power of 2
   61|  13.0k|   const size_t mu_words = mu.sig_words();
   62|  13.0k|   BOTAN_ASSERT_NOMSG(mu_words <= mod_words + 2);
  ------------------
  |  |   77|  13.0k|   do {                                                                     \
  |  |   78|  13.0k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|  13.0k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 13.0k]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|  13.0k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 13.0k]
  |  |  ------------------
  ------------------
   63|       |
   64|  13.0k|   if(ws.size() < 2 * (mod_words + 2)) {
  ------------------
  |  Branch (64:7): [True: 2.38k, False: 10.7k]
  ------------------
   65|  2.38k|      ws.resize(2 * (mod_words + 2));
   66|  2.38k|   }
   67|       |
   68|  13.0k|   CT::poison(x_words);
   69|       |
   70|       |   /*
   71|       |   * Following the notation of Handbook of Applied Cryptography
   72|       |   * Algorithm 14.42 "Barrett modular reduction", page 604
   73|       |   * <https://cacr.uwaterloo.ca/hac/about/chap14.pdf>
   74|       |   *
   75|       |   * Using `mu` for μ in the code
   76|       |   */
   77|       |
   78|       |   // Compute q1 = floor(x / 2^(k - 1)) which is equivalent to ignoring the low (k-1) words
   79|       |
   80|       |   // 2 * mod_words + 1 is sufficient, extra is to enable Karatsuba
   81|  13.0k|   secure_vector<word> r(2 * mu_words + 2);
   82|       |
   83|  13.0k|   copy_mem(r.data(), x_words.data() + (mod_words - 1), mod_words + 1);
   84|       |
   85|       |   // Now compute q2 = q1 * μ
   86|       |
   87|       |   // We allocate more size than required since this allows Karatsuba more often;
   88|       |   // just `mu_words + (mod_words + 1)` is sufficient
   89|  13.0k|   const size_t q2_size = 2 * mu_words + 2;
   90|       |
   91|  13.0k|   secure_vector<word> q2(q2_size);
   92|       |
   93|  13.0k|   bigint_mul(
   94|  13.0k|      q2.data(), q2.size(), r.data(), r.size(), mod_words + 1, mu._data(), mu.size(), mu_words, ws.data(), ws.size());
   95|       |
   96|       |   // Compute r2 = (floor(q2 / b^(k+1)) * m) mod 2^(k+1)
   97|       |   // The division/floor is again effected by just ignoring the low k + 1 words
   98|  13.0k|   bigint_mul(r.data(),
   99|  13.0k|              r.size(),
  100|  13.0k|              &q2[mod_words + 1],  // ignoring the low mod_words + 1 words of the first product
  101|  13.0k|              q2.size() - (mod_words + 1),
  102|  13.0k|              mod_words + 1,
  103|  13.0k|              modulus._data(),
  104|  13.0k|              modulus.size(),
  105|  13.0k|              mod_words,
  106|  13.0k|              ws.data(),
  107|  13.0k|              ws.size());
  108|       |
  109|       |   // Clear the high words of the product, equivalent to computing mod 2^(k+1)
  110|       |   // TODO add masked mul to avoid computing high bits at all
  111|  13.0k|   clear_mem(std::span{r}.subspan(mod_words + 1));
  112|       |
  113|       |   // Compute r = r1 - r2
  114|       |
  115|       |   // The return value of bigint_sub_abs isn't quite right for what we need here so first compare
  116|  13.0k|   const int32_t relative_size = bigint_cmp(r.data(), mod_words + 1, x_words.data(), mod_words + 1);
  117|       |
  118|  13.0k|   bigint_sub_abs(r.data(), r.data(), x_words.data(), mod_words + 1, ws.data());
  119|       |
  120|       |   /*
  121|       |   If r is negative then we have to set r to r + 2^(k+1)
  122|       |
  123|       |   However for r negative computing this sum is equivalent to computing 2^(k+1) - abs(r)
  124|       |   */
  125|  13.0k|   clear_mem(ws.data(), mod_words + 2);
  126|  13.0k|   ws[mod_words + 1] = 1;
  127|  13.0k|   bigint_sub2(ws.data(), mod_words + 2, r.data(), mod_words + 2);
  128|       |
  129|       |   // If relative_size > 0 then assign r to 2^(k+1) - r
  130|  13.0k|   CT::Mask<word>::is_equal(static_cast<word>(relative_size), 1).select_n(r.data(), ws.data(), r.data(), mod_words + 2);
  131|       |
  132|       |   /*
  133|       |   * Per HAC Note 14.44 (ii) "step 4 is repeated at most twice since 0 ≤ r < 3m"
  134|       |   */
  135|  13.0k|   const size_t bound = 2;
  136|       |
  137|  13.0k|   BOTAN_ASSERT_NOMSG(r.size() >= mod_words + 1);
  ------------------
  |  |   77|  13.0k|   do {                                                                     \
  |  |   78|  13.0k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|  13.0k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 13.0k]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|  13.0k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 13.0k]
  |  |  ------------------
  ------------------
  138|  39.2k|   for(size_t i = 0; i != bound; ++i) {
  ------------------
  |  Branch (138:22): [True: 26.1k, False: 13.0k]
  ------------------
  139|  26.1k|      const word borrow = bigint_sub3(ws.data(), r.data(), mod_words + 1, modulus._data(), mod_words);
  140|  26.1k|      CT::Mask<word>::is_zero(borrow).select_n(r.data(), ws.data(), r.data(), mod_words + 1);
  141|  26.1k|   }
  142|       |
  143|  13.0k|   CT::unpoison(q2);
  144|  13.0k|   CT::unpoison(r);
  145|  13.0k|   CT::unpoison(ws);
  146|  13.0k|   CT::unpoison(x_words);
  147|       |
  148|  13.0k|   return BigInt::_from_words(r);
  149|  13.0k|}

_ZN5Botan12random_primeERNS_21RandomNumberGeneratorEmRKNS_6BigIntEmmm:
  195|      1|   RandomNumberGenerator& rng, size_t bits, const BigInt& coprime, size_t equiv, size_t modulo, size_t prob) {
  196|      1|   if(bits <= 1) {
  ------------------
  |  Branch (196:7): [True: 0, False: 1]
  ------------------
  197|      0|      throw Invalid_Argument("random_prime: Can't make a prime of " + std::to_string(bits) + " bits");
  198|      0|   }
  199|      1|   if(coprime.signum() < 0 || (coprime.signum() != 0 && coprime.is_even()) || coprime.bits() >= bits) {
  ------------------
  |  Branch (199:7): [True: 0, False: 1]
  |  Branch (199:32): [True: 0, False: 1]
  |  Branch (199:57): [True: 0, False: 0]
  |  Branch (199:79): [True: 0, False: 1]
  ------------------
  200|      0|      throw Invalid_Argument("random_prime: invalid coprime");
  201|      0|   }
  202|       |   // TODO(Botan4) reduce this to ~1000
  203|      1|   if(modulo == 0 || modulo >= 100000) {
  ------------------
  |  Branch (203:7): [True: 0, False: 1]
  |  Branch (203:22): [True: 0, False: 1]
  ------------------
  204|      0|      throw Invalid_Argument("random_prime: Invalid modulo value");
  205|      0|   }
  206|       |
  207|       |   // TODO(Botan4) reject equiv > modulo instead of reducing here
  208|      1|   equiv %= modulo;
  209|       |
  210|      1|   if(equiv == 0) {
  ------------------
  |  Branch (210:7): [True: 0, False: 1]
  ------------------
  211|      0|      throw Invalid_Argument("random_prime Invalid value for equiv/modulo");
  212|      0|   }
  213|       |
  214|       |   // Handle small values:
  215|       |
  216|      1|   if(bits <= 16) {
  ------------------
  |  Branch (216:7): [True: 0, False: 1]
  ------------------
  217|      0|      if(equiv != 1 || modulo != 2 || coprime != 0) {
  ------------------
  |  Branch (217:10): [True: 0, False: 0]
  |  Branch (217:24): [True: 0, False: 0]
  |  Branch (217:39): [True: 0, False: 0]
  ------------------
  218|      0|         throw Not_Implemented("random_prime equiv/modulo/coprime options not usable for small primes");
  219|      0|      }
  220|       |
  221|      0|      if(bits == 2) {
  ------------------
  |  Branch (221:10): [True: 0, False: 0]
  ------------------
  222|      0|         return BigInt::from_word(((rng.next_byte() % 2) == 0 ? 2 : 3));
  ------------------
  |  Branch (222:36): [True: 0, False: 0]
  ------------------
  223|      0|      } else if(bits == 3) {
  ------------------
  |  Branch (223:17): [True: 0, False: 0]
  ------------------
  224|      0|         return BigInt::from_word(((rng.next_byte() % 2) == 0 ? 5 : 7));
  ------------------
  |  Branch (224:36): [True: 0, False: 0]
  ------------------
  225|      0|      } else if(bits == 4) {
  ------------------
  |  Branch (225:17): [True: 0, False: 0]
  ------------------
  226|      0|         return BigInt::from_word(((rng.next_byte() % 2) == 0 ? 11 : 13));
  ------------------
  |  Branch (226:36): [True: 0, False: 0]
  ------------------
  227|      0|      } else {
  228|      0|         for(;;) {
  229|       |            // This is slightly biased, but for small primes it does not seem to matter
  230|      0|            uint8_t b[4] = {0};
  231|      0|            rng.randomize(b, 4);
  232|      0|            const size_t idx = load_le<uint32_t>(b, 0) % PRIME_TABLE_SIZE;
  233|      0|            const uint16_t small_prime = PRIMES[idx];
  234|       |
  235|      0|            if(high_bit(small_prime) == bits) {
  ------------------
  |  Branch (235:16): [True: 0, False: 0]
  ------------------
  236|      0|               return BigInt::from_word(small_prime);
  237|      0|            }
  238|      0|         }
  239|      0|      }
  240|      0|   }
  241|       |
  242|       |   // The check_2p1 sieve filter is only appropriate when generating q for a
  243|       |   // safe prime; for arbitrary equiv/modulo it can pre-reject every candidate
  244|       |   // (eg equiv=1, modulo=3 makes the residue mod 3 always equal (3-1)/2).
  245|      1|   return random_prime_with_sieve(rng, bits, coprime, equiv, modulo, prob, false);
  246|      1|}
make_prm.cpp:_ZN5Botan12_GLOBAL__N_123random_prime_with_sieveERNS_21RandomNumberGeneratorEmRKNS_6BigIntEmmmb:
  114|      1|                               bool sieve_check_2p1) {
  115|      1|   const size_t MAX_ATTEMPTS = 32 * 1024;
  116|       |
  117|      1|   const size_t mr_trials = miller_rabin_test_iterations(bits, prob, true);
  118|       |
  119|       |   // Variable time gcd here is fine since these are generation parameters, not secrets
  120|      1|   if(std::gcd(equiv, modulo) != 1) {
  ------------------
  |  Branch (120:7): [True: 0, False: 1]
  ------------------
  121|      0|      throw Invalid_Argument("random_prime equiv and modulo must be relatively prime");
  122|      0|   }
  123|       |
  124|      1|   while(true) {
  ------------------
  |  Branch (124:10): [True: 1, Folded]
  ------------------
  125|      1|      BigInt p(rng, bits);
  126|       |
  127|       |      // Force lowest and two top bits on
  128|      1|      p.set_bit(bits - 1);
  129|      1|      p.set_bit(bits - 2);
  130|      1|      p.set_bit(0);
  131|       |
  132|       |      // Force p to be equal to equiv mod modulo
  133|      1|      p += (modulo - (p % modulo)) + equiv;
  134|       |
  135|      1|      Prime_Sieve sieve(p, bits, modulo, sieve_check_2p1);
  136|       |
  137|     96|      for(size_t attempt = 0; attempt <= MAX_ATTEMPTS; ++attempt) {
  ------------------
  |  Branch (137:31): [True: 96, False: 0]
  ------------------
  138|     96|         p += modulo;
  139|       |
  140|     96|         if(!sieve.next()) {
  ------------------
  |  Branch (140:13): [True: 81, False: 15]
  ------------------
  141|     81|            continue;
  142|     81|         }
  143|       |
  144|       |         // here p can be even if modulo is odd, continue on in that case
  145|     15|         if(p.is_even()) {
  ------------------
  |  Branch (145:13): [True: 0, False: 15]
  ------------------
  146|      0|            continue;
  147|      0|         }
  148|       |
  149|     15|         BOTAN_DEBUG_ASSERT(no_small_multiples(p, sieve));
  ------------------
  |  |  130|     15|      do { /* NOLINT(*-avoid-do-while) */ \
  |  |  131|     15|      } while(0)
  |  |  ------------------
  |  |  |  Branch (131:15): [Folded, False: 15]
  |  |  ------------------
  ------------------
  150|       |
  151|     15|         auto mod_p = Barrett_Reduction::for_secret_modulus(p);
  152|     15|         const Montgomery_Params monty_p(p, mod_p);
  153|       |
  154|     15|         if(coprime > 1) {
  ------------------
  |  Branch (154:13): [True: 0, False: 15]
  ------------------
  155|       |            /*
  156|       |            First do a single M-R iteration to quickly eliminate most non-primes,
  157|       |            before doing the coprimality check which is expensive
  158|       |            */
  159|      0|            if(!is_miller_rabin_probable_prime(p, mod_p, monty_p, rng, 1)) {
  ------------------
  |  Branch (159:16): [True: 0, False: 0]
  ------------------
  160|      0|               continue;
  161|      0|            }
  162|       |
  163|       |            /*
  164|       |            * Check if p - 1 and coprime are relatively prime, using gcd.
  165|       |            * The gcd computation is const-time
  166|       |            */
  167|      0|            if(gcd(p - 1, coprime) > 1) {
  ------------------
  |  Branch (167:16): [True: 0, False: 0]
  ------------------
  168|      0|               continue;
  169|      0|            }
  170|      0|         }
  171|       |
  172|     15|         if(p.bits() > bits) {
  ------------------
  |  Branch (172:13): [True: 0, False: 15]
  ------------------
  173|      0|            break;
  174|      0|         }
  175|       |
  176|     15|         if(!is_miller_rabin_probable_prime(p, mod_p, monty_p, rng, mr_trials)) {
  ------------------
  |  Branch (176:13): [True: 14, False: 1]
  ------------------
  177|     14|            continue;
  178|     14|         }
  179|       |
  180|      1|         if(prob > 32 && !is_lucas_probable_prime(p, mod_p)) {
  ------------------
  |  Branch (180:13): [True: 1, False: 0]
  |  Branch (180:26): [True: 0, False: 1]
  ------------------
  181|      0|            continue;
  182|      0|         }
  183|       |
  184|      1|         return p;
  185|      1|      }
  186|      1|   }
  187|      1|}
make_prm.cpp:_ZN5Botan12_GLOBAL__N_111Prime_SieveC2ERKNS_6BigIntEmmb:
   28|      1|            m_sieve(std::min(sieve_size, PRIME_TABLE_SIZE)), m_step(step), m_check_2p1(check_2p1) {
   29|    257|         for(size_t i = 0; i != m_sieve.size(); ++i) {
  ------------------
  |  Branch (29:28): [True: 256, False: 1]
  ------------------
   30|    256|            m_sieve[i] = ct_mod_word(init_value, PRIMES[i]);
   31|    256|         }
   32|      1|      }
make_prm.cpp:_ZN5Botan12_GLOBAL__N_111Prime_Sieve4nextEv:
   38|     96|      bool next() {
   39|     96|         auto passes = CT::Mask<word>::set();
   40|  24.6k|         for(size_t i = 0; i != m_sieve.size(); ++i) {
  ------------------
  |  Branch (40:28): [True: 24.5k, False: 96]
  ------------------
   41|  24.5k|            m_sieve[i] = sieve_step_incr(m_sieve[i], m_step, PRIMES[i]);
   42|       |
   43|       |            // If m_sieve[i] == 0 then val % p == 0 -> not prime
   44|  24.5k|            passes &= CT::Mask<word>::expand(m_sieve[i]);
   45|       |
   46|  24.5k|            if(this->check_2p1()) {
  ------------------
  |  Branch (46:16): [True: 0, False: 24.5k]
  ------------------
   47|       |               /*
   48|       |               If v % p == (p-1)/2 then 2*v+1 == 0 (mod p)
   49|       |
   50|       |               So if potentially generating a safe prime, we want to
   51|       |               avoid this value because 2*v+1 will certainly not be prime.
   52|       |
   53|       |               See "Safe Prime Generation with a Combined Sieve" M. Wiener
   54|       |               https://eprint.iacr.org/2003/186.pdf
   55|       |               */
   56|      0|               passes &= ~CT::Mask<word>::is_equal(m_sieve[i], (PRIMES[i] - 1) / 2);
   57|      0|            }
   58|  24.5k|         }
   59|       |
   60|     96|         return passes.as_bool();
   61|     96|      }
make_prm.cpp:_ZN5Botan12_GLOBAL__N_111Prime_Sieve15sieve_step_incrEmmm:
   67|  24.5k|      static constexpr word sieve_step_incr(word v, word step, word mod) {
   68|  24.5k|         BOTAN_DEBUG_ASSERT(v < mod);
  ------------------
  |  |  130|  24.5k|      do { /* NOLINT(*-avoid-do-while) */ \
  |  |  131|  24.5k|      } while(0)
  |  |  ------------------
  |  |  |  Branch (131:15): [Folded, False: 24.5k]
  |  |  ------------------
  ------------------
   69|       |         // The sieve step and primes are public so this modulo is ok
   70|  24.5k|         const word stepmod = (step >= mod) ? (step % mod) : step;
  ------------------
  |  Branch (70:31): [True: 96, False: 24.4k]
  ------------------
   71|       |
   72|       |         // This sum is at most 2*(mod-1)
   73|  24.5k|         const word next = (v + stepmod);
   74|  24.5k|         return next - CT::Mask<word>::is_gte(next, mod).if_set_return(mod);
   75|  24.5k|      }
make_prm.cpp:_ZNK5Botan12_GLOBAL__N_111Prime_Sieve9check_2p1Ev:
   36|  24.5k|      bool check_2p1() const { return m_check_2p1; }

_ZN5Botan17Montgomery_Params4DataC2ERKNS_6BigIntERKNS_17Barrett_ReductionE:
   40|    689|Montgomery_Params::Data::Data(const BigInt& p, const Barrett_Reduction& mod_p) {
   41|    689|   if(p.is_even() || p < 3) {
  ------------------
  |  Branch (41:7): [True: 0, False: 689]
  |  Branch (41:22): [True: 0, False: 689]
  ------------------
   42|      0|      throw Invalid_Argument("Montgomery_Params invalid modulus");
   43|      0|   }
   44|       |
   45|    689|   m_p = p;
   46|    689|   m_p_words = m_p.sig_words();
   47|    689|   m_p_dash = monty_inverse(m_p.word_at(0));
   48|       |
   49|    689|   const BigInt r = BigInt::power_of_2(m_p_words * WordInfo<word>::bits);
   50|       |
   51|    689|   m_r1 = mod_p.reduce(r);
   52|    689|   m_r2 = mod_p.square(m_r1);
   53|    689|   m_r3 = mod_p.multiply(m_r1, m_r2);
   54|       |
   55|       |   // Barrett should be at least zero prefixing up to modulus size
   56|    689|   BOTAN_ASSERT_NOMSG(m_r1.size() >= m_p_words);
  ------------------
  |  |   77|    689|   do {                                                                     \
  |  |   78|    689|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|    689|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 689]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|    689|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 689]
  |  |  ------------------
  ------------------
   57|    689|   BOTAN_ASSERT_NOMSG(m_r2.size() >= m_p_words);
  ------------------
  |  |   77|    689|   do {                                                                     \
  |  |   78|    689|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|    689|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 689]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|    689|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 689]
  |  |  ------------------
  ------------------
   58|    689|   BOTAN_ASSERT_NOMSG(m_r3.size() >= m_p_words);
  ------------------
  |  |   77|    689|   do {                                                                     \
  |  |   78|    689|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|    689|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 689]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|    689|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 689]
  |  |  ------------------
  ------------------
   59|    689|}
_ZN5Botan17Montgomery_ParamsC2ERKNS_6BigIntERKNS_17Barrett_ReductionE:
   62|    689|      m_data(std::make_shared<Data>(p, mod_p)) {}
_ZNK5Botan17Montgomery_ParamseqERKS0_:
   67|  91.0k|bool Montgomery_Params::operator==(const Montgomery_Params& other) const {
   68|  91.0k|   if(this->m_data == other.m_data) {
  ------------------
  |  Branch (68:7): [True: 91.0k, False: 0]
  ------------------
   69|  91.0k|      return true;
   70|  91.0k|   }
   71|       |
   72|      0|   return (this->m_data->p() == other.m_data->p());
   73|  91.0k|}
_ZN5Botan14Montgomery_IntC2ERKNS_17Montgomery_ParamsENSt3__16vectorImNS_16secure_allocatorImEEEE:
  227|  16.6k|      m_params(params), m_v(std::move(words)) {
  228|  16.6k|   BOTAN_ASSERT_NOMSG(m_v.size() == m_params.p_words());
  ------------------
  |  |   77|  16.6k|   do {                                                                     \
  |  |   78|  16.6k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|  16.6k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 16.6k]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|  16.6k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 16.6k]
  |  |  ------------------
  ------------------
  229|  16.6k|}
_ZN5Botan14Montgomery_Int3oneERKNS_17Montgomery_ParamsE:
  231|  2.38k|Montgomery_Int Montgomery_Int::one(const Montgomery_Params& params) {
  232|  2.38k|   return Montgomery_Int(params, params.R1(), false);
  233|  2.38k|}
_ZN5Botan14Montgomery_IntC2ERKNS_17Montgomery_ParamsERKNS_6BigIntEb:
  242|  4.76k|      m_params(params), m_v(m_params.p_words()) {
  243|  4.76k|   BOTAN_ARG_CHECK(v.signum() >= 0 && v < m_params.p(), "Input out of range");
  ------------------
  |  |   35|  4.76k|   do {                                                          \
  |  |   36|  4.76k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  9.52k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:12): [True: 4.76k, False: 0]
  |  |  |  Branch (37:12): [True: 4.76k, False: 0]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|  4.76k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 4.76k]
  |  |  ------------------
  ------------------
  244|       |
  245|  4.76k|   const size_t p_size = m_params.p_words();
  246|       |
  247|  4.76k|   auto v_span = v._as_span();
  248|       |
  249|  4.76k|   if(v_span.size() > p_size) {
  ------------------
  |  Branch (249:7): [True: 4.76k, False: 0]
  ------------------
  250|       |      // Safe to truncate the span since we already checked v < p
  251|  4.76k|      v_span = v_span.first(p_size);
  252|  4.76k|   }
  253|       |
  254|  4.76k|   BOTAN_ASSERT_NOMSG(m_v.size() >= v_span.size());
  ------------------
  |  |   77|  4.76k|   do {                                                                     \
  |  |   78|  4.76k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|  4.76k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 4.76k]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|  4.76k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 4.76k]
  |  |  ------------------
  ------------------
  255|       |
  256|  4.76k|   copy_mem(std::span{m_v}.first(v_span.size()), v_span);
  257|       |
  258|  4.76k|   if(redc_needed) {
  ------------------
  |  Branch (258:7): [True: 2.38k, False: 2.38k]
  ------------------
  259|  2.38k|      secure_vector<word> ws;
  260|  2.38k|      this->mul_by(m_params.R2()._as_span().first(p_size), ws);
  261|  2.38k|   }
  262|  4.76k|}
_ZN5Botan14Montgomery_IntC2ERKNS_17Montgomery_ParamsENSt3__14spanIKmLm18446744073709551615EEE:
  265|     43|      m_params(params), m_v(words.begin(), words.end()) {
  266|     43|   BOTAN_ARG_CHECK(m_v.size() == m_params.p_words(), "Invalid input span");
  ------------------
  |  |   35|     43|   do {                                                          \
  |  |   36|     43|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|     43|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 43]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|     43|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 43]
  |  |  ------------------
  ------------------
  267|     43|}
_ZNK5Botan14Montgomery_Int5valueEv:
  273|  2.38k|BigInt Montgomery_Int::value() const {
  274|  2.38k|   secure_vector<word> ws(m_params.p_words());
  275|       |
  276|  2.38k|   secure_vector<word> z = m_v;
  277|  2.38k|   z.resize(2 * m_params.p_words());  // zero extend
  278|       |
  279|  2.38k|   bigint_monty_redc_inplace(
  280|  2.38k|      z.data(), m_params.p()._data(), m_params.p_words(), m_params.p_dash(), ws.data(), ws.size());
  281|       |
  282|  2.38k|   return BigInt::_from_words(z);
  283|  2.38k|}
_ZNK5Botan14Montgomery_Int3mulERKS0_RNSt3__16vectorImNS_16secure_allocatorImEEEE:
  320|  16.6k|Montgomery_Int Montgomery_Int::mul(const Montgomery_Int& other, secure_vector<word>& ws) const {
  321|  16.6k|   BOTAN_STATE_CHECK(other.m_params == m_params);
  ------------------
  |  |   51|  16.6k|   do {                                                         \
  |  |   52|  16.6k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */             \
  |  |   53|  16.6k|      if(!(expr)) {                                             \
  |  |  ------------------
  |  |  |  Branch (53:10): [True: 0, False: 16.6k]
  |  |  ------------------
  |  |   54|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */    \
  |  |   55|      0|         Botan::throw_invalid_state(#expr, __func__, __FILE__); \
  |  |   56|      0|      }                                                         \
  |  |   57|  16.6k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (57:12): [Folded, False: 16.6k]
  |  |  ------------------
  ------------------
  322|       |
  323|  16.6k|   const size_t p_size = m_params.p_words();
  324|  16.6k|   BOTAN_ASSERT_NOMSG(m_v.size() == p_size && other.m_v.size() == p_size);
  ------------------
  |  |   77|  16.6k|   do {                                                                     \
  |  |   78|  16.6k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|  33.3k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:12): [True: 16.6k, False: 0]
  |  |  |  Branch (79:12): [True: 16.6k, False: 0]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|  16.6k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 16.6k]
  |  |  ------------------
  ------------------
  325|       |
  326|  16.6k|   if(ws.size() < 2 * p_size) {
  ------------------
  |  Branch (326:7): [True: 0, False: 16.6k]
  ------------------
  327|      0|      ws.resize(2 * p_size);
  328|      0|   }
  329|       |
  330|  16.6k|   secure_vector<word> z(2 * p_size);
  331|       |
  332|  16.6k|   bigint_mul(z.data(), z.size(), m_v.data(), p_size, p_size, other.m_v.data(), p_size, p_size, ws.data(), ws.size());
  333|       |
  334|  16.6k|   bigint_monty_redc_inplace(z.data(), m_params.p()._data(), p_size, m_params.p_dash(), ws.data(), ws.size());
  335|  16.6k|   z.resize(p_size);  // truncate off high zero words
  336|       |
  337|  16.6k|   return Montgomery_Int(m_params, std::move(z));
  338|  16.6k|}
_ZN5Botan14Montgomery_Int6mul_byERKS0_RNSt3__16vectorImNS_16secure_allocatorImEEEE:
  340|  74.4k|Montgomery_Int& Montgomery_Int::mul_by(const Montgomery_Int& other, secure_vector<word>& ws) {
  341|  74.4k|   BOTAN_STATE_CHECK(other.m_params == m_params);
  ------------------
  |  |   51|  74.4k|   do {                                                         \
  |  |   52|  74.4k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */             \
  |  |   53|  74.4k|      if(!(expr)) {                                             \
  |  |  ------------------
  |  |  |  Branch (53:10): [True: 0, False: 74.4k]
  |  |  ------------------
  |  |   54|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */    \
  |  |   55|      0|         Botan::throw_invalid_state(#expr, __func__, __FILE__); \
  |  |   56|      0|      }                                                         \
  |  |   57|  74.4k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (57:12): [Folded, False: 74.4k]
  |  |  ------------------
  ------------------
  342|  74.4k|   return this->mul_by(std::span{other.m_v}, ws);
  343|  74.4k|}
_ZN5Botan14Montgomery_Int6mul_byENSt3__14spanIKmLm18446744073709551615EEERNS1_6vectorImNS_16secure_allocatorImEEEE:
  345|  79.5k|Montgomery_Int& Montgomery_Int::mul_by(std::span<const word> other, secure_vector<word>& ws) {
  346|  79.5k|   const size_t p_size = m_params.p_words();
  347|  79.5k|   BOTAN_ASSERT_NOMSG(m_v.size() == p_size && other.size() == p_size);
  ------------------
  |  |   77|  79.5k|   do {                                                                     \
  |  |   78|  79.5k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|   159k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:12): [True: 79.5k, False: 0]
  |  |  |  Branch (79:12): [True: 79.5k, False: 0]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|  79.5k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 79.5k]
  |  |  ------------------
  ------------------
  348|       |
  349|  79.5k|   if(ws.size() < 2 * p_size) {
  ------------------
  |  Branch (349:7): [True: 2.38k, False: 77.1k]
  ------------------
  350|  2.38k|      ws.resize(2 * p_size);
  351|  2.38k|   }
  352|       |
  353|  79.5k|   auto do_mul_by = [&](std::span<word> z) {
  354|  79.5k|      bigint_mul(z.data(), z.size(), m_v.data(), p_size, p_size, other.data(), p_size, p_size, ws.data(), ws.size());
  355|       |
  356|  79.5k|      bigint_monty_redc_inplace(z.data(), m_params.p()._data(), p_size, m_params.p_dash(), ws.data(), ws.size());
  357|       |
  358|  79.5k|      copy_mem(m_v, z.first(p_size));
  359|  79.5k|   };
  360|       |
  361|  79.5k|   if(p_size <= MontgomeryUseStackLimit) {
  ------------------
  |  Branch (361:7): [True: 79.5k, False: 0]
  ------------------
  362|  79.5k|      std::array<word, 2 * MontgomeryUseStackLimit> z{};
  363|  79.5k|      do_mul_by(z);
  364|  79.5k|   } else {
  365|      0|      secure_vector<word> z(2 * p_size);
  366|      0|      do_mul_by(z);
  367|      0|   }
  368|       |
  369|  79.5k|   return (*this);
  370|  79.5k|}
_ZN5Botan14Montgomery_Int19square_this_n_timesERNSt3__16vectorImNS_16secure_allocatorImEEEEm:
  372|  98.8k|Montgomery_Int& Montgomery_Int::square_this_n_times(secure_vector<word>& ws, size_t n) {
  373|  98.8k|   const size_t p_size = m_params.p_words();
  374|  98.8k|   BOTAN_ASSERT_NOMSG(m_v.size() == p_size);
  ------------------
  |  |   77|  98.8k|   do {                                                                     \
  |  |   78|  98.8k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|  98.8k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 98.8k]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|  98.8k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 98.8k]
  |  |  ------------------
  ------------------
  375|       |
  376|  98.8k|   if(ws.size() < 2 * p_size) {
  ------------------
  |  Branch (376:7): [True: 0, False: 98.8k]
  ------------------
  377|      0|      ws.resize(2 * p_size);
  378|      0|   }
  379|       |
  380|  98.8k|   auto do_sqr_n = [&](std::span<word> z) {
  381|  98.8k|      for(size_t i = 0; i != n; ++i) {
  382|  98.8k|         bigint_sqr(z.data(), 2 * p_size, m_v.data(), p_size, p_size, ws.data(), ws.size());
  383|       |
  384|  98.8k|         bigint_monty_redc_inplace(z.data(), m_params.p()._data(), p_size, m_params.p_dash(), ws.data(), ws.size());
  385|       |
  386|  98.8k|         copy_mem(m_v, std::span{z}.first(p_size));
  387|  98.8k|      }
  388|  98.8k|   };
  389|       |
  390|  98.8k|   if(p_size <= MontgomeryUseStackLimit) {
  ------------------
  |  Branch (390:7): [True: 98.8k, False: 0]
  ------------------
  391|  98.8k|      std::array<word, 2 * MontgomeryUseStackLimit> z{};
  392|  98.8k|      do_sqr_n(z);
  393|  98.8k|   } else {
  394|      0|      secure_vector<word> z(2 * p_size);
  395|      0|      do_sqr_n(z);
  396|      0|   }
  397|       |
  398|  98.8k|   return (*this);
  399|  98.8k|}
_ZNK5Botan14Montgomery_Int6squareERNSt3__16vectorImNS_16secure_allocatorImEEEE:
  401|  16.6k|Montgomery_Int Montgomery_Int::square(secure_vector<word>& ws) const {
  402|  16.6k|   auto z = (*this);
  403|  16.6k|   z.square_this_n_times(ws, 1);
  404|  16.6k|   return z;
  405|  16.6k|}
monty.cpp:_ZZN5Botan14Montgomery_Int6mul_byENSt3__14spanIKmLm18446744073709551615EEERNS1_6vectorImNS_16secure_allocatorImEEEEENK3$_0clENS2_ImLm18446744073709551615EEE:
  353|  79.5k|   auto do_mul_by = [&](std::span<word> z) {
  354|  79.5k|      bigint_mul(z.data(), z.size(), m_v.data(), p_size, p_size, other.data(), p_size, p_size, ws.data(), ws.size());
  355|       |
  356|  79.5k|      bigint_monty_redc_inplace(z.data(), m_params.p()._data(), p_size, m_params.p_dash(), ws.data(), ws.size());
  357|       |
  358|  79.5k|      copy_mem(m_v, z.first(p_size));
  359|  79.5k|   };
monty.cpp:_ZZN5Botan14Montgomery_Int19square_this_n_timesERNSt3__16vectorImNS_16secure_allocatorImEEEEmENK3$_0clENS1_4spanImLm18446744073709551615EEE:
  380|  98.8k|   auto do_sqr_n = [&](std::span<word> z) {
  381|   444k|      for(size_t i = 0; i != n; ++i) {
  ------------------
  |  Branch (381:25): [True: 345k, False: 98.8k]
  ------------------
  382|   345k|         bigint_sqr(z.data(), 2 * p_size, m_v.data(), p_size, p_size, ws.data(), ws.size());
  383|       |
  384|   345k|         bigint_monty_redc_inplace(z.data(), m_params.p()._data(), p_size, m_params.p_dash(), ws.data(), ws.size());
  385|       |
  386|   345k|         copy_mem(m_v, std::span{z}.first(p_size));
  387|   345k|      }
  388|  98.8k|   };

_ZN5Botan31Montgomery_Exponentiation_StateC2ERKNS_14Montgomery_IntEmb:
   36|  2.38k|      m_params(g._params()), m_window_bits(window_bits == 0 ? 4 : window_bits) {
  ------------------
  |  Branch (36:44): [True: 0, False: 2.38k]
  ------------------
   37|  2.38k|   if(m_window_bits < 1 || m_window_bits > 12) {  // really even 8 is too large ...
  ------------------
  |  Branch (37:7): [True: 0, False: 2.38k]
  |  Branch (37:28): [True: 0, False: 2.38k]
  ------------------
   38|      0|      throw Invalid_Argument("Invalid window bits for Montgomery exponentiation");
   39|      0|   }
   40|       |
   41|  2.38k|   const size_t window_size = (static_cast<size_t>(1) << m_window_bits);
   42|       |
   43|  2.38k|   m_g.reserve(window_size);
   44|       |
   45|  2.38k|   m_g.push_back(Montgomery_Int::one(m_params));
   46|       |
   47|  2.38k|   m_g.push_back(g);
   48|       |
   49|  2.38k|   secure_vector<word> ws(2 * m_params.p_words());
   50|       |
   51|  35.7k|   for(size_t i = 2; i != window_size; ++i) {
  ------------------
  |  Branch (51:22): [True: 33.3k, False: 2.38k]
  ------------------
   52|  33.3k|      if(i % 2 == 0) {
  ------------------
  |  Branch (52:10): [True: 16.6k, False: 16.6k]
  ------------------
   53|  16.6k|         m_g.push_back(m_g[i / 2].square(ws));
   54|  16.6k|      } else {
   55|  16.6k|         m_g.push_back(m_g[1].mul(m_g[i - 1], ws));
   56|  16.6k|      }
   57|  33.3k|   }
   58|       |
   59|  2.38k|   if(const_time) {
  ------------------
  |  Branch (59:7): [True: 43, False: 2.33k]
  ------------------
   60|     43|      CT::poison_range(m_g);
   61|     43|   }
   62|  2.38k|}
_ZNK5Botan31Montgomery_Exponentiation_State14exponentiationERKNS_6BigIntEm:
   91|     43|Montgomery_Int Montgomery_Exponentiation_State::exponentiation(const BigInt& scalar, size_t max_k_bits) const {
   92|     43|   BOTAN_ARG_CHECK(scalar.signum() >= 0, "Invalid scalar for Montgomery exponentiation");
  ------------------
  |  |   35|     43|   do {                                                          \
  |  |   36|     43|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|     43|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 43]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|     43|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 43]
  |  |  ------------------
  ------------------
   93|     43|   BOTAN_DEBUG_ASSERT(scalar.bits() <= max_k_bits);
  ------------------
  |  |  130|     43|      do { /* NOLINT(*-avoid-do-while) */ \
  |  |  131|     43|      } while(0)
  |  |  ------------------
  |  |  |  Branch (131:15): [Folded, False: 43]
  |  |  ------------------
  ------------------
   94|       |   // TODO add a const-time implementation of above assert and use it in release builds
   95|       |
   96|     43|   const size_t exp_nibbles = (max_k_bits + m_window_bits - 1) / m_window_bits;
   97|       |
   98|     43|   if(exp_nibbles == 0) {
  ------------------
  |  Branch (98:7): [True: 0, False: 43]
  ------------------
   99|      0|      return Montgomery_Int::one(m_params);
  100|      0|   }
  101|       |
  102|     43|   secure_vector<word> e_bits(m_params.p_words());
  103|     43|   secure_vector<word> ws(2 * m_params.p_words());
  104|       |
  105|     43|   const_time_lookup(e_bits, m_g, scalar.get_substring(m_window_bits * (exp_nibbles - 1), m_window_bits));
  106|     43|   Montgomery_Int x(m_params, std::span{e_bits});
  107|       |
  108|  2.75k|   for(size_t i = exp_nibbles - 1; i > 0; --i) {
  ------------------
  |  Branch (108:36): [True: 2.70k, False: 43]
  ------------------
  109|  2.70k|      x.square_this_n_times(ws, m_window_bits);
  110|  2.70k|      const_time_lookup(e_bits, m_g, scalar.get_substring(m_window_bits * (i - 1), m_window_bits));
  111|  2.70k|      x.mul_by(e_bits, ws);
  112|  2.70k|   }
  113|       |
  114|     43|   CT::unpoison(x);
  115|     43|   return x;
  116|     43|}
_ZNK5Botan31Montgomery_Exponentiation_State22exponentiation_vartimeERKNS_6BigIntE:
  118|  2.33k|Montgomery_Int Montgomery_Exponentiation_State::exponentiation_vartime(const BigInt& scalar) const {
  119|  2.33k|   const size_t exp_nibbles = (scalar.bits() + m_window_bits - 1) / m_window_bits;
  120|       |
  121|  2.33k|   secure_vector<word> ws(2 * m_params.p_words());
  122|       |
  123|  2.33k|   if(exp_nibbles == 0) {
  ------------------
  |  Branch (123:7): [True: 0, False: 2.33k]
  ------------------
  124|      0|      return Montgomery_Int::one(m_params);
  125|      0|   }
  126|       |
  127|  2.33k|   Montgomery_Int x = m_g[scalar.get_substring(m_window_bits * (exp_nibbles - 1), m_window_bits)];
  128|       |
  129|  81.8k|   for(size_t i = exp_nibbles - 1; i > 0; --i) {
  ------------------
  |  Branch (129:36): [True: 79.4k, False: 2.33k]
  ------------------
  130|  79.4k|      x.square_this_n_times(ws, m_window_bits);
  131|       |
  132|  79.4k|      const uint32_t nibble = scalar.get_substring(m_window_bits * (i - 1), m_window_bits);
  133|  79.4k|      if(nibble > 0) {
  ------------------
  |  Branch (133:10): [True: 74.4k, False: 5.06k]
  ------------------
  134|  74.4k|         x.mul_by(m_g[nibble], ws);
  135|  74.4k|      }
  136|  79.4k|   }
  137|       |
  138|  2.33k|   CT::unpoison(x);
  139|  2.33k|   return x;
  140|  2.33k|}
_ZN5Botan16monty_precomputeERKNS_14Montgomery_IntEmb:
  144|  2.38k|                                                                        bool const_time) {
  145|  2.38k|   return std::make_shared<const Montgomery_Exponentiation_State>(g, window_bits, const_time);
  146|  2.38k|}
_ZN5Botan16monty_precomputeERKNS_17Montgomery_ParamsERKNS_6BigIntEmb:
  151|  2.38k|                                                                        bool const_time) {
  152|  2.38k|   BOTAN_ARG_CHECK(g.signum() >= 0 && g < params.p(), "Montgomery exponentiation base integer out of range");
  ------------------
  |  |   35|  2.38k|   do {                                                          \
  |  |   36|  2.38k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  4.76k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:12): [True: 2.38k, False: 0]
  |  |  |  Branch (37:12): [True: 2.38k, False: 0]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|  2.38k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 2.38k]
  |  |  ------------------
  ------------------
  153|  2.38k|   const Montgomery_Int monty_g(params, g);
  154|  2.38k|   return monty_precompute(monty_g, window_bits, const_time);
  155|  2.38k|}
_ZN5Botan13monty_executeERKNS_31Montgomery_Exponentiation_StateERKNS_6BigIntEm:
  159|     43|                             size_t max_k_bits) {
  160|     43|   return precomputed_state.exponentiation(k, max_k_bits);
  161|     43|}
_ZN5Botan21monty_execute_vartimeERKNS_31Montgomery_Exponentiation_StateERKNS_6BigIntE:
  163|  2.33k|Montgomery_Int monty_execute_vartime(const Montgomery_Exponentiation_State& precomputed_state, const BigInt& k) {
  164|  2.33k|   return precomputed_state.exponentiation_vartime(k);
  165|  2.33k|}
monty_exp.cpp:_ZN5Botan12_GLOBAL__N_117const_time_lookupERNSt3__16vectorImNS_16secure_allocatorImEEEERKNS2_INS_14Montgomery_IntENS1_9allocatorIS7_EEEEm:
   66|  2.75k|void const_time_lookup(secure_vector<word>& output, const std::vector<Montgomery_Int>& g, size_t nibble) {
   67|  2.75k|   BOTAN_ASSERT_NOMSG(g.size() % 2 == 0);  // actually a power of 2
  ------------------
  |  |   77|  2.75k|   do {                                                                     \
  |  |   78|  2.75k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|  2.75k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 2.75k]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|  2.75k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 2.75k]
  |  |  ------------------
  ------------------
   68|       |
   69|  2.75k|   const size_t words = output.size();
   70|       |
   71|  2.75k|   clear_mem(output.data(), output.size());
   72|       |
   73|  24.7k|   for(size_t i = 0; i != g.size(); i += 2) {
  ------------------
  |  Branch (73:22): [True: 22.0k, False: 2.75k]
  ------------------
   74|  22.0k|      const secure_vector<word>& vec_0 = g[i].repr();
   75|  22.0k|      const secure_vector<word>& vec_1 = g[i + 1].repr();
   76|       |
   77|  22.0k|      BOTAN_ASSERT_NOMSG(vec_0.size() >= words && vec_1.size() >= words);
  ------------------
  |  |   77|  22.0k|   do {                                                                     \
  |  |   78|  22.0k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|  44.0k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:12): [True: 22.0k, False: 0]
  |  |  |  Branch (79:12): [True: 22.0k, False: 0]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|  22.0k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 22.0k]
  |  |  ------------------
  ------------------
   78|       |
   79|  22.0k|      const auto mask_0 = CT::Mask<word>::is_equal(nibble, i);
   80|  22.0k|      const auto mask_1 = CT::Mask<word>::is_equal(nibble, i + 1);
   81|       |
   82|   110k|      for(size_t w = 0; w != words; ++w) {
  ------------------
  |  Branch (82:25): [True: 88.0k, False: 22.0k]
  ------------------
   83|  88.0k|         output[w] |= mask_0.if_set_return(vec_0[w]);
   84|  88.0k|         output[w] |= mask_1.if_set_return(vec_1[w]);
   85|  88.0k|      }
   86|  22.0k|   }
   87|  2.75k|}

_ZN5Botan17sqrt_modulo_primeERKNS_6BigIntES2_:
   27|  1.19k|BigInt sqrt_modulo_prime(const BigInt& a, const BigInt& p) {
   28|  1.19k|   BOTAN_ARG_CHECK(p > 1, "invalid prime");
  ------------------
  |  |   35|  1.19k|   do {                                                          \
  |  |   36|  1.19k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  1.19k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 1.19k]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|  1.19k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 1.19k]
  |  |  ------------------
  ------------------
   29|  1.19k|   BOTAN_ARG_CHECK(a < p, "value to solve for must be less than p");
  ------------------
  |  |   35|  1.19k|   do {                                                          \
  |  |   36|  1.19k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  1.19k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 1, False: 1.19k]
  |  |  ------------------
  |  |   38|      1|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      1|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      1|      }                                                          \
  |  |   41|  1.19k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 1.19k]
  |  |  ------------------
  ------------------
   30|  1.19k|   BOTAN_ARG_CHECK(a >= 0, "value to solve for must not be negative");
  ------------------
  |  |   35|  1.19k|   do {                                                          \
  |  |   36|  1.19k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  1.19k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 1.19k]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|  1.19k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 1.19k]
  |  |  ------------------
  ------------------
   31|       |
   32|       |   // some very easy cases
   33|  1.19k|   if(p == 2 || a <= 1) {
  ------------------
  |  Branch (33:7): [True: 1, False: 1.19k]
  |  Branch (33:17): [True: 2, False: 1.19k]
  ------------------
   34|      2|      return a;
   35|      2|   }
   36|       |
   37|  1.19k|   BOTAN_ARG_CHECK(p.is_odd(), "invalid prime");
  ------------------
  |  |   35|  1.19k|   do {                                                          \
  |  |   36|  1.19k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  1.19k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 1.19k]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|  1.19k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 1.19k]
  |  |  ------------------
  ------------------
   38|       |
   39|  1.19k|   if(jacobi(a, p) != 1) {  // not a quadratic residue
  ------------------
  |  Branch (39:7): [True: 518, False: 675]
  ------------------
   40|    518|      return BigInt::from_s32(-1);
   41|    518|   }
   42|       |
   43|    675|   auto mod_p = Barrett_Reduction::for_public_modulus(p);
   44|    675|   const Montgomery_Params monty_p(p, mod_p);
   45|       |
   46|       |   // If p == 3 (mod 4) there is a simple solution
   47|    675|   if(p % 4 == 3) {
  ------------------
  |  Branch (47:7): [True: 0, False: 675]
  ------------------
   48|      0|      return monty_exp_vartime(monty_p, a, ((p + 1) >> 2)).value();
   49|      0|   }
   50|       |
   51|       |   // Otherwise we have to use Shanks-Tonelli
   52|    675|   size_t s = low_zero_bits(p - 1);
   53|    675|   BigInt q = p >> s;
   54|       |
   55|    675|   q -= 1;
   56|    675|   q >>= 1;
   57|       |
   58|    675|   BigInt r = monty_exp_vartime(monty_p, a, q).value();
   59|    675|   BigInt n = mod_p.multiply(a, mod_p.square(r));
   60|    675|   r = mod_p.multiply(r, a);
   61|       |
   62|    675|   if(n == 1) {
  ------------------
  |  Branch (62:7): [True: 66, False: 609]
  ------------------
   63|     66|      return r;
   64|     66|   }
   65|       |
   66|       |   // find random quadratic nonresidue z
   67|    609|   word z = 2;
   68|  1.21k|   for(;;) {
   69|  1.21k|      if(jacobi(BigInt::from_word(z), p) == -1) {  // found one
  ------------------
  |  Branch (69:10): [True: 608, False: 608]
  ------------------
   70|    608|         break;
   71|    608|      }
   72|       |
   73|    608|      z += 1;  // try next z
   74|       |
   75|       |      /*
   76|       |      * The expected number of tests to find a non-residue modulo a
   77|       |      * prime is 2. If we have not found one after 256 then almost
   78|       |      * certainly we have been given a non-prime p.
   79|       |      */
   80|    608|      if(z >= 256) {
  ------------------
  |  Branch (80:10): [True: 0, False: 608]
  ------------------
   81|      0|         return BigInt::from_s32(-1);
   82|      0|      }
   83|    608|   }
   84|       |
   85|    609|   BigInt c = monty_exp_vartime(monty_p, BigInt::from_word(z), (q << 1) + 1).value();
   86|       |
   87|  1.66k|   while(n > 1) {
  ------------------
  |  Branch (87:10): [True: 1.05k, False: 609]
  ------------------
   88|  1.05k|      q = n;
   89|       |
   90|  1.05k|      size_t i = 0;
   91|  3.16k|      while(q != 1) {
  ------------------
  |  Branch (91:13): [True: 2.10k, False: 1.05k]
  ------------------
   92|  2.10k|         q = mod_p.square(q);
   93|  2.10k|         ++i;
   94|       |
   95|  2.10k|         if(i >= s) {
  ------------------
  |  Branch (95:13): [True: 0, False: 2.10k]
  ------------------
   96|      0|            return BigInt::from_s32(-1);
   97|      0|         }
   98|  2.10k|      }
   99|       |
  100|  1.05k|      BOTAN_ASSERT_NOMSG(s >= (i + 1));  // No underflow!
  ------------------
  |  |   77|  1.05k|   do {                                                                     \
  |  |   78|  1.05k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|  1.05k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 1.05k]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|  1.05k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 1.05k]
  |  |  ------------------
  ------------------
  101|  1.05k|      c = monty_exp_vartime(monty_p, c, BigInt::power_of_2(s - i - 1)).value();
  102|  1.05k|      r = mod_p.multiply(r, c);
  103|  1.05k|      c = mod_p.square(c);
  104|  1.05k|      n = mod_p.multiply(n, c);
  105|       |
  106|       |      // s decreases as the algorithm proceeds
  107|  1.05k|      BOTAN_ASSERT_NOMSG(s >= i);
  ------------------
  |  |   77|  1.05k|   do {                                                                     \
  |  |   78|  1.05k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|  1.05k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 1.05k]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|  1.05k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 1.05k]
  |  |  ------------------
  ------------------
  108|  1.05k|      s = i;
  109|  1.05k|   }
  110|       |
  111|    609|   return r;
  112|    609|}
_ZN5Botan6jacobiENS_6BigIntES0_:
  119|  2.41k|int32_t jacobi(BigInt a, BigInt n) {
  120|  2.41k|   BOTAN_ARG_CHECK(n.is_odd() && n >= 3, "Argument n must be an odd integer >= 3");
  ------------------
  |  |   35|  2.41k|   do {                                                          \
  |  |   36|  2.41k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  4.82k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:12): [True: 2.41k, False: 0]
  |  |  |  Branch (37:12): [True: 2.41k, False: 0]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|  2.41k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 2.41k]
  |  |  ------------------
  ------------------
  121|       |
  122|  2.41k|   if(a < 0 || a >= n) {
  ------------------
  |  Branch (122:7): [True: 2, False: 2.41k]
  |  Branch (122:16): [True: 0, False: 2.41k]
  ------------------
  123|      2|      a %= n;
  124|      2|   }
  125|       |
  126|  2.41k|   if(a == 0) {
  ------------------
  |  Branch (126:7): [True: 0, False: 2.41k]
  ------------------
  127|      0|      return 0;
  128|      0|   }
  129|  2.41k|   if(a == 1) {
  ------------------
  |  Branch (129:7): [True: 0, False: 2.41k]
  ------------------
  130|      0|      return 1;
  131|      0|   }
  132|       |
  133|  2.41k|   int32_t s = 1;
  134|       |
  135|  41.4k|   for(;;) {
  136|  41.4k|      const size_t e = low_zero_bits(a);
  137|  41.4k|      a >>= e;
  138|  41.4k|      const word n_mod_8 = n.word_at(0) % 8;
  139|  41.4k|      const word n_mod_4 = n_mod_8 % 4;
  140|       |
  141|  41.4k|      if(e % 2 == 1 && (n_mod_8 == 3 || n_mod_8 == 5)) {
  ------------------
  |  Branch (141:10): [True: 15.4k, False: 25.9k]
  |  Branch (141:25): [True: 4.16k, False: 11.2k]
  |  Branch (141:41): [True: 3.35k, False: 7.93k]
  ------------------
  142|  7.51k|         s = -s;
  143|  7.51k|      }
  144|       |
  145|  41.4k|      if(n_mod_4 == 3 && a % 4 == 3) {
  ------------------
  |  Branch (145:10): [True: 20.0k, False: 21.4k]
  |  Branch (145:26): [True: 9.39k, False: 10.6k]
  ------------------
  146|  9.39k|         s = -s;
  147|  9.39k|      }
  148|       |
  149|       |      /*
  150|       |      * The HAC presentation of the algorithm uses recursion, which is not
  151|       |      * desirable or necessary.
  152|       |      *
  153|       |      * Instead we loop accumulating the product of the various jacobi()
  154|       |      * subcomputations into s, until we reach algorithm termination, which
  155|       |      * occurs in one of two ways.
  156|       |      *
  157|       |      * If a == 1 then the recursion has completed; we can return the value of s.
  158|       |      *
  159|       |      * Otherwise, after swapping and reducing, check for a == 0 [this value is
  160|       |      * called `n1` in HAC's presentation]. This would imply that jacobi(n1,a1)
  161|       |      * would have the value 0, due to Line 1 in HAC 2.149, in which case the
  162|       |      * entire product is zero, and we can immediately return that result.
  163|       |      */
  164|       |
  165|  41.4k|      if(a == 1) {
  ------------------
  |  Branch (165:10): [True: 2.41k, False: 39.0k]
  ------------------
  166|  2.41k|         return s;
  167|  2.41k|      }
  168|       |
  169|  39.0k|      std::swap(a, n);
  170|       |
  171|  39.0k|      BOTAN_ASSERT_NOMSG(n.is_odd());
  ------------------
  |  |   77|  39.0k|   do {                                                                     \
  |  |   78|  39.0k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|  39.0k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 39.0k]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|  39.0k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 39.0k]
  |  |  ------------------
  ------------------
  172|       |
  173|  39.0k|      a %= n;
  174|       |
  175|  39.0k|      if(a == 0) {
  ------------------
  |  Branch (175:10): [True: 0, False: 39.0k]
  ------------------
  176|      0|         return 0;
  177|      0|      }
  178|  39.0k|   }
  179|  2.41k|}
_ZN5Botan13low_zero_bitsERKNS_6BigIntE:
  194|  42.1k|size_t low_zero_bits(const BigInt& n) {
  195|  42.1k|   size_t low_zero = 0;
  196|       |
  197|  42.1k|   auto seen_nonempty_word = CT::Mask<word>::cleared();
  198|       |
  199|   369k|   for(size_t i = 0; i != n.size(); ++i) {
  ------------------
  |  Branch (199:22): [True: 327k, False: 42.1k]
  ------------------
  200|   327k|      const word x = n.word_at(i);
  201|       |
  202|       |      // ctz(0) will return sizeof(word)
  203|   327k|      const size_t tz_x = ctz(x);
  204|       |
  205|       |      // if x > 0 we want to count tz_x in total but not any
  206|       |      // further words, so set the mask after the addition
  207|   327k|      low_zero += seen_nonempty_word.if_not_set_return(tz_x);
  208|       |
  209|   327k|      seen_nonempty_word |= CT::Mask<word>::expand(x);
  210|   327k|   }
  211|       |
  212|       |   // if we saw no words with x > 0 then n == 0 and the value we have
  213|       |   // computed is meaningless. Instead return BigInt::zero() in that case.
  214|  42.1k|   return static_cast<size_t>(seen_nonempty_word.if_set_return(low_zero));
  215|  42.1k|}

_ZN5Botan23is_lucas_probable_primeERKNS_6BigIntERKNS_17Barrett_ReductionE:
   18|      1|bool is_lucas_probable_prime(const BigInt& C, const Barrett_Reduction& mod_C) {
   19|      1|   BOTAN_ARG_CHECK(C.signum() >= 0, "Argument must be non-negative");
  ------------------
  |  |   35|      1|   do {                                                          \
  |  |   36|      1|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|      1|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 1]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|      1|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 1]
  |  |  ------------------
  ------------------
   20|       |
   21|      1|   if(C == 2 || C == 3 || C == 5 || C == 7 || C == 11 || C == 13) {
  ------------------
  |  Branch (21:7): [True: 0, False: 1]
  |  Branch (21:17): [True: 0, False: 1]
  |  Branch (21:27): [True: 0, False: 1]
  |  Branch (21:37): [True: 0, False: 1]
  |  Branch (21:47): [True: 0, False: 1]
  |  Branch (21:58): [True: 0, False: 1]
  ------------------
   22|      0|      return true;
   23|      0|   }
   24|       |
   25|      1|   if(C <= 1 || C.is_even()) {
  ------------------
  |  Branch (25:7): [True: 0, False: 1]
  |  Branch (25:17): [True: 0, False: 1]
  ------------------
   26|      0|      return false;
   27|      0|   }
   28|       |
   29|      1|   BigInt D = BigInt::from_word(5);
   30|       |
   31|      5|   for(;;) {
   32|      5|      const int32_t j = jacobi(D, C);
   33|      5|      if(j == 0) {
  ------------------
  |  Branch (33:10): [True: 0, False: 5]
  ------------------
   34|      0|         return false;
   35|      0|      }
   36|       |
   37|      5|      if(j == -1) {
  ------------------
  |  Branch (37:10): [True: 1, False: 4]
  ------------------
   38|      1|         break;
   39|      1|      }
   40|       |
   41|       |      // Check 5, -7, 9, -11, 13, -15, 17, ...
   42|      4|      if(D.signum() < 0) {
  ------------------
  |  Branch (42:10): [True: 2, False: 2]
  ------------------
   43|      2|         D.flip_sign();
   44|      2|         D += 2;
   45|      2|      } else {
   46|      2|         D += 2;
   47|      2|         D.flip_sign();
   48|      2|      }
   49|       |
   50|      4|      if(D == 17 && is_perfect_square(C).signum() != 0) {
  ------------------
  |  Branch (50:10): [True: 0, False: 4]
  |  Branch (50:10): [True: 0, False: 4]
  |  Branch (50:21): [True: 0, False: 0]
  ------------------
   51|      0|         return false;
   52|      0|      }
   53|      4|   }
   54|       |
   55|      1|   if(D.signum() < 0) {
  ------------------
  |  Branch (55:7): [True: 0, False: 1]
  ------------------
   56|      0|      D += C;
   57|      0|   }
   58|       |
   59|      1|   const BigInt K = C + 1;
   60|      1|   const size_t K_bits = K.bits() - 1;
   61|       |
   62|      1|   BigInt U = BigInt::one();
   63|      1|   BigInt V = BigInt::one();
   64|       |
   65|      1|   BigInt Ut;
   66|      1|   BigInt Vt;
   67|      1|   BigInt U2;
   68|      1|   BigInt V2;
   69|       |
   70|    256|   for(size_t i = 0; i != K_bits; ++i) {
  ------------------
  |  Branch (70:22): [True: 255, False: 1]
  ------------------
   71|    255|      const bool k_bit = K.get_bit(K_bits - 1 - i);
   72|       |
   73|    255|      Ut = mod_C.multiply(U, V);
   74|       |
   75|    255|      Vt = mod_C.reduce(mod_C.square(V) + mod_C.multiply(D, mod_C.square(U)));
   76|    255|      Vt.ct_cond_add(Vt.is_odd(), C);
   77|    255|      Vt >>= 1;
   78|    255|      Vt = mod_C.reduce(Vt);
   79|       |
   80|    255|      U = Ut;
   81|    255|      V = Vt;
   82|       |
   83|    255|      U2 = mod_C.reduce(Ut + Vt);
   84|    255|      U2.ct_cond_add(U2.is_odd(), C);
   85|    255|      U2 >>= 1;
   86|       |
   87|    255|      V2 = mod_C.reduce(Vt + mod_C.multiply(Ut, D));
   88|    255|      V2.ct_cond_add(V2.is_odd(), C);
   89|    255|      V2 >>= 1;
   90|       |
   91|    255|      U.ct_cond_assign(k_bit, U2);
   92|    255|      V.ct_cond_assign(k_bit, V2);
   93|    255|   }
   94|       |
   95|      1|   return (U == 0);
   96|      1|}
_ZN5Botan24passes_miller_rabin_testERKNS_6BigIntERKNS_17Barrett_ReductionERKNS_17Montgomery_ParamsES2_:
  113|     43|                              const BigInt& a) {
  114|     43|   if(n < 3 || n.is_even()) {
  ------------------
  |  Branch (114:7): [True: 0, False: 43]
  |  Branch (114:16): [True: 0, False: 43]
  ------------------
  115|      0|      return false;
  116|      0|   }
  117|       |
  118|     43|   BOTAN_ASSERT_NOMSG(n > 1);
  ------------------
  |  |   77|     43|   do {                                                                     \
  |  |   78|     43|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|     43|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 43]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|     43|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 43]
  |  |  ------------------
  ------------------
  119|       |
  120|     43|   const BigInt n_minus_1 = n - 1;
  121|       |   /*
  122|       |   * This unpoison is not ideal but realistically there is no way to
  123|       |   * hide the number of loop iterations (below). The main user of
  124|       |   * secret primes is RSA and we always generate RSA primes such that
  125|       |   * p == 3 (mod 4), which means s is always 1.
  126|       |   */
  127|     43|   const size_t s = CT::driveby_unpoison(low_zero_bits(n_minus_1));
  128|     43|   const BigInt nm1_s = n_minus_1 >> s;
  129|     43|   const size_t n_bits = n.bits();
  130|       |
  131|     43|   const size_t powm_window = 4;
  132|       |
  133|     43|   auto powm_a_n = monty_precompute(monty_n, a, powm_window);
  134|       |
  135|     43|   BigInt y = monty_execute(*powm_a_n, nm1_s, n_bits).value();
  136|       |
  137|     43|   if(y == 1 || y == n_minus_1) {
  ------------------
  |  Branch (137:7): [True: 3, False: 40]
  |  Branch (137:17): [True: 0, False: 40]
  ------------------
  138|      3|      return true;
  139|      3|   }
  140|       |
  141|    103|   for(size_t i = 1; i != s; ++i) {
  ------------------
  |  Branch (141:22): [True: 89, False: 14]
  ------------------
  142|     89|      y = mod_n.square(y);
  143|       |
  144|     89|      if(y == 1) {  // found a non-trivial square root
  ------------------
  |  Branch (144:10): [True: 0, False: 89]
  ------------------
  145|      0|         return false;
  146|      0|      }
  147|       |
  148|       |      /*
  149|       |      -1 is the trivial square root of unity, so ``a`` is not a
  150|       |      witness for this number - give up
  151|       |      */
  152|     89|      if(y == n_minus_1) {
  ------------------
  |  Branch (152:10): [True: 26, False: 63]
  ------------------
  153|     26|         return true;
  154|     26|      }
  155|     89|   }
  156|       |
  157|     14|   return false;
  158|     40|}
_ZN5Botan30is_miller_rabin_probable_primeERKNS_6BigIntERKNS_17Barrett_ReductionERKNS_17Montgomery_ParamsERNS_21RandomNumberGeneratorEm:
  164|     15|                                    size_t test_iterations) {
  165|     15|   if(n < 3 || n.is_even()) {
  ------------------
  |  Branch (165:7): [True: 0, False: 15]
  |  Branch (165:16): [True: 0, False: 15]
  ------------------
  166|      0|      return false;
  167|      0|   }
  168|       |
  169|     44|   for(size_t i = 0; i != test_iterations; ++i) {
  ------------------
  |  Branch (169:22): [True: 43, False: 1]
  ------------------
  170|     43|      const BigInt a = BigInt::random_integer(rng, BigInt::from_word(2), n);
  171|       |
  172|     43|      if(!passes_miller_rabin_test(n, mod_n, monty_n, a)) {
  ------------------
  |  Branch (172:10): [True: 14, False: 29]
  ------------------
  173|     14|         return false;
  174|     14|      }
  175|     43|   }
  176|       |
  177|       |   // Failed to find a counterexample
  178|      1|   return true;
  179|     15|}
_ZN5Botan28miller_rabin_test_iterationsEmmb:
  181|      1|size_t miller_rabin_test_iterations(size_t n_bits, size_t prob, bool random) {
  182|       |   // Cap prob at 512 bits as _way_ more than enough; a random fault causing
  183|       |   // false accept is much more likely to occur than an actual 2^-512 event is.
  184|       |
  185|      1|   prob = std::min<size_t>(512, prob);
  186|       |
  187|      1|   const size_t base = (prob + 2) / 2;  // worst case 4^-t error rate
  188|       |
  189|       |   /*
  190|       |   * If the candidate prime was maliciously constructed, we can't rely
  191|       |   * on arguments based on p being random.
  192|       |   */
  193|      1|   if(!random) {
  ------------------
  |  Branch (193:7): [True: 0, False: 1]
  ------------------
  194|      0|      return base;
  195|      0|   }
  196|       |
  197|       |   /*
  198|       |   * For randomly chosen numbers we can use the estimates from
  199|       |   * http://www.math.dartmouth.edu/~carlp/PDF/paper88.pdf
  200|       |   *
  201|       |   * These values are derived from the inequality for p(k,t) given on
  202|       |   * the second page.
  203|       |   */
  204|      1|   if(prob <= 128) {
  ------------------
  |  Branch (204:7): [True: 1, False: 0]
  ------------------
  205|      1|      if(n_bits >= 1536) {
  ------------------
  |  Branch (205:10): [True: 0, False: 1]
  ------------------
  206|      0|         return 4;  // < 2^-133
  207|      0|      }
  208|      1|      if(n_bits >= 1024) {
  ------------------
  |  Branch (208:10): [True: 0, False: 1]
  ------------------
  209|      0|         return 6;  // < 2^-133
  210|      0|      }
  211|      1|      if(n_bits >= 512) {
  ------------------
  |  Branch (211:10): [True: 0, False: 1]
  ------------------
  212|      0|         return 12;  // < 2^-129
  213|      0|      }
  214|      1|      if(n_bits >= 256) {
  ------------------
  |  Branch (214:10): [True: 1, False: 0]
  ------------------
  215|      1|         return 29;  // < 2^-128
  216|      1|      }
  217|      1|   }
  218|       |
  219|       |   /*
  220|       |   If the user desires a smaller error probability than we have
  221|       |   precomputed error estimates for, just fall back to using the worst
  222|       |   case error rate.
  223|       |   */
  224|      0|   return base;
  225|      1|}

_ZN5Botan10ChaCha_RNGC2ENSt3__14spanIKhLm18446744073709551615EEE:
   20|      1|ChaCha_RNG::ChaCha_RNG(std::span<const uint8_t> seed) {
   21|      1|   m_hmac = MessageAuthenticationCode::create_or_throw("HMAC(SHA-256)");
   22|      1|   m_chacha = StreamCipher::create_or_throw("ChaCha(20)");
   23|      1|   clear();
   24|      1|   add_entropy(seed);
   25|      1|}
_ZN5Botan10ChaCha_RNG11clear_stateEv:
   50|      1|void ChaCha_RNG::clear_state() {
   51|      1|   m_hmac->set_key(std::vector<uint8_t>(m_hmac->output_length(), 0x00));
   52|      1|   m_chacha->set_key(m_hmac->final());
   53|      1|}
_ZN5Botan10ChaCha_RNG15generate_outputENSt3__14spanIhLm18446744073709551615EEENS2_IKhLm18446744073709551615EEE:
   55|     53|void ChaCha_RNG::generate_output(std::span<uint8_t> output, std::span<const uint8_t> input) {
   56|     53|   BOTAN_ASSERT_NOMSG(!output.empty());
  ------------------
  |  |   77|     53|   do {                                                                     \
  |  |   78|     53|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|     53|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 53]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|     53|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 53]
  |  |  ------------------
  ------------------
   57|       |
   58|     53|   if(!input.empty()) {
  ------------------
  |  Branch (58:7): [True: 0, False: 53]
  ------------------
   59|      0|      update(input);
   60|      0|   }
   61|       |
   62|     53|   m_chacha->write_keystream(output);
   63|     53|}
_ZN5Botan10ChaCha_RNG6updateENSt3__14spanIKhLm18446744073709551615EEE:
   65|      1|void ChaCha_RNG::update(std::span<const uint8_t> input) {
   66|      1|   m_hmac->update(input);
   67|      1|   m_chacha->set_key(m_hmac->final());
   68|      1|   const auto mac_key = m_chacha->keystream_bytes(m_hmac->output_length());
   69|      1|   m_hmac->set_key(mac_key);
   70|      1|}
_ZNK5Botan10ChaCha_RNG14security_levelEv:
   72|      1|size_t ChaCha_RNG::security_level() const {
   73|      1|   return 256;
   74|      1|}

_ZN5Botan12Stateful_RNG5clearEv:
   15|      1|void Stateful_RNG::clear() {
   16|      1|   const lock_guard_type<recursive_mutex_type> lock(m_mutex);
   17|      1|   m_reseed_counter = 0;
   18|      1|   m_last_pid = 0;
   19|      1|   clear_state();
   20|      1|}
_ZNK5Botan12Stateful_RNG9is_seededEv:
   27|     53|bool Stateful_RNG::is_seeded() const {
   28|     53|   const lock_guard_type<recursive_mutex_type> lock(m_mutex);
   29|     53|   return m_reseed_counter > 0;
   30|     53|}
_ZN5Botan12Stateful_RNG23generate_batched_outputENSt3__14spanIhLm18446744073709551615EEENS2_IKhLm18446744073709551615EEE:
   39|     53|void Stateful_RNG::generate_batched_output(std::span<uint8_t> output, std::span<const uint8_t> input) {
   40|     53|   BOTAN_ASSERT_NOMSG(!output.empty());
  ------------------
  |  |   77|     53|   do {                                                                     \
  |  |   78|     53|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|     53|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 53]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|     53|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 53]
  |  |  ------------------
  ------------------
   41|       |
   42|     53|   const size_t max_per_request = max_number_of_bytes_per_request();
   43|       |
   44|     53|   if(max_per_request == 0) {
  ------------------
  |  Branch (44:7): [True: 53, False: 0]
  ------------------
   45|       |      // no limit
   46|     53|      reseed_check();
   47|     53|      this->generate_output(output, input);
   48|     53|   } else {
   49|      0|      while(!output.empty()) {
  ------------------
  |  Branch (49:13): [True: 0, False: 0]
  ------------------
   50|      0|         const size_t this_req = std::min(max_per_request, output.size());
   51|       |
   52|      0|         reseed_check();
   53|      0|         this->generate_output(output.subspan(0, this_req), input);
   54|       |
   55|       |         // only include the input for the first iteration
   56|      0|         input = {};
   57|       |
   58|      0|         output = output.subspan(this_req);
   59|      0|      }
   60|      0|   }
   61|     53|}
_ZN5Botan12Stateful_RNG21fill_bytes_with_inputENSt3__14spanIhLm18446744073709551615EEENS2_IKhLm18446744073709551615EEE:
   63|     54|void Stateful_RNG::fill_bytes_with_input(std::span<uint8_t> output, std::span<const uint8_t> input) {
   64|     54|   const lock_guard_type<recursive_mutex_type> lock(m_mutex);
   65|       |
   66|     54|   if(output.empty()) {
  ------------------
  |  Branch (66:7): [True: 1, False: 53]
  ------------------
   67|       |      // Special case for exclusively adding entropy to the stateful RNG.
   68|      1|      this->update(input);
   69|       |
   70|      1|      if(8 * input.size() >= security_level()) {
  ------------------
  |  Branch (70:10): [True: 1, False: 0]
  ------------------
   71|      1|         reset_reseed_counter();
   72|      1|      }
   73|     53|   } else {
   74|     53|      generate_batched_output(output, input);
   75|     53|   }
   76|     54|}
_ZN5Botan12Stateful_RNG20reset_reseed_counterEv:
  100|      1|void Stateful_RNG::reset_reseed_counter() {
  101|       |   // Lock is held whenever this function is called
  102|      1|   m_reseed_counter = 1;
  103|      1|   m_last_pid = OS::get_process_id();
  104|      1|}
_ZN5Botan12Stateful_RNG12reseed_checkEv:
  106|     53|void Stateful_RNG::reseed_check() {
  107|       |   // Lock is held whenever this function is called
  108|       |
  109|     53|   const uint32_t cur_pid = OS::get_process_id();
  110|       |
  111|     53|   const bool fork_detected = (m_last_pid > 0) && (cur_pid != m_last_pid);
  ------------------
  |  Branch (111:31): [True: 53, False: 0]
  |  Branch (111:51): [True: 0, False: 53]
  ------------------
  112|       |
  113|     53|   if(is_seeded() == false || fork_detected || (m_reseed_interval > 0 && m_reseed_counter >= m_reseed_interval)) {
  ------------------
  |  Branch (113:7): [True: 0, False: 53]
  |  Branch (113:31): [True: 0, False: 53]
  |  Branch (113:49): [True: 0, False: 53]
  |  Branch (113:74): [True: 0, False: 0]
  ------------------
  114|      0|      m_reseed_counter = 0;
  115|      0|      m_last_pid = cur_pid;
  116|       |
  117|      0|      if(m_underlying_rng != nullptr) {
  ------------------
  |  Branch (117:10): [True: 0, False: 0]
  ------------------
  118|      0|         reseed_from_rng(*m_underlying_rng, security_level());
  119|      0|      }
  120|       |
  121|      0|      if(m_entropy_sources != nullptr) {
  ------------------
  |  Branch (121:10): [True: 0, False: 0]
  ------------------
  122|      0|         reseed_from_sources(*m_entropy_sources, security_level());
  123|      0|      }
  124|       |
  125|      0|      if(!is_seeded()) {
  ------------------
  |  Branch (125:10): [True: 0, False: 0]
  ------------------
  126|      0|         if(fork_detected) {
  ------------------
  |  Branch (126:13): [True: 0, False: 0]
  ------------------
  127|      0|            throw Invalid_State("Detected use of fork but cannot reseed DRBG");
  128|      0|         } else {
  129|      0|            throw PRNG_Unseeded(name());
  130|      0|         }
  131|      0|      }
  132|     53|   } else {
  133|     53|      BOTAN_ASSERT(m_reseed_counter != 0, "RNG is seeded");
  ------------------
  |  |   64|     53|   do {                                                                                 \
  |  |   65|     53|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                                     \
  |  |   66|     53|      if(!(expr)) {                                                                     \
  |  |  ------------------
  |  |  |  Branch (66:10): [True: 0, False: 53]
  |  |  ------------------
  |  |   67|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                            \
  |  |   68|      0|         Botan::assertion_failure(#expr, assertion_made, __func__, __FILE__, __LINE__); \
  |  |   69|      0|      }                                                                                 \
  |  |   70|     53|   } while(0)
  |  |  ------------------
  |  |  |  Branch (70:12): [Folded, False: 53]
  |  |  ------------------
  ------------------
  134|     53|      m_reseed_counter += 1;
  135|     53|   }
  136|     53|}

_ZN5Botan6ChaChaC2Em:
   92|      1|ChaCha::ChaCha(size_t rounds) : m_rounds(rounds) {
   93|      1|   BOTAN_ARG_CHECK(m_rounds == 8 || m_rounds == 12 || m_rounds == 20, "ChaCha only supports 8, 12 or 20 rounds");
  ------------------
  |  |   35|      1|   do {                                                          \
  |  |   36|      1|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|      4|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:12): [True: 0, False: 1]
  |  |  |  Branch (37:12): [True: 0, False: 1]
  |  |  |  Branch (37:12): [True: 1, False: 0]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|      1|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 1]
  |  |  ------------------
  ------------------
   94|      1|}
_ZN5Botan6ChaCha11parallelismEv:
   96|      2|size_t ChaCha::parallelism() {
   97|      2|#if defined(BOTAN_HAS_CHACHA_AVX512)
   98|      2|   if(CPUID::has(CPUID::Feature::AVX512)) {
  ------------------
  |  Branch (98:7): [True: 0, False: 2]
  ------------------
   99|      0|      return 16;
  100|      0|   }
  101|      2|#endif
  102|       |
  103|      2|#if defined(BOTAN_HAS_CHACHA_AVX2)
  104|      2|   if(CPUID::has(CPUID::Feature::AVX2)) {
  ------------------
  |  Branch (104:7): [True: 2, False: 0]
  ------------------
  105|      2|      return 8;
  106|      2|   }
  107|      0|#endif
  108|       |
  109|      0|   return 4;
  110|      2|}
_ZN5Botan6ChaCha6chachaEPhmPjm:
  134|      5|void ChaCha::chacha(uint8_t output[], size_t output_blocks, uint32_t state[16], size_t rounds) {
  135|      5|   BOTAN_ASSERT(rounds % 2 == 0, "Valid rounds");
  ------------------
  |  |   64|      5|   do {                                                                                 \
  |  |   65|      5|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                                     \
  |  |   66|      5|      if(!(expr)) {                                                                     \
  |  |  ------------------
  |  |  |  Branch (66:10): [True: 0, False: 5]
  |  |  ------------------
  |  |   67|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                            \
  |  |   68|      0|         Botan::assertion_failure(#expr, assertion_made, __func__, __FILE__, __LINE__); \
  |  |   69|      0|      }                                                                                 \
  |  |   70|      5|   } while(0)
  |  |  ------------------
  |  |  |  Branch (70:12): [Folded, False: 5]
  |  |  ------------------
  ------------------
  136|       |
  137|      5|#if defined(BOTAN_HAS_CHACHA_AVX512)
  138|      5|   if(CPUID::has(CPUID::Feature::AVX512)) {
  ------------------
  |  Branch (138:7): [True: 0, False: 5]
  ------------------
  139|      0|      while(output_blocks >= 16) {
  ------------------
  |  Branch (139:13): [True: 0, False: 0]
  ------------------
  140|      0|         ChaCha::chacha_avx512_x16(output, state, rounds);
  141|      0|         output += 16 * 64;
  142|      0|         output_blocks -= 16;
  143|      0|      }
  144|      0|   }
  145|      5|#endif
  146|       |
  147|      5|#if defined(BOTAN_HAS_CHACHA_AVX2)
  148|      5|   if(CPUID::has(CPUID::Feature::AVX2)) {
  ------------------
  |  Branch (148:7): [True: 5, False: 0]
  ------------------
  149|     10|      while(output_blocks >= 8) {
  ------------------
  |  Branch (149:13): [True: 5, False: 5]
  ------------------
  150|      5|         ChaCha::chacha_avx2_x8(output, state, rounds);
  151|      5|         output += 8 * 64;
  152|      5|         output_blocks -= 8;
  153|      5|      }
  154|      5|   }
  155|      5|#endif
  156|       |
  157|      5|#if defined(BOTAN_HAS_CHACHA_SIMD32)
  158|      5|   if(CPUID::has(CPUID::Feature::SIMD_4X32)) {
  ------------------
  |  Branch (158:7): [True: 5, False: 0]
  ------------------
  159|      5|      while(output_blocks >= 4) {
  ------------------
  |  Branch (159:13): [True: 0, False: 5]
  ------------------
  160|      0|         ChaCha::chacha_simd32_x4(output, state, rounds);
  161|      0|         output += 4 * 64;
  162|      0|         output_blocks -= 4;
  163|      0|      }
  164|      5|   }
  165|      5|#endif
  166|       |
  167|       |   // TODO interleave rounds
  168|      5|   for(size_t i = 0; i != output_blocks; ++i) {
  ------------------
  |  Branch (168:22): [True: 0, False: 5]
  ------------------
  169|      0|      uint32_t x00 = state[0];
  170|      0|      uint32_t x01 = state[1];
  171|      0|      uint32_t x02 = state[2];
  172|      0|      uint32_t x03 = state[3];
  173|      0|      uint32_t x04 = state[4];
  174|      0|      uint32_t x05 = state[5];
  175|      0|      uint32_t x06 = state[6];
  176|      0|      uint32_t x07 = state[7];
  177|      0|      uint32_t x08 = state[8];
  178|      0|      uint32_t x09 = state[9];
  179|      0|      uint32_t x10 = state[10];
  180|      0|      uint32_t x11 = state[11];
  181|      0|      uint32_t x12 = state[12];
  182|      0|      uint32_t x13 = state[13];
  183|      0|      uint32_t x14 = state[14];
  184|      0|      uint32_t x15 = state[15];
  185|       |
  186|      0|      for(size_t r = 0; r != rounds / 2; ++r) {
  ------------------
  |  Branch (186:25): [True: 0, False: 0]
  ------------------
  187|      0|         chacha_quarter_round(x00, x04, x08, x12);
  188|      0|         chacha_quarter_round(x01, x05, x09, x13);
  189|      0|         chacha_quarter_round(x02, x06, x10, x14);
  190|      0|         chacha_quarter_round(x03, x07, x11, x15);
  191|       |
  192|      0|         chacha_quarter_round(x00, x05, x10, x15);
  193|      0|         chacha_quarter_round(x01, x06, x11, x12);
  194|      0|         chacha_quarter_round(x02, x07, x08, x13);
  195|      0|         chacha_quarter_round(x03, x04, x09, x14);
  196|      0|      }
  197|       |
  198|      0|      x00 += state[0];
  199|      0|      x01 += state[1];
  200|      0|      x02 += state[2];
  201|      0|      x03 += state[3];
  202|      0|      x04 += state[4];
  203|      0|      x05 += state[5];
  204|      0|      x06 += state[6];
  205|      0|      x07 += state[7];
  206|      0|      x08 += state[8];
  207|      0|      x09 += state[9];
  208|      0|      x10 += state[10];
  209|      0|      x11 += state[11];
  210|      0|      x12 += state[12];
  211|      0|      x13 += state[13];
  212|      0|      x14 += state[14];
  213|      0|      x15 += state[15];
  214|       |
  215|      0|      store_le(x00, output + 64 * i + 4 * 0);
  216|      0|      store_le(x01, output + 64 * i + 4 * 1);
  217|      0|      store_le(x02, output + 64 * i + 4 * 2);
  218|      0|      store_le(x03, output + 64 * i + 4 * 3);
  219|      0|      store_le(x04, output + 64 * i + 4 * 4);
  220|      0|      store_le(x05, output + 64 * i + 4 * 5);
  221|      0|      store_le(x06, output + 64 * i + 4 * 6);
  222|      0|      store_le(x07, output + 64 * i + 4 * 7);
  223|      0|      store_le(x08, output + 64 * i + 4 * 8);
  224|      0|      store_le(x09, output + 64 * i + 4 * 9);
  225|      0|      store_le(x10, output + 64 * i + 4 * 10);
  226|      0|      store_le(x11, output + 64 * i + 4 * 11);
  227|      0|      store_le(x12, output + 64 * i + 4 * 12);
  228|      0|      store_le(x13, output + 64 * i + 4 * 13);
  229|      0|      store_le(x14, output + 64 * i + 4 * 14);
  230|      0|      store_le(x15, output + 64 * i + 4 * 15);
  231|       |
  232|      0|      state[12]++;
  233|      0|      if(state[12] == 0) {
  ------------------
  |  Branch (233:10): [True: 0, False: 0]
  ------------------
  234|      0|         state[13] += 1;
  235|      0|      }
  236|      0|   }
  237|      5|}
_ZN5Botan6ChaCha18generate_keystreamEPhm:
  269|     54|void ChaCha::generate_keystream(uint8_t out[], size_t length) {
  270|     54|   assert_key_material_set();
  271|       |
  272|     54|   if(m_iv_length == 12) {
  ------------------
  |  Branch (272:7): [True: 0, False: 54]
  ------------------
  273|      0|      if(length > m_bytes_remaining) {
  ------------------
  |  Branch (273:10): [True: 0, False: 0]
  ------------------
  274|      0|         throw Invalid_State("ChaCha 96-bit nonce keystream exhausted");
  275|      0|      }
  276|      0|      m_bytes_remaining -= length;
  277|      0|   }
  278|       |
  279|     57|   while(length >= m_buffer.size() - m_position) {
  ------------------
  |  Branch (279:10): [True: 3, False: 54]
  ------------------
  280|      3|      const size_t available = m_buffer.size() - m_position;
  281|       |
  282|       |      // TODO: this could write directly to the output buffer
  283|       |      // instead of bouncing it through m_buffer first
  284|      3|      copy_mem(out, &m_buffer[m_position], available);
  285|      3|      chacha(m_buffer.data(), m_buffer.size() / 64, m_state.data(), m_rounds);
  286|       |
  287|      3|      length -= available;
  288|      3|      out += available;
  289|      3|      m_position = 0;
  290|      3|   }
  291|       |
  292|     54|   copy_mem(out, &m_buffer[m_position], length);
  293|       |
  294|     54|   m_position += length;
  295|     54|}
_ZN5Botan6ChaCha16initialize_stateEv:
  297|      2|void ChaCha::initialize_state() {
  298|      2|   static const uint32_t TAU[] = {0x61707865, 0x3120646e, 0x79622d36, 0x6b206574};
  299|       |
  300|      2|   static const uint32_t SIGMA[] = {0x61707865, 0x3320646e, 0x79622d32, 0x6b206574};
  301|       |
  302|      2|   m_state[4] = m_key[0];
  303|      2|   m_state[5] = m_key[1];
  304|      2|   m_state[6] = m_key[2];
  305|      2|   m_state[7] = m_key[3];
  306|       |
  307|      2|   if(m_key.size() == 4) {
  ------------------
  |  Branch (307:7): [True: 0, False: 2]
  ------------------
  308|      0|      m_state[0] = TAU[0];
  309|      0|      m_state[1] = TAU[1];
  310|      0|      m_state[2] = TAU[2];
  311|      0|      m_state[3] = TAU[3];
  312|       |
  313|      0|      m_state[8] = m_key[0];
  314|      0|      m_state[9] = m_key[1];
  315|      0|      m_state[10] = m_key[2];
  316|      0|      m_state[11] = m_key[3];
  317|      2|   } else {
  318|      2|      m_state[0] = SIGMA[0];
  319|      2|      m_state[1] = SIGMA[1];
  320|      2|      m_state[2] = SIGMA[2];
  321|      2|      m_state[3] = SIGMA[3];
  322|       |
  323|      2|      m_state[8] = m_key[4];
  324|      2|      m_state[9] = m_key[5];
  325|      2|      m_state[10] = m_key[6];
  326|      2|      m_state[11] = m_key[7];
  327|      2|   }
  328|       |
  329|      2|   m_state[12] = 0;
  330|      2|   m_state[13] = 0;
  331|      2|   m_state[14] = 0;
  332|      2|   m_state[15] = 0;
  333|       |
  334|      2|   m_position = 0;
  335|      2|}
_ZNK5Botan6ChaCha19has_keying_materialEv:
  337|     56|bool ChaCha::has_keying_material() const {
  338|     56|   return !m_state.empty();
  339|     56|}
_ZN5Botan6ChaCha12key_scheduleENSt3__14spanIKhLm18446744073709551615EEE:
  348|      2|void ChaCha::key_schedule(std::span<const uint8_t> key) {
  349|      2|   m_key.resize(key.size() / 4);
  350|      2|   load_le<uint32_t>(m_key.data(), key.data(), m_key.size());
  351|       |
  352|      2|   m_state.resize(16);
  353|       |
  354|      2|   const size_t chacha_block = 64;
  355|      2|   m_buffer.resize(parallelism() * chacha_block);
  356|       |
  357|      2|   set_iv(nullptr, 0);
  358|      2|}
_ZNK5Botan6ChaCha8key_specEv:
  364|      2|Key_Length_Specification ChaCha::key_spec() const {
  365|      2|   return Key_Length_Specification(16, 32, 16);
  366|      2|}
_ZNK5Botan6ChaCha15valid_iv_lengthEm:
  372|      2|bool ChaCha::valid_iv_length(size_t iv_len) const {
  373|      2|   return (iv_len == 0 || iv_len == 8 || iv_len == 12 || iv_len == 24);
  ------------------
  |  Branch (373:12): [True: 2, False: 0]
  |  Branch (373:27): [True: 0, False: 0]
  |  Branch (373:42): [True: 0, False: 0]
  |  Branch (373:58): [True: 0, False: 0]
  ------------------
  374|      2|}
_ZN5Botan6ChaCha12set_iv_bytesEPKhm:
  376|      2|void ChaCha::set_iv_bytes(const uint8_t iv[], size_t length) {
  377|      2|   assert_key_material_set();
  378|       |
  379|      2|   if(!valid_iv_length(length)) {
  ------------------
  |  Branch (379:7): [True: 0, False: 2]
  ------------------
  380|      0|      throw Invalid_IV_Length(name(), length);
  381|      0|   }
  382|       |
  383|      2|   initialize_state();
  384|       |
  385|      2|   if(length == 0) {
  ------------------
  |  Branch (385:7): [True: 2, False: 0]
  ------------------
  386|       |      // Treat zero length IV same as an all-zero IV
  387|      2|      m_state[14] = 0;
  388|      2|      m_state[15] = 0;
  389|      2|   } else if(length == 8) {
  ------------------
  |  Branch (389:14): [True: 0, False: 0]
  ------------------
  390|      0|      m_state[14] = load_le<uint32_t>(iv, 0);
  391|      0|      m_state[15] = load_le<uint32_t>(iv, 1);
  392|      0|   } else if(length == 12) {
  ------------------
  |  Branch (392:14): [True: 0, False: 0]
  ------------------
  393|      0|      m_state[13] = load_le<uint32_t>(iv, 0);
  394|      0|      m_state[14] = load_le<uint32_t>(iv, 1);
  395|      0|      m_state[15] = load_le<uint32_t>(iv, 2);
  396|      0|   } else if(length == 24) {
  ------------------
  |  Branch (396:14): [True: 0, False: 0]
  ------------------
  397|      0|      m_state[12] = load_le<uint32_t>(iv, 0);
  398|      0|      m_state[13] = load_le<uint32_t>(iv, 1);
  399|      0|      m_state[14] = load_le<uint32_t>(iv, 2);
  400|      0|      m_state[15] = load_le<uint32_t>(iv, 3);
  401|       |
  402|      0|      secure_vector<uint32_t> hc(8);
  403|      0|      hchacha(hc.data(), m_state.data(), m_rounds);
  404|       |
  405|      0|      m_state[4] = hc[0];
  406|      0|      m_state[5] = hc[1];
  407|      0|      m_state[6] = hc[2];
  408|      0|      m_state[7] = hc[3];
  409|      0|      m_state[8] = hc[4];
  410|      0|      m_state[9] = hc[5];
  411|      0|      m_state[10] = hc[6];
  412|      0|      m_state[11] = hc[7];
  413|      0|      m_state[12] = 0;
  414|      0|      m_state[13] = 0;
  415|      0|      m_state[14] = load_le<uint32_t>(iv, 4);
  416|      0|      m_state[15] = load_le<uint32_t>(iv, 5);
  417|      0|   }
  418|       |
  419|      2|   m_iv_length = length;
  420|      2|   m_state13_post_iv = m_state[13];
  421|      2|   if(length == 12) {
  ------------------
  |  Branch (421:7): [True: 0, False: 2]
  ------------------
  422|      0|      m_bytes_remaining = chacha_96bit_nonce_cap;
  423|      0|   }
  424|       |
  425|      2|   chacha(m_buffer.data(), m_buffer.size() / 64, m_state.data(), m_rounds);
  426|      2|   m_position = 0;
  427|      2|}

_ZN5Botan6ChaCha14chacha_avx2_x8EPhPjm:
   15|      5|void BOTAN_FN_ISA_AVX2 ChaCha::chacha_avx2_x8(uint8_t output[64 * 8], uint32_t state[16], size_t rounds) {
   16|      5|   SIMD_8x32::reset_registers();
   17|       |
   18|      5|   BOTAN_ASSERT(rounds % 2 == 0, "Valid rounds");
  ------------------
  |  |   64|      5|   do {                                                                                 \
  |  |   65|      5|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                                     \
  |  |   66|      5|      if(!(expr)) {                                                                     \
  |  |  ------------------
  |  |  |  Branch (66:10): [True: 0, False: 5]
  |  |  ------------------
  |  |   67|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                            \
  |  |   68|      0|         Botan::assertion_failure(#expr, assertion_made, __func__, __FILE__, __LINE__); \
  |  |   69|      0|      }                                                                                 \
  |  |   70|      5|   } while(0)
  |  |  ------------------
  |  |  |  Branch (70:12): [Folded, False: 5]
  |  |  ------------------
  ------------------
   19|       |
   20|      5|   const SIMD_8x32 CTR_LO = SIMD_8x32::splat(state[12]) + SIMD_8x32(0, 1, 2, 3, 4, 5, 6, 7);
   21|       |   // Carry into the high counter word for lanes whose low word wrapped
   22|      5|   const SIMD_8x32 CTR_HI = SIMD_8x32::splat(state[13]) - CTR_LO.unsigned_lt(SIMD_8x32::splat(state[12]));
   23|       |
   24|      5|   SIMD_8x32 R00 = SIMD_8x32::splat(state[0]);
   25|      5|   SIMD_8x32 R01 = SIMD_8x32::splat(state[1]);
   26|      5|   SIMD_8x32 R02 = SIMD_8x32::splat(state[2]);
   27|      5|   SIMD_8x32 R03 = SIMD_8x32::splat(state[3]);
   28|      5|   SIMD_8x32 R04 = SIMD_8x32::splat(state[4]);
   29|      5|   SIMD_8x32 R05 = SIMD_8x32::splat(state[5]);
   30|      5|   SIMD_8x32 R06 = SIMD_8x32::splat(state[6]);
   31|      5|   SIMD_8x32 R07 = SIMD_8x32::splat(state[7]);
   32|      5|   SIMD_8x32 R08 = SIMD_8x32::splat(state[8]);
   33|      5|   SIMD_8x32 R09 = SIMD_8x32::splat(state[9]);
   34|      5|   SIMD_8x32 R10 = SIMD_8x32::splat(state[10]);
   35|      5|   SIMD_8x32 R11 = SIMD_8x32::splat(state[11]);
   36|      5|   SIMD_8x32 R12 = CTR_LO;
   37|      5|   SIMD_8x32 R13 = CTR_HI;
   38|      5|   SIMD_8x32 R14 = SIMD_8x32::splat(state[14]);
   39|      5|   SIMD_8x32 R15 = SIMD_8x32::splat(state[15]);
   40|       |
   41|     55|   for(size_t r = 0; r != rounds / 2; ++r) {
  ------------------
  |  Branch (41:22): [True: 50, False: 5]
  ------------------
   42|     50|      R00 += R04;
   43|     50|      R01 += R05;
   44|     50|      R02 += R06;
   45|     50|      R03 += R07;
   46|       |
   47|     50|      R12 ^= R00;
   48|     50|      R13 ^= R01;
   49|     50|      R14 ^= R02;
   50|     50|      R15 ^= R03;
   51|       |
   52|     50|      R12 = R12.rotl<16>();
   53|     50|      R13 = R13.rotl<16>();
   54|     50|      R14 = R14.rotl<16>();
   55|     50|      R15 = R15.rotl<16>();
   56|       |
   57|     50|      R08 += R12;
   58|     50|      R09 += R13;
   59|     50|      R10 += R14;
   60|     50|      R11 += R15;
   61|       |
   62|     50|      R04 ^= R08;
   63|     50|      R05 ^= R09;
   64|     50|      R06 ^= R10;
   65|     50|      R07 ^= R11;
   66|       |
   67|     50|      R04 = R04.rotl<12>();
   68|     50|      R05 = R05.rotl<12>();
   69|     50|      R06 = R06.rotl<12>();
   70|     50|      R07 = R07.rotl<12>();
   71|       |
   72|     50|      R00 += R04;
   73|     50|      R01 += R05;
   74|     50|      R02 += R06;
   75|     50|      R03 += R07;
   76|       |
   77|     50|      R12 ^= R00;
   78|     50|      R13 ^= R01;
   79|     50|      R14 ^= R02;
   80|     50|      R15 ^= R03;
   81|       |
   82|     50|      R12 = R12.rotl<8>();
   83|     50|      R13 = R13.rotl<8>();
   84|     50|      R14 = R14.rotl<8>();
   85|     50|      R15 = R15.rotl<8>();
   86|       |
   87|     50|      R08 += R12;
   88|     50|      R09 += R13;
   89|     50|      R10 += R14;
   90|     50|      R11 += R15;
   91|       |
   92|     50|      R04 ^= R08;
   93|     50|      R05 ^= R09;
   94|     50|      R06 ^= R10;
   95|     50|      R07 ^= R11;
   96|       |
   97|     50|      R04 = R04.rotl<7>();
   98|     50|      R05 = R05.rotl<7>();
   99|     50|      R06 = R06.rotl<7>();
  100|     50|      R07 = R07.rotl<7>();
  101|       |
  102|     50|      R00 += R05;
  103|     50|      R01 += R06;
  104|     50|      R02 += R07;
  105|     50|      R03 += R04;
  106|       |
  107|     50|      R15 ^= R00;
  108|     50|      R12 ^= R01;
  109|     50|      R13 ^= R02;
  110|     50|      R14 ^= R03;
  111|       |
  112|     50|      R15 = R15.rotl<16>();
  113|     50|      R12 = R12.rotl<16>();
  114|     50|      R13 = R13.rotl<16>();
  115|     50|      R14 = R14.rotl<16>();
  116|       |
  117|     50|      R10 += R15;
  118|     50|      R11 += R12;
  119|     50|      R08 += R13;
  120|     50|      R09 += R14;
  121|       |
  122|     50|      R05 ^= R10;
  123|     50|      R06 ^= R11;
  124|     50|      R07 ^= R08;
  125|     50|      R04 ^= R09;
  126|       |
  127|     50|      R05 = R05.rotl<12>();
  128|     50|      R06 = R06.rotl<12>();
  129|     50|      R07 = R07.rotl<12>();
  130|     50|      R04 = R04.rotl<12>();
  131|       |
  132|     50|      R00 += R05;
  133|     50|      R01 += R06;
  134|     50|      R02 += R07;
  135|     50|      R03 += R04;
  136|       |
  137|     50|      R15 ^= R00;
  138|     50|      R12 ^= R01;
  139|     50|      R13 ^= R02;
  140|     50|      R14 ^= R03;
  141|       |
  142|     50|      R15 = R15.rotl<8>();
  143|     50|      R12 = R12.rotl<8>();
  144|     50|      R13 = R13.rotl<8>();
  145|     50|      R14 = R14.rotl<8>();
  146|       |
  147|     50|      R10 += R15;
  148|     50|      R11 += R12;
  149|     50|      R08 += R13;
  150|     50|      R09 += R14;
  151|       |
  152|     50|      R05 ^= R10;
  153|     50|      R06 ^= R11;
  154|     50|      R07 ^= R08;
  155|     50|      R04 ^= R09;
  156|       |
  157|     50|      R05 = R05.rotl<7>();
  158|     50|      R06 = R06.rotl<7>();
  159|     50|      R07 = R07.rotl<7>();
  160|     50|      R04 = R04.rotl<7>();
  161|     50|   }
  162|       |
  163|      5|   R00 += SIMD_8x32::splat(state[0]);
  164|      5|   R01 += SIMD_8x32::splat(state[1]);
  165|      5|   R02 += SIMD_8x32::splat(state[2]);
  166|      5|   R03 += SIMD_8x32::splat(state[3]);
  167|      5|   R04 += SIMD_8x32::splat(state[4]);
  168|      5|   R05 += SIMD_8x32::splat(state[5]);
  169|      5|   R06 += SIMD_8x32::splat(state[6]);
  170|      5|   R07 += SIMD_8x32::splat(state[7]);
  171|      5|   R08 += SIMD_8x32::splat(state[8]);
  172|      5|   R09 += SIMD_8x32::splat(state[9]);
  173|      5|   R10 += SIMD_8x32::splat(state[10]);
  174|      5|   R11 += SIMD_8x32::splat(state[11]);
  175|      5|   R12 += CTR_LO;
  176|      5|   R13 += CTR_HI;
  177|      5|   R14 += SIMD_8x32::splat(state[14]);
  178|      5|   R15 += SIMD_8x32::splat(state[15]);
  179|       |
  180|      5|   SIMD_8x32::transpose(R00, R01, R02, R03, R04, R05, R06, R07);
  181|      5|   SIMD_8x32::transpose(R08, R09, R10, R11, R12, R13, R14, R15);
  182|       |
  183|      5|   R00.store_le(output);
  184|      5|   R08.store_le(output + 32 * 1);
  185|      5|   R01.store_le(output + 32 * 2);
  186|      5|   R09.store_le(output + 32 * 3);
  187|      5|   R02.store_le(output + 32 * 4);
  188|      5|   R10.store_le(output + 32 * 5);
  189|      5|   R03.store_le(output + 32 * 6);
  190|      5|   R11.store_le(output + 32 * 7);
  191|      5|   R04.store_le(output + 32 * 8);
  192|      5|   R12.store_le(output + 32 * 9);
  193|      5|   R05.store_le(output + 32 * 10);
  194|      5|   R13.store_le(output + 32 * 11);
  195|      5|   R06.store_le(output + 32 * 12);
  196|      5|   R14.store_le(output + 32 * 13);
  197|      5|   R07.store_le(output + 32 * 14);
  198|      5|   R15.store_le(output + 32 * 15);
  199|       |
  200|      5|   SIMD_8x32::zero_registers();
  201|       |
  202|      5|   state[12] += 8;
  203|      5|   if(state[12] < 8) {
  ------------------
  |  Branch (203:7): [True: 0, False: 5]
  ------------------
  204|      0|      state[13]++;
  205|      0|   }
  206|      5|}

_ZN5Botan12StreamCipher6createENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEES5_:
   40|      1|std::unique_ptr<StreamCipher> StreamCipher::create(std::string_view algo_spec, std::string_view provider) {
   41|      1|#if defined(BOTAN_HAS_SHAKE_CIPHER)
   42|      1|   if(algo_spec == "SHAKE-128" || algo_spec == "SHAKE-128-XOF") {
  ------------------
  |  Branch (42:7): [True: 0, False: 1]
  |  Branch (42:35): [True: 0, False: 1]
  ------------------
   43|      0|      if(provider.empty() || provider == "base") {
  ------------------
  |  Branch (43:10): [True: 0, False: 0]
  |  Branch (43:30): [True: 0, False: 0]
  ------------------
   44|      0|         return std::make_unique<SHAKE_128_Cipher>();
   45|      0|      }
   46|      0|   }
   47|       |
   48|      1|   if(algo_spec == "SHAKE-256" || algo_spec == "SHAKE-256-XOF") {
  ------------------
  |  Branch (48:7): [True: 0, False: 1]
  |  Branch (48:35): [True: 0, False: 1]
  ------------------
   49|      0|      if(provider.empty() || provider == "base") {
  ------------------
  |  Branch (49:10): [True: 0, False: 0]
  |  Branch (49:30): [True: 0, False: 0]
  ------------------
   50|      0|         return std::make_unique<SHAKE_256_Cipher>();
   51|      0|      }
   52|      0|   }
   53|      1|#endif
   54|       |
   55|      1|#if defined(BOTAN_HAS_CHACHA)
   56|      1|   if(algo_spec == "ChaCha20") {
  ------------------
  |  Branch (56:7): [True: 0, False: 1]
  ------------------
   57|      0|      if(provider.empty() || provider == "base") {
  ------------------
  |  Branch (57:10): [True: 0, False: 0]
  |  Branch (57:30): [True: 0, False: 0]
  ------------------
   58|      0|         return std::make_unique<ChaCha>(20);
   59|      0|      }
   60|      0|   }
   61|      1|#endif
   62|       |
   63|      1|#if defined(BOTAN_HAS_SALSA20)
   64|      1|   if(algo_spec == "Salsa20") {
  ------------------
  |  Branch (64:7): [True: 0, False: 1]
  ------------------
   65|      0|      if(provider.empty() || provider == "base") {
  ------------------
  |  Branch (65:10): [True: 0, False: 0]
  |  Branch (65:30): [True: 0, False: 0]
  ------------------
   66|      0|         return std::make_unique<Salsa20>();
   67|      0|      }
   68|      0|   }
   69|      1|#endif
   70|       |
   71|      1|   const SCAN_Name req(algo_spec);
   72|       |
   73|      1|#if defined(BOTAN_HAS_CTR_BE)
   74|      1|   if((req.algo_name() == "CTR-BE" || req.algo_name() == "CTR") && req.arg_count_between(1, 2)) {
  ------------------
  |  Branch (74:8): [True: 0, False: 1]
  |  Branch (74:39): [True: 0, False: 1]
  |  Branch (74:68): [True: 0, False: 0]
  ------------------
   75|      0|      if(provider.empty() || provider == "base") {
  ------------------
  |  Branch (75:10): [True: 0, False: 0]
  |  Branch (75:30): [True: 0, False: 0]
  ------------------
   76|      0|         auto cipher = BlockCipher::create(req.arg(0));
   77|      0|         if(cipher) {
  ------------------
  |  Branch (77:13): [True: 0, False: 0]
  ------------------
   78|      0|            const size_t ctr_size = req.arg_as_integer(1, cipher->block_size());
   79|      0|            return std::make_unique<CTR_BE>(std::move(cipher), ctr_size);
   80|      0|         }
   81|      0|      }
   82|      0|   }
   83|      1|#endif
   84|       |
   85|      1|#if defined(BOTAN_HAS_CHACHA)
   86|      1|   if(req.algo_name() == "ChaCha") {
  ------------------
  |  Branch (86:7): [True: 1, False: 0]
  ------------------
   87|      1|      if(provider.empty() || provider == "base") {
  ------------------
  |  Branch (87:10): [True: 1, False: 0]
  |  Branch (87:30): [True: 0, False: 0]
  ------------------
   88|      1|         return std::make_unique<ChaCha>(req.arg_as_integer(0, 20));
   89|      1|      }
   90|      1|   }
   91|      0|#endif
   92|       |
   93|      0|#if defined(BOTAN_HAS_OFB)
   94|      0|   if(req.algo_name() == "OFB" && req.arg_count() == 1) {
  ------------------
  |  Branch (94:7): [True: 0, False: 0]
  |  Branch (94:35): [True: 0, False: 0]
  ------------------
   95|      0|      if(provider.empty() || provider == "base") {
  ------------------
  |  Branch (95:10): [True: 0, False: 0]
  |  Branch (95:30): [True: 0, False: 0]
  ------------------
   96|      0|         if(auto cipher = BlockCipher::create(req.arg(0))) {
  ------------------
  |  Branch (96:18): [True: 0, False: 0]
  ------------------
   97|      0|            return std::make_unique<OFB>(std::move(cipher));
   98|      0|         }
   99|      0|      }
  100|      0|   }
  101|      0|#endif
  102|       |
  103|      0|#if defined(BOTAN_HAS_RC4)
  104|       |
  105|      0|   if(req.algo_name() == "RC4" || req.algo_name() == "ARC4" || req.algo_name() == "MARK-4") {
  ------------------
  |  Branch (105:7): [True: 0, False: 0]
  |  Branch (105:35): [True: 0, False: 0]
  |  Branch (105:64): [True: 0, False: 0]
  ------------------
  106|      0|      const size_t skip = (req.algo_name() == "MARK-4") ? 256 : req.arg_as_integer(0, 0);
  ------------------
  |  Branch (106:27): [True: 0, False: 0]
  ------------------
  107|       |
  108|      0|      if(provider.empty() || provider == "base") {
  ------------------
  |  Branch (108:10): [True: 0, False: 0]
  |  Branch (108:30): [True: 0, False: 0]
  ------------------
  109|      0|         return std::make_unique<RC4>(skip);
  110|      0|      }
  111|      0|   }
  112|       |
  113|      0|#endif
  114|       |
  115|      0|   BOTAN_UNUSED(req);
  ------------------
  |  |  144|      0|#define BOTAN_UNUSED Botan::ignore_params
  ------------------
  116|      0|   BOTAN_UNUSED(provider);
  ------------------
  |  |  144|      0|#define BOTAN_UNUSED Botan::ignore_params
  ------------------
  117|       |
  118|      0|   return nullptr;
  119|      0|}
_ZN5Botan12StreamCipher15create_or_throwENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEES5_:
  122|      1|std::unique_ptr<StreamCipher> StreamCipher::create_or_throw(std::string_view algo, std::string_view provider) {
  123|      1|   if(auto sc = StreamCipher::create(algo, provider)) {
  ------------------
  |  Branch (123:12): [True: 1, False: 0]
  ------------------
  124|      1|      return sc;
  125|      1|   }
  126|      0|   throw Lookup_Error("Stream cipher", algo, provider);
  127|      1|}

_ZN5Botan15allocate_memoryEmm:
   21|   262k|BOTAN_MALLOC_FN void* allocate_memory(size_t elems, size_t elem_size) {
   22|   262k|   if(elems == 0 || elem_size == 0) {
  ------------------
  |  Branch (22:7): [True: 0, False: 262k]
  |  Branch (22:21): [True: 0, False: 262k]
  ------------------
   23|      0|      return nullptr;
   24|      0|   }
   25|       |
   26|       |   // Some calloc implementations do not check for overflow (?!?)
   27|   262k|   if(!checked_mul(elems, elem_size).has_value()) {
  ------------------
  |  Branch (27:7): [True: 0, False: 262k]
  ------------------
   28|      0|      throw std::bad_alloc();
   29|      0|   }
   30|       |
   31|       |#if defined(BOTAN_HAS_LOCKING_ALLOCATOR)
   32|       |   // NOLINTNEXTLINE(*-const-correctness) bug in clang-tidy
   33|       |   if(void* p = mlock_allocator::instance().allocate(elems, elem_size)) {
   34|       |      return p;
   35|       |   }
   36|       |#endif
   37|       |
   38|       |#if defined(BOTAN_TARGET_OS_HAS_ALLOC_CONCEAL)
   39|       |   void* ptr = ::calloc_conceal(elems, elem_size);
   40|       |#else
   41|       |   // NOLINTNEXTLINE(*-const-correctness) bug in clang-tidy
   42|   262k|   void* ptr = std::calloc(elems, elem_size);  // NOLINT(*-no-malloc,*-owning-memory)
   43|   262k|#endif
   44|   262k|   if(ptr == nullptr) {
  ------------------
  |  Branch (44:7): [True: 0, False: 262k]
  ------------------
   45|      0|      [[unlikely]] throw std::bad_alloc();
   46|      0|   }
   47|   262k|   return ptr;
   48|   262k|}
_ZN5Botan17deallocate_memoryEPvmm:
   50|   262k|void deallocate_memory(void* p, size_t elems, size_t elem_size) {
   51|   262k|   if(p == nullptr) {
  ------------------
  |  Branch (51:7): [True: 0, False: 262k]
  ------------------
   52|      0|      [[unlikely]] return;
   53|      0|   }
   54|       |
   55|   262k|   secure_scrub_memory(p, elems * elem_size);
   56|       |
   57|       |#if defined(BOTAN_HAS_LOCKING_ALLOCATOR)
   58|       |   if(mlock_allocator::instance().deallocate(p, elems, elem_size)) {
   59|       |      return;
   60|       |   }
   61|       |#endif
   62|       |
   63|   262k|   std::free(p);  // NOLINT(*-no-malloc,*-owning-memory)
   64|   262k|}

_ZN5Botan22throw_invalid_argumentEPKcS1_S1_:
   23|      1|void throw_invalid_argument(const char* message, const char* func, const char* file) {
   24|      1|   throw Invalid_Argument(fmt("{} in {}:{}", message, func, file));
   25|      1|}

_ZN5Botan5CPUID10CPUID_DataC2Ev:
   80|      1|CPUID::CPUID_Data::CPUID_Data() {
   81|       |   // NOLINTBEGIN(*-prefer-member-initializer)
   82|      1|#if defined(BOTAN_HAS_CPUID_DETECTION)
   83|      1|   m_processor_features = detect_cpu_features(~cleared_cpuid_bits());
   84|       |#else
   85|       |   m_processor_features = 0;
   86|       |#endif
   87|       |   // NOLINTEND(*-prefer-member-initializer)
   88|      1|}
cpuid.cpp:_ZN5Botan12_GLOBAL__N_118cleared_cpuid_bitsEv:
   59|      1|uint32_t cleared_cpuid_bits() {
   60|      1|   uint32_t cleared = 0;
   61|       |
   62|      1|   #if defined(BOTAN_HAS_OS_UTILS)
   63|      1|   std::string clear_cpuid_env;
   64|      1|   if(OS::read_env_variable(clear_cpuid_env, "BOTAN_CLEAR_CPUID")) {
  ------------------
  |  Branch (64:7): [True: 0, False: 1]
  ------------------
   65|      0|      for(const auto& cpuid : split_on(clear_cpuid_env, ',')) {
  ------------------
  |  Branch (65:29): [True: 0, False: 0]
  ------------------
   66|      0|         if(auto bit = CPUID::bit_from_string(cpuid)) {
  ------------------
  |  Branch (66:18): [True: 0, False: 0]
  ------------------
   67|      0|            cleared |= bit->as_u32();
   68|      0|         }
   69|      0|      }
   70|      0|   }
   71|      1|   #endif
   72|       |
   73|      1|   return cleared;
   74|      1|}

_ZN5Botan5CPUID10CPUID_Data19detect_cpu_featuresEj:
   62|      1|uint32_t CPUID::CPUID_Data::detect_cpu_features(uint32_t allowed) {
   63|      1|   enum class x86_CPUID_1_bits : uint64_t {
   64|      1|      RDTSC = (1ULL << 4),
   65|      1|      SSE2 = (1ULL << 26),
   66|      1|      CLMUL = (1ULL << 33),
   67|      1|      SSSE3 = (1ULL << 41),
   68|      1|      SSE41 = (1ULL << 51),
   69|      1|      AESNI = (1ULL << 57),
   70|       |      // AVX + OSXSAVE
   71|      1|      OSXSAVE = (1ULL << 59) | (1ULL << 60),
   72|      1|      RDRAND = (1ULL << 62)
   73|      1|   };
   74|       |
   75|      1|   enum class x86_CPUID_7_bits : uint64_t {
   76|      1|      BMI1 = (1ULL << 3),
   77|      1|      AVX2 = (1ULL << 5),
   78|      1|      BMI2 = (1ULL << 8),
   79|      1|      BMI_1_AND_2 = BMI1 | BMI2,
   80|      1|      AVX512_F = (1ULL << 16),
   81|      1|      AVX512_DQ = (1ULL << 17),
   82|      1|      RDSEED = (1ULL << 18),
   83|      1|      ADX = (1ULL << 19),
   84|      1|      AVX512_IFMA = (1ULL << 21),
   85|      1|      SHA = (1ULL << 29),
   86|      1|      AVX512_BW = (1ULL << 30),
   87|      1|      AVX512_VL = (1ULL << 31),
   88|      1|      AVX512_VBMI = (1ULL << 33),
   89|      1|      AVX512_VBMI2 = (1ULL << 38),
   90|      1|      GFNI = (1ULL << 40),
   91|      1|      AVX512_VAES = (1ULL << 41),
   92|      1|      AVX512_VCLMUL = (1ULL << 42),
   93|      1|      AVX512_VBITALG = (1ULL << 44),
   94|       |
   95|       |      /*
   96|       |      We only enable AVX512 support if all of the below flags are available
   97|       |
   98|       |      This is more than we strictly need for most uses, however it also has
   99|       |      the effect of preventing execution of AVX512 codepaths on cores that
  100|       |      have serious downclocking problems when AVX512 code executes,
  101|       |      especially Intel Skylake.
  102|       |
  103|       |      VBMI2/VBITALG are the key flags here as they restrict us to Intel Ice
  104|       |      Lake/Rocket Lake, or AMD Zen4, all of which do not have penalties for
  105|       |      executing AVX512.
  106|       |
  107|       |      There is nothing stopping some future processor from supporting the
  108|       |      above flags and having AVX512 penalties, but maybe you should not have
  109|       |      bought such a processor.
  110|       |      */
  111|      1|      AVX512_PROFILE =
  112|      1|         AVX512_F | AVX512_DQ | AVX512_IFMA | AVX512_BW | AVX512_VL | AVX512_VBMI | AVX512_VBMI2 | AVX512_VBITALG,
  113|      1|   };
  114|       |
  115|       |   // NOLINTNEXTLINE(performance-enum-size)
  116|      1|   enum class x86_CPUID_7_1_bits : uint64_t {
  117|      1|      SHA512 = (1 << 0),
  118|      1|      SM3 = (1 << 1),
  119|      1|      SM4 = (1 << 2),
  120|      1|   };
  121|       |
  122|      1|   uint32_t feat = 0;
  123|      1|   uint32_t cpuid[4] = {0};
  124|      1|   bool has_os_ymm_support = false;
  125|      1|   bool has_os_zmm_support = false;
  126|       |
  127|       |   // CPUID 0: vendor identification, max sublevel
  128|      1|   invoke_cpuid(0, cpuid);
  129|       |
  130|      1|   const uint32_t max_supported_sublevel = cpuid[0];
  131|       |
  132|      1|   if(max_supported_sublevel >= 1) {
  ------------------
  |  Branch (132:7): [True: 1, False: 0]
  ------------------
  133|       |      // CPUID 1: feature bits
  134|      1|      invoke_cpuid(1, cpuid);
  135|      1|      const uint64_t flags0 = (static_cast<uint64_t>(cpuid[2]) << 32) | cpuid[3];
  136|       |
  137|      1|      feat |= if_set(flags0, x86_CPUID_1_bits::RDTSC, CPUFeature::Bit::RDTSC, allowed);
  138|       |
  139|      1|      feat |= if_set(flags0, x86_CPUID_1_bits::RDRAND, CPUFeature::Bit::RDRAND, allowed);
  140|       |
  141|      1|      feat |= if_set(flags0, x86_CPUID_1_bits::SSE2, CPUFeature::Bit::SSE2, allowed);
  142|       |
  143|      1|      if(is_set(feat, CPUFeature::Bit::SSE2)) {
  ------------------
  |  Branch (143:10): [True: 1, False: 0]
  ------------------
  144|      1|         feat |= if_set(flags0, x86_CPUID_1_bits::SSSE3, CPUFeature::Bit::SSSE3, allowed);
  145|       |
  146|      1|         if(is_set(feat, CPUFeature::Bit::SSSE3)) {
  ------------------
  |  Branch (146:13): [True: 1, False: 0]
  ------------------
  147|      1|            feat |= if_set(flags0, x86_CPUID_1_bits::CLMUL, CPUFeature::Bit::CLMUL, allowed);
  148|      1|            feat |= if_set(flags0, x86_CPUID_1_bits::AESNI, CPUFeature::Bit::AESNI, allowed);
  149|      1|         }
  150|       |
  151|      1|         const uint64_t osxsave64 = static_cast<uint64_t>(x86_CPUID_1_bits::OSXSAVE);
  152|      1|         if((flags0 & osxsave64) == osxsave64) {
  ------------------
  |  Branch (152:13): [True: 1, False: 0]
  ------------------
  153|      1|            const uint64_t xcr_flags = xgetbv();
  154|      1|            if((xcr_flags & 0x6) == 0x6) {
  ------------------
  |  Branch (154:16): [True: 1, False: 0]
  ------------------
  155|      1|               has_os_ymm_support = true;
  156|      1|               has_os_zmm_support = (xcr_flags & 0xE0) == 0xE0;
  157|      1|            }
  158|      1|         }
  159|      1|      }
  160|      1|   }
  161|       |
  162|      1|   if(max_supported_sublevel >= 7) {
  ------------------
  |  Branch (162:7): [True: 1, False: 0]
  ------------------
  163|      1|      clear_mem(cpuid, 4);
  164|      1|      invoke_cpuid_sublevel(7, 0, cpuid);
  165|       |
  166|      1|      const uint64_t flags7 = (static_cast<uint64_t>(cpuid[2]) << 32) | cpuid[1];
  167|       |
  168|      1|      clear_mem(cpuid, 4);
  169|      1|      invoke_cpuid_sublevel(7, 1, cpuid);
  170|      1|      const uint32_t flags7_1 = cpuid[0];
  171|       |
  172|      1|      feat |= if_set(flags7, x86_CPUID_7_bits::RDSEED, CPUFeature::Bit::RDSEED, allowed);
  173|      1|      feat |= if_set(flags7, x86_CPUID_7_bits::ADX, CPUFeature::Bit::ADX, allowed);
  174|       |
  175|       |      /*
  176|       |      We only set the BMI bit if both BMI1 and BMI2 are supported, since
  177|       |      typically we want to use both extensions in the same code.
  178|       |      */
  179|      1|      feat |= if_set(flags7, x86_CPUID_7_bits::BMI_1_AND_2, CPUFeature::Bit::BMI, allowed);
  180|       |
  181|      1|      if(is_set(feat, CPUFeature::Bit::SSSE3)) {
  ------------------
  |  Branch (181:10): [True: 1, False: 0]
  ------------------
  182|      1|         feat |= if_set(flags7, x86_CPUID_7_bits::SHA, CPUFeature::Bit::SHA, allowed);
  183|      1|         feat |= if_set(flags7_1, x86_CPUID_7_1_bits::SM3, CPUFeature::Bit::SM3, allowed);
  184|       |
  185|       |         // We only consider AVX2 if SSSE3 is supported
  186|      1|         if(has_os_ymm_support) {
  ------------------
  |  Branch (186:13): [True: 1, False: 0]
  ------------------
  187|      1|            feat |= if_set(flags7, x86_CPUID_7_bits::AVX2, CPUFeature::Bit::AVX2, allowed);
  188|       |
  189|      1|            if(is_set(feat, CPUFeature::Bit::AVX2)) {
  ------------------
  |  Branch (189:16): [True: 1, False: 0]
  ------------------
  190|      1|               feat |= if_set(flags7, x86_CPUID_7_bits::GFNI, CPUFeature::Bit::GFNI, allowed);
  191|      1|               feat |= if_set(flags7, x86_CPUID_7_bits::AVX512_VAES, CPUFeature::Bit::AVX2_AES, allowed);
  192|      1|               feat |= if_set(flags7, x86_CPUID_7_bits::AVX512_VCLMUL, CPUFeature::Bit::AVX2_CLMUL, allowed);
  193|      1|               feat |= if_set(flags7_1, x86_CPUID_7_1_bits::SHA512, CPUFeature::Bit::SHA512, allowed);
  194|      1|               feat |= if_set(flags7_1, x86_CPUID_7_1_bits::SM4, CPUFeature::Bit::SM4, allowed);
  195|       |
  196|       |               // Likewise we only consider AVX-512 if AVX2 is supported
  197|      1|               if(has_os_zmm_support) {
  ------------------
  |  Branch (197:19): [True: 0, False: 1]
  ------------------
  198|      0|                  feat |= if_set(flags7, x86_CPUID_7_bits::AVX512_PROFILE, CPUFeature::Bit::AVX512, allowed);
  199|       |
  200|      0|                  if(is_set(feat, CPUFeature::Bit::AVX512)) {
  ------------------
  |  Branch (200:22): [True: 0, False: 0]
  ------------------
  201|      0|                     feat |= if_set(flags7, x86_CPUID_7_bits::AVX512_VAES, CPUFeature::Bit::AVX512_AES, allowed);
  202|      0|                     feat |= if_set(flags7, x86_CPUID_7_bits::AVX512_VCLMUL, CPUFeature::Bit::AVX512_CLMUL, allowed);
  203|      0|                  }
  204|      0|               }
  205|      1|            }
  206|      1|         }
  207|      1|      }
  208|      1|   }
  209|       |
  210|       |/*
  211|       |   * If we don't have access to CPUID, we can still safely assume that
  212|       |   * any x86-64 processor has SSE2 and RDTSC
  213|       |   */
  214|      1|#if defined(BOTAN_TARGET_ARCH_IS_X86_64)
  215|      1|   if(feat == 0) {
  ------------------
  |  Branch (215:7): [True: 0, False: 1]
  ------------------
  216|      0|      feat |= CPUFeature::Bit::SSE2 & allowed;
  217|      0|      feat |= CPUFeature::Bit::RDTSC & allowed;
  218|      0|   }
  219|      1|#endif
  220|       |
  221|      1|   return feat;
  222|      1|}
cpuid_x86.cpp:_ZN5Botan12_GLOBAL__N_112invoke_cpuidEjPj:
   24|      2|void invoke_cpuid(uint32_t type, uint32_t out[4]) {
   25|      2|   clear_mem(out, 4);
   26|       |
   27|      2|#if defined(BOTAN_USE_GCC_INLINE_ASM)
   28|       |   // NOLINTNEXTLINE(*-no-assembler)
   29|      2|   asm volatile("cpuid\n\t" : "=a"(out[0]), "=b"(out[1]), "=c"(out[2]), "=d"(out[3]) : "0"(type));
   30|       |
   31|       |#elif defined(BOTAN_BUILD_COMPILER_IS_MSVC)
   32|       |   __cpuid((int*)out, type);
   33|       |
   34|       |#else
   35|       |   BOTAN_UNUSED(type);
   36|       |   #warning "No way of calling x86 cpuid instruction for this compiler"
   37|       |#endif
   38|      2|}
cpuid_x86.cpp:_ZN5Botan12_GLOBAL__N_16xgetbvEv:
   56|      1|BOTAN_FUNC_ISA("xsave") uint64_t xgetbv() {
   57|       |   return _xgetbv(0);
   58|      1|}
cpuid_x86.cpp:_ZN5Botan12_GLOBAL__N_121invoke_cpuid_sublevelEjjPj:
   40|      2|void invoke_cpuid_sublevel(uint32_t type, uint32_t level, uint32_t out[4]) {
   41|      2|   clear_mem(out, 4);
   42|       |
   43|      2|#if defined(BOTAN_USE_GCC_INLINE_ASM)
   44|       |   // NOLINTNEXTLINE(*-no-assembler)
   45|      2|   asm volatile("cpuid\n\t" : "=a"(out[0]), "=b"(out[1]), "=c"(out[2]), "=d"(out[3]) : "0"(type), "2"(level));
   46|       |
   47|       |#elif defined(BOTAN_BUILD_COMPILER_IS_MSVC)
   48|       |   __cpuidex((int*)out, type, level);
   49|       |
   50|       |#else
   51|       |   BOTAN_UNUSED(type, level);
   52|       |   #warning "No way of calling x86 cpuid instruction for this compiler"
   53|       |#endif
   54|      2|}

_ZN5Botan9ExceptionC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
   71|      1|Exception::Exception(std::string_view msg) : m_msg(msg) {}
_ZN5Botan16Invalid_ArgumentC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
   77|      1|Invalid_Argument::Invalid_Argument(std::string_view msg) : Exception(msg) {}

_ZN5Botan19secure_scrub_memoryEPvm:
   25|   262k|void secure_scrub_memory(void* ptr, size_t n) {
   26|   262k|   return secure_zeroize_buffer(ptr, n);
   27|   262k|}
_ZN5Botan21secure_zeroize_bufferEPvm:
   29|   262k|void secure_zeroize_buffer(void* ptr, size_t n) {
   30|   262k|   if(n == 0) {
  ------------------
  |  Branch (30:7): [True: 0, False: 262k]
  ------------------
   31|      0|      return;
   32|      0|   }
   33|       |
   34|       |#if defined(BOTAN_TARGET_OS_HAS_RTLSECUREZEROMEMORY)
   35|       |   ::RtlSecureZeroMemory(ptr, n);
   36|       |
   37|       |#elif defined(BOTAN_TARGET_OS_HAS_EXPLICIT_BZERO)
   38|   262k|   ::explicit_bzero(ptr, n);
   39|       |
   40|       |#elif defined(BOTAN_TARGET_OS_HAS_EXPLICIT_MEMSET)
   41|       |   (void)::explicit_memset(ptr, 0, n);
   42|       |
   43|       |#else
   44|       |   /*
   45|       |   * Call memset through a static volatile pointer, which the compiler should
   46|       |   * not elide. This construct should be safe in conforming compilers, but who
   47|       |   * knows. This has been checked to generate the expected code, which saves the
   48|       |   * memset address in the data segment and unconditionally loads and jumps to
   49|       |   * that address, with the following targets:
   50|       |   *
   51|       |   * x86-64: Clang 19, GCC 6, 11, 13, 14
   52|       |   * riscv64: GCC 14
   53|       |   * aarch64: GCC 14
   54|       |   * armv7: GCC 14
   55|       |   *
   56|       |   * Actually all of them generated the expected jump even without marking the
   57|       |   * function pointer as volatile. However this seems worth including as an
   58|       |   * additional precaution.
   59|       |   */
   60|       |   static void* (*const volatile memset_ptr)(void*, int, size_t) = std::memset;
   61|       |   (memset_ptr)(ptr, 0, n);
   62|       |#endif
   63|   262k|}

_ZN5Botan2OS14get_process_idEv:
   77|     54|uint32_t OS::get_process_id() {
   78|     54|#if defined(BOTAN_TARGET_OS_HAS_POSIX1)
   79|     54|   return ::getpid();
   80|       |#elif defined(BOTAN_TARGET_OS_HAS_WIN32)
   81|       |   return ::GetCurrentProcessId();
   82|       |#elif defined(BOTAN_TARGET_OS_IS_LLVM) || defined(BOTAN_TARGET_OS_IS_NONE)
   83|       |   return 0;  // truly no meaningful value
   84|       |#else
   85|       |   #error "Missing get_process_id"
   86|       |#endif
   87|     54|}
_ZN5Botan2OS17read_env_variableERNSt3__112basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEENS1_17basic_string_viewIcS4_EE:
  449|      1|bool OS::read_env_variable(std::string& value_out, std::string_view name_view) {
  450|      1|   value_out = "";
  451|       |
  452|      1|   if(running_in_privileged_state()) {
  ------------------
  |  Branch (452:7): [True: 0, False: 1]
  ------------------
  453|      0|      return false;
  454|      0|   }
  455|       |
  456|       |#if defined(BOTAN_TARGET_OS_HAS_WIN32) && \
  457|       |   (defined(BOTAN_BUILD_COMPILER_IS_MSVC) || defined(BOTAN_BUILD_COMPILER_IS_CLANGCL))
  458|       |   const std::string name(name_view);
  459|       |   char val[128] = {0};
  460|       |   size_t req_size = 0;
  461|       |   if(getenv_s(&req_size, val, sizeof(val), name.c_str()) == 0) {
  462|       |      // Microsoft's implementation always writes a terminating \0,
  463|       |      // and includes it in the reported length of the environment variable
  464|       |      // if a value exists.
  465|       |      if(req_size > 0 && val[req_size - 1] == '\0') {
  466|       |         value_out = std::string(val);
  467|       |      } else {
  468|       |         value_out = std::string(val, req_size);
  469|       |      }
  470|       |      return true;
  471|       |   }
  472|       |#else
  473|      1|   const std::string name(name_view);
  474|      1|   if(const char* val = std::getenv(name.c_str())) {
  ------------------
  |  Branch (474:19): [True: 0, False: 1]
  ------------------
  475|      0|      value_out = val;
  476|      0|      return true;
  477|      0|   }
  478|      1|#endif
  479|       |
  480|      1|   return false;
  481|      1|}
os_utils.cpp:_ZN5Botan12_GLOBAL__N_110get_auxvalENSt3__18optionalImEE:
  119|      1|std::optional<unsigned long> get_auxval(std::optional<unsigned long> id) {
  120|      1|   if(id) {
  ------------------
  |  Branch (120:7): [True: 1, False: 0]
  ------------------
  121|      1|#if defined(BOTAN_TARGET_OS_HAS_GETAUXVAL)
  122|      1|      return ::getauxval(*id);
  123|       |#elif defined(BOTAN_TARGET_OS_HAS_ELF_AUX_INFO)
  124|       |      unsigned long auxinfo = 0;
  125|       |      if(::elf_aux_info(static_cast<int>(*id), &auxinfo, sizeof(auxinfo)) == 0) {
  126|       |         return auxinfo;
  127|       |      }
  128|       |#endif
  129|      1|   }
  130|       |
  131|      0|   return {};
  132|      1|}
os_utils.cpp:_ZN5Botan12_GLOBAL__N_127running_in_privileged_stateEv:
  153|      1|bool running_in_privileged_state() {
  154|      1|#if defined(AT_SECURE)
  155|      1|   if(auto at_secure = get_auxval(AT_SECURE)) {
  ------------------
  |  Branch (155:12): [True: 1, False: 0]
  ------------------
  156|      1|      return at_secure != 0;
  157|      1|   }
  158|      0|#endif
  159|       |
  160|      0|#if defined(BOTAN_TARGET_OS_HAS_POSIX1)
  161|      0|   return (::getuid() != ::geteuid()) || (::getgid() != ::getegid());
  ------------------
  |  Branch (161:11): [True: 0, False: 0]
  |  Branch (161:42): [True: 0, False: 0]
  ------------------
  162|       |#else
  163|       |   return false;
  164|       |#endif
  165|      1|}

_ZN5Botan9parse_u32ENSt3__117basic_string_viewIcNS0_11char_traitsIcEEEEb:
   64|      1|std::optional<uint32_t> parse_u32(std::string_view input, bool require_canonical) {
   65|      1|   return parse_decimal_integer<uint32_t>(input, require_canonical);
   66|      1|}
_ZN5Botan9to_u32bitENSt3__117basic_string_viewIcNS0_11char_traitsIcEEEE:
   76|      1|uint32_t to_u32bit(std::string_view input) {
   77|      1|   if(const auto parsed = parse_u32(input)) {
  ------------------
  |  Branch (77:18): [True: 1, False: 0]
  ------------------
   78|      1|      return *parsed;
   79|      1|   } else {
   80|      0|      throw Invalid_Argument(fmt("Failed to parse input '{}' as a 32-bit integer", input));
   81|      0|   }
   82|      1|}
parsing.cpp:_ZN5Botan12_GLOBAL__N_116digit_from_asciiEc:
   23|      2|std::optional<size_t> digit_from_ascii(char c) {
   24|      2|   if(c >= '0' && c <= '9') {
  ------------------
  |  Branch (24:7): [True: 2, False: 0]
  |  Branch (24:19): [True: 2, False: 0]
  ------------------
   25|      2|      return c - '0';
   26|      2|   } else {
   27|      0|      return {};
   28|      0|   }
   29|      2|}
parsing.cpp:_ZN5Botan12_GLOBAL__N_121parse_decimal_integerITkNSt3__117unsigned_integralEjEENS2_8optionalIT_EENS2_17basic_string_viewIcNS2_11char_traitsIcEEEEb:
   32|      1|std::optional<T> parse_decimal_integer(std::string_view input, bool require_canonical) {
   33|      1|   if(input.empty() || input.size() > (std::numeric_limits<T>::digits10 + 1)) {
  ------------------
  |  Branch (33:7): [True: 0, False: 1]
  |  Branch (33:24): [True: 0, False: 1]
  ------------------
   34|      0|      return {};
   35|      0|   }
   36|       |
   37|       |   // The canonical encoding of zero is "0"; no other value starts with a zero
   38|      1|   if(require_canonical && input.size() > 1 && input.front() == '0') {
  ------------------
  |  Branch (38:7): [True: 0, False: 1]
  |  Branch (38:28): [True: 0, False: 0]
  |  Branch (38:48): [True: 0, False: 0]
  ------------------
   39|      0|      return {};
   40|      0|   }
   41|       |
   42|      1|   T accum = 0;
   43|       |
   44|      2|   for(const char c : input) {
  ------------------
  |  Branch (44:21): [True: 2, False: 1]
  ------------------
   45|      2|      if(const auto digit = digit_from_ascii(c)) {
  ------------------
  |  Branch (45:21): [True: 2, False: 0]
  ------------------
   46|      2|         if(accum > (std::numeric_limits<T>::max() - static_cast<T>(*digit)) / 10) {
  ------------------
  |  Branch (46:13): [True: 0, False: 2]
  ------------------
   47|      0|            return {};
   48|      0|         }
   49|      2|         accum = accum * 10 + static_cast<T>(*digit);
   50|      2|      } else {
   51|      0|         return {};
   52|      0|      }
   53|      2|   }
   54|       |
   55|      1|   return accum;
   56|      1|}

_ZN5Botan9SCAN_NameC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
   61|      2|SCAN_Name::SCAN_Name(std::string_view algo_spec) : m_orig_algo_spec(algo_spec) {
   62|      2|   if(algo_spec.empty()) {
  ------------------
  |  Branch (62:7): [True: 0, False: 2]
  ------------------
   63|      0|      throw Invalid_Argument("Expected algorithm name, got empty string");
   64|      0|   }
   65|       |
   66|       |   // Fast path for a bare name with no arguments or modes (eg "SHA-256"),
   67|       |   // which is the common case. Equivalent to the general parse below, which
   68|       |   // for such input produces a single token and no args/modes.
   69|      2|   if(algo_spec.find_first_of("(),/") == std::string_view::npos) {
  ------------------
  |  Branch (69:7): [True: 0, False: 2]
  ------------------
   70|      0|      m_alg_name = std::string(algo_spec);
   71|      0|      return;
   72|      0|   }
   73|       |
   74|      2|   std::vector<std::pair<size_t, std::string>> name;
   75|      2|   size_t level = 0;
   76|      2|   std::pair<size_t, std::string> accum = std::make_pair(level, "");
   77|       |
   78|      2|   bool expect_token = true;
   79|       |
   80|     23|   for(const char c : algo_spec) {
  ------------------
  |  Branch (80:21): [True: 23, False: 2]
  ------------------
   81|     23|      if(c == '/' || c == ',' || c == '(' || c == ')') {
  ------------------
  |  Branch (81:10): [True: 0, False: 23]
  |  Branch (81:22): [True: 0, False: 23]
  |  Branch (81:34): [True: 2, False: 21]
  |  Branch (81:46): [True: 2, False: 19]
  ------------------
   82|      4|         if(c == '(') {
  ------------------
  |  Branch (82:13): [True: 2, False: 2]
  ------------------
   83|      2|            ++level;
   84|      2|         } else if(c == ')') {
  ------------------
  |  Branch (84:20): [True: 2, False: 0]
  ------------------
   85|      2|            if(level == 0) {
  ------------------
  |  Branch (85:16): [True: 0, False: 2]
  ------------------
   86|      0|               throw Invalid_Algorithm_Name(m_orig_algo_spec);
   87|      0|            }
   88|      2|            --level;
   89|      2|         }
   90|       |
   91|      4|         if(c == '/' && level > 0) {
  ------------------
  |  Branch (91:13): [True: 0, False: 4]
  |  Branch (91:25): [True: 0, False: 0]
  ------------------
   92|      0|            accum.second.push_back(c);
   93|      0|            expect_token = false;
   94|      4|         } else {
   95|      4|            if(expect_token) {
  ------------------
  |  Branch (95:16): [True: 0, False: 4]
  ------------------
   96|      0|               throw Invalid_Algorithm_Name(m_orig_algo_spec);
   97|      0|            }
   98|      4|            if(!accum.second.empty()) {
  ------------------
  |  Branch (98:16): [True: 4, False: 0]
  ------------------
   99|      4|               name.push_back(accum);
  100|      4|            }
  101|      4|            accum = std::make_pair(level, "");
  102|      4|            expect_token = (c != ')');
  103|      4|         }
  104|     19|      } else {
  105|     19|         accum.second.push_back(c);
  106|     19|         expect_token = false;
  107|     19|      }
  108|     23|   }
  109|       |
  110|      2|   if(!accum.second.empty()) {
  ------------------
  |  Branch (110:7): [True: 0, False: 2]
  ------------------
  111|      0|      name.push_back(accum);
  112|      0|   }
  113|       |
  114|      2|   if(level != 0) {
  ------------------
  |  Branch (114:7): [True: 0, False: 2]
  ------------------
  115|      0|      throw Invalid_Algorithm_Name(m_orig_algo_spec);
  116|      0|   }
  117|       |
  118|      2|   if(expect_token) {
  ------------------
  |  Branch (118:7): [True: 0, False: 2]
  ------------------
  119|       |      // A trailing separator with no following token, eg "Foo/" or "Foo,"
  120|      0|      throw Invalid_Algorithm_Name(m_orig_algo_spec);
  121|      0|   }
  122|       |
  123|      2|   if(name.empty()) {
  ------------------
  |  Branch (123:7): [True: 0, False: 2]
  ------------------
  124|      0|      throw Invalid_Algorithm_Name(m_orig_algo_spec);
  125|      0|   }
  126|       |
  127|      2|   m_alg_name = name[0].second;
  128|       |
  129|      2|   bool in_modes = false;
  130|       |
  131|      4|   for(size_t i = 1; i != name.size(); ++i) {
  ------------------
  |  Branch (131:22): [True: 2, False: 2]
  ------------------
  132|      2|      if(name[i].first == 0) {
  ------------------
  |  Branch (132:10): [True: 0, False: 2]
  ------------------
  133|      0|         m_mode_info.push_back(make_arg(name, i));
  134|      0|         in_modes = true;
  135|      2|      } else if(name[i].first == 1 && !in_modes) {
  ------------------
  |  Branch (135:17): [True: 2, False: 0]
  |  Branch (135:39): [True: 2, False: 0]
  ------------------
  136|      2|         m_args.push_back(make_arg(name, i));
  137|      2|      }
  138|      2|   }
  139|      2|}
_ZNK5Botan9SCAN_Name3argEm:
  141|      1|std::string SCAN_Name::arg(size_t i) const {
  142|      1|   if(i >= arg_count()) {
  ------------------
  |  Branch (142:7): [True: 0, False: 1]
  ------------------
  143|      0|      throw Invalid_Argument("SCAN_Name::arg " + std::to_string(i) + " out of range for '" + to_string() + "'");
  144|      0|   }
  145|      1|   return m_args[i];
  146|      1|}
_ZNK5Botan9SCAN_Name14arg_as_integerEmm:
  155|      1|size_t SCAN_Name::arg_as_integer(size_t i, size_t def_value) const {
  156|      1|   if(i >= arg_count()) {
  ------------------
  |  Branch (156:7): [True: 0, False: 1]
  ------------------
  157|      0|      return def_value;
  158|      0|   }
  159|      1|   return to_u32bit(m_args[i]);
  160|      1|}
scan_name.cpp:_ZN5Botan12_GLOBAL__N_18make_argERKNSt3__16vectorINS1_4pairImNS1_12basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEEEENS7_ISA_EEEEm:
   18|      2|std::string make_arg(const std::vector<std::pair<size_t, std::string>>& name, size_t start) {
   19|      2|   std::string output = name[start].second;
   20|      2|   size_t level = name[start].first;
   21|       |
   22|      2|   size_t paren_depth = 0;
   23|       |
   24|      2|   for(size_t i = start + 1; i != name.size(); ++i) {
  ------------------
  |  Branch (24:30): [True: 0, False: 2]
  ------------------
   25|      0|      if(name[i].first <= name[start].first) {
  ------------------
  |  Branch (25:10): [True: 0, False: 0]
  ------------------
   26|      0|         break;
   27|      0|      }
   28|       |
   29|      0|      if(name[i].first > level) {
  ------------------
  |  Branch (29:10): [True: 0, False: 0]
  ------------------
   30|      0|         for(size_t j = level; j < name[i].first; j++) {
  ------------------
  |  Branch (30:32): [True: 0, False: 0]
  ------------------
   31|      0|            output += "(";
   32|      0|            ++paren_depth;
   33|      0|         }
   34|      0|         output += name[i].second;
   35|      0|      } else if(name[i].first < level) {
  ------------------
  |  Branch (35:17): [True: 0, False: 0]
  ------------------
   36|      0|         for(size_t j = name[i].first; j < level; j++) {
  ------------------
  |  Branch (36:40): [True: 0, False: 0]
  ------------------
   37|      0|            output += ")";
   38|      0|            BOTAN_ASSERT_NOMSG(paren_depth != 0);
  ------------------
  |  |   77|      0|   do {                                                                     \
  |  |   78|      0|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   79|      0|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (79:10): [True: 0, False: 0]
  |  |  ------------------
  |  |   80|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   81|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   82|      0|      }                                                                     \
  |  |   83|      0|   } while(0)
  |  |  ------------------
  |  |  |  Branch (83:12): [Folded, False: 0]
  |  |  ------------------
  ------------------
   39|      0|            --paren_depth;
   40|      0|         }
   41|      0|         output += "," + name[i].second;
   42|      0|      } else {
   43|      0|         if(output[output.size() - 1] != '(') {
  ------------------
  |  Branch (43:13): [True: 0, False: 0]
  ------------------
   44|      0|            output += ",";
   45|      0|         }
   46|      0|         output += name[i].second;
   47|      0|      }
   48|       |
   49|      0|      level = name[i].first;
   50|      0|   }
   51|       |
   52|      2|   for(size_t i = 0; i != paren_depth; ++i) {
  ------------------
  |  Branch (52:22): [True: 0, False: 2]
  ------------------
   53|      0|      output += ")";
   54|      0|   }
   55|       |
   56|      2|   return output;
   57|      2|}

