_ZN5Botan8high_bitITkNSt3__117unsigned_integralEjEEmT_:
   73|  1.60k|BOTAN_FORCE_INLINE constexpr size_t high_bit(T n) {
   74|  1.60k|   size_t hb = 0;
   75|       |
   76|  9.60k|   for(size_t s = 8 * sizeof(T) / 2; s > 0; s /= 2) {
  ------------------
  |  Branch (76:38): [True: 8.00k, False: 1.60k]
  ------------------
   77|       |      // Equivalent to: ((n >> s) == 0) ? 0 : s;
   78|  8.00k|      const size_t z = s - ct_if_is_zero_ret<T>(n >> s, s);
   79|  8.00k|      hb += z;
   80|  8.00k|      n >>= z;
   81|  8.00k|   }
   82|       |
   83|  1.60k|   hb += static_cast<size_t>(n);
   84|       |
   85|  1.60k|   return hb;
   86|  1.60k|}
_ZN5Botan17ct_if_is_zero_retITkNSt3__117unsigned_integralEjEEmT_m:
   45|  8.00k|BOTAN_FORCE_INLINE constexpr size_t ct_if_is_zero_ret(T x, size_t s) {
   46|       |   /*
   47|       |   Similar to `return ct_is_zero(x) & s` but has to account for possibility that
   48|       |   sizeof(T) is smaller than sizeof(size_t) which would lead to incomplete masking
   49|       |   */
   50|  8.00k|   const T a = ~x & (x - 1);
   51|  8.00k|   const size_t a_top = static_cast<size_t>(CT::value_barrier<T>(a >> (sizeof(T) * 8 - 1)));
   52|  8.00k|   const size_t mask = static_cast<size_t>(0) - a_top;
   53|  8.00k|   return mask & s;
   54|  8.00k|}
_ZN5Botan17ct_if_is_zero_retITkNSt3__117unsigned_integralEmEEmT_m:
   45|   138k|BOTAN_FORCE_INLINE constexpr size_t ct_if_is_zero_ret(T x, size_t s) {
   46|       |   /*
   47|       |   Similar to `return ct_is_zero(x) & s` but has to account for possibility that
   48|       |   sizeof(T) is smaller than sizeof(size_t) which would lead to incomplete masking
   49|       |   */
   50|   138k|   const T a = ~x & (x - 1);
   51|   138k|   const size_t a_top = static_cast<size_t>(CT::value_barrier<T>(a >> (sizeof(T) * 8 - 1)));
   52|   138k|   const size_t mask = static_cast<size_t>(0) - a_top;
   53|   138k|   return mask & s;
   54|   138k|}
_ZN5Botan6chooseITkNSt3__117unsigned_integralEmEET_S2_S2_S2_:
  216|  12.9k|BOTAN_FORCE_INLINE constexpr T choose(T mask, T a, T b) {
  217|       |   //return (mask & a) | (~mask & b);
  218|  12.9k|   return (b ^ (mask & (a ^ b)));
  219|  12.9k|}
_ZN5Botan17ct_expand_top_bitITkNSt3__117unsigned_integralEmEET_S2_:
   28|   128k|BOTAN_FORCE_INLINE constexpr T ct_expand_top_bit(T a) {
   29|   128k|   const T top = CT::value_barrier<T>(a >> (sizeof(T) * 8 - 1));
   30|   128k|   return static_cast<T>(0) - top;
   31|   128k|}
_ZN5Botan10ct_is_zeroITkNSt3__117unsigned_integralEmEET_S2_:
   37|   122k|BOTAN_FORCE_INLINE constexpr T ct_is_zero(T x) {
   38|   122k|   return ct_expand_top_bit<T>(~x & (x - 1));
   39|   122k|}
_ZN5Botan8high_bitITkNSt3__117unsigned_integralEmEEmT_:
   73|  23.0k|BOTAN_FORCE_INLINE constexpr size_t high_bit(T n) {
   74|  23.0k|   size_t hb = 0;
   75|       |
   76|   161k|   for(size_t s = 8 * sizeof(T) / 2; s > 0; s /= 2) {
  ------------------
  |  Branch (76:38): [True: 138k, False: 23.0k]
  ------------------
   77|       |      // Equivalent to: ((n >> s) == 0) ? 0 : s;
   78|   138k|      const size_t z = s - ct_if_is_zero_ret<T>(n >> s, s);
   79|   138k|      hb += z;
   80|   138k|      n >>= z;
   81|   138k|   }
   82|       |
   83|  23.0k|   hb += static_cast<size_t>(n);
   84|       |
   85|  23.0k|   return hb;
   86|  23.0k|}

_ZN5Botan13reverse_bytesITkNSt3__117unsigned_integralEtQooooooeqstT_Li1EeqstS2_Li2EeqstS2_Li4EeqstS2_Li8EEES2_S2_:
   25|  1.06k|inline constexpr T reverse_bytes(T x) {
   26|       |   if constexpr(sizeof(T) == 1) {
   27|       |      return x;
   28|  1.06k|   } else if constexpr(sizeof(T) == 2) {
   29|  1.06k|#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap16)
   30|  1.06k|      return static_cast<T>(__builtin_bswap16(x));
   31|       |#else
   32|       |      return static_cast<T>((x << 8) | (x >> 8));
   33|       |#endif
   34|       |   } else if constexpr(sizeof(T) == 4) {
   35|       |#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap32)
   36|       |      return static_cast<T>(__builtin_bswap32(x));
   37|       |#else
   38|       |      // MSVC at least recognizes this as a bswap
   39|       |      return static_cast<T>(((x & 0x000000FF) << 24) | ((x & 0x0000FF00) << 8) | ((x & 0x00FF0000) >> 8) |
   40|       |                            ((x & 0xFF000000) >> 24));
   41|       |#endif
   42|       |   } else if constexpr(sizeof(T) == 8) {
   43|       |#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap64)
   44|       |      return static_cast<T>(__builtin_bswap64(x));
   45|       |#else
   46|       |      uint32_t hi = static_cast<uint32_t>(x >> 32);
   47|       |      uint32_t lo = static_cast<uint32_t>(x);
   48|       |
   49|       |      hi = reverse_bytes(hi);
   50|       |      lo = reverse_bytes(lo);
   51|       |
   52|       |      return (static_cast<T>(lo) << 32) | hi;
   53|       |#endif
   54|       |   }
   55|  1.06k|}
_ZN5Botan13reverse_bytesITkNSt3__117unsigned_integralEjQooooooeqstT_Li1EeqstS2_Li2EeqstS2_Li4EeqstS2_Li8EEES2_S2_:
   25|    686|inline constexpr T reverse_bytes(T x) {
   26|       |   if constexpr(sizeof(T) == 1) {
   27|       |      return x;
   28|       |   } else if constexpr(sizeof(T) == 2) {
   29|       |#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap16)
   30|       |      return static_cast<T>(__builtin_bswap16(x));
   31|       |#else
   32|       |      return static_cast<T>((x << 8) | (x >> 8));
   33|       |#endif
   34|    686|   } else if constexpr(sizeof(T) == 4) {
   35|    686|#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap32)
   36|    686|      return static_cast<T>(__builtin_bswap32(x));
   37|       |#else
   38|       |      // MSVC at least recognizes this as a bswap
   39|       |      return static_cast<T>(((x & 0x000000FF) << 24) | ((x & 0x0000FF00) << 8) | ((x & 0x00FF0000) >> 8) |
   40|       |                            ((x & 0xFF000000) >> 24));
   41|       |#endif
   42|       |   } else if constexpr(sizeof(T) == 8) {
   43|       |#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap64)
   44|       |      return static_cast<T>(__builtin_bswap64(x));
   45|       |#else
   46|       |      uint32_t hi = static_cast<uint32_t>(x >> 32);
   47|       |      uint32_t lo = static_cast<uint32_t>(x);
   48|       |
   49|       |      hi = reverse_bytes(hi);
   50|       |      lo = reverse_bytes(lo);
   51|       |
   52|       |      return (static_cast<T>(lo) << 32) | hi;
   53|       |#endif
   54|       |   }
   55|    686|}
_ZN5Botan13reverse_bytesITkNSt3__117unsigned_integralEmQooooooeqstT_Li1EeqstS2_Li2EeqstS2_Li4EeqstS2_Li8EEES2_S2_:
   25|  24.4k|inline constexpr T reverse_bytes(T x) {
   26|       |   if constexpr(sizeof(T) == 1) {
   27|       |      return x;
   28|       |   } else if constexpr(sizeof(T) == 2) {
   29|       |#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap16)
   30|       |      return static_cast<T>(__builtin_bswap16(x));
   31|       |#else
   32|       |      return static_cast<T>((x << 8) | (x >> 8));
   33|       |#endif
   34|       |   } else if constexpr(sizeof(T) == 4) {
   35|       |#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap32)
   36|       |      return static_cast<T>(__builtin_bswap32(x));
   37|       |#else
   38|       |      // MSVC at least recognizes this as a bswap
   39|       |      return static_cast<T>(((x & 0x000000FF) << 24) | ((x & 0x0000FF00) << 8) | ((x & 0x00FF0000) >> 8) |
   40|       |                            ((x & 0xFF000000) >> 24));
   41|       |#endif
   42|  24.4k|   } else if constexpr(sizeof(T) == 8) {
   43|  24.4k|#if BOTAN_COMPILER_HAS_BUILTIN(__builtin_bswap64)
   44|  24.4k|      return static_cast<T>(__builtin_bswap64(x));
   45|       |#else
   46|       |      uint32_t hi = static_cast<uint32_t>(x >> 32);
   47|       |      uint32_t lo = static_cast<uint32_t>(x);
   48|       |
   49|       |      hi = reverse_bytes(hi);
   50|       |      lo = reverse_bytes(lo);
   51|       |
   52|       |      return (static_cast<T>(lo) << 32) | hi;
   53|       |#endif
   54|  24.4k|   }
   55|  24.4k|}

_ZN5Botan12BufferSlicerC2ENSt3__14spanIKhLm18446744073709551615EEE:
   25|  23.3k|      explicit BufferSlicer(std::span<const uint8_t> buffer) : m_remaining(buffer) {}
_ZNK5Botan12BufferSlicer5emptyEv:
   68|   219k|      bool empty() const { return m_remaining.empty(); }
_ZN5Botan12BufferSlicer9take_byteEv:
   57|   109k|      uint8_t take_byte() { return take(1)[0]; }
_ZN5Botan12BufferSlicer4takeEm:
   37|   109k|      std::span<const uint8_t> take(const size_t count) {
   38|   109k|         BOTAN_STATE_CHECK(remaining() >= count);
  ------------------
  |  |   51|   109k|   do {                                                         \
  |  |   52|   109k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */             \
  |  |   53|   109k|      if(!(expr)) {                                             \
  |  |  ------------------
  |  |  |  Branch (53:10): [True: 0, False: 109k]
  |  |  ------------------
  |  |   54|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */    \
  |  |   55|      0|         Botan::throw_invalid_state(#expr, __func__, __FILE__); \
  |  |   56|      0|      }                                                         \
  |  |   57|   109k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (57:12): [Folded, False: 109k]
  |  |  ------------------
  ------------------
   39|   109k|         auto result = m_remaining.first(count);
   40|   109k|         m_remaining = m_remaining.subspan(count);
   41|   109k|         return result;
   42|   109k|      }
_ZNK5Botan12BufferSlicer9remainingEv:
   66|   109k|      size_t remaining() const { return m_remaining.size(); }

_ZN5Botan13nibble_to_hexEh:
   76|     80|inline constexpr char nibble_to_hex(uint8_t b) {
   77|     80|   const uint8_t n = b & 0x0F;
   78|     80|   return static_cast<char>(n < 10 ? '0' + n : 'A' + (n - 10));
  ------------------
  |  Branch (78:29): [True: 50, False: 30]
  ------------------
   79|     80|}
_ZNK5Botan22CharacterValidityTableclEc:
  125|  28.1k|      constexpr bool operator()(char c) const {
  126|  28.1k|         const uint8_t uc = static_cast<uint8_t>(c);
  127|  28.1k|         return ((m_tbl[uc / 32] >> (uc % 32)) & 1) != 0;
  128|  28.1k|      }

base64.cpp:_ZN5Botan11base_decodeINS_12_GLOBAL__N_16Base64EEEmRKT_PhPKcmRmbb:
  124|    185|                   bool ignore_ws = true) {
  125|       |   // TODO(Botan4) Check if we can use just base. or Base:: here instead
  126|    185|   constexpr size_t decoding_bytes_in = std::remove_reference_t<Base>::decoding_bytes_in();
  127|    185|   constexpr size_t decoding_bytes_out = std::remove_reference_t<Base>::decoding_bytes_out();
  128|       |
  129|    185|   input_consumed = 0;
  130|       |
  131|    185|   uint8_t* out_ptr = output;
  132|    185|   std::array<uint8_t, decoding_bytes_in> decode_buf{};
  133|    185|   size_t decode_buf_pos = 0;
  134|    185|   size_t final_truncate = 0;
  135|    185|   bool seen_padding = false;
  136|       |
  137|    185|   clear_mem(output, base.decode_max_output(input_length));
  138|       |
  139|  37.1k|   for(size_t i = 0; i != input_length; ++i) {
  ------------------
  |  Branch (139:22): [True: 36.9k, False: 176]
  ------------------
  140|  36.9k|      const uint8_t bin = base.lookup_binary_value(input[i]);
  141|       |
  142|       |      // This call might throw Invalid_Argument
  143|  36.9k|      if(base.check_bad_char(bin, input[i], ignore_ws)) {
  ------------------
  |  Branch (143:10): [True: 11.9k, False: 25.0k]
  ------------------
  144|       |         // Padding may only appear at the end, so a data symbol must never
  145|       |         // follow one (0x81 marks a padding character)
  146|  11.9k|         if(seen_padding) {
  ------------------
  |  Branch (146:13): [True: 2, False: 11.9k]
  ------------------
  147|      2|            throw Invalid_Argument(base.name() + " decoding failed, data follows padding");
  148|      2|         }
  149|  11.9k|         decode_buf[decode_buf_pos] = bin;
  150|  11.9k|         ++decode_buf_pos;
  151|  25.0k|      } else if(bin == 0x81) {
  ------------------
  |  Branch (151:17): [True: 219, False: 24.8k]
  ------------------
  152|    219|         seen_padding = true;
  153|    219|      }
  154|       |
  155|       |      /*
  156|       |      * If we're at the end of the input, pad with 0s and truncate
  157|       |      */
  158|  36.9k|      if(final_inputs && (i == input_length - 1)) {
  ------------------
  |  Branch (158:10): [True: 36.9k, False: 49]
  |  Branch (158:26): [True: 83, False: 36.8k]
  ------------------
  159|     83|         if(decode_buf_pos) {
  ------------------
  |  Branch (159:13): [True: 33, False: 50]
  ------------------
  160|     33|            const size_t bits_per_symbol = base.bits_consumed();
  161|     33|            const size_t pad_bits = (decode_buf_pos * bits_per_symbol) % 8;
  162|       |
  163|       |            // A trailing symbol contributing only pad bits cannot occur in a
  164|       |            // valid encoding; RFC 4648 4 and 6 enumerate the reachable cases
  165|     33|            if(pad_bits >= bits_per_symbol) {
  ------------------
  |  Branch (165:16): [True: 6, False: 27]
  ------------------
  166|      6|               throw Invalid_Argument(base.name() + " decoding failed, invalid length");
  167|      6|            }
  168|       |
  169|       |            // RFC 4648 3.5: "decoders MAY chose to reject an encoding if the
  170|       |            // pad bits have not been set to zero"
  171|     27|            const uint8_t pad_mask = static_cast<uint8_t>((1U << pad_bits) - 1);
  172|     27|            if(decode_buf[decode_buf_pos - 1] & pad_mask) {
  ------------------
  |  Branch (172:16): [True: 1, False: 26]
  ------------------
  173|      1|               throw Invalid_Argument(base.name() + " decoding failed, nonzero padding bits");
  174|      1|            }
  175|       |
  176|     55|            for(size_t j = decode_buf_pos; j < decoding_bytes_in; ++j) {
  ------------------
  |  Branch (176:44): [True: 29, False: 26]
  ------------------
  177|     29|               decode_buf[j] = 0;
  178|     29|            }
  179|       |
  180|     26|            final_truncate = decoding_bytes_in - decode_buf_pos;
  181|     26|            decode_buf_pos = decoding_bytes_in;
  182|     26|         }
  183|     83|      }
  184|       |
  185|  36.9k|      if(decode_buf_pos == decoding_bytes_in) {
  ------------------
  |  Branch (185:10): [True: 2.98k, False: 34.0k]
  ------------------
  186|  2.98k|         base.decode(out_ptr, decode_buf.data());
  187|       |
  188|  2.98k|         out_ptr += decoding_bytes_out;
  189|  2.98k|         decode_buf_pos = 0;
  190|  2.98k|         input_consumed = i + 1;
  191|  2.98k|      }
  192|  36.9k|   }
  193|       |
  194|  12.7k|   while(input_consumed < input_length && base.lookup_binary_value(input[input_consumed]) == 0x80) {
  ------------------
  |  Branch (194:10): [True: 12.5k, False: 151]
  |  Branch (194:43): [True: 12.5k, False: 25]
  ------------------
  195|  12.5k|      ++input_consumed;
  196|  12.5k|   }
  197|       |
  198|    176|   const size_t written = (out_ptr - output) - base.bytes_to_remove(final_truncate);
  199|       |
  200|    176|   return written;
  201|    185|}
base64.cpp:_ZN5Botan16base_decode_fullINS_12_GLOBAL__N_16Base64EEEmRKT_PhPKcmb:
  204|    185|size_t base_decode_full(const Base& base, uint8_t output[], const char input[], size_t input_length, bool ignore_ws) {
  205|    185|   size_t consumed = 0;
  206|    185|   const size_t written = base_decode(base, output, input, input_length, consumed, true, ignore_ws);
  207|       |
  208|    185|   if(consumed != input_length) {
  ------------------
  |  Branch (208:7): [True: 25, False: 160]
  ------------------
  209|     25|      throw Invalid_Argument(base.name() + " decoding failed, input did not have full bytes");
  210|     25|   }
  211|       |
  212|    160|   return written;
  213|    185|}
base64.cpp:_ZN5Botan18base_decode_to_vecINSt3__16vectorIhNS_16secure_allocatorIhEEEENS_12_GLOBAL__N_16Base64EEET_RKT0_PKcmb:
  216|    185|Vector base_decode_to_vec(const Base& base, const char input[], size_t input_length, bool ignore_ws) {
  217|    185|   const size_t output_length = base.decode_max_output(input_length);
  218|    185|   Vector bin(output_length);
  219|       |
  220|    185|   const size_t written = base_decode_full(base, bin.data(), input, input_length, ignore_ws);
  221|       |
  222|    185|   bin.resize(written);
  223|    185|   return bin;
  224|    185|}

_ZN5Botan2CT4MaskImE5is_ltEmm:
  450|  6.34k|      static constexpr Mask<T> is_lt(T x, T y) {
  451|  6.34k|         T u = x ^ ((x ^ y) | ((x - y) ^ x));
  452|  6.34k|         return Mask<T>::expand_top_bit(u);
  453|  6.34k|      }
_ZN5Botan2CT4MaskImE14expand_top_bitEm:
  415|  6.34k|      static constexpr Mask<T> expand_top_bit(T v) { return Mask<T>(ct_expand_top_bit<T>(v)); }
_ZN5Botan2CT4MaskImEC2Em:
  637|  12.9k|      constexpr explicit Mask(T m) : m_mask(m) {}
_ZN5Botan2CT8unpoisonITkNSt3__18integralEmEEvRKT_:
  112|  43.7k|constexpr void unpoison(const T& p) {
  113|  43.7k|   unpoison(&p, 1);
  114|  43.7k|}
_ZN5Botan2CT4MaskImE7is_zeroEm:
  437|  6.59k|      static constexpr Mask<T> is_zero(T x) { return Mask<T>(ct_is_zero<T>(value_barrier<T>(x))); }
_ZNK5Botan2CT4MaskImE5valueEv:
  630|  12.9k|      constexpr T value() const { return value_barrier<T>(m_mask); }
_ZNK5Botan2CT4MaskImE6selectEmm:
  548|  12.9k|      constexpr T select(T x, T y) const { return choose(value(), x, y); }
_ZN5Botan2CT4MaskImE8is_equalEmm:
  442|  6.34k|      static constexpr Mask<T> is_equal(T x, T y) {
  443|  6.34k|         const T diff = value_barrier(x) ^ value_barrier(y);
  444|  6.34k|         return Mask<T>::is_zero(diff);
  445|  6.34k|      }
_ZN5Botan2CT8unpoisonImEEvPKT_m:
   67|  73.4k|constexpr inline void unpoison(const T* p, size_t n) {
   68|       |#if defined(BOTAN_HAS_VALGRIND)
   69|       |   if(!std::is_constant_evaluated()) {
   70|       |      VALGRIND_MAKE_MEM_DEFINED(p, n * sizeof(T));
   71|       |   }
   72|       |#endif
   73|       |
   74|  73.4k|   BOTAN_UNUSED(p, n);
  ------------------
  |  |  151|  73.4k|#define BOTAN_UNUSED Botan::ignore_params
  ------------------
   75|  73.4k|}

_ZN5Botan3fmtIJNSt3__117basic_string_viewIcNS1_11char_traitsIcEEEEEEENS1_12basic_stringIcS4_NS1_9allocatorIcEEEES5_DpRKT_:
   53|  8.37k|std::string fmt(std::string_view format, const T&... args) {
   54|  8.37k|   std::ostringstream oss;
   55|  8.37k|   oss.imbue(std::locale::classic());
   56|  8.37k|   fmt_detail::do_fmt(oss, format, args...);
   57|  8.37k|   return oss.str();
   58|  8.37k|}
_ZN5Botan10fmt_detail6do_fmtINSt3__117basic_string_viewIcNS2_11char_traitsIcEEEEJEEEvRNS2_19basic_ostringstreamIcS5_NS2_9allocatorIcEEEES6_RKT_DpRKT0_:
   25|  8.37k|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|  8.37k|   size_t i = 0;
   27|       |
   28|  71.7k|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 71.7k, False: 0]
  ------------------
   29|  71.7k|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 8.37k, False: 63.4k]
  |  Branch (29:30): [True: 8.37k, False: 0]
  |  Branch (29:59): [True: 8.37k, False: 0]
  ------------------
   30|  8.37k|         oss << val;
   31|  8.37k|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|  63.4k|      } else {
   33|  63.4k|         oss << format[i];
   34|  63.4k|      }
   35|       |
   36|  63.4k|      i += 1;
   37|  63.4k|   }
   38|  8.37k|}
_ZN5Botan10fmt_detail6do_fmtERNSt3__119basic_ostringstreamIcNS1_11char_traitsIcEENS1_9allocatorIcEEEENS1_17basic_string_viewIcS4_EE:
   20|  14.0k|inline void do_fmt(std::ostringstream& oss, std::string_view format) {
   21|  14.0k|   oss << format;
   22|  14.0k|}
_ZN5Botan3fmtIJNSt3__117basic_string_viewIcNS1_11char_traitsIcEEEEPKcEEENS1_12basic_stringIcS4_NS1_9allocatorIcEEEES5_DpRKT_:
   53|  3.72k|std::string fmt(std::string_view format, const T&... args) {
   54|  3.72k|   std::ostringstream oss;
   55|  3.72k|   oss.imbue(std::locale::classic());
   56|  3.72k|   fmt_detail::do_fmt(oss, format, args...);
   57|  3.72k|   return oss.str();
   58|  3.72k|}
_ZN5Botan10fmt_detail6do_fmtINSt3__117basic_string_viewIcNS2_11char_traitsIcEEEEJPKcEEEvRNS2_19basic_ostringstreamIcS5_NS2_9allocatorIcEEEES6_RKT_DpRKT0_:
   25|  3.72k|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|  3.72k|   size_t i = 0;
   27|       |
   28|  3.72k|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 3.72k, False: 0]
  ------------------
   29|  3.72k|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 3.72k, False: 0]
  |  Branch (29:30): [True: 3.72k, False: 0]
  |  Branch (29:59): [True: 3.72k, False: 0]
  ------------------
   30|  3.72k|         oss << val;
   31|  3.72k|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|  3.72k|      } else {
   33|      0|         oss << format[i];
   34|      0|      }
   35|       |
   36|      0|      i += 1;
   37|      0|   }
   38|  3.72k|}
_ZN5Botan10fmt_detail6do_fmtIPKcJEEEvRNSt3__119basic_ostringstreamIcNS4_11char_traitsIcEENS4_9allocatorIcEEEENS4_17basic_string_viewIcS7_EERKT_DpRKT0_:
   25|  3.87k|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|  3.87k|   size_t i = 0;
   27|       |
   28|  55.4k|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 55.4k, False: 0]
  ------------------
   29|  55.4k|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 3.87k, False: 51.5k]
  |  Branch (29:30): [True: 3.87k, False: 0]
  |  Branch (29:59): [True: 3.87k, False: 0]
  ------------------
   30|  3.87k|         oss << val;
   31|  3.87k|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|  51.5k|      } else {
   33|  51.5k|         oss << format[i];
   34|  51.5k|      }
   35|       |
   36|  51.5k|      i += 1;
   37|  51.5k|   }
   38|  3.87k|}
_ZN5Botan3fmtIJPKcNSt3__117basic_string_viewIcNS3_11char_traitsIcEEEEEEENS3_12basic_stringIcS6_NS3_9allocatorIcEEEES7_DpRKT_:
   53|      3|std::string fmt(std::string_view format, const T&... args) {
   54|      3|   std::ostringstream oss;
   55|      3|   oss.imbue(std::locale::classic());
   56|      3|   fmt_detail::do_fmt(oss, format, args...);
   57|      3|   return oss.str();
   58|      3|}
_ZN5Botan10fmt_detail6do_fmtIPKcJNSt3__117basic_string_viewIcNS4_11char_traitsIcEEEEEEEvRNS4_19basic_ostringstreamIcS7_NS4_9allocatorIcEEEES8_RKT_DpRKT0_:
   25|      3|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|      3|   size_t i = 0;
   27|       |
   28|      3|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 3, False: 0]
  ------------------
   29|      3|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 3, False: 0]
  |  Branch (29:30): [True: 3, False: 0]
  |  Branch (29:59): [True: 3, False: 0]
  ------------------
   30|      3|         oss << val;
   31|      3|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|      3|      } else {
   33|      0|         oss << format[i];
   34|      0|      }
   35|       |
   36|      0|      i += 1;
   37|      0|   }
   38|      3|}
_ZN5Botan10fmt_detail6do_fmtImJEEEvRNSt3__119basic_ostringstreamIcNS2_11char_traitsIcEENS2_9allocatorIcEEEENS2_17basic_string_viewIcS5_EERKT_DpRKT0_:
   25|    568|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|    568|   size_t i = 0;
   27|       |
   28|  23.2k|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 23.2k, False: 0]
  ------------------
   29|  23.2k|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 568, False: 22.6k]
  |  Branch (29:30): [True: 568, False: 0]
  |  Branch (29:59): [True: 568, False: 0]
  ------------------
   30|    568|         oss << val;
   31|    568|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|  22.6k|      } else {
   33|  22.6k|         oss << format[i];
   34|  22.6k|      }
   35|       |
   36|  22.6k|      i += 1;
   37|  22.6k|   }
   38|    568|}
_ZN5Botan3fmtIJPKcEEENSt3__112basic_stringIcNS3_11char_traitsIcEENS3_9allocatorIcEEEENS3_17basic_string_viewIcS6_EEDpRKT_:
   53|    113|std::string fmt(std::string_view format, const T&... args) {
   54|    113|   std::ostringstream oss;
   55|    113|   oss.imbue(std::locale::classic());
   56|    113|   fmt_detail::do_fmt(oss, format, args...);
   57|    113|   return oss.str();
   58|    113|}
_ZN5Botan3fmtIJNSt3__112basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEEEEES7_NS1_17basic_string_viewIcS4_EEDpRKT_:
   53|    677|std::string fmt(std::string_view format, const T&... args) {
   54|    677|   std::ostringstream oss;
   55|    677|   oss.imbue(std::locale::classic());
   56|    677|   fmt_detail::do_fmt(oss, format, args...);
   57|    677|   return oss.str();
   58|    677|}
_ZN5Botan10fmt_detail6do_fmtINSt3__112basic_stringIcNS2_11char_traitsIcEENS2_9allocatorIcEEEEJEEEvRNS2_19basic_ostringstreamIcS5_S7_EENS2_17basic_string_viewIcS5_EERKT_DpRKT0_:
   25|    677|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|    677|   size_t i = 0;
   27|       |
   28|  12.1k|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 12.1k, False: 0]
  ------------------
   29|  12.1k|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 677, False: 11.5k]
  |  Branch (29:30): [True: 677, False: 0]
  |  Branch (29:59): [True: 677, False: 0]
  ------------------
   30|    677|         oss << val;
   31|    677|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|  11.5k|      } else {
   33|  11.5k|         oss << format[i];
   34|  11.5k|      }
   35|       |
   36|  11.5k|      i += 1;
   37|  11.5k|   }
   38|    677|}
_ZN5Botan3fmtIJmmEEENSt3__112basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEENS1_17basic_string_viewIcS4_EEDpRKT_:
   53|      3|std::string fmt(std::string_view format, const T&... args) {
   54|      3|   std::ostringstream oss;
   55|      3|   oss.imbue(std::locale::classic());
   56|      3|   fmt_detail::do_fmt(oss, format, args...);
   57|      3|   return oss.str();
   58|      3|}
_ZN5Botan10fmt_detail6do_fmtImJmEEEvRNSt3__119basic_ostringstreamIcNS2_11char_traitsIcEENS2_9allocatorIcEEEENS2_17basic_string_viewIcS5_EERKT_DpRKT0_:
   25|      3|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|      3|   size_t i = 0;
   27|       |
   28|    135|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 135, False: 0]
  ------------------
   29|    135|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 3, False: 132]
  |  Branch (29:30): [True: 3, False: 0]
  |  Branch (29:59): [True: 3, False: 0]
  ------------------
   30|      3|         oss << val;
   31|      3|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|    132|      } else {
   33|    132|         oss << format[i];
   34|    132|      }
   35|       |
   36|    132|      i += 1;
   37|    132|   }
   38|      3|}
_ZN5Botan3fmtIJmEEENSt3__112basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEENS1_17basic_string_viewIcS4_EEDpRKT_:
   53|    565|std::string fmt(std::string_view format, const T&... args) {
   54|    565|   std::ostringstream oss;
   55|    565|   oss.imbue(std::locale::classic());
   56|    565|   fmt_detail::do_fmt(oss, format, args...);
   57|    565|   return oss.str();
   58|    565|}
_ZN5Botan3fmtIJjEEENSt3__112basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEENS1_17basic_string_viewIcS4_EEDpRKT_:
   53|     22|std::string fmt(std::string_view format, const T&... args) {
   54|     22|   std::ostringstream oss;
   55|     22|   oss.imbue(std::locale::classic());
   56|     22|   fmt_detail::do_fmt(oss, format, args...);
   57|     22|   return oss.str();
   58|     22|}
_ZN5Botan10fmt_detail6do_fmtIjJEEEvRNSt3__119basic_ostringstreamIcNS2_11char_traitsIcEENS2_9allocatorIcEEEENS2_17basic_string_viewIcS5_EERKT_DpRKT0_:
   25|    525|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|    525|   size_t i = 0;
   27|       |
   28|  2.83k|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 2.83k, False: 0]
  ------------------
   29|  2.83k|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 525, False: 2.31k]
  |  Branch (29:30): [True: 525, False: 0]
  |  Branch (29:59): [True: 525, False: 0]
  ------------------
   30|    525|         oss << val;
   31|    525|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|  2.31k|      } else {
   33|  2.31k|         oss << format[i];
   34|  2.31k|      }
   35|       |
   36|  2.31k|      i += 1;
   37|  2.31k|   }
   38|    525|}
_ZN5Botan3fmtIJNSt3__117basic_string_viewIcNS1_11char_traitsIcEEEEjEEENS1_12basic_stringIcS4_NS1_9allocatorIcEEEES5_DpRKT_:
   53|     70|std::string fmt(std::string_view format, const T&... args) {
   54|     70|   std::ostringstream oss;
   55|     70|   oss.imbue(std::locale::classic());
   56|     70|   fmt_detail::do_fmt(oss, format, args...);
   57|     70|   return oss.str();
   58|     70|}
_ZN5Botan10fmt_detail6do_fmtINSt3__117basic_string_viewIcNS2_11char_traitsIcEEEEJjEEEvRNS2_19basic_ostringstreamIcS5_NS2_9allocatorIcEEEES6_RKT_DpRKT0_:
   25|     70|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|     70|   size_t i = 0;
   27|       |
   28|     70|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 70, False: 0]
  ------------------
   29|     70|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 70, False: 0]
  |  Branch (29:30): [True: 70, False: 0]
  |  Branch (29:59): [True: 70, False: 0]
  ------------------
   30|     70|         oss << val;
   31|     70|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|     70|      } else {
   33|      0|         oss << format[i];
   34|      0|      }
   35|       |
   36|      0|      i += 1;
   37|      0|   }
   38|     70|}
_ZN5Botan3fmtIJjjEEENSt3__112basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEENS1_17basic_string_viewIcS4_EEDpRKT_:
   53|    433|std::string fmt(std::string_view format, const T&... args) {
   54|    433|   std::ostringstream oss;
   55|    433|   oss.imbue(std::locale::classic());
   56|    433|   fmt_detail::do_fmt(oss, format, args...);
   57|    433|   return oss.str();
   58|    433|}
_ZN5Botan10fmt_detail6do_fmtIjJjEEEvRNSt3__119basic_ostringstreamIcNS2_11char_traitsIcEENS2_9allocatorIcEEEENS2_17basic_string_viewIcS5_EERKT_DpRKT0_:
   25|    433|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|    433|   size_t i = 0;
   27|       |
   28|  11.6k|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 11.6k, False: 0]
  ------------------
   29|  11.6k|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 433, False: 11.1k]
  |  Branch (29:30): [True: 433, False: 0]
  |  Branch (29:59): [True: 433, False: 0]
  ------------------
   30|    433|         oss << val;
   31|    433|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|  11.1k|      } else {
   33|  11.1k|         oss << format[i];
   34|  11.1k|      }
   35|       |
   36|  11.1k|      i += 1;
   37|  11.1k|   }
   38|    433|}
_ZN5Botan3fmtIJtttEEENSt3__112basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEENS1_17basic_string_viewIcS4_EEDpRKT_:
   53|      5|std::string fmt(std::string_view format, const T&... args) {
   54|      5|   std::ostringstream oss;
   55|      5|   oss.imbue(std::locale::classic());
   56|      5|   fmt_detail::do_fmt(oss, format, args...);
   57|      5|   return oss.str();
   58|      5|}
_ZN5Botan10fmt_detail6do_fmtItJttEEEvRNSt3__119basic_ostringstreamIcNS2_11char_traitsIcEENS2_9allocatorIcEEEENS2_17basic_string_viewIcS5_EERKT_DpRKT0_:
   25|      5|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|      5|   size_t i = 0;
   27|       |
   28|     80|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 80, False: 0]
  ------------------
   29|     80|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 5, False: 75]
  |  Branch (29:30): [True: 5, False: 0]
  |  Branch (29:59): [True: 5, False: 0]
  ------------------
   30|      5|         oss << val;
   31|      5|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|     75|      } else {
   33|     75|         oss << format[i];
   34|     75|      }
   35|       |
   36|     75|      i += 1;
   37|     75|   }
   38|      5|}
_ZN5Botan10fmt_detail6do_fmtItJtEEEvRNSt3__119basic_ostringstreamIcNS2_11char_traitsIcEENS2_9allocatorIcEEEENS2_17basic_string_viewIcS5_EERKT_DpRKT0_:
   25|      5|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|      5|   size_t i = 0;
   27|       |
   28|     95|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 95, False: 0]
  ------------------
   29|     95|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 5, False: 90]
  |  Branch (29:30): [True: 5, False: 0]
  |  Branch (29:59): [True: 5, False: 0]
  ------------------
   30|      5|         oss << val;
   31|      5|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|     90|      } else {
   33|     90|         oss << format[i];
   34|     90|      }
   35|       |
   36|     90|      i += 1;
   37|     90|   }
   38|      5|}
_ZN5Botan10fmt_detail6do_fmtItJEEEvRNSt3__119basic_ostringstreamIcNS2_11char_traitsIcEENS2_9allocatorIcEEEENS2_17basic_string_viewIcS5_EERKT_DpRKT0_:
   25|      5|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|      5|   size_t i = 0;
   27|       |
   28|     25|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 25, False: 0]
  ------------------
   29|     25|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 5, False: 20]
  |  Branch (29:30): [True: 5, False: 0]
  |  Branch (29:59): [True: 5, False: 0]
  ------------------
   30|      5|         oss << val;
   31|      5|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|     20|      } else {
   33|     20|         oss << format[i];
   34|     20|      }
   35|       |
   36|     20|      i += 1;
   37|     20|   }
   38|      5|}
_ZN5Botan3fmtIJPKcS2_S2_EEENSt3__112basic_stringIcNS3_11char_traitsIcEENS3_9allocatorIcEEEENS3_17basic_string_viewIcS6_EEDpRKT_:
   53|     42|std::string fmt(std::string_view format, const T&... args) {
   54|     42|   std::ostringstream oss;
   55|     42|   oss.imbue(std::locale::classic());
   56|     42|   fmt_detail::do_fmt(oss, format, args...);
   57|     42|   return oss.str();
   58|     42|}
_ZN5Botan10fmt_detail6do_fmtIPKcJS3_S3_EEEvRNSt3__119basic_ostringstreamIcNS4_11char_traitsIcEENS4_9allocatorIcEEEENS4_17basic_string_viewIcS7_EERKT_DpRKT0_:
   25|     42|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|     42|   size_t i = 0;
   27|       |
   28|     42|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 42, False: 0]
  ------------------
   29|     42|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 42, False: 0]
  |  Branch (29:30): [True: 42, False: 0]
  |  Branch (29:59): [True: 42, False: 0]
  ------------------
   30|     42|         oss << val;
   31|     42|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|     42|      } else {
   33|      0|         oss << format[i];
   34|      0|      }
   35|       |
   36|      0|      i += 1;
   37|      0|   }
   38|     42|}
_ZN5Botan10fmt_detail6do_fmtIPKcJS3_EEEvRNSt3__119basic_ostringstreamIcNS4_11char_traitsIcEENS4_9allocatorIcEEEENS4_17basic_string_viewIcS7_EERKT_DpRKT0_:
   25|     42|void do_fmt(std::ostringstream& oss, std::string_view format, const T& val, const Ts&... rest) {
   26|     42|   size_t i = 0;
   27|       |
   28|    210|   while(i < format.size()) {
  ------------------
  |  Branch (28:10): [True: 210, False: 0]
  ------------------
   29|    210|      if(format[i] == '{' && (format.size() > (i + 1)) && format.at(i + 1) == '}') {
  ------------------
  |  Branch (29:10): [True: 42, False: 168]
  |  Branch (29:30): [True: 42, False: 0]
  |  Branch (29:59): [True: 42, False: 0]
  ------------------
   30|     42|         oss << val;
   31|     42|         return do_fmt(oss, format.substr(i + 2), rest...);
   32|    168|      } else {
   33|    168|         oss << format[i];
   34|    168|      }
   35|       |
   36|    168|      i += 1;
   37|    168|   }
   38|     42|}

_ZN5Botan11checked_mulITkNSt3__117unsigned_integralEmEENS1_8optionalIT_EES3_S3_:
   46|  34.3k|constexpr inline std::optional<T> checked_mul(T a, T b) {
   47|       |   // Multiplication by 1U is a hack to work around C's insane
   48|       |   // integer promotion rules.
   49|       |   // https://stackoverflow.com/questions/24795651
   50|  34.3k|   const T r = (1U * a) * b;
   51|       |   // If a == 0 then the multiply certainly did not overflow
   52|       |   // Otherwise r / a == b unless overflow occurred
   53|  34.3k|   if(a != 0 && r / a != b) {
  ------------------
  |  Branch (53:7): [True: 34.3k, False: 0]
  |  Branch (53:17): [True: 0, False: 34.3k]
  ------------------
   54|      0|      return {};
   55|      0|   }
   56|  34.3k|   return r;
   57|  34.3k|}
_ZN5Botan15checked_cast_toItmQaasr3stdE8integralINS_6detail19wrapped_type_helperIu14__remove_cvrefIT_EE4typeEEsr3stdE8integralINS2_Iu14__remove_cvrefIT0_EE4typeEEEES3_S7_:
  104|     19|constexpr RT checked_cast_to(AT i) {
  105|     19|   return checked_cast_to_or_throw<RT, Internal_Error>(i, "Error during integer conversion");
  106|     19|}
_ZN5Botan24checked_cast_to_or_throwItNS_14Internal_ErrorEmQaasr3stdE8integralINS_6detail19wrapped_type_helperIu14__remove_cvrefIT_EE4typeEEsr3stdE8integralINS3_Iu14__remove_cvrefIT1_EE4typeEEEES4_S8_NSt3__117basic_string_viewIcNSC_11char_traitsIcEEEE:
   91|     19|constexpr RT checked_cast_to_or_throw(AT i, std::string_view error_msg_on_fail) {
   92|     19|   const auto unwrapped_input = unwrap_strong_type(i);
   93|       |
   94|     19|   const auto unwrapped_result = static_cast<strong_type_wrapped_type<RT>>(unwrapped_input);
   95|     19|   if(unwrapped_input != static_cast<strong_type_wrapped_type<AT>>(unwrapped_result)) [[unlikely]] {
  ------------------
  |  Branch (95:7): [True: 0, False: 19]
  ------------------
   96|      0|      throw ExceptionType(error_msg_on_fail);
   97|      0|   }
   98|       |
   99|     19|   return wrap_strong_type<RT>(unwrapped_result);
  100|     19|}
_ZN5Botan11checked_addITkNSt3__117unsigned_integralEjEENS1_8optionalIT_EES3_S3_:
   19|  2.33k|constexpr inline std::optional<T> checked_add(T a, T b) {
   20|  2.33k|   const T r = a + b;
   21|  2.33k|   if(r < a || r < b) {
  ------------------
  |  Branch (21:7): [True: 0, False: 2.33k]
  |  Branch (21:16): [True: 0, False: 2.33k]
  ------------------
   22|      0|      return {};
   23|      0|   }
   24|  2.33k|   return r;
   25|  2.33k|}
_ZN5Botan11checked_addITkNSt3__117unsigned_integralEmTpTkNS1_17unsigned_integralEJmmEQ10all_same_vIT_DpT0_EEENS1_8optionalIS2_EES2_S2_S4_:
   37|  4.32k|constexpr inline std::optional<T> checked_add(T a, T b, Ts... rest) {
   38|  4.32k|   if(auto r = checked_add(a, b)) {
  ------------------
  |  Branch (38:12): [True: 4.32k, False: 0]
  ------------------
   39|  4.32k|      return checked_add(r.value(), rest...);
   40|  4.32k|   } else {
   41|      0|      return {};
   42|      0|   }
   43|  4.32k|}
_ZN5Botan11checked_addITkNSt3__117unsigned_integralEmEENS1_8optionalIT_EES3_S3_:
   19|  13.5k|constexpr inline std::optional<T> checked_add(T a, T b) {
   20|  13.5k|   const T r = a + b;
   21|  13.5k|   if(r < a || r < b) {
  ------------------
  |  Branch (21:7): [True: 0, False: 13.5k]
  |  Branch (21:16): [True: 0, False: 13.5k]
  ------------------
   22|      0|      return {};
   23|      0|   }
   24|  13.5k|   return r;
   25|  13.5k|}
_ZN5Botan11checked_addITkNSt3__117unsigned_integralEmTpTkNS1_17unsigned_integralEJmEQ10all_same_vIT_DpT0_EEENS1_8optionalIS2_EES2_S2_S4_:
   37|  4.32k|constexpr inline std::optional<T> checked_add(T a, T b, Ts... rest) {
   38|  4.32k|   if(auto r = checked_add(a, b)) {
  ------------------
  |  Branch (38:12): [True: 4.32k, False: 0]
  ------------------
   39|  4.32k|      return checked_add(r.value(), rest...);
   40|  4.32k|   } else {
   41|      0|      return {};
   42|      0|   }
   43|  4.32k|}
_ZN5Botan13swar_in_rangeITkNSt3__117unsigned_integralEmEET_S2_S2_S2_:
  144|  49.5k|constexpr T swar_in_range(T v, T lower, T upper) {
  145|       |   // The constant 0x808080... as a T
  146|  49.5k|   constexpr T hi1 = (static_cast<T>(-1) / 255) << 7;
  147|       |   // The constant 0x7F7F7F... as a T
  148|  49.5k|   constexpr T lo7 = ~hi1;
  149|       |
  150|  49.5k|   const T sub = ((v | hi1) - (lower & lo7)) ^ ((v ^ (~lower)) & hi1);
  151|  49.5k|   const T a_lo = sub & lo7;
  152|  49.5k|   const T a_hi = sub & hi1;
  153|  49.5k|   return (lo7 - a_lo + upper) & hi1 & ~a_hi;
  154|  49.5k|}
_ZN5Botan11checked_addITkNSt3__117unsigned_integralEmTpTkNS1_17unsigned_integralEJmmmmmmEQ10all_same_vIT_DpT0_EEENS1_8optionalIS2_EES2_S2_S4_:
   37|    152|constexpr inline std::optional<T> checked_add(T a, T b, Ts... rest) {
   38|    152|   if(auto r = checked_add(a, b)) {
  ------------------
  |  Branch (38:12): [True: 152, False: 0]
  ------------------
   39|    152|      return checked_add(r.value(), rest...);
   40|    152|   } else {
   41|      0|      return {};
   42|      0|   }
   43|    152|}
_ZN5Botan11checked_addITkNSt3__117unsigned_integralEmTpTkNS1_17unsigned_integralEJmmmmmEQ10all_same_vIT_DpT0_EEENS1_8optionalIS2_EES2_S2_S4_:
   37|    152|constexpr inline std::optional<T> checked_add(T a, T b, Ts... rest) {
   38|    152|   if(auto r = checked_add(a, b)) {
  ------------------
  |  Branch (38:12): [True: 152, False: 0]
  ------------------
   39|    152|      return checked_add(r.value(), rest...);
   40|    152|   } else {
   41|      0|      return {};
   42|      0|   }
   43|    152|}
_ZN5Botan11checked_addITkNSt3__117unsigned_integralEmTpTkNS1_17unsigned_integralEJmmmmEQ10all_same_vIT_DpT0_EEENS1_8optionalIS2_EES2_S2_S4_:
   37|    152|constexpr inline std::optional<T> checked_add(T a, T b, Ts... rest) {
   38|    152|   if(auto r = checked_add(a, b)) {
  ------------------
  |  Branch (38:12): [True: 152, False: 0]
  ------------------
   39|    152|      return checked_add(r.value(), rest...);
   40|    152|   } else {
   41|      0|      return {};
   42|      0|   }
   43|    152|}
_ZN5Botan11checked_addITkNSt3__117unsigned_integralEmTpTkNS1_17unsigned_integralEJmmmEQ10all_same_vIT_DpT0_EEENS1_8optionalIS2_EES2_S2_S4_:
   37|    152|constexpr inline std::optional<T> checked_add(T a, T b, Ts... rest) {
   38|    152|   if(auto r = checked_add(a, b)) {
  ------------------
  |  Branch (38:12): [True: 152, False: 0]
  ------------------
   39|    152|      return checked_add(r.value(), rest...);
   40|    152|   } else {
   41|      0|      return {};
   42|      0|   }
   43|    152|}

_ZN5Botan8store_leINS_6detail10AutoDetectEJmEEEDaDpOT0_:
  736|  6.99k|inline constexpr auto store_le(ParamTs&&... params) {
  737|  6.99k|   return detail::store_any<std::endian::little, ModifierT>(std::forward<ParamTs>(params)...);
  738|  6.99k|}
_ZN5Botan6detail9store_anyILNSt3__16endianE57005ENS0_10AutoDetectETpTkNS0_20unsigned_integralishEJmEQ10all_same_vIDpT1_EEEDaS6_:
  696|  6.99k|inline constexpr auto store_any(Ts... ins) {
  697|  6.99k|   return store_any<endianness, OutR>(std::array{ins...});
  698|  6.99k|}
_ZN5Botan6detail9store_anyILNSt3__16endianE57005ENS0_10AutoDetectETkNS_6ranges14spanable_rangeENS2_5arrayImLm1EEEQoooosr3stdE7same_asIS4_T0_Eaasr6rangesE25statically_spanable_rangeIS8_Esr3stdE21default_initializableIS8_Esr8conceptsE21resizable_byte_bufferIS8_EEEDaOT1_:
  663|  6.99k|inline constexpr auto store_any(InR&& in_range) {
  664|  6.99k|   auto out = []([[maybe_unused]] const auto& in) {
  665|  6.99k|      if constexpr(std::same_as<AutoDetect, OutR>) {
  666|  6.99k|         if constexpr(ranges::statically_spanable_range<InR>) {
  667|  6.99k|            constexpr size_t bytes = decltype(std::span{in})::extent * sizeof(std::ranges::range_value_t<InR>);
  668|  6.99k|            return std::array<uint8_t, bytes>();
  669|  6.99k|         } else {
  670|  6.99k|            static_assert(
  671|  6.99k|               !std::same_as<AutoDetect, OutR>,
  672|  6.99k|               "cannot infer a suitable result container type from the given parameters at compile time, please specify it explicitly");
  673|  6.99k|         }
  674|  6.99k|      } else if constexpr(concepts::resizable_byte_buffer<OutR>) {
  675|  6.99k|         return OutR(std::span{in}.size_bytes());
  676|  6.99k|      } else {
  677|  6.99k|         return OutR{};
  678|  6.99k|      }
  679|  6.99k|   }(in_range);
  680|       |
  681|  6.99k|   store_any<endianness, std::ranges::range_value_t<InR>>(out, std::forward<InR>(in_range));
  682|  6.99k|   return out;
  683|  6.99k|}
_ZZN5Botan6detail9store_anyILNSt3__16endianE57005ENS0_10AutoDetectETkNS_6ranges14spanable_rangeENS2_5arrayImLm1EEEQoooosr3stdE7same_asIS4_T0_Eaasr6rangesE25statically_spanable_rangeIS8_Esr3stdE21default_initializableIS8_Esr8conceptsE21resizable_byte_bufferIS8_EEEDaOT1_ENKUlRKT_E_clIS7_EEDaSD_:
  664|  6.99k|   auto out = []([[maybe_unused]] const auto& in) {
  665|  6.99k|      if constexpr(std::same_as<AutoDetect, OutR>) {
  666|  6.99k|         if constexpr(ranges::statically_spanable_range<InR>) {
  667|  6.99k|            constexpr size_t bytes = decltype(std::span{in})::extent * sizeof(std::ranges::range_value_t<InR>);
  668|  6.99k|            return std::array<uint8_t, bytes>();
  669|       |         } else {
  670|       |            static_assert(
  671|       |               !std::same_as<AutoDetect, OutR>,
  672|       |               "cannot infer a suitable result container type from the given parameters at compile time, please specify it explicitly");
  673|       |         }
  674|       |      } else if constexpr(concepts::resizable_byte_buffer<OutR>) {
  675|       |         return OutR(std::span{in}.size_bytes());
  676|       |      } else {
  677|       |         return OutR{};
  678|       |      }
  679|  6.99k|   }(in_range);
_ZN5Botan6detail9store_anyILNSt3__16endianE57005EmTkNS_6ranges23contiguous_output_rangeIhEERNS2_5arrayIhLm8EEETkNS4_14spanable_rangeENS6_ImLm1EEEQoosr3stdE7same_asINS0_10AutoDetectET0_Esr3stdE7same_asISB_NS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT2_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISJ_EESK_E4type10value_typeEEEEvOT1_RKSG_:
  603|  6.99k|inline constexpr void store_any(OutR&& out /* NOLINT(*-std-forward) */, const InR& in) {
  604|  6.99k|   ranges::assert_equal_byte_lengths(out, in);
  605|  6.99k|   using element_type = std::ranges::range_value_t<InR>;
  606|       |
  607|  6.99k|   auto store_elementwise = [&] {
  608|  6.99k|      constexpr size_t bytes_per_element = sizeof(element_type);
  609|  6.99k|      std::span<uint8_t> out_s(out);
  610|  6.99k|      for(auto in_elem : in) {
  611|  6.99k|         store_any<endianness, element_type>(out_s.template first<bytes_per_element>(), in_elem);
  612|  6.99k|         out_s = out_s.subspan(bytes_per_element);
  613|  6.99k|      }
  614|  6.99k|   };
  615|       |
  616|       |   // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  617|       |   // internally to copy ranges on a byte-by-byte basis, which is not allowed
  618|       |   // in a `constexpr` context.
  619|  6.99k|   if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  ------------------
  |  Branch (619:7): [Folded, False: 6.99k]
  ------------------
  620|      0|      store_elementwise();
  621|  6.99k|   } else {
  622|  6.99k|      if constexpr(endianness == std::endian::native && !custom_storable<element_type>) {
  623|  6.99k|         typecast_copy(out, in);
  624|       |      } else {
  625|       |         store_elementwise();
  626|       |      }
  627|  6.99k|   }
  628|  6.99k|}
_ZN5Botan6detail26unwrap_strong_type_or_enumITkNS0_20unsigned_integralishEmEEDaT_:
  190|  5.23k|constexpr auto unwrap_strong_type_or_enum(InT t) {
  191|       |   if constexpr(std::is_enum_v<InT>) {
  192|       |      // TODO: C++23: use std::to_underlying(in) instead
  193|       |      return static_cast<std::underlying_type_t<InT>>(t);
  194|  5.23k|   } else {
  195|  5.23k|      return Botan::unwrap_strong_type(t);
  196|  5.23k|   }
  197|  5.23k|}
_ZN5Botan8get_byteILm0EmEEhT0_QltT_stS1_:
   81|    192|{
   82|    192|   const size_t shift = ((~B) & (sizeof(T) - 1)) << 3;
   83|    192|   return static_cast<uint8_t>((input >> shift) & 0xFF);
   84|    192|}
_ZN5Botan8get_byteILm0EtEEhT0_QltT_stS1_:
   81|     73|{
   82|     73|   const size_t shift = ((~B) & (sizeof(T) - 1)) << 3;
   83|     73|   return static_cast<uint8_t>((input >> shift) & 0xFF);
   84|     73|}
_ZN5Botan8get_byteILm1EtEEhT0_QltT_stS1_:
   81|     73|{
   82|     73|   const size_t shift = ((~B) & (sizeof(T) - 1)) << 3;
   83|     73|   return static_cast<uint8_t>((input >> shift) & 0xFF);
   84|     73|}
_ZN5Botan12get_byte_varImEEhmT_:
   69|  41.2k|inline constexpr uint8_t get_byte_var(size_t byte_num, T input) {
   70|  41.2k|   return static_cast<uint8_t>(input >> (((~byte_num) & (sizeof(T) - 1)) << 3));
   71|  41.2k|}
_ZN5Botan6detail9store_anyILNSt3__16endianE64206ENS0_10AutoDetectETkNS0_20unsigned_integralishEmQoosr3stdE7same_asIS4_T0_Esr3stdE7same_asIT1_S5_EEEvS6_Ph:
  711|  5.23k|inline constexpr void store_any(T in, uint8_t out[]) {
  712|       |   // asserts that *out points to enough bytes to write into
  713|  5.23k|   store_any<endianness, InT>(in, std::span<uint8_t, sizeof(T)>(out, sizeof(T)));
  714|  5.23k|}
_ZN5Botan6detail9store_anyILNSt3__16endianE64206ENS0_10AutoDetectETkNS0_20unsigned_integralishEmTkNS_6ranges23contiguous_output_rangeIhEENS2_4spanIhLm8EEEQsr3stdE7same_asIS4_T0_EEEvT1_OT2_:
  646|  5.23k|inline constexpr void store_any(T in, OutR&& out_range) {
  647|  5.23k|   store_any<endianness, T>(in, std::forward<OutR>(out_range));
  648|  5.23k|}
_ZN5Botan6detail9store_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEmTkNS_6ranges23contiguous_output_rangeIhEENS2_4spanIhLm8EEEQnt15custom_storableINS0_19wrapped_type_helperIu14__remove_cvrefIT0_EE4typeEEEEvS9_OT1_:
  525|  5.23k|inline constexpr void store_any(WrappedInT wrapped_in, OutR&& out_range) {
  526|  5.23k|   const auto in = detail::unwrap_strong_type_or_enum(wrapped_in);
  527|  5.23k|   using InT = decltype(in);
  528|  5.23k|   ranges::assert_exact_byte_length<sizeof(in)>(out_range);
  529|  5.23k|   const std::span out{out_range};
  530|       |
  531|       |   // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  532|       |   // internally to copy ranges on a byte-by-byte basis, which is not allowed
  533|       |   // in a `constexpr` context.
  534|  5.23k|   if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  ------------------
  |  Branch (534:7): [Folded, False: 5.23k]
  ------------------
  535|      0|      return fallback_store_any<endianness, InT>(in, std::forward<OutR>(out_range));
  536|  5.23k|   } else {
  537|       |      if constexpr(sizeof(InT) == 1) {
  538|       |         out[0] = static_cast<uint8_t>(in);
  539|       |      } else if constexpr(endianness == std::endian::native) {
  540|       |         typecast_copy(out, in);
  541|  5.23k|      } else {
  542|  5.23k|         static_assert(opposite(endianness) == std::endian::native);
  543|  5.23k|         typecast_copy(out, reverse_bytes(in));
  544|  5.23k|      }
  545|  5.23k|   }
  546|  5.23k|}
_ZN5Botan6detail24wrap_strong_type_or_enumITkNS0_20unsigned_integralishEjTkNSt3__117unsigned_integralEjEEDaT0_:
  200|    686|constexpr auto wrap_strong_type_or_enum(T t) {
  201|       |   if constexpr(std::is_enum_v<OutT>) {
  202|       |      return static_cast<OutT>(t);
  203|    686|   } else {
  204|    686|      return Botan::wrap_strong_type<OutT>(t);
  205|    686|   }
  206|    686|}
_ZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEjTkNS_6ranges16contiguous_rangeIhEENS2_4spanIKhLm4EEEQnt15custom_loadableINS0_19wrapped_type_helperIu14__remove_cvrefIT0_EE4typeEEEESA_OT1_:
  278|    686|inline constexpr WrappedOutT load_any(InR&& in_range) {
  279|    686|   using OutT = detail::wrapped_type<WrappedOutT>;
  280|    686|   ranges::assert_exact_byte_length<sizeof(OutT)>(in_range);
  281|       |
  282|    686|   return detail::wrap_strong_type_or_enum<WrappedOutT>([&]() -> OutT {
  283|       |      // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  284|       |      // internally to copy ranges on a byte-by-byte basis, which is not allowed
  285|       |      // in a `constexpr` context.
  286|    686|      if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  287|    686|         return fallback_load_any<endianness, OutT>(std::forward<InR>(in_range));
  288|    686|      } else {
  289|    686|         const std::span in{in_range};
  290|    686|         if constexpr(sizeof(OutT) == 1) {
  291|    686|            return static_cast<OutT>(in[0]);
  292|    686|         } else if constexpr(endianness == std::endian::native) {
  293|    686|            return typecast_copy<OutT>(in);
  294|    686|         } else {
  295|    686|            static_assert(opposite(endianness) == std::endian::native);
  296|    686|            return reverse_bytes(typecast_copy<OutT>(in));
  297|    686|         }
  298|    686|      }
  299|    686|   }());
  300|    686|}
_ZZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEjTkNS_6ranges16contiguous_rangeIhEENS2_4spanIKhLm4EEEQnt15custom_loadableINS0_19wrapped_type_helperIu14__remove_cvrefIT0_EE4typeEEEESA_OT1_ENKUlvE_clEv:
  282|    686|   return detail::wrap_strong_type_or_enum<WrappedOutT>([&]() -> OutT {
  283|       |      // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  284|       |      // internally to copy ranges on a byte-by-byte basis, which is not allowed
  285|       |      // in a `constexpr` context.
  286|    686|      if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  ------------------
  |  Branch (286:10): [Folded, False: 686]
  ------------------
  287|      0|         return fallback_load_any<endianness, OutT>(std::forward<InR>(in_range));
  288|    686|      } else {
  289|    686|         const std::span in{in_range};
  290|       |         if constexpr(sizeof(OutT) == 1) {
  291|       |            return static_cast<OutT>(in[0]);
  292|       |         } else if constexpr(endianness == std::endian::native) {
  293|       |            return typecast_copy<OutT>(in);
  294|    686|         } else {
  295|    686|            static_assert(opposite(endianness) == std::endian::native);
  296|    686|            return reverse_bytes(typecast_copy<OutT>(in));
  297|    686|         }
  298|    686|      }
  299|    686|   }());
_ZN5Botan8store_beINS_6detail10AutoDetectEJRKmPhEEEDaDpOT0_:
  745|  5.23k|inline constexpr auto store_be(ParamTs&&... params) {
  746|  5.23k|   return detail::store_any<std::endian::big, ModifierT>(std::forward<ParamTs>(params)...);
  747|  5.23k|}
_ZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEmTkNS_6ranges16contiguous_rangeIhEENS2_4spanIKhLm8EEEQnt15custom_loadableINS0_19wrapped_type_helperIu14__remove_cvrefIT0_EE4typeEEEESA_OT1_:
  278|  6.92k|inline constexpr WrappedOutT load_any(InR&& in_range) {
  279|  6.92k|   using OutT = detail::wrapped_type<WrappedOutT>;
  280|  6.92k|   ranges::assert_exact_byte_length<sizeof(OutT)>(in_range);
  281|       |
  282|  6.92k|   return detail::wrap_strong_type_or_enum<WrappedOutT>([&]() -> OutT {
  283|       |      // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  284|       |      // internally to copy ranges on a byte-by-byte basis, which is not allowed
  285|       |      // in a `constexpr` context.
  286|  6.92k|      if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  287|  6.92k|         return fallback_load_any<endianness, OutT>(std::forward<InR>(in_range));
  288|  6.92k|      } else {
  289|  6.92k|         const std::span in{in_range};
  290|  6.92k|         if constexpr(sizeof(OutT) == 1) {
  291|  6.92k|            return static_cast<OutT>(in[0]);
  292|  6.92k|         } else if constexpr(endianness == std::endian::native) {
  293|  6.92k|            return typecast_copy<OutT>(in);
  294|  6.92k|         } else {
  295|  6.92k|            static_assert(opposite(endianness) == std::endian::native);
  296|  6.92k|            return reverse_bytes(typecast_copy<OutT>(in));
  297|  6.92k|         }
  298|  6.92k|      }
  299|  6.92k|   }());
  300|  6.92k|}
_ZN5Botan6detail24wrap_strong_type_or_enumITkNS0_20unsigned_integralishEmTkNSt3__117unsigned_integralEmEEDaT0_:
  200|  19.2k|constexpr auto wrap_strong_type_or_enum(T t) {
  201|       |   if constexpr(std::is_enum_v<OutT>) {
  202|       |      return static_cast<OutT>(t);
  203|  19.2k|   } else {
  204|  19.2k|      return Botan::wrap_strong_type<OutT>(t);
  205|  19.2k|   }
  206|  19.2k|}
_ZZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEmTkNS_6ranges16contiguous_rangeIhEENS2_4spanIKhLm8EEEQnt15custom_loadableINS0_19wrapped_type_helperIu14__remove_cvrefIT0_EE4typeEEEESA_OT1_ENKUlvE_clEv:
  282|  6.92k|   return detail::wrap_strong_type_or_enum<WrappedOutT>([&]() -> OutT {
  283|       |      // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  284|       |      // internally to copy ranges on a byte-by-byte basis, which is not allowed
  285|       |      // in a `constexpr` context.
  286|  6.92k|      if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  ------------------
  |  Branch (286:10): [Folded, False: 6.92k]
  ------------------
  287|      0|         return fallback_load_any<endianness, OutT>(std::forward<InR>(in_range));
  288|  6.92k|      } else {
  289|  6.92k|         const std::span in{in_range};
  290|       |         if constexpr(sizeof(OutT) == 1) {
  291|       |            return static_cast<OutT>(in[0]);
  292|       |         } else if constexpr(endianness == std::endian::native) {
  293|       |            return typecast_copy<OutT>(in);
  294|  6.92k|         } else {
  295|  6.92k|            static_assert(opposite(endianness) == std::endian::native);
  296|  6.92k|            return reverse_bytes(typecast_copy<OutT>(in));
  297|  6.92k|         }
  298|  6.92k|      }
  299|  6.92k|   }());
_ZN5Botan7load_beImJNSt3__14spanIKhLm8EEEEEEDaDpOT0_:
  504|  6.92k|inline constexpr auto load_be(ParamTs&&... params) {
  505|  6.92k|   return detail::load_any<std::endian::big, OutT>(std::forward<ParamTs>(params)...);
  506|  6.92k|}
_ZN5Botan7load_beImJRNSt3__15arrayIhLm8EEEEEEDaDpOT0_:
  504|  12.3k|inline constexpr auto load_be(ParamTs&&... params) {
  505|  12.3k|   return detail::load_any<std::endian::big, OutT>(std::forward<ParamTs>(params)...);
  506|  12.3k|}
_ZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEmTkNS_6ranges16contiguous_rangeIhEERNS2_5arrayIhLm8EEEQnt15custom_loadableINS0_19wrapped_type_helperIu14__remove_cvrefIT0_EE4typeEEEESA_OT1_:
  278|  12.3k|inline constexpr WrappedOutT load_any(InR&& in_range) {
  279|  12.3k|   using OutT = detail::wrapped_type<WrappedOutT>;
  280|  12.3k|   ranges::assert_exact_byte_length<sizeof(OutT)>(in_range);
  281|       |
  282|  12.3k|   return detail::wrap_strong_type_or_enum<WrappedOutT>([&]() -> OutT {
  283|       |      // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  284|       |      // internally to copy ranges on a byte-by-byte basis, which is not allowed
  285|       |      // in a `constexpr` context.
  286|  12.3k|      if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  287|  12.3k|         return fallback_load_any<endianness, OutT>(std::forward<InR>(in_range));
  288|  12.3k|      } else {
  289|  12.3k|         const std::span in{in_range};
  290|  12.3k|         if constexpr(sizeof(OutT) == 1) {
  291|  12.3k|            return static_cast<OutT>(in[0]);
  292|  12.3k|         } else if constexpr(endianness == std::endian::native) {
  293|  12.3k|            return typecast_copy<OutT>(in);
  294|  12.3k|         } else {
  295|  12.3k|            static_assert(opposite(endianness) == std::endian::native);
  296|  12.3k|            return reverse_bytes(typecast_copy<OutT>(in));
  297|  12.3k|         }
  298|  12.3k|      }
  299|  12.3k|   }());
  300|  12.3k|}
_ZZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEmTkNS_6ranges16contiguous_rangeIhEERNS2_5arrayIhLm8EEEQnt15custom_loadableINS0_19wrapped_type_helperIu14__remove_cvrefIT0_EE4typeEEEESA_OT1_ENKUlvE_clEv:
  282|  12.3k|   return detail::wrap_strong_type_or_enum<WrappedOutT>([&]() -> OutT {
  283|       |      // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  284|       |      // internally to copy ranges on a byte-by-byte basis, which is not allowed
  285|       |      // in a `constexpr` context.
  286|  12.3k|      if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  ------------------
  |  Branch (286:10): [Folded, False: 12.3k]
  ------------------
  287|      0|         return fallback_load_any<endianness, OutT>(std::forward<InR>(in_range));
  288|  12.3k|      } else {
  289|  12.3k|         const std::span in{in_range};
  290|       |         if constexpr(sizeof(OutT) == 1) {
  291|       |            return static_cast<OutT>(in[0]);
  292|       |         } else if constexpr(endianness == std::endian::native) {
  293|       |            return typecast_copy<OutT>(in);
  294|  12.3k|         } else {
  295|  12.3k|            static_assert(opposite(endianness) == std::endian::native);
  296|  12.3k|            return reverse_bytes(typecast_copy<OutT>(in));
  297|  12.3k|         }
  298|  12.3k|      }
  299|  12.3k|   }());
_ZN5Botan7load_beItJPKhRmEEEDaDpOT0_:
  504|  1.06k|inline constexpr auto load_be(ParamTs&&... params) {
  505|  1.06k|   return detail::load_any<std::endian::big, OutT>(std::forward<ParamTs>(params)...);
  506|  1.06k|}
_ZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEtEET0_PKhm:
  454|  1.06k|inline constexpr OutT load_any(const uint8_t in[], size_t off) {
  455|       |   // asserts that *in points to enough bytes to read at offset off
  456|  1.06k|   constexpr size_t out_size = sizeof(OutT);
  457|  1.06k|   return load_any<endianness, OutT>(std::span<const uint8_t, out_size>(in + off * out_size, out_size));
  458|  1.06k|}
_ZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEtTkNS_6ranges16contiguous_rangeIhEENS2_4spanIKhLm2EEEQnt15custom_loadableINS0_19wrapped_type_helperIu14__remove_cvrefIT0_EE4typeEEEESA_OT1_:
  278|  1.06k|inline constexpr WrappedOutT load_any(InR&& in_range) {
  279|  1.06k|   using OutT = detail::wrapped_type<WrappedOutT>;
  280|  1.06k|   ranges::assert_exact_byte_length<sizeof(OutT)>(in_range);
  281|       |
  282|  1.06k|   return detail::wrap_strong_type_or_enum<WrappedOutT>([&]() -> OutT {
  283|       |      // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  284|       |      // internally to copy ranges on a byte-by-byte basis, which is not allowed
  285|       |      // in a `constexpr` context.
  286|  1.06k|      if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  287|  1.06k|         return fallback_load_any<endianness, OutT>(std::forward<InR>(in_range));
  288|  1.06k|      } else {
  289|  1.06k|         const std::span in{in_range};
  290|  1.06k|         if constexpr(sizeof(OutT) == 1) {
  291|  1.06k|            return static_cast<OutT>(in[0]);
  292|  1.06k|         } else if constexpr(endianness == std::endian::native) {
  293|  1.06k|            return typecast_copy<OutT>(in);
  294|  1.06k|         } else {
  295|  1.06k|            static_assert(opposite(endianness) == std::endian::native);
  296|  1.06k|            return reverse_bytes(typecast_copy<OutT>(in));
  297|  1.06k|         }
  298|  1.06k|      }
  299|  1.06k|   }());
  300|  1.06k|}
_ZN5Botan6detail24wrap_strong_type_or_enumITkNS0_20unsigned_integralishEtTkNSt3__117unsigned_integralEtEEDaT0_:
  200|  1.06k|constexpr auto wrap_strong_type_or_enum(T t) {
  201|       |   if constexpr(std::is_enum_v<OutT>) {
  202|       |      return static_cast<OutT>(t);
  203|  1.06k|   } else {
  204|  1.06k|      return Botan::wrap_strong_type<OutT>(t);
  205|  1.06k|   }
  206|  1.06k|}
_ZZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEtTkNS_6ranges16contiguous_rangeIhEENS2_4spanIKhLm2EEEQnt15custom_loadableINS0_19wrapped_type_helperIu14__remove_cvrefIT0_EE4typeEEEESA_OT1_ENKUlvE_clEv:
  282|  1.06k|   return detail::wrap_strong_type_or_enum<WrappedOutT>([&]() -> OutT {
  283|       |      // At compile time we cannot use `typecast_copy` as it uses `std::memcpy`
  284|       |      // internally to copy ranges on a byte-by-byte basis, which is not allowed
  285|       |      // in a `constexpr` context.
  286|  1.06k|      if(std::is_constant_evaluated()) /* TODO: C++23: if consteval {} */ {
  ------------------
  |  Branch (286:10): [Folded, False: 1.06k]
  ------------------
  287|      0|         return fallback_load_any<endianness, OutT>(std::forward<InR>(in_range));
  288|  1.06k|      } else {
  289|  1.06k|         const std::span in{in_range};
  290|       |         if constexpr(sizeof(OutT) == 1) {
  291|       |            return static_cast<OutT>(in[0]);
  292|       |         } else if constexpr(endianness == std::endian::native) {
  293|       |            return typecast_copy<OutT>(in);
  294|  1.06k|         } else {
  295|  1.06k|            static_assert(opposite(endianness) == std::endian::native);
  296|  1.06k|            return reverse_bytes(typecast_copy<OutT>(in));
  297|  1.06k|         }
  298|  1.06k|      }
  299|  1.06k|   }());
_ZN5Botan7load_beIjJPKhRmEEEDaDpOT0_:
  504|    165|inline constexpr auto load_be(ParamTs&&... params) {
  505|    165|   return detail::load_any<std::endian::big, OutT>(std::forward<ParamTs>(params)...);
  506|    165|}
_ZN5Botan6detail8load_anyILNSt3__16endianE64206ETkNS0_20unsigned_integralishEjEET0_PKhm:
  454|    686|inline constexpr OutT load_any(const uint8_t in[], size_t off) {
  455|       |   // asserts that *in points to enough bytes to read at offset off
  456|    686|   constexpr size_t out_size = sizeof(OutT);
  457|    686|   return load_any<endianness, OutT>(std::span<const uint8_t, out_size>(in + off * out_size, out_size));
  458|    686|}
_ZN5Botan7load_beIjJPKhiEEEDaDpOT0_:
  504|    521|inline constexpr auto load_be(ParamTs&&... params) {
  505|    521|   return detail::load_any<std::endian::big, OutT>(std::forward<ParamTs>(params)...);
  506|    521|}

_ZN5Botan15bytes_to_stringENSt3__14spanIKhLm18446744073709551615EEE:
   76|  17.6k|inline std::string bytes_to_string(std::span<const uint8_t> bytes) {
   77|  17.6k|   return std::string(reinterpret_cast<const char*>(bytes.data()), bytes.size());
   78|  17.6k|}

_ZN5Botan10bigint_cmpITkNS_8WordTypeEmEEiPKT_mS3_m:
  460|  6.59k|inline constexpr int32_t bigint_cmp(const W x[], size_t x_size, const W y[], size_t y_size) {
  461|  6.59k|   static_assert(sizeof(W) >= sizeof(uint32_t), "Size assumption");
  462|       |
  463|  6.59k|   const W LT = static_cast<W>(-1);
  464|  6.59k|   const W EQ = 0;
  465|  6.59k|   const W GT = 1;
  466|       |
  467|  6.59k|   const size_t common_elems = std::min(x_size, y_size);
  468|       |
  469|  6.59k|   W result = EQ;  // until found otherwise
  470|       |
  471|  12.9k|   for(size_t i = 0; i != common_elems; i++) {
  ------------------
  |  Branch (471:22): [True: 6.34k, False: 6.59k]
  ------------------
  472|  6.34k|      const auto is_eq = CT::Mask<W>::is_equal(x[i], y[i]);
  473|  6.34k|      const auto is_lt = CT::Mask<W>::is_lt(x[i], y[i]);
  474|       |
  475|  6.34k|      result = is_eq.select(result, is_lt.select(LT, GT));
  476|  6.34k|   }
  477|       |
  478|  6.59k|   if(x_size < y_size) {
  ------------------
  |  Branch (478:7): [True: 250, False: 6.34k]
  ------------------
  479|    250|      W mask = 0;
  480|    500|      for(size_t i = x_size; i != y_size; i++) {
  ------------------
  |  Branch (480:30): [True: 250, False: 250]
  ------------------
  481|    250|         mask |= y[i];
  482|    250|      }
  483|       |
  484|       |      // If any bits were set in high part of y, then x < y
  485|    250|      result = CT::Mask<W>::is_zero(mask).select(result, LT);
  486|  6.34k|   } else if(y_size < x_size) {
  ------------------
  |  Branch (486:14): [True: 0, False: 6.34k]
  ------------------
  487|      0|      W mask = 0;
  488|      0|      for(size_t i = y_size; i != x_size; i++) {
  ------------------
  |  Branch (488:30): [True: 0, False: 0]
  ------------------
  489|      0|         mask |= x[i];
  490|      0|      }
  491|       |
  492|       |      // If any bits were set in high part of x, then x > y
  493|      0|      result = CT::Mask<W>::is_zero(mask).select(result, GT);
  494|      0|   }
  495|       |
  496|  6.59k|   CT::unpoison(result);
  497|  6.59k|   BOTAN_DEBUG_ASSERT(result == LT || result == GT || result == EQ);
  ------------------
  |  |  137|  6.59k|      do { /* NOLINT(*-avoid-do-while) */ \
  |  |  138|  6.59k|      } while(0)
  |  |  ------------------
  |  |  |  Branch (138:15): [Folded, False: 6.59k]
  |  |  ------------------
  ------------------
  498|  6.59k|   return static_cast<int32_t>(result);
  499|  6.59k|}

_ZN5Botan8round_upEmm:
   26|  33.3k|constexpr inline size_t round_up(size_t n, size_t align_to) {
   27|       |   // Arguably returning n in this case would also be sensible
   28|  33.3k|   BOTAN_ARG_CHECK(align_to != 0, "align_to must not be 0");
  ------------------
  |  |   35|  33.3k|   do {                                                          \
  |  |   36|  33.3k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  33.3k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 33.3k]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|  33.3k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 33.3k]
  |  |  ------------------
  ------------------
   29|       |
   30|  33.3k|   if(n % align_to > 0) {
  ------------------
  |  Branch (30:7): [True: 32.1k, False: 1.21k]
  ------------------
   31|  32.1k|      const size_t adj = align_to - (n % align_to);
   32|  32.1k|      BOTAN_ARG_CHECK(n + adj >= n, "Integer overflow during rounding");
  ------------------
  |  |   35|  32.1k|   do {                                                          \
  |  |   36|  32.1k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  32.1k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 32.1k]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|  32.1k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 32.1k]
  |  |  ------------------
  ------------------
   33|  32.1k|      n += adj;
   34|  32.1k|   }
   35|  33.3k|   return n;
   36|  33.3k|}

_ZN5Botan2CT13value_barrierITkNSt3__117unsigned_integralEjQntsr3stdE7same_asIbT_EEES3_S3_:
   43|  8.00k|constexpr inline T value_barrier(T x) {
   44|  8.00k|   if(std::is_constant_evaluated()) {
  ------------------
  |  Branch (44:7): [Folded, False: 8.00k]
  ------------------
   45|      0|      return x;
   46|  8.00k|   } else {
   47|  8.00k|#if defined(BOTAN_CT_VALUE_BARRIER_USE_ASM)
   48|       |      /*
   49|       |      * We may want a "stronger" statement such as
   50|       |      *     asm volatile("" : "+r,m"(x) : : "memory);
   51|       |      * (see https://theunixzoo.co.uk/blog/2021-10-14-preventing-optimisations.html)
   52|       |      * however the current approach seems sufficient with current compilers,
   53|       |      * and is minimally damaging with regards to degrading code generation.
   54|       |      */
   55|  8.00k|      asm("" : "+r"(x) : /* no input */);  // NOLINT(*-no-assembler)
   56|  8.00k|      return x;
   57|       |#elif defined(BOTAN_CT_VALUE_BARRIER_USE_VOLATILE)
   58|       |      volatile T vx = x;
   59|       |      return vx;
   60|       |#else
   61|       |      return x;
   62|       |#endif
   63|  8.00k|   }
   64|  8.00k|}
_ZN5Botan2CT13value_barrierITkNSt3__117unsigned_integralEmQntsr3stdE7same_asIbT_EEES3_S3_:
   43|   322k|constexpr inline T value_barrier(T x) {
   44|   322k|   if(std::is_constant_evaluated()) {
  ------------------
  |  Branch (44:7): [Folded, False: 322k]
  ------------------
   45|      0|      return x;
   46|   322k|   } else {
   47|   322k|#if defined(BOTAN_CT_VALUE_BARRIER_USE_ASM)
   48|       |      /*
   49|       |      * We may want a "stronger" statement such as
   50|       |      *     asm volatile("" : "+r,m"(x) : : "memory);
   51|       |      * (see https://theunixzoo.co.uk/blog/2021-10-14-preventing-optimisations.html)
   52|       |      * however the current approach seems sufficient with current compilers,
   53|       |      * and is minimally damaging with regards to degrading code generation.
   54|       |      */
   55|   322k|      asm("" : "+r"(x) : /* no input */);  // NOLINT(*-no-assembler)
   56|   322k|      return x;
   57|       |#elif defined(BOTAN_CT_VALUE_BARRIER_USE_VOLATILE)
   58|       |      volatile T vx = x;
   59|       |      return vx;
   60|       |#else
   61|       |      return x;
   62|       |#endif
   63|   322k|   }
   64|   322k|}

_ZN5Botan17is_sub_element_ofERKNS_3OIDESt16initializer_listIjE:
   22|  21.6k|inline std::optional<uint32_t> is_sub_element_of(const OID& oid, std::initializer_list<uint32_t> prefix) {
   23|  21.6k|   const auto& c = oid.get_components();
   24|       |
   25|  21.6k|   if(c.size() != prefix.size() + 1) {
  ------------------
  |  Branch (25:7): [True: 9.67k, False: 11.9k]
  ------------------
   26|  9.67k|      return {};
   27|  9.67k|   }
   28|       |
   29|  11.9k|   if(!std::equal(c.begin(), c.end() - 1, prefix.begin(), prefix.end())) {
  ------------------
  |  Branch (29:7): [True: 1.12k, False: 10.8k]
  ------------------
   30|  1.12k|      return {};
   31|  1.12k|   }
   32|       |
   33|  10.8k|   return c[c.size() - 1];
   34|  11.9k|}

_ZN5Botan11ASN1_ObjectD2Ev:
  168|   209k|      virtual ~ASN1_Object() = default;
_ZNK5Botan14ASN1_BitString5bytesEv:
  206|  5.38k|      std::span<const uint8_t> bytes() const { return std::span{m_bytes}; }
_ZNK5Botan14ASN1_BitString11unused_bitsEv:
  211|  2.69k|      size_t unused_bits() const { return m_unused_bits; }
_ZNK5Botan10BER_Object6is_setEv:
  267|   375k|      bool is_set() const { return m_type_tag != ASN1_Type::NoObject; }
_ZNK5Botan10BER_Object7taggingEv:
  272|   157k|      uint32_t tagging() const { return type_tag() | class_tag(); }
_ZNK5Botan10BER_Object8type_tagEv:
  277|   159k|      ASN1_Type type_tag() const { return m_type_tag; }
_ZNK5Botan10BER_Object9class_tagEv:
  282|   178k|      ASN1_Class class_tag() const { return m_class_tag; }
_ZNK5Botan10BER_Object4typeEv:
  287|  30.8k|      ASN1_Type type() const { return m_type_tag; }
_ZNK5Botan10BER_Object9get_classEv:
  292|  15.5k|      ASN1_Class get_class() const { return m_class_tag; }
_ZNK5Botan10BER_Object4bitsEv:
  298|   410k|      const uint8_t* bits() const { return m_value.data(); }
_ZNK5Botan10BER_Object6lengthEv:
  303|  1.08M|      size_t length() const { return m_value.size(); }
_ZNK5Botan10BER_Object4dataEv:
  308|  59.3k|      std::span<const uint8_t> data() const { return std::span{m_value}; }
_ZN5Botan10BER_Object12mutable_bitsEm:
  344|   134k|      uint8_t* mutable_bits(size_t length) {
  345|   134k|         m_value.resize(length);
  346|   134k|         return m_value.data();
  347|   134k|      }
_ZNK5Botan3OID5emptyEv:
  468|    891|      bool empty() const { return m_id.empty(); }
_ZNK5Botan3OID9has_valueEv:
  474|    891|      bool has_value() const { return !empty(); }
_ZNK5Botan3OIDeqERKS0_:
  510|  11.8k|      bool operator==(const OID& other) const { return m_id == other.m_id; }
_ZNK5Botan3OID14get_componentsEv:
  530|  82.9k|      const std::vector<uint32_t>& get_components() const {
  531|  82.9k|         return m_id;
  532|  82.9k|      }
_ZNK5Botan11ASN1_String5valueEv:
  590|  2.77k|      const std::string& value() const { return m_utf8_str; }
_ZN5BotanltERKNS_11ASN1_StringES2_:
  612|    222|      friend bool operator<(const ASN1_String& a, const ASN1_String& b) { return a.value() < b.value(); }
_ZNK5Botan19AlgorithmIdentifier3oidEv:
  688|  4.85k|      const OID& oid() const { return m_oid; }
_ZNK5Botan19AlgorithmIdentifier10parametersEv:
  693|  4.73k|      const std::vector<uint8_t>& parameters() const { return m_parameters; }
_ZNK5Botan19AlgorithmIdentifier20parameters_are_emptyEv:
  715|  5.30k|      bool parameters_are_empty() const { return m_parameters.empty(); }
_ZNK5Botan19AlgorithmIdentifier28parameters_are_null_or_emptyEv:
  720|  5.30k|      bool parameters_are_null_or_empty() const { return parameters_are_empty() || parameters_are_null(); }
  ------------------
  |  Branch (720:58): [True: 3.28k, False: 2.01k]
  |  Branch (720:84): [True: 1.78k, False: 239]
  ------------------
_ZN5BotanorENS_10ASN1_ClassES0_:
   91|  68.3k|inline ASN1_Class operator|(ASN1_Class x, ASN1_Class y) {
   92|  68.3k|   return static_cast<ASN1_Class>(static_cast<uint32_t>(x) | static_cast<uint32_t>(y));
   93|  68.3k|}
_ZN5BotanorENS_9ASN1_TypeENS_10ASN1_ClassE:
   98|   157k|inline uint32_t operator|(ASN1_Type x, ASN1_Class y) {
   99|   157k|   return static_cast<uint32_t>(x) | static_cast<uint32_t>(y);
  100|   157k|}
_ZN5BotanorENS_10ASN1_ClassENS_9ASN1_TypeE:
  105|  23.3k|inline uint32_t operator|(ASN1_Class x, ASN1_Type y) {
  106|  23.3k|   return static_cast<uint32_t>(x) | static_cast<uint32_t>(y);
  107|  23.3k|}
_ZN5BotanneERKNS_3OIDES2_:
  561|  1.06k|inline bool operator!=(const OID& a, const OID& b) {
  562|  1.06k|   return !(a == b);
  563|  1.06k|}
_ZNKSt3__14hashIN5Botan3OIDEEclERKS2_:
  761|      4|      size_t operator()(const Botan::OID& oid) const noexcept { return static_cast<size_t>(oid.hash_code()); }
_ZN5Botan11ASN1_ObjectC2Ev:
  146|   123k|      ASN1_Object() = default;
_ZN5Botan19AlgorithmIdentifierC2Ev:
  655|  6.01k|      AlgorithmIdentifier() = default;
_ZN5Botan3OIDC2Ev:
  423|  24.4k|      explicit OID() = default;
_ZN5Botan11ASN1_ObjectC2EOS0_:
  161|  51.4k|      ASN1_Object(ASN1_Object&&) = default;
_ZN5Botan10BER_ObjectaSEOS0_:
  259|  57.1k|      BER_Object& operator=(BER_Object&& other) = default;
_ZN5Botan11ASN1_ObjectC2ERKS0_:
  151|  34.6k|      ASN1_Object(const ASN1_Object&) = default;
_ZN5Botan11ASN1_ObjectaSEOS0_:
  166|  20.3k|      ASN1_Object& operator=(ASN1_Object&&) = default;
_ZN5Botan14ASN1_BitStringC2Ev:
  179|  2.80k|      ASN1_BitString() = default;
_ZN5Botan10BER_ObjectC2EOS0_:
  249|  73.3k|      BER_Object(BER_Object&& other) = default;
_ZN5Botan10BER_ObjectC2Ev:
  239|   228k|      BER_Object() = default;
_ZN5Botan10BER_ObjectC2ERKS0_:
  244|    224|      BER_Object(const BER_Object& other) = default;

_ZN5Botan9ASN1_TimeC2Ev:
   42|  14.3k|      ASN1_Time() = default;

_ZN5Botan13ignore_paramsIJPKmmEEEvDpRKT_:
  149|  73.4k|constexpr void ignore_params([[maybe_unused]] const T&... args) {}
_ZN5Botan13ignore_paramsIJjEEEvDpRKT_:
  149|  15.1k|constexpr void ignore_params([[maybe_unused]] const T&... args) {}

_ZN5Botan11BER_Decoder6Limits3DEREv:
   43|  12.7k|            static Limits DER() { return Limits(false, 0, false, DefaultMaxObjectSize, false); }
_ZN5Botan11BER_Decoder6LimitsC2EbmbNSt3__18optionalImEEb:
  134|  12.7k|                  m_allow_ber(allow_ber),
  135|  12.7k|                  m_max_nested_indef(max_nested_indef),
  136|  12.7k|                  m_allow_standalone_eoc(allow_standalone_eoc),
  137|  12.7k|                  m_max_object_size(max_object_size),
  138|  12.7k|                  m_reject_default_value_encoding(reject_default_value_encoding) {}
_ZN5Botan11BER_Decoder15decode_optionalImEERS0_RT_NS_9ASN1_TypeENS_10ASN1_ClassERKS3_:
  551|  2.67k|      BER_Decoder& decode_optional(T& out, ASN1_Type type_tag, ASN1_Class class_tag, const T& default_value = T()) {
  552|  2.67k|         std::optional<T> optval;
  553|  2.67k|         this->decode_optional(optval, type_tag, class_tag);
  554|  2.67k|         out = optval ? *optval : default_value;
  ------------------
  |  Branch (554:16): [True: 2.36k, False: 307]
  ------------------
  555|  2.67k|         return (*this);
  556|  2.67k|      }
_ZN5Botan11BER_Decoder15decode_optionalImEERS0_RNSt3__18optionalIT_EENS_9ASN1_TypeENS_10ASN1_ClassE:
  827|  2.67k|BER_Decoder& BER_Decoder::decode_optional(std::optional<T>& optval, ASN1_Type type_tag, ASN1_Class class_tag) {
  828|  2.67k|   BER_Object obj = get_next_object();
  829|       |
  830|  2.67k|   if(obj.is_a(type_tag, class_tag)) {
  ------------------
  |  Branch (830:7): [True: 2.48k, False: 186]
  ------------------
  831|  2.48k|      T out{};
  832|  2.48k|      if(class_tag == ASN1_Class::ExplicitContextSpecific) {
  ------------------
  |  Branch (832:10): [True: 0, False: 2.48k]
  ------------------
  833|      0|         BER_Decoder(obj, m_limits).decode(out).verify_end();
  834|  2.48k|      } else {
  835|  2.48k|         this->push_back(std::move(obj));
  836|       |         if constexpr(std::is_base_of_v<ASN1_Object, T>) {
  837|       |            // Object types check the tag in decode_from; a re-tagging
  838|       |            // implicit override of an object is not supported here
  839|       |            this->decode(out);
  840|  2.48k|         } else {
  841|  2.48k|            this->decode(out, type_tag, class_tag);
  842|  2.48k|         }
  843|  2.48k|      }
  844|  2.48k|      optval = std::move(out);
  845|  2.48k|   } else {
  846|    186|      this->push_back(std::move(obj));
  847|    186|      optval = std::nullopt;
  848|    186|   }
  849|       |
  850|  2.67k|   return (*this);
  851|  2.67k|}
_ZNK5Botan11BER_Decoder6limitsEv:
  198|  60.6k|      Limits limits() const { return m_limits; }
_ZN5Botan11BER_DecoderC2ERKNS_10BER_ObjectENS0_6LimitsE:
  168|  3.70k|            BER_Decoder(obj.data(), limits) {}
_ZNK5Botan11BER_Decoder6Limits18allow_ber_encodingEv:
   57|   342k|            bool allow_ber_encoding() const { return m_allow_ber; }
_ZNK5Botan11BER_Decoder6Limits20require_der_encodingEv:
   62|   206k|            bool require_der_encoding() const { return !allow_ber_encoding(); }
_ZNK5Botan11BER_Decoder6Limits15max_object_sizeEv:
   81|   135k|            std::optional<size_t> max_object_size() const { return m_max_object_size; }
_ZN5Botan11BER_Decoder14start_sequenceEv:
  276|  52.8k|      BER_Decoder start_sequence() { return start_cons(ASN1_Type::Sequence, ASN1_Class::Universal); }
_ZN5Botan11BER_Decoder9start_setEv:
  282|  2.94k|      BER_Decoder start_set() { return start_cons(ASN1_Type::Set, ASN1_Class::Universal); }
_ZN5Botan11BER_Decoder22start_context_specificEj:
  291|     39|      BER_Decoder start_context_specific(uint32_t tag) {
  292|     39|         return start_cons(ASN1_Type(tag), ASN1_Class::ContextSpecific);
  293|     39|      }
_ZN5Botan11BER_Decoder6decodeERNS_6BigIntE:
  366|  9.01k|      BER_Decoder& decode(BigInt& out) { return decode(out, ASN1_Type::Integer, ASN1_Class::Universal); }
_ZN5Botan11BER_Decoder6decodeINSt3__19allocatorIhEEEERS0_RNS2_6vectorIhT_EENS_9ASN1_TypeE:
  384|  14.0k|      BER_Decoder& decode(std::vector<uint8_t, Alloc>& out, ASN1_Type real_type) {
  385|  14.0k|         return decode(out, real_type, real_type, ASN1_Class::Universal);
  386|  14.0k|      }
_ZN5Botan11BER_Decoder9raw_bytesINSt3__19allocatorIhEEEERS0_RNS2_6vectorIhT_EE:
  339|  10.9k|      BER_Decoder& raw_bytes(std::vector<uint8_t, Alloc>& out) {
  340|  10.9k|         out.clear();
  341|  10.9k|         uint8_t buf[64];
  342|  47.1k|         while(const size_t got = this->read_bytes(std::span{buf})) {
  ------------------
  |  Branch (342:29): [True: 36.2k, False: 10.9k]
  ------------------
  343|  36.2k|            out.insert(out.end(), buf, buf + got);
  344|  36.2k|         }
  345|  10.9k|         return (*this);
  346|  10.9k|      }
_ZN5Botan11BER_Decoder15decode_optionalIbEERS0_RT_NS_9ASN1_TypeENS_10ASN1_ClassERKS3_:
  551|  14.0k|      BER_Decoder& decode_optional(T& out, ASN1_Type type_tag, ASN1_Class class_tag, const T& default_value = T()) {
  552|  14.0k|         std::optional<T> optval;
  553|  14.0k|         this->decode_optional(optval, type_tag, class_tag);
  554|  14.0k|         out = optval ? *optval : default_value;
  ------------------
  |  Branch (554:16): [True: 4, False: 14.0k]
  ------------------
  555|  14.0k|         return (*this);
  556|  14.0k|      }
_ZN5Botan11BER_Decoder15decode_optionalIbEERS0_RNSt3__18optionalIT_EENS_9ASN1_TypeENS_10ASN1_ClassE:
  827|  14.0k|BER_Decoder& BER_Decoder::decode_optional(std::optional<T>& optval, ASN1_Type type_tag, ASN1_Class class_tag) {
  828|  14.0k|   BER_Object obj = get_next_object();
  829|       |
  830|  14.0k|   if(obj.is_a(type_tag, class_tag)) {
  ------------------
  |  Branch (830:7): [True: 19, False: 14.0k]
  ------------------
  831|     19|      T out{};
  832|     19|      if(class_tag == ASN1_Class::ExplicitContextSpecific) {
  ------------------
  |  Branch (832:10): [True: 0, False: 19]
  ------------------
  833|      0|         BER_Decoder(obj, m_limits).decode(out).verify_end();
  834|     19|      } else {
  835|     19|         this->push_back(std::move(obj));
  836|       |         if constexpr(std::is_base_of_v<ASN1_Object, T>) {
  837|       |            // Object types check the tag in decode_from; a re-tagging
  838|       |            // implicit override of an object is not supported here
  839|       |            this->decode(out);
  840|     19|         } else {
  841|     19|            this->decode(out, type_tag, class_tag);
  842|     19|         }
  843|     19|      }
  844|     19|      optval = std::move(out);
  845|  14.0k|   } else {
  846|  14.0k|      this->push_back(std::move(obj));
  847|  14.0k|      optval = std::nullopt;
  848|  14.0k|   }
  849|       |
  850|  14.0k|   return (*this);
  851|  14.0k|}
x509_ext.cpp:_ZN5Botan11BER_Decoder21decode_optional_fieldIZNS_14Cert_Extension16Authority_Key_ID12decode_innerERKNSt3__16vectorIhNS4_9allocatorIhEEEEE3$_0EERS0_jNS_10ASN1_ClassEOT_:
  624|     75|      BER_Decoder& decode_optional_field(uint32_t tag_no, ASN1_Class class_tag, F&& fn) {
  625|     75|         if(peek_next_object().is_a(tag_no, class_tag)) {
  ------------------
  |  Branch (625:13): [True: 16, False: 59]
  ------------------
  626|     16|            std::forward<F>(fn)(*this);
  627|     16|         }
  628|     75|         return (*this);
  629|     75|      }
_ZN5Botan11BER_Decoder15decode_implicitINS_15AlternativeNameEEERS0_RT_NS_9ASN1_TypeENS_10ASN1_ClassES6_S7_:
  661|     41|         T& out, ASN1_Type type_tag, ASN1_Class class_tag, ASN1_Type real_type, ASN1_Class real_class) {
  662|     41|         BER_Object obj = get_next_object();
  663|     41|         obj.assert_is_a(type_tag, class_tag);
  664|     41|         return decode_implicit(std::move(obj), out, real_type, real_class);
  665|     41|      }
_ZN5Botan11BER_Decoder15decode_implicitINS_15AlternativeNameEEERS0_NS_10BER_ObjectERT_NS_9ASN1_TypeENS_10ASN1_ClassE:
  638|     41|      BER_Decoder& decode_implicit(BER_Object obj, T& out, ASN1_Type real_type, ASN1_Class real_class) {
  639|     41|         obj.set_tagging(real_type, real_class);
  640|     41|         push_back(std::move(obj));
  641|     41|         if constexpr(std::is_base_of_v<ASN1_Object, T>) {
  642|       |            // The object was re-tagged above; decode_from checks the real tag itself
  643|     41|            return decode(out);
  644|       |         } else {
  645|       |            return decode(out, real_type, real_class);
  646|       |         }
  647|     41|      }
x509_ext.cpp:_ZN5Botan11BER_Decoder21decode_optional_fieldIZNS_14Cert_Extension16Authority_Key_ID12decode_innerERKNSt3__16vectorIhNS4_9allocatorIhEEEEE3$_1EERS0_jNS_10ASN1_ClassEOT_:
  624|     64|      BER_Decoder& decode_optional_field(uint32_t tag_no, ASN1_Class class_tag, F&& fn) {
  625|     64|         if(peek_next_object().is_a(tag_no, class_tag)) {
  ------------------
  |  Branch (625:13): [True: 9, False: 55]
  ------------------
  626|      9|            std::forward<F>(fn)(*this);
  627|      9|         }
  628|     64|         return (*this);
  629|     64|      }
x509_ext.cpp:_ZN5Botan11BER_Decoder21decode_optional_fieldIZNS_14Cert_Extension16Authority_Key_ID12decode_innerERKNSt3__16vectorIhNS4_9allocatorIhEEEEE3$_2EERS0_jNS_10ASN1_ClassEOT_:
  624|     57|      BER_Decoder& decode_optional_field(uint32_t tag_no, ASN1_Class class_tag, F&& fn) {
  625|     57|         if(peek_next_object().is_a(tag_no, class_tag)) {
  ------------------
  |  Branch (625:13): [True: 10, False: 47]
  ------------------
  626|     10|            std::forward<F>(fn)(*this);
  627|     10|         }
  628|     57|         return (*this);
  629|     57|      }
_ZN5Botan11BER_Decoder15decode_implicitINS_18X509_Serial_NumberEEERS0_RT_NS_9ASN1_TypeENS_10ASN1_ClassES6_S7_:
  661|     10|         T& out, ASN1_Type type_tag, ASN1_Class class_tag, ASN1_Type real_type, ASN1_Class real_class) {
  662|     10|         BER_Object obj = get_next_object();
  663|     10|         obj.assert_is_a(type_tag, class_tag);
  664|     10|         return decode_implicit(std::move(obj), out, real_type, real_class);
  665|     10|      }
_ZN5Botan11BER_Decoder15decode_implicitINS_18X509_Serial_NumberEEERS0_NS_10BER_ObjectERT_NS_9ASN1_TypeENS_10ASN1_ClassE:
  638|     10|      BER_Decoder& decode_implicit(BER_Object obj, T& out, ASN1_Type real_type, ASN1_Class real_class) {
  639|     10|         obj.set_tagging(real_type, real_class);
  640|     10|         push_back(std::move(obj));
  641|     10|         if constexpr(std::is_base_of_v<ASN1_Object, T>) {
  642|       |            // The object was re-tagged above; decode_from checks the real tag itself
  643|     10|            return decode(out);
  644|       |         } else {
  645|       |            return decode(out, real_type, real_class);
  646|       |         }
  647|     10|      }
x509_ext.cpp:_ZN5Botan11BER_Decoder21decode_optional_fieldIZNS_14Cert_Extension30CRL_Issuing_Distribution_Point12decode_innerERKNSt3__16vectorIhNS4_9allocatorIhEEEEE3$_1EERS0_jNS_10ASN1_ClassEOT_:
  624|    169|      BER_Decoder& decode_optional_field(uint32_t tag_no, ASN1_Class class_tag, F&& fn) {
  625|    169|         if(peek_next_object().is_a(tag_no, class_tag)) {
  ------------------
  |  Branch (625:13): [True: 39, False: 130]
  ------------------
  626|     39|            std::forward<F>(fn)(*this);
  627|     39|         }
  628|    169|         return (*this);
  629|    169|      }
x509_ext.cpp:_ZN5Botan11BER_Decoder21decode_optional_fieldIZNS_14Cert_Extension30CRL_Issuing_Distribution_Point12decode_innerERKNSt3__16vectorIhNS4_9allocatorIhEEEEE3$_2EERS0_jNS_10ASN1_ClassEOT_:
  624|    138|      BER_Decoder& decode_optional_field(uint32_t tag_no, ASN1_Class class_tag, F&& fn) {
  625|    138|         if(peek_next_object().is_a(tag_no, class_tag)) {
  ------------------
  |  Branch (625:13): [True: 8, False: 130]
  ------------------
  626|      8|            std::forward<F>(fn)(*this);
  627|      8|         }
  628|    138|         return (*this);
  629|    138|      }
x509_ext.cpp:_ZN5Botan11BER_Decoder21decode_optional_fieldIZNS_14Cert_Extension30CRL_Issuing_Distribution_Point12decode_innerERKNSt3__16vectorIhNS4_9allocatorIhEEEEE3$_3EERS0_jNS_10ASN1_ClassEOT_:
  624|    131|      BER_Decoder& decode_optional_field(uint32_t tag_no, ASN1_Class class_tag, F&& fn) {
  625|    131|         if(peek_next_object().is_a(tag_no, class_tag)) {
  ------------------
  |  Branch (625:13): [True: 14, False: 117]
  ------------------
  626|     14|            std::forward<F>(fn)(*this);
  627|     14|         }
  628|    131|         return (*this);
  629|    131|      }
x509_ext.cpp:_ZN5Botan11BER_Decoder21decode_optional_fieldIZNS_14Cert_Extension30CRL_Issuing_Distribution_Point12decode_innerERKNSt3__16vectorIhNS4_9allocatorIhEEEEE3$_4EERS0_jNS_10ASN1_ClassEOT_:
  624|    124|      BER_Decoder& decode_optional_field(uint32_t tag_no, ASN1_Class class_tag, F&& fn) {
  625|    124|         if(peek_next_object().is_a(tag_no, class_tag)) {
  ------------------
  |  Branch (625:13): [True: 42, False: 82]
  ------------------
  626|     42|            std::forward<F>(fn)(*this);
  627|     42|         }
  628|    124|         return (*this);
  629|    124|      }
x509_ext.cpp:_ZN5Botan11BER_Decoder21decode_optional_fieldIZNS_14Cert_Extension30CRL_Issuing_Distribution_Point12decode_innerERKNSt3__16vectorIhNS4_9allocatorIhEEEEE3$_5EERS0_jNS_10ASN1_ClassEOT_:
  624|     83|      BER_Decoder& decode_optional_field(uint32_t tag_no, ASN1_Class class_tag, F&& fn) {
  625|     83|         if(peek_next_object().is_a(tag_no, class_tag)) {
  ------------------
  |  Branch (625:13): [True: 6, False: 77]
  ------------------
  626|      6|            std::forward<F>(fn)(*this);
  627|      6|         }
  628|     83|         return (*this);
  629|     83|      }
x509_ext.cpp:_ZN5Botan11BER_Decoder21decode_optional_fieldIZNS_14Cert_Extension30CRL_Issuing_Distribution_Point12decode_innerERKNSt3__16vectorIhNS4_9allocatorIhEEEEE3$_6EERS0_jNS_10ASN1_ClassEOT_:
  624|     76|      BER_Decoder& decode_optional_field(uint32_t tag_no, ASN1_Class class_tag, F&& fn) {
  625|     76|         if(peek_next_object().is_a(tag_no, class_tag)) {
  ------------------
  |  Branch (625:13): [True: 9, False: 67]
  ------------------
  626|      9|            std::forward<F>(fn)(*this);
  627|      9|         }
  628|     76|         return (*this);
  629|     76|      }
_ZN5Botan11BER_Decoder30decode_octet_aligned_bitstringINSt3__19allocatorIhEEEERS0_RNS2_6vectorIhT_EENS_9ASN1_TypeENS_10ASN1_ClassE:
  462|  2.76k|                                                  ASN1_Class class_tag = ASN1_Class::Universal) {
  463|  2.76k|         ASN1_BitString bits;
  464|  2.76k|         decode_bitstring(bits, type_tag, class_tag);
  465|       |
  466|  2.76k|         if(bits.unused_bits() != 0) {
  ------------------
  |  Branch (466:13): [True: 5, False: 2.75k]
  ------------------
  467|      5|            throw Decoding_Error("Expected octet-aligned BIT STRING");
  468|      5|         }
  469|       |
  470|  2.75k|         out.assign(bits.bytes().begin(), bits.bytes().end());
  471|  2.75k|         return (*this);
  472|  2.76k|      }
_ZN5Botan11BER_Decoder15decode_implicitINS_3OIDEEERS0_NS_10BER_ObjectERT_NS_9ASN1_TypeENS_10ASN1_ClassE:
  638|    224|      BER_Decoder& decode_implicit(BER_Object obj, T& out, ASN1_Type real_type, ASN1_Class real_class) {
  639|    224|         obj.set_tagging(real_type, real_class);
  640|    224|         push_back(std::move(obj));
  641|    224|         if constexpr(std::is_base_of_v<ASN1_Object, T>) {
  642|       |            // The object was re-tagged above; decode_from checks the real tag itself
  643|    224|            return decode(out);
  644|       |         } else {
  645|       |            return decode(out, real_type, real_class);
  646|       |         }
  647|    224|      }

_ZN5Botan6BigIntC2ERKS0_:
   88|     12|      BigInt(const BigInt& other) = default;
_ZN5Botan6BigIntD2Ev:
  185|  29.7k|      ~BigInt() { _const_time_unpoison(); }
_ZNK5Botan6BigInt6signumEv:
  493|  22.1k|      int signum() const {
  494|  22.1k|         if(sig_words() == 0) {
  ------------------
  |  Branch (494:13): [True: 328, False: 21.8k]
  ------------------
  495|    328|            return 0;
  496|    328|         }
  497|  21.8k|         return (sign() == Negative) ? -1 : 1;
  ------------------
  |  Branch (497:17): [True: 1.71k, False: 20.1k]
  ------------------
  498|  22.1k|      }
_ZNK5Botan6BigInt9sig_wordsEv:
  687|  78.2k|      size_t sig_words() const { return m_data.sig_words(); }
_ZNK5Botan6BigInt4Data9sig_wordsEv:
 1163|  78.2k|            size_t sig_words() const {
 1164|  78.2k|               if(m_sig_words == sig_words_npos) {
  ------------------
  |  Branch (1164:19): [True: 14.1k, False: 64.0k]
  ------------------
 1165|  14.1k|                  m_sig_words = calc_sig_words();
 1166|  14.1k|               }
 1167|  78.2k|               return m_sig_words;
 1168|  78.2k|            }
_ZNK5Botan6BigInt4signEv:
  641|  21.8k|      Sign sign() const { return (m_signedness); }
_ZN5Botan6BigInt4zeroEv:
   50|     39|      static BigInt zero() { return BigInt(); }
_ZN5Botan6BigIntaSEOS0_:
  190|  13.4k|      BigInt& operator=(BigInt&& other) noexcept {
  191|  13.4k|         if(this != &other) {
  ------------------
  |  Branch (191:13): [True: 13.4k, False: 0]
  ------------------
  192|  13.4k|            this->swap(other);
  193|  13.4k|         }
  194|       |
  195|  13.4k|         return (*this);
  196|  13.4k|      }
_ZN5Botan6BigInt4swapERS0_:
  207|  13.4k|      void swap(BigInt& other) noexcept {
  208|  13.4k|         m_data.swap(other.m_data);
  209|  13.4k|         std::swap(m_signedness, other.m_signedness);
  210|  13.4k|      }
_ZN5Botan6BigInt5clearEv:
  441|  14.1k|      void clear() {
  442|  14.1k|         m_data.set_to_zero();
  443|  14.1k|         m_signedness = Positive;
  444|  14.1k|      }
_ZNK5Botan6BigInt7is_zeroEv:
  510|  1.67k|      bool is_zero() const { return sig_words() == 0; }
_ZNK5Botan6BigInt7word_atEm:
  601|  54.3k|      word word_at(size_t n) const { return m_data.get_word_at(n); }
_ZN5Botan6BigInt8set_signENS0_4SignE:
  663|  1.67k|      void set_sign(Sign sign) {
  664|  1.67k|         if(sign == Negative && is_zero()) {
  ------------------
  |  Branch (664:13): [True: 1.67k, False: 0]
  |  Branch (664:33): [True: 0, False: 1.67k]
  ------------------
  665|      0|            sign = Positive;
  666|      0|         }
  667|       |
  668|  1.67k|         m_signedness = sign;
  669|  1.67k|      }
_ZNK5Botan6BigInt5_dataEv:
 1033|  6.59k|      const word* _data() const { return m_data.const_data(); }
_ZN5Botan6BigInt18_assign_from_bytesENSt3__14spanIKhLm18446744073709551615EEE:
 1044|  14.1k|      void _assign_from_bytes(std::span<const uint8_t> bytes) { assign_from_bytes(bytes); }
_ZNK5Botan6BigInt4Data10const_dataEv:
 1088|  36.2k|            const word* const_data() const { return m_reg.data(); }
_ZNK5Botan6BigInt4Data11get_word_atEm:
 1099|  54.3k|            word get_word_at(size_t n) const {
 1100|  54.3k|               if(n < m_reg.size()) {
  ------------------
  |  Branch (1100:19): [True: 54.3k, False: 4]
  ------------------
 1101|  54.3k|                  return m_reg[n];
 1102|  54.3k|               }
 1103|      4|               return 0;
 1104|  54.3k|            }
_ZNK5Botan6BigInt4Data4sizeEv:
 1136|  29.7k|            size_t size() const { return m_reg.size(); }
_ZN5Botan6BigInt4Data4swapERS1_:
 1151|  13.4k|            void swap(Data& other) noexcept {
 1152|  13.4k|               m_reg.swap(other.m_reg);
 1153|  13.4k|               std::swap(m_sig_words, other.m_sig_words);
 1154|  13.4k|            }
_ZN5Botan6BigInt4Data4swapERNSt3__16vectorImNS_16secure_allocatorImEEEE:
 1156|  14.1k|            void swap(secure_vector<word>& reg) noexcept {
 1157|  14.1k|               m_reg.swap(reg);
 1158|  14.1k|               invalidate_sig_words();
 1159|  14.1k|            }
_ZNK5Botan6BigInt4Data20invalidate_sig_wordsEv:
 1161|  14.1k|            void invalidate_sig_words() const noexcept { m_sig_words = sig_words_npos; }
_ZN5BotaneqERKNS_6BigIntEm:
 1373|  8.96k|inline bool operator==(const BigInt& a, word b) {
 1374|  8.96k|   return (a.cmp_word(b) == 0);
 1375|  8.96k|}
_ZNK5Botan6BigInt9serializeINSt3__16vectorIhNS2_9allocatorIhEEEEEET_m:
  790|  9.43k|      T serialize(size_t len) const {
  791|       |         // TODO this supports std::vector and secure_vector
  792|       |         // it would be nice if this also could work with std::array as in
  793|       |         //   bn.serialize_to<std::array<uint8_t, 32>>(32);
  794|  9.43k|         T out(len);
  795|  9.43k|         this->serialize_to(out);
  796|  9.43k|         return out;
  797|  9.43k|      }
_ZN5Botan6BigIntC2Ev:
   45|  29.6k|      BigInt() = default;
_ZNK5Botan6BigInt9serializeINSt3__16vectorIhNS2_9allocatorIhEEEEEET_v:
  803|    723|      T serialize() const {
  804|    723|         return serialize<T>(this->bytes());
  805|    723|      }

_ZN5Botan17DataSource_MemoryC2ENSt3__14spanIKhLm18446744073709551615EEE:
  181|  19.4k|      explicit DataSource_Memory(std::span<const uint8_t> in) : m_offset(0) {
  182|       |         // Guard against forming a range from a null pointer (eg an empty span)
  183|  19.4k|         if(!in.empty()) {
  ------------------
  |  Branch (183:13): [True: 18.0k, False: 1.42k]
  ------------------
  184|  18.0k|            m_source.assign(in.begin(), in.end());
  185|  18.0k|         }
  186|  19.4k|      }
_ZN5Botan10DataSourceC2Ev:
  107|  77.3k|      DataSource() = default;
_ZN5Botan10DataSourceD2Ev:
  109|  73.8k|      virtual ~DataSource() = default;
_ZN5Botan17DataSource_MemoryC2ENSt3__16vectorIhNS_16secure_allocatorIhEEEE:
  175|    102|      explicit DataSource_Memory(secure_vector<uint8_t> in) : m_source(std::move(in)), m_offset(0) {}

_ZN5Botan11DER_Encoder12DER_SequenceD2Ev:
  504|    573|            ~DER_Sequence() = default;
_ZN5Botan11DER_Encoder14start_sequenceEv:
   86|    191|      DER_Encoder& start_sequence() { return start_cons(ASN1_Type::Sequence, ASN1_Class::Universal); }
_ZN5Botan11DER_Encoder10add_objectENS_9ASN1_TypeENS_10ASN1_ClassENSt3__14spanIKhLm18446744073709551615EEE:
  410|  3.27k|      DER_Encoder& add_object(ASN1_Type type_tag, ASN1_Class class_tag, std::span<const uint8_t> rep) {
  411|  3.27k|         return add_object(type_tag, class_tag, rep.data(), rep.size());
  412|  3.27k|      }
_ZN5Botan11DER_Encoder10add_objectENS_9ASN1_TypeENS_10ASN1_ClassERKNSt3__16vectorIhNS3_9allocatorIhEEEE:
  421|  2.33k|      DER_Encoder& add_object(ASN1_Type type_tag, ASN1_Class class_tag, const std::vector<uint8_t>& rep) {
  422|  2.33k|         return add_object(type_tag, class_tag, std::span{rep});
  423|  2.33k|      }
_ZN5Botan11DER_Encoder12DER_SequenceC2EOS1_:
  487|    382|                  m_type_tag(seq.m_type_tag),
  488|    382|                  m_class_tag(seq.m_class_tag),
  489|    382|                  m_sort_contents(seq.m_sort_contents),
  490|    382|                  m_contents(std::move(seq.m_contents)),
  491|    382|                  m_set_contents(std::move(seq.m_set_contents)) {}

_ZN5Botan7DNSNameC2ENSt3__112basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEE:
  101|  1.78k|      explicit DNSName(std::string canonical) : m_name(std::move(canonical)) {}
_ZNK5Botan7DNSNamessERKS0_:
   84|  5.26k|      auto operator<=>(const DNSName&) const = default;

_ZN5Botan12EmailAddressC2ENSt3__112basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEENS_7DNSNameE:
   69|    483|            m_local_part(std::move(local_part)), m_domain(std::move(domain)) {}
_ZNK5Botan12EmailAddressssERKS0_:
   59|  2.48k|      auto operator<=>(const EmailAddress&) const = default;

_ZNK5Botan9Exception4whatEv:
   94|  3.83k|      const char* what() const noexcept override { return m_msg.c_str(); }

_ZN5Botan11IPv4AddressC2Ej:
   29|    608|      explicit IPv4Address(uint32_t ip) : m_ip(ip) {}
_ZNK5Botan11IPv4AddressssERKS0_:
   61|  3.36k|      auto operator<=>(const IPv4Address&) const = default;

_ZN5Botan11IPv6AddressC2ENSt3__15arrayIhLm16EEE:
   37|     19|      explicit IPv6Address(std::array<uint8_t, 16> ip) : m_ip(ip) {}
_ZNK5Botan11IPv6AddressssERKS0_:
   73|    424|      auto operator<=>(const IPv6Address&) const = default;

_ZN5Botan11clear_bytesEPvm:
  101|  14.3k|inline constexpr void clear_bytes(void* ptr, size_t bytes) {
  102|  14.3k|   if(bytes > 0) {
  ------------------
  |  Branch (102:7): [True: 134, False: 14.2k]
  ------------------
  103|    134|      std::memset(ptr, 0, bytes);
  104|    134|   }
  105|  14.3k|}
_ZN5Botan8copy_memIhQsr3stdE12is_trivial_vIu7__decayIT_EEEEvPS1_PKS1_m:
  144|   612k|inline constexpr void copy_mem(T* out, const T* in, size_t n) {
  145|   612k|   BOTAN_ASSERT_IMPLICATION(n > 0, in != nullptr && out != nullptr, "If n > 0 then args are not null");
  ------------------
  |  |  110|   612k|   do {                                                                                          \
  |  |  111|   612k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                                              \
  |  |  112|  1.19M|      if((expr1) && !(expr2)) {                                                                  \
  |  |  ------------------
  |  |  |  Branch (112:10): [True: 597k, False: 14.6k]
  |  |  |  Branch (112:23): [True: 597k, False: 0]
  |  |  |  Branch (112:23): [True: 597k, False: 0]
  |  |  ------------------
  |  |  113|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                                     \
  |  |  114|      0|         Botan::assertion_failure(#expr1 " implies " #expr2, msg, __func__, __FILE__, __LINE__); \
  |  |  115|      0|      }                                                                                          \
  |  |  116|   612k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (116:12): [Folded, False: 612k]
  |  |  ------------------
  ------------------
  146|       |
  147|   612k|   if(in != nullptr && out != nullptr && n > 0) {
  ------------------
  |  Branch (147:7): [True: 610k, False: 1.71k]
  |  Branch (147:24): [True: 607k, False: 3.10k]
  |  Branch (147:42): [True: 597k, False: 9.87k]
  ------------------
  148|   597k|      std::memmove(out, in, sizeof(T) * n);
  149|   597k|   }
  150|   612k|}
_ZN5Botan13typecast_copyITkNS_6ranges23contiguous_output_rangeERNSt3__15arrayIhLm8EEETkNS1_16contiguous_rangeENS3_ImLm1EEEQaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISE_EESF_E4type10value_typeEEsr3stdE23is_trivially_copyable_vINS7_IXsr21__is_primary_templateINS8_Iu14__remove_cvrefIDTclL_ZNSA_5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENSG_ISO_EESP_E4type10value_typeEEEEvOSL_RKSB_:
  176|  6.99k|inline constexpr void typecast_copy(ToR&& out /* NOLINT(*-std-forward) */, const FromR& in) {
  177|  6.99k|   ranges::assert_equal_byte_lengths(out, in);
  178|  6.99k|   std::memcpy(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  179|  6.99k|}
_ZN5Botan13typecast_copyITkNS_6ranges23contiguous_output_rangeERKNSt3__14spanIhLm8EEETkNS1_16contiguous_rangeENS3_IKmLm1EEEQaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISG_EESH_E4type10value_typeEEsr3stdE23is_trivially_copyable_vINS9_IXsr21__is_primary_templateINSA_Iu14__remove_cvrefIDTclL_ZNSC_5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENSI_ISQ_EESR_E4type10value_typeEEEEvOSN_RKSD_:
  176|  5.23k|inline constexpr void typecast_copy(ToR&& out /* NOLINT(*-std-forward) */, const FromR& in) {
  177|  5.23k|   ranges::assert_equal_byte_lengths(out, in);
  178|  5.23k|   std::memcpy(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  179|  5.23k|}
_ZN5Botan13typecast_copyITkNS_6ranges23contiguous_output_rangeERKNSt3__14spanIhLm8EEEmQaaaasr3stdE23is_trivially_copyable_vIT0_Entsr3std6rangesE5rangeIS7_Esr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISF_EESG_E4type10value_typeEEEEvOSC_RKS7_:
  199|  5.23k|inline constexpr void typecast_copy(ToR&& out /* NOLINT(*-std-forward) */, const FromT& in) {
  200|  5.23k|   typecast_copy(out, std::span<const FromT, 1>(&in, 1));
  201|  5.23k|}
_ZN5Botan19secure_scrub_memoryITkNS_6ranges23contiguous_output_rangeERNSt3__16vectorIhNS2_9allocatorIhEEEEEEvOT_:
   59|   302k|void secure_scrub_memory(ranges::contiguous_output_range auto&& data) {
   60|   302k|   secure_scrub_memory(std::ranges::data(data), ranges::size_bytes(data));
   61|   302k|}
_ZN5Botan9clear_memIhEEvPT_m:
  118|    185|inline constexpr void clear_mem(T* ptr, size_t n) {
  119|    185|   clear_bytes(ptr, sizeof(T) * n);
  120|    185|}
_ZN5Botan13typecast_copyITkNS_6ranges23contiguous_output_rangeENSt3__14spanIjLm1EEETkNS1_16contiguous_rangeENS3_IKhLm4EEEQaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISE_EESF_E4type10value_typeEEsr3stdE23is_trivially_copyable_vINS7_IXsr21__is_primary_templateINS8_Iu14__remove_cvrefIDTclL_ZNSA_5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENSG_ISO_EESP_E4type10value_typeEEEEvOSL_RKSB_:
  176|    686|inline constexpr void typecast_copy(ToR&& out /* NOLINT(*-std-forward) */, const FromR& in) {
  177|    686|   ranges::assert_equal_byte_lengths(out, in);
  178|    686|   std::memcpy(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  179|    686|}
_ZN5Botan13typecast_copyIjTkNS_6ranges16contiguous_rangeENSt3__14spanIKhLm4EEEQaaaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISD_EESE_E4type10value_typeEEsr3stdE23is_trivially_copyable_vIT_Entsr3std6rangesE5rangeISK_EEEvRSK_RKSA_:
  188|    686|inline constexpr void typecast_copy(ToT& out, const FromR& in) {
  189|    686|   typecast_copy(std::span<ToT, 1>(&out, 1), in);
  190|    686|}
_ZN5Botan13typecast_copyIjTkNS_6ranges16contiguous_rangeENSt3__14spanIKhLm4EEEQaaaasr3stdE26is_default_constructible_vIT_Esr3stdE23is_trivially_copyable_vIS6_Esr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISE_EESF_E4type10value_typeEEEES6_RKSB_:
  210|    686|inline constexpr ToT typecast_copy(const FromR& src) {
  211|    686|   ToT dst;  // NOLINT(*-member-init)
  212|    686|   typecast_copy(dst, src);
  213|    686|   return dst;
  214|    686|}
_ZN5Botan13typecast_copyImTkNS_6ranges16contiguous_rangeENSt3__14spanIKhLm8EEEQaaaasr3stdE26is_default_constructible_vIT_Esr3stdE23is_trivially_copyable_vIS6_Esr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISE_EESF_E4type10value_typeEEEES6_RKSB_:
  210|  6.92k|inline constexpr ToT typecast_copy(const FromR& src) {
  211|  6.92k|   ToT dst;  // NOLINT(*-member-init)
  212|  6.92k|   typecast_copy(dst, src);
  213|  6.92k|   return dst;
  214|  6.92k|}
_ZN5Botan13typecast_copyImTkNS_6ranges16contiguous_rangeENSt3__14spanIKhLm8EEEQaaaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISD_EESE_E4type10value_typeEEsr3stdE23is_trivially_copyable_vIT_Entsr3std6rangesE5rangeISK_EEEvRSK_RKSA_:
  188|  6.92k|inline constexpr void typecast_copy(ToT& out, const FromR& in) {
  189|  6.92k|   typecast_copy(std::span<ToT, 1>(&out, 1), in);
  190|  6.92k|}
_ZN5Botan13typecast_copyITkNS_6ranges23contiguous_output_rangeENSt3__14spanImLm1EEETkNS1_16contiguous_rangeENS3_IKhLm8EEEQaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISE_EESF_E4type10value_typeEEsr3stdE23is_trivially_copyable_vINS7_IXsr21__is_primary_templateINS8_Iu14__remove_cvrefIDTclL_ZNSA_5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENSG_ISO_EESP_E4type10value_typeEEEEvOSL_RKSB_:
  176|  6.92k|inline constexpr void typecast_copy(ToR&& out /* NOLINT(*-std-forward) */, const FromR& in) {
  177|  6.92k|   ranges::assert_equal_byte_lengths(out, in);
  178|  6.92k|   std::memcpy(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  179|  6.92k|}
_ZN5Botan9clear_memImEEvPT_m:
  118|  14.1k|inline constexpr void clear_mem(T* ptr, size_t n) {
  119|  14.1k|   clear_bytes(ptr, sizeof(T) * n);
  120|  14.1k|}
_ZN5Botan8copy_memITkNS_6ranges23contiguous_output_rangeENSt3__14spanIhLm18446744073709551615EEETkNS1_16contiguous_rangeENS3_IKhLm18446744073709551615EEEQaasr3stdE9is_same_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISE_EESF_E4type10value_typeENS7_IXsr21__is_primary_templateINS8_Iu14__remove_cvrefIDTclL_ZNSA_5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENSG_ISO_EESP_E4type10value_typeEEsr3stdE23is_trivially_copyable_vIST_EEEvOSB_RKSL_:
  160|  12.3k|inline constexpr void copy_mem(OutR&& out /* NOLINT(*-std-forward) */, const InR& in) {
  161|  12.3k|   ranges::assert_equal_byte_lengths(out, in);
  162|  12.3k|   if(std::is_constant_evaluated()) {
  ------------------
  |  Branch (162:7): [Folded, False: 12.3k]
  ------------------
  163|      0|      std::copy(std::ranges::begin(in), std::ranges::end(in), std::ranges::begin(out));
  164|  12.3k|   } else if(ranges::size_bytes(out) > 0) {
  ------------------
  |  Branch (164:14): [True: 12.3k, False: 0]
  ------------------
  165|  12.3k|      std::memmove(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  166|  12.3k|   }
  167|  12.3k|}
_ZN5Botan13typecast_copyImTkNS_6ranges16contiguous_rangeENSt3__14spanIhLm8EEEQaaaasr3stdE26is_default_constructible_vIT_Esr3stdE23is_trivially_copyable_vIS5_Esr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISD_EESE_E4type10value_typeEEEES5_RKSA_:
  210|  12.3k|inline constexpr ToT typecast_copy(const FromR& src) {
  211|  12.3k|   ToT dst;  // NOLINT(*-member-init)
  212|  12.3k|   typecast_copy(dst, src);
  213|  12.3k|   return dst;
  214|  12.3k|}
_ZN5Botan13typecast_copyImTkNS_6ranges16contiguous_rangeENSt3__14spanIhLm8EEEQaaaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISC_EESD_E4type10value_typeEEsr3stdE23is_trivially_copyable_vIT_Entsr3std6rangesE5rangeISJ_EEEvRSJ_RKS9_:
  188|  12.3k|inline constexpr void typecast_copy(ToT& out, const FromR& in) {
  189|  12.3k|   typecast_copy(std::span<ToT, 1>(&out, 1), in);
  190|  12.3k|}
_ZN5Botan13typecast_copyITkNS_6ranges23contiguous_output_rangeENSt3__14spanImLm1EEETkNS1_16contiguous_rangeENS3_IhLm8EEEQaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISD_EESE_E4type10value_typeEEsr3stdE23is_trivially_copyable_vINS6_IXsr21__is_primary_templateINS7_Iu14__remove_cvrefIDTclL_ZNS9_5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENSF_ISN_EESO_E4type10value_typeEEEEvOSK_RKSA_:
  176|  12.3k|inline constexpr void typecast_copy(ToR&& out /* NOLINT(*-std-forward) */, const FromR& in) {
  177|  12.3k|   ranges::assert_equal_byte_lengths(out, in);
  178|  12.3k|   std::memcpy(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  179|  12.3k|}
_ZN5Botan13typecast_copyItTkNS_6ranges16contiguous_rangeENSt3__14spanIKhLm2EEEQaaaasr3stdE26is_default_constructible_vIT_Esr3stdE23is_trivially_copyable_vIS6_Esr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISE_EESF_E4type10value_typeEEEES6_RKSB_:
  210|  1.06k|inline constexpr ToT typecast_copy(const FromR& src) {
  211|  1.06k|   ToT dst;  // NOLINT(*-member-init)
  212|  1.06k|   typecast_copy(dst, src);
  213|  1.06k|   return dst;
  214|  1.06k|}
_ZN5Botan13typecast_copyItTkNS_6ranges16contiguous_rangeENSt3__14spanIKhLm2EEEQaaaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISD_EESE_E4type10value_typeEEsr3stdE23is_trivially_copyable_vIT_Entsr3std6rangesE5rangeISK_EEEvRSK_RKSA_:
  188|  1.06k|inline constexpr void typecast_copy(ToT& out, const FromR& in) {
  189|  1.06k|   typecast_copy(std::span<ToT, 1>(&out, 1), in);
  190|  1.06k|}
_ZN5Botan13typecast_copyITkNS_6ranges23contiguous_output_rangeENSt3__14spanItLm1EEETkNS1_16contiguous_rangeENS3_IKhLm2EEEQaasr3stdE23is_trivially_copyable_vINS2_11conditionalIXsr21__is_primary_templateINS2_15iterator_traitsIu14__remove_cvrefIDTclL_ZNS2_6ranges5__cpo5beginEEclsr3stdE7declvalIRT0_EEEEEEEEE5valueENS2_26indirectly_readable_traitsISE_EESF_E4type10value_typeEEsr3stdE23is_trivially_copyable_vINS7_IXsr21__is_primary_templateINS8_Iu14__remove_cvrefIDTclL_ZNSA_5beginEEclsr3stdE7declvalIRT_EEEEEEEEE5valueENSG_ISO_EESP_E4type10value_typeEEEEvOSL_RKSB_:
  176|  1.06k|inline constexpr void typecast_copy(ToR&& out /* NOLINT(*-std-forward) */, const FromR& in) {
  177|  1.06k|   ranges::assert_equal_byte_lengths(out, in);
  178|  1.06k|   std::memcpy(std::ranges::data(out), std::ranges::data(in), ranges::size_bytes(out));
  179|  1.06k|}

_ZN5Botan15Key_ConstraintsC2ENS0_4BitsE:
  162|      1|      Key_Constraints(Key_Constraints::Bits bits) : m_value(bits) {}
_ZN5Botan11ReasonFlagsC2Et:
  247|     19|      explicit ReasonFlags(uint16_t bits) : m_value(bits) {
  248|     19|         if((m_value & static_cast<uint16_t>(~DefinedReasonBits)) != 0) {
  ------------------
  |  Branch (248:13): [True: 6, False: 13]
  ------------------
  249|      6|            throw Decoding_Error("ReasonFlags contains undefined reason bits");
  250|      6|         }
  251|     13|         if(m_value == 0) {
  ------------------
  |  Branch (251:13): [True: 5, False: 8]
  ------------------
  252|      5|            throw Decoding_Error("ReasonFlags must have at least one defined reason");
  253|      5|         }
  254|     13|      }

_ZN5Botan7X509_DNC2Ev:
  159|  3.01k|      X509_DN() = default;
_ZN5Botan10ExtensionsC2Ev:
 1029|  11.6k|      Extensions() = default;
_ZNK5Botan10Extensions30has_unknown_critical_extensionEv:
  936|  8.76k|      bool has_unknown_critical_extension() const { return m_has_unknown_critical_extension; }
_ZNK5Botan10Extensions5countEv:
 1027|    315|      size_t count() const { return m_extension_oids.size(); }
_ZNK5Botan10Extensions23get_extension_object_asINS_14Cert_Extension10CRL_NumberEEEPKT_RKNS_3OIDE:
  884|     43|      const T* get_extension_object_as(const OID& oid = T::static_oid()) const {
  885|     43|         if(const Certificate_Extension* extn = get_extension_object(oid)) {
  ------------------
  |  Branch (885:42): [True: 14, False: 29]
  ------------------
  886|       |            // Unknown_Extension oid_name is empty
  887|     14|            if(extn->oid_name().empty()) {
  ------------------
  |  Branch (887:16): [True: 2, False: 12]
  ------------------
  888|      2|               return nullptr;
  889|     12|            } else if(const T* extn_as_T = dynamic_cast<const T*>(extn)) {
  ------------------
  |  Branch (889:32): [True: 12, False: 0]
  ------------------
  890|     12|               return extn_as_T;
  891|     12|            } else {
  892|      0|               throw Decoding_Error("Exception::get_extension_object_as dynamic_cast failed");
  893|      0|            }
  894|     14|         }
  895|       |
  896|     29|         return nullptr;
  897|     43|      }
_ZNK5Botan10Extensions23get_extension_object_asINS_14Cert_Extension16Authority_Key_IDEEEPKT_RKNS_3OIDE:
  884|     43|      const T* get_extension_object_as(const OID& oid = T::static_oid()) const {
  885|     43|         if(const Certificate_Extension* extn = get_extension_object(oid)) {
  ------------------
  |  Branch (885:42): [True: 5, False: 38]
  ------------------
  886|       |            // Unknown_Extension oid_name is empty
  887|      5|            if(extn->oid_name().empty()) {
  ------------------
  |  Branch (887:16): [True: 1, False: 4]
  ------------------
  888|      1|               return nullptr;
  889|      4|            } else if(const T* extn_as_T = dynamic_cast<const T*>(extn)) {
  ------------------
  |  Branch (889:32): [True: 4, False: 0]
  ------------------
  890|      4|               return extn_as_T;
  891|      4|            } else {
  892|      0|               throw Decoding_Error("Exception::get_extension_object_as dynamic_cast failed");
  893|      0|            }
  894|      5|         }
  895|       |
  896|     38|         return nullptr;
  897|     43|      }
_ZNK5Botan15AlternativeName15directory_namesEv:
  443|     26|      const std::set<X509_DN>& directory_names() const { return m_dn_names; }
_ZN5Botan10ExtensionsD2Ev:
 1037|  11.6k|      ~Extensions() override = default;
_ZNK5Botan10Extensions23get_extension_object_asINS_14Cert_Extension30CRL_Issuing_Distribution_PointEEEPKT_RKNS_3OIDE:
  884|     43|      const T* get_extension_object_as(const OID& oid = T::static_oid()) const {
  885|     43|         if(const Certificate_Extension* extn = get_extension_object(oid)) {
  ------------------
  |  Branch (885:42): [True: 5, False: 38]
  ------------------
  886|       |            // Unknown_Extension oid_name is empty
  887|      5|            if(extn->oid_name().empty()) {
  ------------------
  |  Branch (887:16): [True: 5, False: 0]
  ------------------
  888|      5|               return nullptr;
  889|      5|            } else if(const T* extn_as_T = dynamic_cast<const T*>(extn)) {
  ------------------
  |  Branch (889:32): [True: 0, False: 0]
  ------------------
  890|      0|               return extn_as_T;
  891|      0|            } else {
  892|      0|               throw Decoding_Error("Exception::get_extension_object_as dynamic_cast failed");
  893|      0|            }
  894|      5|         }
  895|       |
  896|     38|         return nullptr;
  897|     43|      }
_ZN5Botan18X509_Serial_NumberC2Ev:
   70|  9.02k|      X509_Serial_Number() : m_contents{0x00} {}
_ZNK5Botan7X509_DN5emptyEv:
  202|      2|      bool empty() const { return m_rdn.empty(); }
_ZNK5Botan7X509_DN16_canonical_bytesEv:
  274|    382|      const std::vector<uint8_t>& _canonical_bytes() const { return m_canonical_dn_bits; }
_ZNK5Botan15AlternativeName14OtherNameValue3oidEv:
  311|  3.66k|            const OID& oid() const { return m_oid; }
_ZNK5Botan15AlternativeName14OtherNameValueltERKS1_:
  315|  1.06k|            bool operator<(const OtherNameValue& other) const {
  316|  1.06k|               if(oid() != other.oid()) {
  ------------------
  |  Branch (316:19): [True: 770, False: 293]
  ------------------
  317|    770|                  return oid() < other.oid();
  318|    770|               }
  319|    293|               return m_value < other.m_value;
  320|  1.06k|            }
_ZN5Botan15AlternativeName14OtherNameValueC2ERKNS_3OIDENSt3__16vectorIhNS5_9allocatorIhEEEE:
  325|    745|            OtherNameValue(const OID& oid, std::vector<uint8_t> value) : m_oid(oid), m_value(std::move(value)) {}
_ZN5Botan15AlternativeName16add_ipv4_addressEj:
  374|    521|      BOTAN_DEPRECATED("Use variant taking IPv4Address") void add_ipv4_address(uint32_t ipv4) {
  375|    521|         this->add_ipv4_address(IPv4Address(ipv4));
  376|    521|      }
_ZN5Botan10Extensions15Extensions_InfoC2EbNSt3__16vectorIhNS2_9allocatorIhEEEENS2_10unique_ptrINS_21Certificate_ExtensionENS2_14default_deleteIS8_EEEE:
 1051|  13.9k|                  m_obj(std::move(ext)), m_bits(std::move(encoding)), m_critical(critical) {}
_ZN5Botan15NameConstraintsC2Ev:
  755|      1|      NameConstraints() = default;
_ZN5Botan21Certificate_ExtensionD2Ev:
  858|  18.9k|      virtual ~Certificate_Extension() = default;
_ZN5Botan15AlternativeNameC2Ev:
  338|  2.15k|      AlternativeName() = default;
_ZNK5Botan10Extensions23get_extension_object_asINS_14Cert_Extension14CRL_ReasonCodeEEEPKT_RKNS_3OIDE:
  884|  7.27k|      const T* get_extension_object_as(const OID& oid = T::static_oid()) const {
  885|  7.27k|         if(const Certificate_Extension* extn = get_extension_object(oid)) {
  ------------------
  |  Branch (885:42): [True: 4.03k, False: 3.23k]
  ------------------
  886|       |            // Unknown_Extension oid_name is empty
  887|  4.03k|            if(extn->oid_name().empty()) {
  ------------------
  |  Branch (887:16): [True: 2.77k, False: 1.26k]
  ------------------
  888|  2.77k|               return nullptr;
  889|  2.77k|            } else if(const T* extn_as_T = dynamic_cast<const T*>(extn)) {
  ------------------
  |  Branch (889:32): [True: 1.26k, False: 0]
  ------------------
  890|  1.26k|               return extn_as_T;
  891|  1.26k|            } else {
  892|      0|               throw Decoding_Error("Exception::get_extension_object_as dynamic_cast failed");
  893|      0|            }
  894|  4.03k|         }
  895|       |
  896|  3.23k|         return nullptr;
  897|  7.27k|      }

_ZN5Botan6ranges25assert_equal_byte_lengthsITkNS0_14spanable_rangeENSt3__14spanIhLm18446744073709551615EEETpTkNS0_14spanable_rangeEJNS3_IKhLm18446744073709551615EEEEEEvRKT_DpRKT0_QgtsZT0_Li0E:
  100|  12.3k|{
  101|  12.3k|   const std::span s0{r0};
  102|       |
  103|       |   if constexpr(statically_spanable_range<R0>) {
  104|       |      constexpr size_t expected_size = s0.size_bytes();
  105|       |      (assert_exact_byte_length<expected_size>(rs), ...);
  106|  12.3k|   } else {
  107|  12.3k|      const size_t expected_size = s0.size_bytes();
  108|  12.3k|      const bool correct_size =
  109|  12.3k|         ((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...);
  110|       |
  111|  12.3k|      if(!correct_size) {
  ------------------
  |  Branch (111:10): [True: 0, False: 12.3k]
  ------------------
  112|      0|         memory_region_size_violation();
  113|      0|      }
  114|  12.3k|   }
  115|  12.3k|}
_ZN5Botan6ranges25assert_equal_byte_lengthsITkNS0_14spanable_rangeENSt3__15arrayIhLm8EEETpTkNS0_14spanable_rangeEJNS3_ImLm1EEEEEEvRKT_DpRKT0_QgtsZT0_Li0E:
  100|  13.9k|{
  101|  13.9k|   const std::span s0{r0};
  102|       |
  103|  13.9k|   if constexpr(statically_spanable_range<R0>) {
  104|  13.9k|      constexpr size_t expected_size = s0.size_bytes();
  105|  13.9k|      (assert_exact_byte_length<expected_size>(rs), ...);
  106|       |   } else {
  107|       |      const size_t expected_size = s0.size_bytes();
  108|       |      const bool correct_size =
  109|       |         ((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...);
  110|       |
  111|       |      if(!correct_size) {
  112|       |         memory_region_size_violation();
  113|       |      }
  114|       |   }
  115|  13.9k|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm8ETkNS0_14spanable_rangeENSt3__15arrayImLm1EEEEEvRKT0_:
   77|  13.9k|inline constexpr void assert_exact_byte_length(const R& r) {
   78|  13.9k|   const std::span s{r};
   79|  13.9k|   if constexpr(statically_spanable_range<R>) {
   80|  13.9k|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   81|       |   } else {
   82|       |      if(s.size_bytes() != expected) {
   83|       |         memory_region_size_violation();
   84|       |      }
   85|       |   }
   86|  13.9k|}
_ZN5Botan6ranges10size_bytesITkNS0_14spanable_rangeENSt3__15arrayIhLm8EEEEEmRKT_:
   59|  6.99k|inline constexpr size_t size_bytes(const spanable_range auto& r) {
   60|  6.99k|   return std::span{r}.size_bytes();
   61|  6.99k|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm8ETkNS0_14spanable_rangeENSt3__14spanIhLm8EEEEEvRKT0_:
   77|  17.5k|inline constexpr void assert_exact_byte_length(const R& r) {
   78|  17.5k|   const std::span s{r};
   79|  17.5k|   if constexpr(statically_spanable_range<R>) {
   80|  17.5k|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   81|       |   } else {
   82|       |      if(s.size_bytes() != expected) {
   83|       |         memory_region_size_violation();
   84|       |      }
   85|       |   }
   86|  17.5k|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm8ETkNS0_14spanable_rangeENSt3__14spanIKmLm1EEEEEvRKT0_:
   77|  5.23k|inline constexpr void assert_exact_byte_length(const R& r) {
   78|  5.23k|   const std::span s{r};
   79|  5.23k|   if constexpr(statically_spanable_range<R>) {
   80|  5.23k|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   81|       |   } else {
   82|       |      if(s.size_bytes() != expected) {
   83|       |         memory_region_size_violation();
   84|       |      }
   85|       |   }
   86|  5.23k|}
_ZN5Botan6ranges25assert_equal_byte_lengthsITkNS0_14spanable_rangeENSt3__14spanIhLm8EEETpTkNS0_14spanable_rangeEJNS3_IKmLm1EEEEEEvRKT_DpRKT0_QgtsZT0_Li0E:
  100|  5.23k|{
  101|  5.23k|   const std::span s0{r0};
  102|       |
  103|  5.23k|   if constexpr(statically_spanable_range<R0>) {
  104|  5.23k|      constexpr size_t expected_size = s0.size_bytes();
  105|  5.23k|      (assert_exact_byte_length<expected_size>(rs), ...);
  106|       |   } else {
  107|       |      const size_t expected_size = s0.size_bytes();
  108|       |      const bool correct_size =
  109|       |         ((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...);
  110|       |
  111|       |      if(!correct_size) {
  112|       |         memory_region_size_violation();
  113|       |      }
  114|       |   }
  115|  5.23k|}
_ZN5Botan6ranges10size_bytesITkNS0_14spanable_rangeENSt3__14spanIhLm8EEEEEmRKT_:
   59|  5.23k|inline constexpr size_t size_bytes(const spanable_range auto& r) {
   60|  5.23k|   return std::span{r}.size_bytes();
   61|  5.23k|}
_ZN5Botan6ranges10size_bytesITkNS0_14spanable_rangeENSt3__16vectorIhNS2_9allocatorIhEEEEEEmRKT_:
   59|   302k|inline constexpr size_t size_bytes(const spanable_range auto& r) {
   60|   302k|   return std::span{r}.size_bytes();
   61|   302k|}
_ZN5Botan6ranges10size_bytesITkNS0_14spanable_rangeENSt3__14spanIhLm18446744073709551615EEEEEmRKT_:
   59|  24.6k|inline constexpr size_t size_bytes(const spanable_range auto& r) {
   60|  24.6k|   return std::span{r}.size_bytes();
   61|  24.6k|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm4ETkNS0_14spanable_rangeENSt3__14spanIKhLm4EEEEEvRKT0_:
   77|  1.37k|inline constexpr void assert_exact_byte_length(const R& r) {
   78|  1.37k|   const std::span s{r};
   79|  1.37k|   if constexpr(statically_spanable_range<R>) {
   80|  1.37k|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   81|       |   } else {
   82|       |      if(s.size_bytes() != expected) {
   83|       |         memory_region_size_violation();
   84|       |      }
   85|       |   }
   86|  1.37k|}
_ZN5Botan6ranges25assert_equal_byte_lengthsITkNS0_14spanable_rangeENSt3__14spanIjLm1EEETpTkNS0_14spanable_rangeEJNS3_IKhLm4EEEEEEvRKT_DpRKT0_QgtsZT0_Li0E:
  100|    686|{
  101|    686|   const std::span s0{r0};
  102|       |
  103|    686|   if constexpr(statically_spanable_range<R0>) {
  104|    686|      constexpr size_t expected_size = s0.size_bytes();
  105|    686|      (assert_exact_byte_length<expected_size>(rs), ...);
  106|       |   } else {
  107|       |      const size_t expected_size = s0.size_bytes();
  108|       |      const bool correct_size =
  109|       |         ((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...);
  110|       |
  111|       |      if(!correct_size) {
  112|       |         memory_region_size_violation();
  113|       |      }
  114|       |   }
  115|    686|}
_ZN5Botan6ranges10size_bytesITkNS0_14spanable_rangeENSt3__14spanIjLm1EEEEEmRKT_:
   59|    686|inline constexpr size_t size_bytes(const spanable_range auto& r) {
   60|    686|   return std::span{r}.size_bytes();
   61|    686|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm8ETkNS0_14spanable_rangeENSt3__14spanIKhLm8EEEEEvRKT0_:
   77|  13.8k|inline constexpr void assert_exact_byte_length(const R& r) {
   78|  13.8k|   const std::span s{r};
   79|  13.8k|   if constexpr(statically_spanable_range<R>) {
   80|  13.8k|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   81|       |   } else {
   82|       |      if(s.size_bytes() != expected) {
   83|       |         memory_region_size_violation();
   84|       |      }
   85|       |   }
   86|  13.8k|}
_ZN5Botan6ranges25assert_equal_byte_lengthsITkNS0_14spanable_rangeENSt3__14spanImLm1EEETpTkNS0_14spanable_rangeEJNS3_IKhLm8EEEEEEvRKT_DpRKT0_QgtsZT0_Li0E:
  100|  6.92k|{
  101|  6.92k|   const std::span s0{r0};
  102|       |
  103|  6.92k|   if constexpr(statically_spanable_range<R0>) {
  104|  6.92k|      constexpr size_t expected_size = s0.size_bytes();
  105|  6.92k|      (assert_exact_byte_length<expected_size>(rs), ...);
  106|       |   } else {
  107|       |      const size_t expected_size = s0.size_bytes();
  108|       |      const bool correct_size =
  109|       |         ((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...);
  110|       |
  111|       |      if(!correct_size) {
  112|       |         memory_region_size_violation();
  113|       |      }
  114|       |   }
  115|  6.92k|}
_ZN5Botan6ranges10size_bytesITkNS0_14spanable_rangeENSt3__14spanImLm1EEEEEmRKT_:
   59|  19.2k|inline constexpr size_t size_bytes(const spanable_range auto& r) {
   60|  19.2k|   return std::span{r}.size_bytes();
   61|  19.2k|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm8ETkNS0_14spanable_rangeENSt3__15arrayIhLm8EEEEEvRKT0_:
   77|  12.3k|inline constexpr void assert_exact_byte_length(const R& r) {
   78|  12.3k|   const std::span s{r};
   79|  12.3k|   if constexpr(statically_spanable_range<R>) {
   80|  12.3k|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   81|       |   } else {
   82|       |      if(s.size_bytes() != expected) {
   83|       |         memory_region_size_violation();
   84|       |      }
   85|       |   }
   86|  12.3k|}
_ZN5Botan6ranges25assert_equal_byte_lengthsITkNS0_14spanable_rangeENSt3__14spanImLm1EEETpTkNS0_14spanable_rangeEJNS3_IhLm8EEEEEEvRKT_DpRKT0_QgtsZT0_Li0E:
  100|  12.3k|{
  101|  12.3k|   const std::span s0{r0};
  102|       |
  103|  12.3k|   if constexpr(statically_spanable_range<R0>) {
  104|  12.3k|      constexpr size_t expected_size = s0.size_bytes();
  105|  12.3k|      (assert_exact_byte_length<expected_size>(rs), ...);
  106|       |   } else {
  107|       |      const size_t expected_size = s0.size_bytes();
  108|       |      const bool correct_size =
  109|       |         ((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...);
  110|       |
  111|       |      if(!correct_size) {
  112|       |         memory_region_size_violation();
  113|       |      }
  114|       |   }
  115|  12.3k|}
_ZN5Botan6ranges24assert_exact_byte_lengthILm2ETkNS0_14spanable_rangeENSt3__14spanIKhLm2EEEEEvRKT0_:
   77|  2.13k|inline constexpr void assert_exact_byte_length(const R& r) {
   78|  2.13k|   const std::span s{r};
   79|  2.13k|   if constexpr(statically_spanable_range<R>) {
   80|  2.13k|      static_assert(s.size_bytes() == expected, "memory region does not have expected byte lengths");
   81|       |   } else {
   82|       |      if(s.size_bytes() != expected) {
   83|       |         memory_region_size_violation();
   84|       |      }
   85|       |   }
   86|  2.13k|}
_ZN5Botan6ranges25assert_equal_byte_lengthsITkNS0_14spanable_rangeENSt3__14spanItLm1EEETpTkNS0_14spanable_rangeEJNS3_IKhLm2EEEEEEvRKT_DpRKT0_QgtsZT0_Li0E:
  100|  1.06k|{
  101|  1.06k|   const std::span s0{r0};
  102|       |
  103|  1.06k|   if constexpr(statically_spanable_range<R0>) {
  104|  1.06k|      constexpr size_t expected_size = s0.size_bytes();
  105|  1.06k|      (assert_exact_byte_length<expected_size>(rs), ...);
  106|       |   } else {
  107|       |      const size_t expected_size = s0.size_bytes();
  108|       |      const bool correct_size =
  109|       |         ((std::span<const std::ranges::range_value_t<Rs>>{rs}.size_bytes() == expected_size) && ...);
  110|       |
  111|       |      if(!correct_size) {
  112|       |         memory_region_size_violation();
  113|       |      }
  114|       |   }
  115|  1.06k|}
_ZN5Botan6ranges10size_bytesITkNS0_14spanable_rangeENSt3__14spanItLm1EEEEEmRKT_:
   59|  1.06k|inline constexpr size_t size_bytes(const spanable_range auto& r) {
   60|  1.06k|   return std::span{r}.size_bytes();
   61|  1.06k|}

_ZN5Botan16secure_allocatorIhE10deallocateEPhm:
  102|  20.1k|      void deallocate(T* p, std::size_t n) { deallocate_memory(p, n, sizeof(T)); }
_ZN5Botan16secure_allocatorIhE8allocateEm:
   95|  20.1k|      T* allocate(std::size_t n) { return static_cast<T*>(allocate_memory(n, sizeof(T))); }
_ZN5Botan16secure_allocatorImE10deallocateEPmm:
  102|  14.1k|      void deallocate(T* p, std::size_t n) { deallocate_memory(p, n, sizeof(T)); }
_ZN5Botan16secure_allocatorImE8allocateEm:
   95|  14.1k|      T* allocate(std::size_t n) { return static_cast<T*>(allocate_memory(n, sizeof(T))); }
_ZN5BotanpLIhNS_16secure_allocatorIhEEmEERNSt3__16vectorIT_T0_EES8_RKNS3_4pairIPKS5_T1_EE:
  204|    382|std::vector<T, Alloc>& operator+=(std::vector<T, Alloc>& out, const std::pair<const T*, L>& in) {
  205|    382|   if(in.second > 0) {
  ------------------
  |  Branch (205:7): [True: 357, False: 25]
  ------------------
  206|    357|      out.insert(out.end(), in.first, in.first + in.second);
  207|    357|   }
  208|    382|   return out;
  209|    382|}

_ZN5Botan18unwrap_strong_typeIRmEEDcOT_:
  328|  5.25k|[[nodiscard]] constexpr decltype(auto) unwrap_strong_type(T&& t) {
  329|  5.25k|   if constexpr(!concepts::strong_type<std::remove_cvref_t<T>>) {
  330|       |      // If the parameter type isn't a strong type, return it as is.
  331|  5.25k|      return std::forward<T>(t);
  332|       |   } else {
  333|       |      // Unwrap the strong type and return the underlying value.
  334|       |      return std::forward<T>(t).get();
  335|       |   }
  336|  5.25k|}
_ZN5Botan16wrap_strong_typeItRKtQoosr3stdE18constructible_fromIT_T0_Eaasr8conceptsE11strong_typeIS3_Esr3stdE18constructible_fromINS3_12wrapped_typeES4_EEEDcOS4_:
  353|     19|[[nodiscard]] constexpr decltype(auto) wrap_strong_type(ParamT&& t) {
  354|     19|   if constexpr(std::same_as<std::remove_cvref_t<ParamT>, T>) {
  355|       |      // Noop, if the parameter type already is the desired return type.
  356|     19|      return std::forward<ParamT>(t);
  357|       |   } else if constexpr(std::constructible_from<T, ParamT>) {
  358|       |      // Implicit conversion from the parameter type to the return type.
  359|       |      return T{std::forward<ParamT>(t)};
  360|       |   } else {
  361|       |      // Explicitly calling the wrapped type's constructor to support
  362|       |      // implicit conversions on types that mark their constructors as explicit.
  363|       |      static_assert(concepts::strong_type<T> && std::constructible_from<typename T::wrapped_type, ParamT>);
  364|       |      return T{typename T::wrapped_type{std::forward<ParamT>(t)}};
  365|       |   }
  366|     19|}
_ZN5Botan16wrap_strong_typeIjRjQoosr3stdE18constructible_fromIT_T0_Eaasr8conceptsE11strong_typeIS2_Esr3stdE18constructible_fromINS2_12wrapped_typeES3_EEEDcOS3_:
  353|    686|[[nodiscard]] constexpr decltype(auto) wrap_strong_type(ParamT&& t) {
  354|    686|   if constexpr(std::same_as<std::remove_cvref_t<ParamT>, T>) {
  355|       |      // Noop, if the parameter type already is the desired return type.
  356|    686|      return std::forward<ParamT>(t);
  357|       |   } else if constexpr(std::constructible_from<T, ParamT>) {
  358|       |      // Implicit conversion from the parameter type to the return type.
  359|       |      return T{std::forward<ParamT>(t)};
  360|       |   } else {
  361|       |      // Explicitly calling the wrapped type's constructor to support
  362|       |      // implicit conversions on types that mark their constructors as explicit.
  363|       |      static_assert(concepts::strong_type<T> && std::constructible_from<typename T::wrapped_type, ParamT>);
  364|       |      return T{typename T::wrapped_type{std::forward<ParamT>(t)}};
  365|       |   }
  366|    686|}
_ZN5Botan16wrap_strong_typeImRmQoosr3stdE18constructible_fromIT_T0_Eaasr8conceptsE11strong_typeIS2_Esr3stdE18constructible_fromINS2_12wrapped_typeES3_EEEDcOS3_:
  353|  19.2k|[[nodiscard]] constexpr decltype(auto) wrap_strong_type(ParamT&& t) {
  354|  19.2k|   if constexpr(std::same_as<std::remove_cvref_t<ParamT>, T>) {
  355|       |      // Noop, if the parameter type already is the desired return type.
  356|  19.2k|      return std::forward<ParamT>(t);
  357|       |   } else if constexpr(std::constructible_from<T, ParamT>) {
  358|       |      // Implicit conversion from the parameter type to the return type.
  359|       |      return T{std::forward<ParamT>(t)};
  360|       |   } else {
  361|       |      // Explicitly calling the wrapped type's constructor to support
  362|       |      // implicit conversions on types that mark their constructors as explicit.
  363|       |      static_assert(concepts::strong_type<T> && std::constructible_from<typename T::wrapped_type, ParamT>);
  364|       |      return T{typename T::wrapped_type{std::forward<ParamT>(t)}};
  365|       |   }
  366|  19.2k|}
_ZN5Botan16wrap_strong_typeItRtQoosr3stdE18constructible_fromIT_T0_Eaasr8conceptsE11strong_typeIS2_Esr3stdE18constructible_fromINS2_12wrapped_typeES3_EEEDcOS3_:
  353|  1.06k|[[nodiscard]] constexpr decltype(auto) wrap_strong_type(ParamT&& t) {
  354|  1.06k|   if constexpr(std::same_as<std::remove_cvref_t<ParamT>, T>) {
  355|       |      // Noop, if the parameter type already is the desired return type.
  356|  1.06k|      return std::forward<ParamT>(t);
  357|       |   } else if constexpr(std::constructible_from<T, ParamT>) {
  358|       |      // Implicit conversion from the parameter type to the return type.
  359|       |      return T{std::forward<ParamT>(t)};
  360|       |   } else {
  361|       |      // Explicitly calling the wrapped type's constructor to support
  362|       |      // implicit conversions on types that mark their constructors as explicit.
  363|       |      static_assert(concepts::strong_type<T> && std::constructible_from<typename T::wrapped_type, ParamT>);
  364|       |      return T{typename T::wrapped_type{std::forward<ParamT>(t)}};
  365|       |   }
  366|  1.06k|}

_ZN5Botan3URI9AuthorityC2ENSt3__112basic_stringIcNS2_11char_traitsIcEENS2_9allocatorIcEEEENS2_8optionalIS8_EENS2_7variantIJNS_7DNSNameENS_11IPv4AddressENS_11IPv6AddressEEEENS9_ItEE:
  105|    754|                  m_raw(std::move(raw)), m_userinfo(std::move(userinfo)), m_host(std::move(host)), m_port(port) {}
_ZN5Botan3URIC2ENSt3__112basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEES7_NS1_8optionalINS0_9AuthorityEEES7_NS8_IS7_EESB_:
  202|  1.45k|            m_raw(std::move(raw)),
  203|  1.45k|            m_scheme(std::move(scheme)),
  204|  1.45k|            m_authority(std::move(authority)),
  205|  1.45k|            m_path(std::move(path)),
  206|  1.45k|            m_query(std::move(query)),
  207|  1.45k|            m_fragment(std::move(fragment)) {}

_ZN5Botan9CRL_EntryC2Ev:
   73|  9.01k|      CRL_Entry() = default;

_ZN5Botan14Cert_Extension10CRL_Number10static_oidEv:
  511|     43|      static OID static_oid() { return OID({2, 5, 29, 20}); }
_ZN5Botan14Cert_Extension16Authority_Key_ID10static_oidEv:
  180|     43|      static OID static_oid() { return OID({2, 5, 29, 35}); }
_ZNK5Botan14Cert_Extension16Authority_Key_ID10get_key_idEv:
  173|      4|      const std::vector<uint8_t>& get_key_id() const { return m_key_id; }
_ZN5Botan14Cert_Extension30CRL_Issuing_Distribution_Point10static_oidEv:
  744|     43|      static OID static_oid() { return OID({2, 5, 29, 28}); }
_ZNK5Botan14Cert_Extension17Basic_Constraints8oid_nameEv:
   62|      1|      std::string oid_name() const override { return "X509v3.BasicConstraints"; }
_ZN5Botan14Cert_Extension9Key_UsageC2Ev:
   84|      1|      explicit Key_Usage() : m_constraints(Key_Constraints::None) {}
_ZNK5Botan14Cert_Extension9Key_Usage8oid_nameEv:
   93|      1|      std::string oid_name() const override { return "X509v3.KeyUsage"; }
_ZNK5Botan14Cert_Extension14Subject_Key_ID8oid_nameEv:
  138|      3|      std::string oid_name() const override { return "X509v3.SubjectKeyIdentifier"; }
_ZNK5Botan14Cert_Extension16Authority_Key_ID8oid_nameEv:
  185|      5|      std::string oid_name() const override { return "X509v3.AuthorityKeyIdentifier"; }
_ZN5Botan14Cert_Extension24Subject_Alternative_NameC2ERKNS_15AlternativeNameE:
  213|      1|      explicit Subject_Alternative_Name(const AlternativeName& name = AlternativeName()) : m_alt_name(name) {}
_ZNK5Botan14Cert_Extension24Subject_Alternative_Name8oid_nameEv:
  216|      1|      std::string oid_name() const override { return "X509v3.SubjectAlternativeName"; }
_ZN5Botan14Cert_Extension23Issuer_Alternative_NameC2ERKNS_15AlternativeNameE:
  243|  1.92k|      explicit Issuer_Alternative_Name(const AlternativeName& name = AlternativeName()) : m_alt_name(name) {}
_ZNK5Botan14Cert_Extension23Issuer_Alternative_Name8oid_nameEv:
  246|      1|      std::string oid_name() const override { return "X509v3.IssuerAlternativeName"; }
_ZNK5Botan14Cert_Extension18Extended_Key_Usage8oid_nameEv:
  278|      1|      std::string oid_name() const override { return "X509v3.ExtendedKeyUsage"; }
_ZNK5Botan14Cert_Extension16Name_Constraints8oid_nameEv:
  316|      1|      std::string oid_name() const override { return "X509v3.NameConstraints"; }
_ZNK5Botan14Cert_Extension20Certificate_Policies8oid_nameEv:
  354|      2|      std::string oid_name() const override { return "X509v3.CertificatePolicies"; }
_ZN5Botan14Cert_Extension28Authority_Information_Access17AccessDescriptionC2ENS_3OIDENS_9ASN1_TypeENS_10ASN1_ClassENSt3__16vectorIhNS6_9allocatorIhEEEE:
  386|    144|                  m_method(std::move(method)),
  387|    144|                  m_location_tag(location_tag),
  388|    144|                  m_location_class(location_class),
  389|    144|                  m_location_value(std::move(location_value)) {}
_ZN5Botan14Cert_Extension10CRL_NumberC2Ev:
  501|     39|      CRL_Number() : m_has_value(false), m_crl_number(BigInt::zero()) {}
_ZNK5Botan14Cert_Extension10CRL_Number8oid_nameEv:
  516|     13|      std::string oid_name() const override { return "X509v3.CRLNumber"; }
_ZN5Botan14Cert_Extension14CRL_ReasonCodeC2ENS_8CRL_CodeE:
  538|  4.03k|      explicit CRL_ReasonCode(CRL_Code r = CRL_Code::Unspecified) : m_reason(r) {}
_ZNK5Botan14Cert_Extension14CRL_ReasonCode10get_reasonEv:
  540|  1.26k|      CRL_Code get_reason() const { return m_reason; }
_ZN5Botan14Cert_Extension14CRL_ReasonCode10static_oidEv:
  542|  7.27k|      static OID static_oid() { return OID({2, 5, 29, 21}); }
_ZNK5Botan14Cert_Extension14CRL_ReasonCode8oid_nameEv:
  547|  1.26k|      std::string oid_name() const override { return "X509v3.ReasonCode"; }
_ZNK5Botan14Cert_Extension23CRL_Distribution_Points8oid_nameEv:
  667|      2|      std::string oid_name() const override { return "X509v3.CRLDistributionPoints"; }
_ZNK5Botan14Cert_Extension30CRL_Issuing_Distribution_Point8oid_nameEv:
  749|      2|      std::string oid_name() const override { return "X509v3.CRLIssuingDistributionPoint"; }
_ZN5Botan14Cert_Extension12OCSP_NoCheck10static_oidEv:
  791|  7.57k|      static OID static_oid() { return OID({1, 3, 6, 1, 5, 5, 7, 48, 1, 5}); }
_ZNK5Botan14Cert_Extension21NoRevocationAvailable8oid_nameEv:
  845|      1|      std::string oid_name() const override { return "X509v3.NoRevocationAvailable"; }
_ZNK5Botan14Cert_Extension10TNAuthList8oid_nameEv:
  908|      1|      std::string oid_name() const override { return "PKIX.TNAuthList"; }
_ZNK5Botan14Cert_Extension15IPAddressBlocks8oid_nameEv:
 1115|      1|      std::string oid_name() const override { return "PKIX.IpAddrBlocks"; }
_ZNK5Botan14Cert_Extension8ASBlocks8oid_nameEv:
 1262|      1|      std::string oid_name() const override { return "PKIX.AutonomousSysIds"; }
_ZN5Botan14Cert_Extension17Unknown_ExtensionC2ERKNS_3OIDEbb:
 1281|  12.5k|            m_oid(oid), m_critical(critical), m_failed_to_decode(failed_to_decode) {}
_ZNK5Botan14Cert_Extension17Unknown_Extension8oid_nameEv:
 1323|  2.78k|      std::string oid_name() const override { return ""; }
_ZN5Botan14Cert_Extension14Subject_Key_IDC2Ev:
  110|      3|      Subject_Key_ID() = default;
_ZN5Botan14Cert_Extension30CRL_Issuing_Distribution_PointC2Ev:
  693|    198|      CRL_Issuing_Distribution_Point() = default;
_ZN5Botan14Cert_Extension16Name_ConstraintsC2Ev:
  299|      1|      Name_Constraints() = default;
_ZN5Botan14Cert_Extension23CRL_Distribution_PointsC2Ev:
  652|      2|      CRL_Distribution_Points() = default;
_ZN5Botan14Cert_Extension20Certificate_PoliciesC2Ev:
  337|      2|      Certificate_Policies() = default;
_ZN5Botan14Cert_Extension16Authority_Key_IDC2Ev:
  157|    106|      Authority_Key_ID() = default;
_ZN5Botan14Cert_Extension18Extended_Key_UsageC2Ev:
  267|      1|      Extended_Key_Usage() = default;
_ZN5Botan14Cert_Extension21NoRevocationAvailableC2Ev:
  830|      1|      NoRevocationAvailable() = default;
_ZN5Botan14Cert_Extension28Authority_Information_AccessC2Ev:
  422|     74|      Authority_Information_Access() = default;
_ZN5Botan14Cert_Extension15IPAddressBlocksC2Ev:
 1056|      1|      IPAddressBlocks() = default;
_ZN5Botan14Cert_Extension8ASBlocksC2Ev:
 1207|      1|      ASBlocks() = default;
_ZN5Botan14Cert_Extension8ASBlocks13ASIdentifiersC2Ev:
 1201|      1|            ASIdentifiers() = default;
_ZN5Botan14Cert_Extension10TNAuthListC2Ev:
  897|      1|      TNAuthList() = default;
_ZN5Botan14Cert_Extension21DistributionPointNameC2Ev:
  572|     39|      DistributionPointName() = default;

_ZN5Botan11X509_ObjectC2Ev:
  120|  3.84k|      X509_Object() = default;

_Z4fuzzNSt3__14spanIKhLm18446744073709551615EEE:
   12|  3.84k|void fuzz(std::span<const uint8_t> in) {
   13|  3.84k|   try {
   14|  3.84k|      Botan::DataSource_Memory input(in);
   15|  3.84k|      const Botan::X509_CRL crl(input);
   16|  3.84k|   } catch(const Botan::Exception& e) {}
   17|  3.84k|}

LLVMFuzzerInitialize:
   28|      2|extern "C" int LLVMFuzzerInitialize(int* /*argc*/, char*** /*argv*/) {
   29|       |   /*
   30|       |   * This disables the mlock pool, as overwrites within the pool are
   31|       |   * opaque to ASan or other instrumentation.
   32|       |   */
   33|      2|   ::setenv("BOTAN_MLOCK_POOL_SIZE", "0", 1);
   34|      2|   return 0;
   35|      2|}
LLVMFuzzerTestOneInput:
   39|  3.85k|extern "C" int LLVMFuzzerTestOneInput(const uint8_t in[], size_t len) {
   40|  3.85k|   if(len <= max_fuzzer_input_size) {
  ------------------
  |  Branch (40:7): [True: 3.84k, False: 9]
  ------------------
   41|  3.84k|      try {
   42|  3.84k|         fuzz(std::span<const uint8_t>(in, len));
   43|  3.84k|      } catch(const std::exception& e) {
   44|      0|         std::cerr << "Uncaught exception from fuzzer driver " << e.what() << "\n";
   45|      0|         abort();
   46|      0|      } catch(...) {
   47|      0|         std::cerr << "Uncaught exception from fuzzer driver (unknown type)\n";
   48|      0|         abort();
   49|      0|      }
   50|  3.84k|   }
   51|  3.85k|   return 0;
   52|  3.85k|}

_ZNK5Botan19AlgorithmIdentifier19parameters_are_nullEv:
   50|  2.01k|bool AlgorithmIdentifier::parameters_are_null() const {
   51|  2.01k|   return (m_parameters.size() == 2 && (m_parameters[0] == 0x05) && (m_parameters[1] == 0x00));
  ------------------
  |  Branch (51:12): [True: 1.83k, False: 180]
  |  Branch (51:40): [True: 1.78k, False: 56]
  |  Branch (51:69): [True: 1.78k, False: 3]
  ------------------
   52|  2.01k|}
_ZN5BotaneqERKNS_19AlgorithmIdentifierES2_:
   54|  2.42k|bool operator==(const AlgorithmIdentifier& x, const AlgorithmIdentifier& y) {
   55|  2.42k|   return (x.oid() == y.oid() && x.parameters() == y.parameters());
  ------------------
  |  Branch (55:12): [True: 2.36k, False: 58]
  |  Branch (55:34): [True: 2.33k, False: 37]
  ------------------
   56|  2.42k|}
_ZN5BotanneERKNS_19AlgorithmIdentifierES2_:
   58|  2.42k|bool operator!=(const AlgorithmIdentifier& x, const AlgorithmIdentifier& y) {
   59|  2.42k|   return !(x == y);
   60|  2.42k|}
_ZN5Botan19AlgorithmIdentifier11decode_fromERNS_11BER_DecoderE:
   72|  5.50k|void AlgorithmIdentifier::decode_from(BER_Decoder& codec) {
   73|  5.50k|   codec.start_sequence().decode(m_oid).raw_bytes(m_parameters).end_cons();
   74|       |
   75|       |   /*
   76|       |   * The parameters field is OPTIONAL ANY but in practice it is one of
   77|       |   * - empty
   78|       |   * - NULL
   79|       |   * - SEQUENCE
   80|       |   * - OBJECT IDENTIFIER (namedCurve)
   81|       |   * - OCTET STRING (CBC IV in PBES2)
   82|       |   *
   83|       |   * So require it be exactly one of these values. In particular this ensures that
   84|       |   * there is not any additional trailing data (eg after the SEQUENCE encoding)
   85|       |   * that might be otherwise skipped over by a reader.
   86|       |   */
   87|       |
   88|  5.50k|   const bool acceptable_parameters = [&]() {
   89|  5.50k|      if(this->parameters_are_null_or_empty()) {
   90|  5.50k|         return true;
   91|  5.50k|      }
   92|  5.50k|      if(ASN1::is_der_sequence_header(m_parameters)) {
   93|  5.50k|         return true;
   94|  5.50k|      }
   95|  5.50k|      if(ASN1::is_single_der_object(m_parameters, ASN1_Type::ObjectId, ASN1_Class::Universal)) {
   96|  5.50k|         return true;
   97|  5.50k|      }
   98|  5.50k|      if(ASN1::is_single_der_object(m_parameters, ASN1_Type::OctetString, ASN1_Class::Universal)) {
   99|  5.50k|         return true;
  100|  5.50k|      }
  101|  5.50k|      return false;
  102|  5.50k|   }();
  103|       |
  104|  5.50k|   if(!acceptable_parameters) {
  ------------------
  |  Branch (104:7): [True: 120, False: 5.38k]
  ------------------
  105|    120|      throw Decoding_Error("AlgorithmIdentifier parameters were not NULL, a SEQUENCE, an OID, or an OCTET STRING");
  106|    120|   }
  107|  5.50k|}
alg_id.cpp:_ZZN5Botan19AlgorithmIdentifier11decode_fromERNS_11BER_DecoderEENK3$_0clEv:
   88|  5.30k|   const bool acceptable_parameters = [&]() {
   89|  5.30k|      if(this->parameters_are_null_or_empty()) {
  ------------------
  |  Branch (89:10): [True: 5.06k, False: 239]
  ------------------
   90|  5.06k|         return true;
   91|  5.06k|      }
   92|    239|      if(ASN1::is_der_sequence_header(m_parameters)) {
  ------------------
  |  Branch (92:10): [True: 28, False: 211]
  ------------------
   93|     28|         return true;
   94|     28|      }
   95|    211|      if(ASN1::is_single_der_object(m_parameters, ASN1_Type::ObjectId, ASN1_Class::Universal)) {
  ------------------
  |  Branch (95:10): [True: 38, False: 173]
  ------------------
   96|     38|         return true;
   97|     38|      }
   98|    173|      if(ASN1::is_single_der_object(m_parameters, ASN1_Type::OctetString, ASN1_Class::Universal)) {
  ------------------
  |  Branch (98:10): [True: 53, False: 120]
  ------------------
   99|     53|         return true;
  100|     53|      }
  101|    120|      return false;
  102|    173|   }();

_ZNK5Botan11ASN1_Object10BER_encodeEv:
   21|  2.33k|std::vector<uint8_t> ASN1_Object::BER_encode() const {
   22|  2.33k|   std::vector<uint8_t> output;
   23|  2.33k|   DER_Encoder der(output);
   24|  2.33k|   this->encode_into(der);
   25|  2.33k|   return output;
   26|  2.33k|}
_ZN5Botan14ASN1_BitStringC2ENSt3__16vectorIhNS1_9allocatorIhEEEEm:
   29|  2.73k|      m_bytes(std::move(bytes)), m_unused_bits(unused_bits) {
   30|  2.73k|   if(m_unused_bits >= 8) {
  ------------------
  |  Branch (30:7): [True: 0, False: 2.73k]
  ------------------
   31|      0|      throw Invalid_Argument("ASN1_BitString: Invalid unused bit count");
   32|      0|   }
   33|       |
   34|  2.73k|   if(m_bytes.empty() && m_unused_bits != 0) {
  ------------------
  |  Branch (34:7): [True: 11, False: 2.71k]
  |  Branch (34:26): [True: 0, False: 11]
  ------------------
   35|      0|      throw Invalid_Argument("ASN1_BitString: Empty BIT STRING cannot have unused bits");
   36|      0|   }
   37|       |
   38|  2.73k|   if(m_unused_bits > 0 && (m_bytes.back() & ((1U << m_unused_bits) - 1)) != 0) {
  ------------------
  |  Branch (38:7): [True: 12, False: 2.71k]
  |  Branch (38:28): [True: 0, False: 12]
  ------------------
   39|      0|      throw Invalid_Argument("ASN1_BitString: Unused bits must be zero");
   40|      0|   }
   41|  2.73k|}
_ZNK5Botan14ASN1_BitString10bit_lengthEv:
   46|    284|size_t ASN1_BitString::bit_length() const {
   47|    284|   return 8 * m_bytes.size() - m_unused_bits;
   48|    284|}
_ZNK5Botan14ASN1_BitString6bit_atEm:
   50|    104|bool ASN1_BitString::bit_at(size_t bit) const {
   51|    104|   if(bit >= bit_length()) {
  ------------------
  |  Branch (51:7): [True: 0, False: 104]
  ------------------
   52|      0|      throw Invalid_Argument("ASN1_BitString: Bit index out of range");
   53|      0|   }
   54|       |
   55|    104|   return (m_bytes[bit / 8] & (0x80 >> (bit % 8))) != 0;
   56|    104|}
_ZN5Botan10BER_ObjectD2Ev:
   58|   302k|BER_Object::~BER_Object() {
   59|   302k|   secure_scrub_memory(m_value);
   60|   302k|}
_ZNK5Botan10BER_Object11assert_is_aENS_9ASN1_TypeENS_10ASN1_ClassENSt3__117basic_string_viewIcNS3_11char_traitsIcEEEE:
   65|  87.2k|void BER_Object::assert_is_a(ASN1_Type expected_type_tag, ASN1_Class expected_class_tag, std::string_view descr) const {
   66|  87.2k|   if(!this->is_a(expected_type_tag, expected_class_tag)) {
  ------------------
  |  Branch (66:7): [True: 2.33k, False: 84.8k]
  ------------------
   67|  2.33k|      std::stringstream msg;
   68|       |
   69|  2.33k|      msg << "Tag mismatch when decoding " << descr << " got ";
   70|       |
   71|  2.33k|      if(m_class_tag == ASN1_Class::NoObject && m_type_tag == ASN1_Type::NoObject) {
  ------------------
  |  Branch (71:10): [True: 74, False: 2.25k]
  |  Branch (71:49): [True: 74, False: 0]
  ------------------
   72|     74|         msg << "EOF";
   73|  2.25k|      } else {
   74|  2.25k|         if(m_class_tag == ASN1_Class::Universal || m_class_tag == ASN1_Class::Constructed) {
  ------------------
  |  Branch (74:13): [True: 1.27k, False: 979]
  |  Branch (74:53): [True: 445, False: 534]
  ------------------
   75|  1.72k|            msg << asn1_tag_to_string(m_type_tag);
   76|  1.72k|         } else {
   77|    534|            msg << std::to_string(static_cast<uint32_t>(m_type_tag));
   78|    534|         }
   79|       |
   80|  2.25k|         msg << "/" << asn1_class_to_string(m_class_tag);
   81|  2.25k|      }
   82|       |
   83|  2.33k|      msg << " expected ";
   84|       |
   85|  2.33k|      if(expected_class_tag == ASN1_Class::Universal || expected_class_tag == ASN1_Class::Constructed) {
  ------------------
  |  Branch (85:10): [True: 1.67k, False: 658]
  |  Branch (85:57): [True: 658, False: 0]
  ------------------
   86|  2.33k|         msg << asn1_tag_to_string(expected_type_tag);
   87|  2.33k|      } else {
   88|      0|         msg << std::to_string(static_cast<uint32_t>(expected_type_tag));
   89|      0|      }
   90|       |
   91|  2.33k|      msg << "/" << asn1_class_to_string(expected_class_tag);
   92|       |
   93|  2.33k|      throw BER_Decoding_Error(msg.str());
   94|  2.33k|   }
   95|  87.2k|}
_ZNK5Botan10BER_Object4is_aENS_9ASN1_TypeENS_10ASN1_ClassE:
   97|   143k|bool BER_Object::is_a(ASN1_Type expected_type_tag, ASN1_Class expected_class_tag) const {
   98|   143k|   return (m_type_tag == expected_type_tag && m_class_tag == expected_class_tag);
  ------------------
  |  Branch (98:12): [True: 97.1k, False: 45.9k]
  |  Branch (98:47): [True: 96.8k, False: 337]
  ------------------
   99|   143k|}
_ZNK5Botan10BER_Object4is_aEiNS_10ASN1_ClassE:
  101|  34.6k|bool BER_Object::is_a(int expected_type_tag, ASN1_Class expected_class_tag) const {
  102|  34.6k|   return is_a(ASN1_Type(expected_type_tag), expected_class_tag);
  103|  34.6k|}
_ZN5Botan10BER_Object11set_taggingENS_9ASN1_TypeENS_10ASN1_ClassE:
  105|   136k|void BER_Object::set_tagging(ASN1_Type type_tag, ASN1_Class class_tag) {
  106|   136k|   m_type_tag = type_tag;
  107|   136k|   m_class_tag = class_tag;
  108|   136k|}
_ZN5Botan20asn1_class_to_stringENS_10ASN1_ClassE:
  110|  4.59k|std::string asn1_class_to_string(ASN1_Class type) {
  111|  4.59k|   switch(type) {
  112|  2.95k|      case ASN1_Class::Universal:
  ------------------
  |  Branch (112:7): [True: 2.95k, False: 1.63k]
  ------------------
  113|  2.95k|         return "UNIVERSAL";
  114|  1.10k|      case ASN1_Class::Constructed:
  ------------------
  |  Branch (114:7): [True: 1.10k, False: 3.48k]
  ------------------
  115|  1.10k|         return "CONSTRUCTED";
  116|    269|      case ASN1_Class::ContextSpecific:
  ------------------
  |  Branch (116:7): [True: 269, False: 4.32k]
  ------------------
  117|    269|         return "CONTEXT_SPECIFIC";
  118|     92|      case ASN1_Class::Application:
  ------------------
  |  Branch (118:7): [True: 92, False: 4.49k]
  ------------------
  119|     92|         return "APPLICATION";
  120|     23|      case ASN1_Class::Private:
  ------------------
  |  Branch (120:7): [True: 23, False: 4.56k]
  ------------------
  121|     23|         return "PRIVATE";
  122|      0|      case ASN1_Class::NoObject:
  ------------------
  |  Branch (122:7): [True: 0, False: 4.59k]
  ------------------
  123|      0|         return "NO_OBJECT";
  124|    150|      default:
  ------------------
  |  Branch (124:7): [True: 150, False: 4.44k]
  ------------------
  125|    150|         return "CLASS(" + std::to_string(static_cast<size_t>(type)) + ")";
  126|  4.59k|   }
  127|  4.59k|}
_ZN5Botan18asn1_tag_to_stringENS_9ASN1_TypeE:
  129|  4.39k|std::string asn1_tag_to_string(ASN1_Type type) {
  130|  4.39k|   switch(type) {
  131|    643|      case ASN1_Type::Sequence:
  ------------------
  |  Branch (131:7): [True: 643, False: 3.75k]
  ------------------
  132|    643|         return "SEQUENCE";
  133|       |
  134|     40|      case ASN1_Type::Set:
  ------------------
  |  Branch (134:7): [True: 40, False: 4.35k]
  ------------------
  135|     40|         return "SET";
  136|       |
  137|    147|      case ASN1_Type::PrintableString:
  ------------------
  |  Branch (137:7): [True: 147, False: 4.25k]
  ------------------
  138|    147|         return "PRINTABLE STRING";
  139|       |
  140|    100|      case ASN1_Type::NumericString:
  ------------------
  |  Branch (140:7): [True: 100, False: 4.29k]
  ------------------
  141|    100|         return "NUMERIC STRING";
  142|       |
  143|     36|      case ASN1_Type::Ia5String:
  ------------------
  |  Branch (143:7): [True: 36, False: 4.36k]
  ------------------
  144|     36|         return "IA5 STRING";
  145|       |
  146|     17|      case ASN1_Type::TeletexString:
  ------------------
  |  Branch (146:7): [True: 17, False: 4.38k]
  ------------------
  147|     17|         return "T61 STRING";
  148|       |
  149|    112|      case ASN1_Type::Utf8String:
  ------------------
  |  Branch (149:7): [True: 112, False: 4.28k]
  ------------------
  150|    112|         return "UTF8 STRING";
  151|       |
  152|     72|      case ASN1_Type::VisibleString:
  ------------------
  |  Branch (152:7): [True: 72, False: 4.32k]
  ------------------
  153|     72|         return "VISIBLE STRING";
  154|       |
  155|     11|      case ASN1_Type::BmpString:
  ------------------
  |  Branch (155:7): [True: 11, False: 4.38k]
  ------------------
  156|     11|         return "BMP STRING";
  157|       |
  158|     13|      case ASN1_Type::UniversalString:
  ------------------
  |  Branch (158:7): [True: 13, False: 4.38k]
  ------------------
  159|     13|         return "UNIVERSAL STRING";
  160|       |
  161|     20|      case ASN1_Type::UtcTime:
  ------------------
  |  Branch (161:7): [True: 20, False: 4.37k]
  ------------------
  162|     20|         return "UTC TIME";
  163|       |
  164|     17|      case ASN1_Type::GeneralizedTime:
  ------------------
  |  Branch (164:7): [True: 17, False: 4.38k]
  ------------------
  165|     17|         return "GENERALIZED TIME";
  166|       |
  167|     57|      case ASN1_Type::OctetString:
  ------------------
  |  Branch (167:7): [True: 57, False: 4.34k]
  ------------------
  168|     57|         return "OCTET STRING";
  169|       |
  170|     77|      case ASN1_Type::BitString:
  ------------------
  |  Branch (170:7): [True: 77, False: 4.32k]
  ------------------
  171|     77|         return "BIT STRING";
  172|       |
  173|  1.62k|      case ASN1_Type::Enumerated:
  ------------------
  |  Branch (173:7): [True: 1.62k, False: 2.77k]
  ------------------
  174|  1.62k|         return "ENUMERATED";
  175|       |
  176|    115|      case ASN1_Type::Integer:
  ------------------
  |  Branch (176:7): [True: 115, False: 4.28k]
  ------------------
  177|    115|         return "INTEGER";
  178|       |
  179|     34|      case ASN1_Type::Null:
  ------------------
  |  Branch (179:7): [True: 34, False: 4.36k]
  ------------------
  180|     34|         return "NULL";
  181|       |
  182|     29|      case ASN1_Type::ObjectId:
  ------------------
  |  Branch (182:7): [True: 29, False: 4.36k]
  ------------------
  183|     29|         return "OBJECT";
  184|       |
  185|    134|      case ASN1_Type::Boolean:
  ------------------
  |  Branch (185:7): [True: 134, False: 4.26k]
  ------------------
  186|    134|         return "BOOLEAN";
  187|       |
  188|      0|      case ASN1_Type::NoObject:
  ------------------
  |  Branch (188:7): [True: 0, False: 4.39k]
  ------------------
  189|      0|         return "NO_OBJECT";
  190|       |
  191|  1.10k|      default:
  ------------------
  |  Branch (191:7): [True: 1.10k, False: 3.29k]
  ------------------
  192|  1.10k|         return "TAG(" + std::to_string(static_cast<uint32_t>(type)) + ")";
  193|  4.39k|   }
  194|  4.39k|}
_ZN5Botan18BER_Decoding_ErrorC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
  199|  4.83k|BER_Decoding_Error::BER_Decoding_Error(std::string_view err) : Decoding_Error(fmt("BER: {}", err)) {}
_ZN5Botan11BER_Bad_TagC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEEj:
  201|     70|BER_Bad_Tag::BER_Bad_Tag(std::string_view str, uint32_t tagging) : BER_Decoding_Error(fmt("{}: {}", str, tagging)) {}
_ZN5Botan4ASN19to_stringERKNS_10BER_ObjectE:
  224|  17.6k|std::string to_string(const BER_Object& obj) {
  225|  17.6k|   return bytes_to_string(obj.data());
  226|  17.6k|}
_ZN5Botan4ASN19maybe_BERERNS_10DataSourceE:
  231|  3.84k|bool maybe_BER(DataSource& source) {
  232|  3.84k|   uint8_t first_u8 = 0;
  233|  3.84k|   if(source.peek_byte(first_u8) == 0) {
  ------------------
  |  Branch (233:7): [True: 0, False: 3.84k]
  ------------------
  234|      0|      BOTAN_ASSERT_EQUAL(source.read_byte(first_u8), 0, "Expected EOF");
  ------------------
  |  |   97|      0|   do {                                                                                                \
  |  |   98|      0|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                                                    \
  |  |   99|      0|      if((expr1) != (expr2)) {                                                                         \
  |  |  ------------------
  |  |  |  Branch (99:10): [True: 0, False: 0]
  |  |  ------------------
  |  |  100|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                                           \
  |  |  101|      0|         Botan::assertion_failure(#expr1 " == " #expr2, assertion_made, __func__, __FILE__, __LINE__); \
  |  |  102|      0|      }                                                                                                \
  |  |  103|      0|   } while(0)
  |  |  ------------------
  |  |  |  Branch (103:12): [Folded, False: 0]
  |  |  ------------------
  ------------------
  235|      0|      throw Stream_IO_Error("ASN1::maybe_BER: Source was empty");
  236|      0|   }
  237|       |
  238|  3.84k|   const auto cons_seq = static_cast<uint8_t>(ASN1_Class::Constructed) | static_cast<uint8_t>(ASN1_Type::Sequence);
  239|  3.84k|   return first_u8 == cons_seq;
  240|  3.84k|}

_ZN5Botan3OID11from_stringENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
   80|    891|OID OID::from_string(std::string_view str) {
   81|    891|   if(str.empty()) {
  ------------------
  |  Branch (81:7): [True: 0, False: 891]
  ------------------
   82|      0|      throw Invalid_Argument("OID::from_string argument must be non-empty");
   83|      0|   }
   84|       |
   85|    891|   OID o = OID_Map::global_registry().str2oid(str);
   86|    891|   if(o.has_value()) {
  ------------------
  |  Branch (86:7): [True: 891, False: 0]
  ------------------
   87|    891|      return o;
   88|    891|   }
   89|       |
   90|       |   // Try to parse as a dotted decimal
   91|      0|   try {
   92|      0|      return OID(str);
   93|      0|   } catch(...) {}
   94|       |
   95|      0|   throw Lookup_Error(fmt("No OID associated with name '{}'", str));
   96|      0|}
_ZN5Botan3OIDC2ESt16initializer_listIjE:
   98|  15.8k|OID::OID(std::initializer_list<uint32_t> init) : m_id(init) {
   99|  15.8k|   oid_valid_check(m_id);
  100|  15.8k|}
_ZNK5Botan3OID9hash_codeEv:
  162|      4|uint64_t OID::hash_code() const {
  163|       |   // If this is changed also update gen_oids.py to match
  164|      4|   uint64_t hash = 0x621F302327D9A49A;
  165|     32|   for(auto id : m_id) {
  ------------------
  |  Branch (165:16): [True: 32, False: 4]
  ------------------
  166|     32|      hash *= 193;
  167|     32|      hash += id;
  168|     32|   }
  169|      4|   return hash;
  170|      4|}
_ZN5BotanltERKNS_3OIDES2_:
  175|  30.6k|bool operator<(const OID& a, const OID& b) {
  176|  30.6k|   const std::vector<uint32_t>& oid1 = a.get_components();
  177|  30.6k|   const std::vector<uint32_t>& oid2 = b.get_components();
  178|       |
  179|  30.6k|   return std::lexicographical_compare(oid1.begin(), oid1.end(), oid2.begin(), oid2.end());
  180|  30.6k|}
_ZNK5Botan3OID11encode_intoERNS_11DER_EncoderE:
  185|  2.33k|void OID::encode_into(DER_Encoder& der) const {
  186|  2.33k|   if(m_id.size() < 2) {
  ------------------
  |  Branch (186:7): [True: 0, False: 2.33k]
  ------------------
  187|      0|      throw Invalid_Argument("OID::encode_into: OID is invalid");
  188|      0|   }
  189|       |
  190|  2.33k|   auto append = [](std::vector<uint8_t>& encoding, uint32_t z) {
  191|  2.33k|      if(z <= 0x7F) {
  192|  2.33k|         encoding.push_back(static_cast<uint8_t>(z));
  193|  2.33k|      } else {
  194|  2.33k|         const size_t z7 = (high_bit(z) + 7 - 1) / 7;
  195|       |
  196|  2.33k|         for(size_t j = 0; j != z7; ++j) {
  197|  2.33k|            uint8_t zp = static_cast<uint8_t>(z >> (7 * (z7 - j - 1)) & 0x7F);
  198|       |
  199|  2.33k|            if(j != z7 - 1) {
  200|  2.33k|               zp |= 0x80;
  201|  2.33k|            }
  202|       |
  203|  2.33k|            encoding.push_back(zp);
  204|  2.33k|         }
  205|  2.33k|      }
  206|  2.33k|   };
  207|       |
  208|  2.33k|   std::vector<uint8_t> encoding;
  209|       |
  210|       |   // We know 40 * root can't overflow because root is between 0 and 2
  211|  2.33k|   auto first = checked_add(40 * m_id[0], m_id[1]);
  212|  2.33k|   BOTAN_ASSERT_NOMSG(first.has_value());
  ------------------
  |  |   84|  2.33k|   do {                                                                     \
  |  |   85|  2.33k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|  2.33k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 2.33k]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|  2.33k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 2.33k]
  |  |  ------------------
  ------------------
  213|       |
  214|  2.33k|   append(encoding, *first);
  215|       |
  216|  6.24k|   for(size_t i = 2; i != m_id.size(); ++i) {
  ------------------
  |  Branch (216:22): [True: 3.91k, False: 2.33k]
  ------------------
  217|  3.91k|      append(encoding, m_id[i]);
  218|  3.91k|   }
  219|  2.33k|   der.add_object(ASN1_Type::ObjectId, ASN1_Class::Universal, encoding);
  220|  2.33k|}
_ZN5Botan3OID11decode_fromERNS_11BER_DecoderE:
  225|  23.4k|void OID::decode_from(BER_Decoder& decoder) {
  226|  23.4k|   const BER_Object obj = decoder.get_next_object();
  227|  23.4k|   if(obj.tagging() != (ASN1_Class::Universal | ASN1_Type::ObjectId)) {
  ------------------
  |  Branch (227:7): [True: 70, False: 23.3k]
  ------------------
  228|     70|      throw BER_Bad_Tag("Error decoding OID, unknown tag", obj.tagging());
  229|     70|   }
  230|       |
  231|  23.3k|   if(obj.length() == 0) {
  ------------------
  |  Branch (231:7): [True: 3, False: 23.3k]
  ------------------
  232|      3|      throw BER_Decoding_Error("OID encoding is too short");
  233|      3|   }
  234|       |
  235|  23.3k|   auto consume = [](BufferSlicer& data) -> uint32_t {
  236|  23.3k|      BOTAN_ASSERT_NOMSG(!data.empty());
  237|  23.3k|      uint32_t b = data.take_byte();
  238|       |
  239|  23.3k|      if(b > 0x7F) {
  240|  23.3k|         b &= 0x7F;
  241|       |
  242|       |         // Even BER requires that the OID have minimal length, ie that
  243|       |         // the first byte of a multibyte encoding cannot be zero
  244|       |         // See X.690 section 8.19.2
  245|  23.3k|         if(b == 0) {
  246|  23.3k|            throw Decoding_Error("Leading zero byte in multibyte OID encoding");
  247|  23.3k|         }
  248|       |
  249|  23.3k|         while(true) {
  250|  23.3k|            if(data.empty()) {
  251|  23.3k|               throw Decoding_Error("Truncated OID value");
  252|  23.3k|            }
  253|       |
  254|  23.3k|            const uint8_t next = data.take_byte();
  255|  23.3k|            const bool more = (next & 0x80) == 0x80;
  256|  23.3k|            const uint8_t value = next & 0x7F;
  257|       |
  258|  23.3k|            if((b >> (32 - 7)) != 0) {
  259|  23.3k|               throw Decoding_Error("OID component overflow");
  260|  23.3k|            }
  261|       |
  262|  23.3k|            b = (b << 7) | value;
  263|       |
  264|  23.3k|            if(!more) {
  265|  23.3k|               break;
  266|  23.3k|            }
  267|  23.3k|         }
  268|  23.3k|      }
  269|       |
  270|  23.3k|      return b;
  271|  23.3k|   };
  272|       |
  273|  23.3k|   BufferSlicer data(obj.data());
  274|  23.3k|   std::vector<uint32_t> parts;
  275|       |
  276|       |   // Each byte of the DER encoding can result in at most one additional arc,
  277|       |   // except the first byte which always encodes two.
  278|  23.3k|   parts.reserve(obj.length() + 1);
  279|       |
  280|   110k|   while(!data.empty()) {
  ------------------
  |  Branch (280:10): [True: 86.9k, False: 23.3k]
  ------------------
  281|  86.9k|      const uint32_t comp = consume(data);
  282|       |
  283|  86.9k|      if(parts.empty()) {
  ------------------
  |  Branch (283:10): [True: 23.3k, False: 63.6k]
  ------------------
  284|       |         // divide into root and second arc
  285|       |
  286|  23.3k|         const uint32_t root_arc = [](uint32_t b0) -> uint32_t {
  287|  23.3k|            if(b0 < 40) {
  288|  23.3k|               return 0;
  289|  23.3k|            } else if(b0 < 80) {
  290|  23.3k|               return 1;
  291|  23.3k|            } else {
  292|  23.3k|               return 2;
  293|  23.3k|            }
  294|  23.3k|         }(comp);
  295|       |
  296|  23.3k|         parts.push_back(root_arc);
  297|  23.3k|         BOTAN_ASSERT_NOMSG(comp >= 40 * root_arc);
  ------------------
  |  |   84|  23.3k|   do {                                                                     \
  |  |   85|  23.3k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|  23.3k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 23.3k]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|  23.3k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 23.3k]
  |  |  ------------------
  ------------------
  298|  23.3k|         parts.push_back(comp - 40 * root_arc);
  299|  63.6k|      } else {
  300|  63.6k|         parts.push_back(comp);
  301|  63.6k|      }
  302|  86.9k|   }
  303|       |
  304|  23.3k|   m_id = std::move(parts);
  305|  23.3k|}
asn1_oid.cpp:_ZN5Botan12_GLOBAL__N_115oid_valid_checkENSt3__14spanIKjLm18446744073709551615EEE:
   26|  15.8k|void oid_valid_check(std::span<const uint32_t> oid) {
   27|  15.8k|   BOTAN_ARG_CHECK(oid.size() >= 2, "OID too short to be valid");
  ------------------
  |  |   35|  15.8k|   do {                                                          \
  |  |   36|  15.8k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  15.8k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 15.8k]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|  15.8k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 15.8k]
  |  |  ------------------
  ------------------
   28|  15.8k|   BOTAN_ARG_CHECK(oid[0] <= 2, "OID root out of range");
  ------------------
  |  |   35|  15.8k|   do {                                                          \
  |  |   36|  15.8k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  15.8k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 15.8k]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|  15.8k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 15.8k]
  |  |  ------------------
  ------------------
   29|  15.8k|   BOTAN_ARG_CHECK(oid[1] <= 39 || oid[0] == 2, "OID second arc too large");
  ------------------
  |  |   35|  15.8k|   do {                                                          \
  |  |   36|  15.8k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  15.8k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:12): [True: 15.8k, False: 0]
  |  |  |  Branch (37:12): [True: 0, False: 0]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|  15.8k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 15.8k]
  |  |  ------------------
  ------------------
   30|       |   // This last is a limitation of using 32 bit integers when decoding
   31|       |   // not a limitation of ASN.1 object identifiers in general
   32|  15.8k|   BOTAN_ARG_CHECK(oid[1] <= 0xFFFFFFAF, "OID second arc too large");
  ------------------
  |  |   35|  15.8k|   do {                                                          \
  |  |   36|  15.8k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  15.8k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 15.8k]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|  15.8k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 15.8k]
  |  |  ------------------
  ------------------
   33|  15.8k|}
asn1_oid.cpp:_ZZNK5Botan3OID11encode_intoERNS_11DER_EncoderEENK3$_0clERNSt3__16vectorIhNS4_9allocatorIhEEEEj:
  190|  6.24k|   auto append = [](std::vector<uint8_t>& encoding, uint32_t z) {
  191|  6.24k|      if(z <= 0x7F) {
  ------------------
  |  Branch (191:10): [True: 4.76k, False: 1.48k]
  ------------------
  192|  4.76k|         encoding.push_back(static_cast<uint8_t>(z));
  193|  4.76k|      } else {
  194|  1.48k|         const size_t z7 = (high_bit(z) + 7 - 1) / 7;
  195|       |
  196|  5.38k|         for(size_t j = 0; j != z7; ++j) {
  ------------------
  |  Branch (196:28): [True: 3.89k, False: 1.48k]
  ------------------
  197|  3.89k|            uint8_t zp = static_cast<uint8_t>(z >> (7 * (z7 - j - 1)) & 0x7F);
  198|       |
  199|  3.89k|            if(j != z7 - 1) {
  ------------------
  |  Branch (199:16): [True: 2.41k, False: 1.48k]
  ------------------
  200|  2.41k|               zp |= 0x80;
  201|  2.41k|            }
  202|       |
  203|  3.89k|            encoding.push_back(zp);
  204|  3.89k|         }
  205|  1.48k|      }
  206|  6.24k|   };
asn1_oid.cpp:_ZZN5Botan3OID11decode_fromERNS_11BER_DecoderEENK3$_0clERNS_12BufferSlicerE:
  235|  86.9k|   auto consume = [](BufferSlicer& data) -> uint32_t {
  236|  86.9k|      BOTAN_ASSERT_NOMSG(!data.empty());
  ------------------
  |  |   84|  86.9k|   do {                                                                     \
  |  |   85|  86.9k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|  86.9k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 86.9k]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|  86.9k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 86.9k]
  |  |  ------------------
  ------------------
  237|  86.9k|      uint32_t b = data.take_byte();
  238|       |
  239|  86.9k|      if(b > 0x7F) {
  ------------------
  |  Branch (239:10): [True: 14.9k, False: 72.0k]
  ------------------
  240|  14.9k|         b &= 0x7F;
  241|       |
  242|       |         // Even BER requires that the OID have minimal length, ie that
  243|       |         // the first byte of a multibyte encoding cannot be zero
  244|       |         // See X.690 section 8.19.2
  245|  14.9k|         if(b == 0) {
  ------------------
  |  Branch (245:13): [True: 3, False: 14.9k]
  ------------------
  246|      3|            throw Decoding_Error("Leading zero byte in multibyte OID encoding");
  247|      3|         }
  248|       |
  249|  22.0k|         while(true) {
  ------------------
  |  Branch (249:16): [True: 22.0k, Folded]
  ------------------
  250|  22.0k|            if(data.empty()) {
  ------------------
  |  Branch (250:16): [True: 30, False: 22.0k]
  ------------------
  251|     30|               throw Decoding_Error("Truncated OID value");
  252|     30|            }
  253|       |
  254|  22.0k|            const uint8_t next = data.take_byte();
  255|  22.0k|            const bool more = (next & 0x80) == 0x80;
  256|  22.0k|            const uint8_t value = next & 0x7F;
  257|       |
  258|  22.0k|            if((b >> (32 - 7)) != 0) {
  ------------------
  |  Branch (258:16): [True: 22, False: 22.0k]
  ------------------
  259|     22|               throw Decoding_Error("OID component overflow");
  260|     22|            }
  261|       |
  262|  22.0k|            b = (b << 7) | value;
  263|       |
  264|  22.0k|            if(!more) {
  ------------------
  |  Branch (264:16): [True: 14.8k, False: 7.13k]
  ------------------
  265|  14.8k|               break;
  266|  14.8k|            }
  267|  22.0k|         }
  268|  14.9k|      }
  269|       |
  270|  86.9k|      return b;
  271|  86.9k|   };
asn1_oid.cpp:_ZZN5Botan3OID11decode_fromERNS_11BER_DecoderEENK3$_1clEj:
  286|  23.3k|         const uint32_t root_arc = [](uint32_t b0) -> uint32_t {
  287|  23.3k|            if(b0 < 40) {
  ------------------
  |  Branch (287:16): [True: 1.56k, False: 21.7k]
  ------------------
  288|  1.56k|               return 0;
  289|  21.7k|            } else if(b0 < 80) {
  ------------------
  |  Branch (289:23): [True: 5.95k, False: 15.7k]
  ------------------
  290|  5.95k|               return 1;
  291|  15.7k|            } else {
  292|  15.7k|               return 2;
  293|  15.7k|            }
  294|  23.3k|         }(comp);

_ZN5Botan11ASN1_String14is_string_typeENS_9ASN1_TypeE:
  131|    745|bool ASN1_String::is_string_type(ASN1_Type tag) {
  132|    745|   return is_asn1_string_type(tag);
  133|    745|}
_ZN5Botan11ASN1_StringC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEENS_9ASN1_TypeE:
  135|  3.28k|ASN1_String::ASN1_String(std::string_view str, ASN1_Type t) : m_utf8_str(str), m_tag(t) {
  136|  3.28k|   if(!is_utf8_subset_string_type(m_tag)) {
  ------------------
  |  Branch (136:7): [True: 26, False: 3.25k]
  ------------------
  137|     26|      throw Invalid_Argument("ASN1_String only supports encoding to UTF-8 or a UTF-8 subset");
  138|     26|   }
  139|       |
  140|  3.25k|   if(!is_valid_asn1_string_content(m_utf8_str, m_tag)) {
  ------------------
  |  Branch (140:7): [True: 307, False: 2.94k]
  ------------------
  141|    307|      throw Invalid_Argument(fmt("ASN1_String: Invalid {} encoding", asn1_tag_to_string(m_tag)));
  142|    307|   }
  143|  3.25k|}
_ZN5Botan11ASN1_StringC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
  145|  2.70k|ASN1_String::ASN1_String(std::string_view str) : ASN1_String(str, choose_encoding(str)) {}
_ZN5Botan11ASN1_String11decode_fromERNS_11BER_DecoderE:
  162|  2.69k|void ASN1_String::decode_from(BER_Decoder& source) {
  163|  2.69k|   const BER_Object obj = source.get_next_object();
  164|       |
  165|  2.69k|   if(obj.get_class() != ASN1_Class::Universal || !is_asn1_string_type(obj.type())) {
  ------------------
  |  Branch (165:7): [True: 8, False: 2.68k]
  |  Branch (165:51): [True: 58, False: 2.62k]
  ------------------
  166|     64|      auto typ = static_cast<uint32_t>(obj.type());
  167|     64|      auto cls = static_cast<uint32_t>(obj.get_class());
  168|     64|      throw Decoding_Error(fmt("ASN1_String: Unknown string type {}/{}", typ, cls));
  169|     64|   }
  170|       |
  171|  2.62k|   m_tag = obj.type();
  172|  2.62k|   m_data.assign(obj.bits(), obj.bits() + obj.length());
  173|       |
  174|  2.62k|   if(m_tag == ASN1_Type::BmpString) {
  ------------------
  |  Branch (174:7): [True: 286, False: 2.34k]
  ------------------
  175|    286|      m_utf8_str = ucs2_to_utf8(m_data);
  176|  2.34k|   } else if(m_tag == ASN1_Type::UniversalString) {
  ------------------
  |  Branch (176:14): [True: 96, False: 2.24k]
  ------------------
  177|     96|      m_utf8_str = ucs4_to_utf8(m_data);
  178|  2.24k|   } else if(m_tag == ASN1_Type::TeletexString) {
  ------------------
  |  Branch (178:14): [True: 246, False: 2.00k]
  ------------------
  179|       |      /*
  180|       |      TeletexString is nominally ITU T.61 not ISO-8859-1 but it seems
  181|       |      the majority of implementations actually used that charset here.
  182|       |      */
  183|    246|      m_utf8_str = latin1_to_utf8(m_data);
  184|  2.00k|   } else {
  185|       |      // All other supported string types are UTF-8 or some subset thereof
  186|  2.00k|      m_utf8_str = ASN1::to_string(obj);
  187|       |
  188|  2.00k|      if(!is_valid_asn1_string_content(m_utf8_str, m_tag)) {
  ------------------
  |  Branch (188:10): [True: 35, False: 1.96k]
  ------------------
  189|     35|         throw Decoding_Error(fmt("ASN1_String: Invalid {} encoding", asn1_tag_to_string(m_tag)));
  190|     35|      }
  191|  2.00k|   }
  192|  2.62k|}
asn1_str.cpp:_ZN5Botan12_GLOBAL__N_119is_asn1_string_typeENS_9ASN1_TypeE:
   99|  3.42k|bool is_asn1_string_type(ASN1_Type tag) {
  100|  3.42k|   return (is_utf8_subset_string_type(tag) || tag == ASN1_Type::TeletexString || tag == ASN1_Type::BmpString ||
  ------------------
  |  Branch (100:12): [True: 2.55k, False: 876]
  |  Branch (100:47): [True: 264, False: 612]
  |  Branch (100:82): [True: 316, False: 296]
  ------------------
  101|    296|           tag == ASN1_Type::UniversalString);
  ------------------
  |  Branch (101:12): [True: 102, False: 194]
  ------------------
  102|  3.42k|}
asn1_str.cpp:_ZN5Botan12_GLOBAL__N_126is_utf8_subset_string_typeENS_9ASN1_TypeE:
   94|  11.9k|bool is_utf8_subset_string_type(ASN1_Type tag) {
   95|  11.9k|   return (tag == ASN1_Type::NumericString || tag == ASN1_Type::PrintableString || tag == ASN1_Type::VisibleString ||
  ------------------
  |  Branch (95:12): [True: 183, False: 11.7k]
  |  Branch (95:47): [True: 6.39k, False: 5.38k]
  |  Branch (95:84): [True: 64, False: 5.31k]
  ------------------
   96|  5.31k|           tag == ASN1_Type::Ia5String || tag == ASN1_Type::Utf8String);
  ------------------
  |  Branch (96:12): [True: 1.43k, False: 3.88k]
  |  Branch (96:43): [True: 2.97k, False: 902]
  ------------------
   97|  11.9k|}
asn1_str.cpp:_ZN5Botan12_GLOBAL__N_128is_valid_asn1_string_contentERKNSt3__112basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEENS_9ASN1_TypeE:
  104|  5.25k|bool is_valid_asn1_string_content(const std::string& str, ASN1_Type tag) {
  105|  5.25k|   BOTAN_ASSERT_NOMSG(is_utf8_subset_string_type(tag));
  ------------------
  |  |   84|  5.25k|   do {                                                                     \
  |  |   85|  5.25k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|  5.25k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 5.25k]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|  5.25k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 5.25k]
  |  |  ------------------
  ------------------
  106|       |
  107|  5.25k|   switch(tag) {
  108|  1.34k|      case ASN1_Type::Utf8String:
  ------------------
  |  Branch (108:7): [True: 1.34k, False: 3.90k]
  ------------------
  109|  1.34k|         return is_valid_utf8(str);
  110|     62|      case ASN1_Type::NumericString:
  ------------------
  |  Branch (110:7): [True: 62, False: 5.19k]
  ------------------
  111|  3.19k|      case ASN1_Type::PrintableString:
  ------------------
  |  Branch (111:7): [True: 3.12k, False: 2.12k]
  ------------------
  112|  3.88k|      case ASN1_Type::Ia5String:
  ------------------
  |  Branch (112:7): [True: 692, False: 4.56k]
  ------------------
  113|  3.90k|      case ASN1_Type::VisibleString:
  ------------------
  |  Branch (113:7): [True: 21, False: 5.23k]
  ------------------
  114|  3.90k|         return g_char_validator.valid_encoding(str, tag);
  115|      0|      default:
  ------------------
  |  Branch (115:7): [True: 0, False: 5.25k]
  ------------------
  116|      0|         return false;
  117|  5.25k|   }
  118|  5.25k|}
asn1_str.cpp:_ZNK5Botan12_GLOBAL__N_131ASN1_String_Codepoint_Validator14valid_encodingENSt3__117basic_string_viewIcNS2_11char_traitsIcEEEENS_9ASN1_TypeE:
   25|  6.61k|      constexpr bool valid_encoding(std::string_view str, ASN1_Type tag) const {
   26|  6.61k|         const uint8_t mask = mask_for(tag);
   27|  7.48k|         for(const char c : str) {
  ------------------
  |  Branch (27:27): [True: 7.48k, False: 6.36k]
  ------------------
   28|  7.48k|            const uint8_t codepoint = static_cast<uint8_t>(c);
   29|  7.48k|            const bool is_valid = (m_table[codepoint] & mask) != 0;
   30|       |
   31|  7.48k|            if(!is_valid) {
  ------------------
  |  Branch (31:16): [True: 249, False: 7.23k]
  ------------------
   32|    249|               return false;
   33|    249|            }
   34|  7.48k|         }
   35|       |
   36|  6.36k|         return true;
   37|  6.61k|      }
asn1_str.cpp:_ZN5Botan12_GLOBAL__N_131ASN1_String_Codepoint_Validator8mask_forENS_9ASN1_TypeE:
   45|  6.61k|      static constexpr uint8_t mask_for(ASN1_Type tag) {
   46|  6.61k|         switch(tag) {
   47|     62|            case ASN1_Type::NumericString:
  ------------------
  |  Branch (47:13): [True: 62, False: 6.55k]
  ------------------
   48|     62|               return Numeric_String;
   49|  5.83k|            case ASN1_Type::PrintableString:
  ------------------
  |  Branch (49:13): [True: 5.83k, False: 775]
  ------------------
   50|  5.83k|               return Printable_String;
   51|    692|            case ASN1_Type::Ia5String:
  ------------------
  |  Branch (51:13): [True: 692, False: 5.92k]
  ------------------
   52|    692|               return IA5_String;
   53|     21|            case ASN1_Type::VisibleString:
  ------------------
  |  Branch (53:13): [True: 21, False: 6.59k]
  ------------------
   54|     21|               return Visible_String;
   55|      0|            default:
  ------------------
  |  Branch (55:13): [True: 0, False: 6.61k]
  ------------------
   56|      0|               return 0;
   57|  6.61k|         }
   58|  6.61k|      }
asn1_str.cpp:_ZN5Botan12_GLOBAL__N_115choose_encodingENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
  120|  2.70k|ASN1_Type choose_encoding(std::string_view str) {
  121|  2.70k|   if(g_char_validator.valid_encoding(str, ASN1_Type::PrintableString)) {
  ------------------
  |  Branch (121:7): [True: 2.70k, False: 0]
  ------------------
  122|  2.70k|      return ASN1_Type::PrintableString;
  123|  2.70k|   } else {
  124|      0|      return ASN1_Type::Utf8String;
  125|      0|   }
  126|  2.70k|}

_ZN5Botan9ASN1_TimeC2EthhhhhNS_9ASN1_TypeE:
   43|  11.4k|      m_year(year), m_month(month), m_day(day), m_hour(hour), m_minute(minute), m_second(second), m_tag(tag) {
   44|  11.4k|   if(tag != ASN1_Type::UtcTime && tag != ASN1_Type::GeneralizedTime) {
  ------------------
  |  Branch (44:7): [True: 844, False: 10.5k]
  |  Branch (44:36): [True: 0, False: 844]
  ------------------
   45|      0|      throw Invalid_Argument("ASN1_Time tag must be UtcTime or GeneralizedTime");
   46|      0|   }
   47|       |
   48|       |   /*
   49|       |   * RFC 5280 Section 4.1.2.5:
   50|       |   *    To indicate that a certificate has no well-defined expiration date,
   51|       |   *    the notAfter SHOULD be assigned the GeneralizedTime value of
   52|       |   *    99991231235959Z.
   53|       |   */
   54|  11.4k|   const uint16_t min_year = 1950;
   55|  11.4k|   const uint16_t max_year = (tag == ASN1_Type::UtcTime) ? 2049 : 9999;
  ------------------
  |  Branch (55:30): [True: 10.5k, False: 844]
  ------------------
   56|       |
   57|  11.4k|   if(m_year < min_year || m_year > max_year) {
  ------------------
  |  Branch (57:7): [True: 5, False: 11.4k]
  |  Branch (57:28): [True: 0, False: 11.4k]
  ------------------
   58|      5|      throw Invalid_Argument(fmt("ASN1_Time year {} is out of range ({} to {})", m_year, min_year, max_year));
   59|      5|   }
   60|       |
   61|  11.4k|   if(m_month < 1 || m_month > 12) {
  ------------------
  |  Branch (61:7): [True: 2, False: 11.4k]
  |  Branch (61:22): [True: 8, False: 11.4k]
  ------------------
   62|     10|      throw Invalid_Argument(fmt("ASN1_Time month {} is out of range", static_cast<uint32_t>(m_month)));
   63|     10|   }
   64|       |
   65|  11.4k|   constexpr uint8_t days_in_month[12] = {31, 28, 31, 30, 31, 30, 31, 31, 30, 31, 30, 31};
   66|       |
   67|  11.4k|   const bool is_leap_year = (m_year % 4 == 0) && (m_year % 100 != 0 || m_year % 400 == 0);
  ------------------
  |  Branch (67:30): [True: 4.52k, False: 6.89k]
  |  Branch (67:52): [True: 4.42k, False: 100]
  |  Branch (67:73): [True: 91, False: 9]
  ------------------
   68|  11.4k|   const uint8_t max_day = (m_month == 2 && is_leap_year) ? 29 : days_in_month[m_month - 1];
  ------------------
  |  Branch (68:29): [True: 468, False: 10.9k]
  |  Branch (68:45): [True: 307, False: 161]
  ------------------
   69|       |
   70|  11.4k|   if(m_day < 1 || m_day > max_day) {
  ------------------
  |  Branch (70:7): [True: 2, False: 11.4k]
  |  Branch (70:20): [True: 12, False: 11.4k]
  ------------------
   71|     14|      throw Invalid_Argument(fmt("ASN1_Time day {} is out of range for month {}",
   72|     14|                                 static_cast<uint32_t>(m_day),
   73|     14|                                 static_cast<uint32_t>(m_month)));
   74|     14|   }
   75|       |
   76|  11.4k|   if(m_hour > 23) {
  ------------------
  |  Branch (76:7): [True: 5, False: 11.4k]
  ------------------
   77|      5|      throw Invalid_Argument(fmt("ASN1_Time hour {} is out of range", static_cast<uint32_t>(m_hour)));
   78|      5|   }
   79|       |
   80|  11.4k|   if(m_minute > 59) {
  ------------------
  |  Branch (80:7): [True: 6, False: 11.3k]
  ------------------
   81|      6|      throw Invalid_Argument(fmt("ASN1_Time minute {} is out of range", static_cast<uint32_t>(m_minute)));
   82|      6|   }
   83|       |
   84|       |   /*
   85|       |   * RFC 5280 is silent on the issue of leap seconds in certificate fields, but both
   86|       |   * OpenSSL and Go reject which suggests they are rarely if ever used in practice.
   87|       |   */
   88|  11.3k|   if(m_second > 59) {
  ------------------
  |  Branch (88:7): [True: 1, False: 11.3k]
  ------------------
   89|      1|      throw Invalid_Argument(fmt("ASN1_Time second {} is out of range", static_cast<uint32_t>(m_second)));
   90|      1|   }
   91|  11.3k|}
_ZN5Botan9ASN1_Time11from_stringENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEENS_9ASN1_TypeE:
  109|  11.5k|ASN1_Time ASN1_Time::from_string(std::string_view t_spec, ASN1_Type tag) {
  110|  11.5k|   BOTAN_ARG_CHECK(tag == ASN1_Type::UtcTime || tag == ASN1_Type::GeneralizedTime, "Invalid tag for ASN1_Time");
  ------------------
  |  |   35|  11.5k|   do {                                                          \
  |  |   36|  11.5k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  12.3k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:12): [True: 10.6k, False: 858]
  |  |  |  Branch (37:12): [True: 858, False: 0]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|  11.5k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 11.5k]
  |  |  ------------------
  ------------------
  111|       |
  112|  11.5k|   if(tag == ASN1_Type::GeneralizedTime) {
  ------------------
  |  Branch (112:7): [True: 858, False: 10.6k]
  ------------------
  113|    858|      BOTAN_ARG_CHECK(t_spec.size() == 15, "Invalid GeneralizedTime input string");
  ------------------
  |  |   35|    858|   do {                                                          \
  |  |   36|    858|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|    858|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 9, False: 849]
  |  |  ------------------
  |  |   38|      9|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      9|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      9|      }                                                          \
  |  |   41|    858|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 858]
  |  |  ------------------
  ------------------
  114|  10.6k|   } else {
  115|  10.6k|      BOTAN_ARG_CHECK(t_spec.size() == 13, "Invalid UTCTime input string");
  ------------------
  |  |   35|  10.6k|   do {                                                          \
  |  |   36|  10.6k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  10.6k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 13, False: 10.6k]
  |  |  ------------------
  |  |   38|     13|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|     13|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|     13|      }                                                          \
  |  |   41|  10.6k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 10.6k]
  |  |  ------------------
  ------------------
  116|  10.6k|   }
  117|       |
  118|  11.5k|   BOTAN_ARG_CHECK(t_spec.back() == 'Z', "Botan does not support ASN1 times with timezones other than Z");
  ------------------
  |  |   35|  11.5k|   do {                                                          \
  |  |   36|  11.5k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  11.5k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 20, False: 11.4k]
  |  |  ------------------
  |  |   38|     20|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|     20|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|     20|      }                                                          \
  |  |   41|  11.5k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 11.5k]
  |  |  ------------------
  ------------------
  119|       |
  120|  11.5k|   const size_t field_len = 2;
  121|  11.5k|   const size_t year_len = (tag == ASN1_Type::UtcTime) ? 2 : 4;
  ------------------
  |  Branch (121:28): [True: 10.6k, False: 890]
  ------------------
  122|       |
  123|  11.5k|   const size_t year_start = 0;
  124|  11.5k|   const size_t month_start = year_start + year_len;
  125|  11.5k|   const size_t day_start = month_start + field_len;
  126|  11.5k|   const size_t hour_start = day_start + field_len;
  127|  11.5k|   const size_t min_start = hour_start + field_len;
  128|  11.5k|   const size_t sec_start = min_start + field_len;
  129|       |
  130|  11.5k|   uint32_t year = to_u32bit(t_spec.substr(year_start, year_len));
  131|  11.5k|   const uint32_t month = to_u32bit(t_spec.substr(month_start, field_len));
  132|  11.5k|   const uint32_t day = to_u32bit(t_spec.substr(day_start, field_len));
  133|  11.5k|   const uint32_t hour = to_u32bit(t_spec.substr(hour_start, field_len));
  134|  11.5k|   const uint32_t minute = to_u32bit(t_spec.substr(min_start, field_len));
  135|  11.5k|   const uint32_t second = to_u32bit(t_spec.substr(sec_start, field_len));
  136|       |
  137|  11.5k|   if(tag == ASN1_Type::UtcTime) {
  ------------------
  |  Branch (137:7): [True: 10.5k, False: 916]
  ------------------
  138|       |      // Interpret the two digit year by the 1950/2050 split (RFC 5280 Section 4.1.2.5.1)
  139|  10.5k|      year += (year >= 50) ? 1900 : 2000;
  ------------------
  |  Branch (139:15): [True: 178, False: 10.4k]
  ------------------
  140|  10.5k|   }
  141|       |
  142|  11.5k|   return ASN1_Time(static_cast<uint16_t>(year),
  143|  11.5k|                    static_cast<uint8_t>(month),
  144|  11.5k|                    static_cast<uint8_t>(day),
  145|  11.5k|                    static_cast<uint8_t>(hour),
  146|  11.5k|                    static_cast<uint8_t>(minute),
  147|  11.5k|                    static_cast<uint8_t>(second),
  148|  11.5k|                    tag);
  149|  11.5k|}
_ZN5Botan9ASN1_Time11decode_fromERNS_11BER_DecoderE:
  168|  11.7k|void ASN1_Time::decode_from(BER_Decoder& source) {
  169|  11.7k|   const BER_Object ber_time = source.get_next_object();
  170|       |
  171|  11.7k|   if(ber_time.get_class() != ASN1_Class::Universal ||
  ------------------
  |  Branch (171:7): [True: 182, False: 11.5k]
  ------------------
  172|  11.5k|      (ber_time.type() != ASN1_Type::UtcTime && ber_time.type() != ASN1_Type::GeneralizedTime)) {
  ------------------
  |  Branch (172:8): [True: 925, False: 10.6k]
  |  Branch (172:49): [True: 67, False: 858]
  ------------------
  173|    185|      throw Decoding_Error(fmt("ASN1_Time: Unexpected tag {}/{}",
  174|    185|                               static_cast<uint32_t>(ber_time.type()),
  175|    185|                               static_cast<uint32_t>(ber_time.get_class())));
  176|    185|   }
  177|       |
  178|  11.5k|   try {
  179|       |      // Assigning only after a successful parse means that a decoding error
  180|       |      // cannot leave this object in a partially written state
  181|  11.5k|      *this = ASN1_Time::from_string(ASN1::to_string(ber_time), ber_time.type());
  182|  11.5k|   } catch(Invalid_Argument& e) {
  183|    113|      throw Decoding_Error(fmt("Invalid ASN1_Time encoding: {}", e.what()));
  184|    113|   }
  185|  11.5k|}

_ZN5Botan11BER_DecoderD2Ev:
  456|  73.4k|BER_Decoder::~BER_Decoder() = default;
_ZNK5Botan11BER_Decoder10more_itemsEv:
  461|  57.0k|bool BER_Decoder::more_items() const {
  462|  57.0k|   if(m_source->end_of_data() && !m_pushed.is_set()) {
  ------------------
  |  Branch (462:7): [True: 13.8k, False: 43.2k]
  |  Branch (462:34): [True: 13.8k, False: 0]
  ------------------
  463|  13.8k|      return false;
  464|  13.8k|   }
  465|  43.2k|   return true;
  466|  57.0k|}
_ZN5Botan11BER_Decoder10verify_endEv:
  471|  11.2k|BER_Decoder& BER_Decoder::verify_end() {
  472|  11.2k|   return verify_end("BER_Decoder::verify_end called, but data remains");
  473|  11.2k|}
_ZN5Botan11BER_Decoder10verify_endENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
  478|  11.3k|BER_Decoder& BER_Decoder::verify_end(std::string_view err) {
  479|  11.3k|   if(!m_source->end_of_data() || m_pushed.is_set()) {
  ------------------
  |  Branch (479:7): [True: 73, False: 11.2k]
  |  Branch (479:35): [True: 0, False: 11.2k]
  ------------------
  480|     73|      throw Decoding_Error(err);
  481|     73|   }
  482|  11.2k|   return (*this);
  483|  11.3k|}
_ZN5Botan11BER_Decoder10read_bytesENSt3__14spanIhLm18446744073709551615EEE:
  505|  47.1k|size_t BER_Decoder::read_bytes(std::span<uint8_t> out) {
  506|  47.1k|   BOTAN_ASSERT_NOMSG(m_source != nullptr);
  ------------------
  |  |   84|  47.1k|   do {                                                                     \
  |  |   85|  47.1k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|  47.1k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 47.1k]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|  47.1k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 47.1k]
  |  |  ------------------
  ------------------
  507|  47.1k|   return m_source->read(out.data(), out.size());
  508|  47.1k|}
_ZN5Botan11BER_Decoder16peek_next_objectEv:
  510|  2.76k|const BER_Object& BER_Decoder::peek_next_object() {
  511|  2.76k|   if(!m_pushed.is_set()) {
  ------------------
  |  Branch (511:7): [True: 2.20k, False: 565]
  ------------------
  512|  2.20k|      m_pushed = get_next_object();
  513|  2.20k|   }
  514|       |
  515|  2.76k|   return m_pushed;
  516|  2.76k|}
_ZN5Botan11BER_Decoder15get_next_objectEv:
  521|   155k|BER_Object BER_Decoder::get_next_object() {
  522|   155k|   BER_Object next;
  523|       |
  524|   155k|   if(m_pushed.is_set()) {
  ------------------
  |  Branch (524:7): [True: 18.9k, False: 136k]
  ------------------
  525|  18.9k|      std::swap(next, m_pushed);
  526|  18.9k|      return next;
  527|  18.9k|   }
  528|       |
  529|   136k|   for(;;) {
  530|   136k|      ASN1_Type type_tag = ASN1_Type::NoObject;
  531|   136k|      ASN1_Class class_tag = ASN1_Class::NoObject;
  532|   136k|      decode_tag(m_source, type_tag, class_tag);
  533|   136k|      next.set_tagging(type_tag, class_tag);
  534|   136k|      if(next.is_set() == false) {  // no more objects
  ------------------
  |  Branch (534:10): [True: 258, False: 136k]
  ------------------
  535|    258|         return next;
  536|    258|      }
  537|       |
  538|   136k|      const size_t allow_indef = m_limits.allow_ber_encoding() ? m_limits.max_nested_indefinite_length() : 0;
  ------------------
  |  Branch (538:34): [True: 0, False: 136k]
  ------------------
  539|   136k|      const bool der_mode = m_limits.require_der_encoding();
  540|   136k|      const auto dl = decode_length(m_source, allow_indef, der_mode, is_constructed(class_tag));
  541|       |
  542|       |      // Per X.690 8.1.5 the only valid EOC encoding is the two-octet
  543|       |      // sequence 0x00 0x00. Reject any other length encoding on a tag of
  544|       |      // (Eoc, Universal) before we consume the "content" bytes.
  545|   136k|      if(type_tag == ASN1_Type::Eoc && class_tag == ASN1_Class::Universal &&
  ------------------
  |  Branch (545:10): [True: 3.39k, False: 132k]
  |  Branch (545:40): [True: 193, False: 3.19k]
  ------------------
  546|    193|         (dl.content_length() != 0 || dl.indefinite_length())) {
  ------------------
  |  Branch (546:11): [True: 96, False: 97]
  |  Branch (546:39): [True: 0, False: 97]
  ------------------
  547|     96|         throw BER_Decoding_Error("EOC marker with non-zero length");
  548|     96|      }
  549|       |
  550|   135k|      if(const auto max_size = m_limits.max_object_size(); max_size && dl.content_length() > *max_size) {
  ------------------
  |  Branch (550:60): [True: 135k, False: 706]
  |  Branch (550:72): [True: 41, False: 135k]
  ------------------
  551|     41|         throw BER_Decoding_Error("Encoded object exceeds maximum size");
  552|     41|      }
  553|       |
  554|   135k|      if(!m_source->check_available(dl.total_length())) {
  ------------------
  |  Branch (554:10): [True: 870, False: 135k]
  ------------------
  555|    870|         throw BER_Decoding_Error("Value truncated");
  556|    870|      }
  557|       |
  558|   135k|      uint8_t* out = next.mutable_bits(dl.content_length());
  559|   135k|      if(m_source->read(out, dl.content_length()) != dl.content_length()) {
  ------------------
  |  Branch (559:10): [True: 0, False: 135k]
  ------------------
  560|      0|         throw BER_Decoding_Error("Value truncated");
  561|      0|      }
  562|       |
  563|   135k|      if(dl.indefinite_length()) {
  ------------------
  |  Branch (563:10): [True: 0, False: 135k]
  ------------------
  564|       |         // After reading the data consume the 2-byte EOC
  565|      0|         uint8_t eoc[2] = {0xFF, 0xFF};
  566|      0|         if(m_source->read(eoc, 2) != 2 || eoc[0] != 0x00 || eoc[1] != 0x00) {
  ------------------
  |  Branch (566:13): [True: 0, False: 0]
  |  Branch (566:44): [True: 0, False: 0]
  |  Branch (566:62): [True: 0, False: 0]
  ------------------
  567|      0|            throw BER_Decoding_Error("Missing or malformed EOC marker");
  568|      0|         }
  569|      0|      }
  570|       |
  571|   135k|      if(next.tagging() == static_cast<uint32_t>(ASN1_Type::Eoc)) {
  ------------------
  |  Branch (571:10): [True: 97, False: 134k]
  ------------------
  572|     97|         if(m_limits.require_der_encoding()) {
  ------------------
  |  Branch (572:13): [True: 97, False: 0]
  ------------------
  573|     97|            throw BER_Decoding_Error("Detected EOC marker in DER structure");
  574|     97|         }
  575|       |         // An EOC marker is only valid as an indefinite-length terminator, which
  576|       |         // is consumed above when reading the indefinite-length object. A
  577|       |         // standalone EOC is rejected unless the caller opted to tolerate it.
  578|      0|         if(m_limits.allow_standalone_eoc()) {
  ------------------
  |  Branch (578:13): [True: 0, False: 0]
  ------------------
  579|      0|            continue;
  580|      0|         }
  581|      0|         throw BER_Decoding_Error("Encountered EOC marker outside of indefinite-length encoding");
  582|      0|      }
  583|       |
  584|   134k|      break;
  585|   135k|   }
  586|       |
  587|   134k|   return next;
  588|   136k|}
_ZN5Botan11BER_Decoder9push_backEONS_10BER_ObjectE:
  612|  16.9k|void BER_Decoder::push_back(BER_Object&& obj) {
  613|  16.9k|   if(m_pushed.is_set()) {
  ------------------
  |  Branch (613:7): [True: 0, False: 16.9k]
  ------------------
  614|      0|      throw Invalid_State("BER_Decoder: Only one push back is allowed");
  615|      0|   }
  616|  16.9k|   m_pushed = std::move(obj);
  617|  16.9k|}
_ZN5Botan11BER_Decoder10start_consENS_9ASN1_TypeENS_10ASN1_ClassE:
  619|  55.7k|BER_Decoder BER_Decoder::start_cons(ASN1_Type type_tag, ASN1_Class class_tag) {
  620|  55.7k|   BER_Object obj = get_next_object();
  621|  55.7k|   obj.assert_is_a(type_tag, class_tag | ASN1_Class::Constructed);
  622|       |
  623|       |   // In DER mode the elements of a universal SET must appear in sorted order
  624|  55.7k|   if(m_limits.require_der_encoding() && type_tag == ASN1_Type::Set && class_tag == ASN1_Class::Universal) {
  ------------------
  |  Branch (624:7): [True: 54.5k, False: 1.26k]
  |  Branch (624:42): [True: 2.91k, False: 51.6k]
  |  Branch (624:72): [True: 2.91k, False: 0]
  ------------------
  625|  2.91k|      verify_set_is_sorted(std::span<const uint8_t>{obj.bits(), obj.length()});
  626|  2.91k|   }
  627|       |
  628|  55.7k|   BER_Decoder child(std::move(obj), this);
  629|  55.7k|   return child;
  630|  55.7k|}
_ZN5Botan11BER_Decoder8end_consEv:
  635|  39.1k|BER_Decoder& BER_Decoder::end_cons() {
  636|  39.1k|   if(m_parent == nullptr) {
  ------------------
  |  Branch (636:7): [True: 0, False: 39.1k]
  ------------------
  637|      0|      throw Invalid_State("BER_Decoder::end_cons called with null parent");
  638|      0|   }
  639|  39.1k|   if(!m_source->end_of_data() || m_pushed.is_set()) {
  ------------------
  |  Branch (639:7): [True: 114, False: 39.0k]
  |  Branch (639:35): [True: 54, False: 38.9k]
  ------------------
  640|    168|      throw Decoding_Error("BER_Decoder::end_cons called with data left");
  641|    168|   }
  642|  38.9k|   return (*m_parent);
  643|  39.1k|}
_ZN5Botan11BER_DecoderC2EONS_10BER_ObjectEPS0_:
  646|  54.3k|      m_limits(parent != nullptr ? parent->limits() : BER_Decoder::Limits::BER()), m_parent(parent) {
  ------------------
  |  Branch (646:16): [True: 54.3k, False: 0]
  ------------------
  647|  54.3k|   m_data_src = std::make_unique<DataSource_BERObject>(std::move(obj));
  648|  54.3k|   m_source = m_data_src.get();
  649|  54.3k|}
_ZN5Botan11BER_DecoderC2ERNS_10DataSourceENS0_6LimitsE:
  659|  3.50k|BER_Decoder::BER_Decoder(DataSource& src, Limits limits) : m_limits(limits), m_source(&src) {}
_ZN5Botan11BER_DecoderC2ENSt3__14spanIKhLm18446744073709551615EEENS0_6LimitsE:
  664|  15.5k|BER_Decoder::BER_Decoder(std::span<const uint8_t> buf, Limits limits) : m_limits(limits) {
  665|  15.5k|   m_data_src = std::make_unique<DataSource_Memory>(buf);
  666|  15.5k|   m_source = m_data_src.get();
  667|  15.5k|}
_ZN5Botan11BER_Decoder6decodeERNS_11ASN1_ObjectENS_9ASN1_TypeENS_10ASN1_ClassE:
  676|  66.2k|BER_Decoder& BER_Decoder::decode(ASN1_Object& obj, ASN1_Type type_tag, ASN1_Class class_tag) {
  677|       |   // TODO support this case properly
  678|  66.2k|   if(type_tag != ASN1_Type::NoObject || class_tag != ASN1_Class::NoObject) {
  ------------------
  |  Branch (678:7): [True: 0, False: 66.2k]
  |  Branch (678:42): [True: 0, False: 66.2k]
  ------------------
  679|      0|      throw Not_Implemented("BER_Decoder::decode(ASN1_Object) does not support implicit tagged decoding");
  680|      0|   }
  681|  66.2k|   obj.decode_from(*this);
  682|  66.2k|   return (*this);
  683|  66.2k|}
_ZN5Botan11BER_Decoder6decodeERbNS_9ASN1_TypeENS_10ASN1_ClassE:
  707|     56|BER_Decoder& BER_Decoder::decode(bool& out, ASN1_Type type_tag, ASN1_Class class_tag) {
  708|     56|   const BER_Object obj = get_next_object();
  709|     56|   obj.assert_is_a(type_tag, class_tag);
  710|       |
  711|     56|   if(obj.length() != 1) {
  ------------------
  |  Branch (711:7): [True: 16, False: 40]
  ------------------
  712|     16|      throw BER_Decoding_Error("BER boolean value had invalid size");
  713|     16|   }
  714|       |
  715|     40|   const uint8_t val = obj.bits()[0];
  716|       |
  717|       |   // DER requires boolean values to be exactly 0x00 or 0xFF
  718|     40|   if(m_limits.require_der_encoding() && val != 0x00 && val != 0xFF) {
  ------------------
  |  Branch (718:7): [True: 40, False: 0]
  |  Branch (718:42): [True: 31, False: 9]
  |  Branch (718:57): [True: 12, False: 19]
  ------------------
  719|     12|      throw BER_Decoding_Error("Detected non-canonical boolean encoding in DER structure");
  720|     12|   }
  721|       |
  722|     28|   out = (val != 0) ? true : false;
  ------------------
  |  Branch (722:10): [True: 19, False: 9]
  ------------------
  723|       |
  724|     28|   return (*this);
  725|     40|}
_ZN5Botan11BER_Decoder6decodeERmNS_9ASN1_TypeENS_10ASN1_ClassE:
  730|  6.52k|BER_Decoder& BER_Decoder::decode(size_t& out, ASN1_Type type_tag, ASN1_Class class_tag) {
  731|  6.52k|   BigInt integer;
  732|  6.52k|   decode(integer, type_tag, class_tag);
  733|       |
  734|  6.52k|   if(integer.signum() < 0) {
  ------------------
  |  Branch (734:7): [True: 189, False: 6.33k]
  ------------------
  735|    189|      throw BER_Decoding_Error("Decoded small integer value was negative");
  736|    189|   }
  737|       |
  738|  6.33k|   if(integer.bits() > 32) {
  ------------------
  |  Branch (738:7): [True: 58, False: 6.27k]
  ------------------
  739|     58|      throw BER_Decoding_Error("Decoded integer value larger than expected");
  740|     58|   }
  741|       |
  742|  6.27k|   out = 0;
  743|  23.0k|   for(size_t i = 0; i != 4; ++i) {
  ------------------
  |  Branch (743:22): [True: 16.7k, False: 6.27k]
  ------------------
  744|  16.7k|      out = (out << 8) | integer.byte_at(3 - i);
  745|  16.7k|   }
  746|       |
  747|  6.27k|   return (*this);
  748|  6.33k|}
_ZN5Botan11BER_Decoder6decodeERNS_6BigIntENS_9ASN1_TypeENS_10ASN1_ClassE:
  780|  15.5k|BER_Decoder& BER_Decoder::decode(BigInt& out, ASN1_Type type_tag, ASN1_Class class_tag) {
  781|  15.5k|   const BER_Object obj = get_next_object();
  782|  15.5k|   obj.assert_is_a(type_tag, class_tag);
  783|       |
  784|       |   // An INTEGER must have at least one content octet (X.690 section 8.3.1)
  785|  15.5k|   if(obj.length() == 0) {
  ------------------
  |  Branch (785:7): [True: 29, False: 15.5k]
  ------------------
  786|     29|      throw BER_Decoding_Error("INTEGER encoding has no content octets");
  787|     29|   }
  788|       |
  789|       |   // DER requires minimal INTEGER encoding (X.690 section 8.3.2)
  790|  15.5k|   if(m_limits.require_der_encoding()) {
  ------------------
  |  Branch (790:7): [True: 13.4k, False: 2.07k]
  ------------------
  791|  13.4k|      if(obj.length() > 1) {
  ------------------
  |  Branch (791:10): [True: 7.67k, False: 5.76k]
  ------------------
  792|  7.67k|         if(obj.bits()[0] == 0x00 && (obj.bits()[1] & 0x80) == 0) {
  ------------------
  |  Branch (792:13): [True: 304, False: 7.37k]
  |  Branch (792:38): [True: 6, False: 298]
  ------------------
  793|      6|            throw BER_Decoding_Error("Detected non-minimal INTEGER encoding in DER structure");
  794|      6|         }
  795|  7.67k|         if(obj.bits()[0] == 0xFF && (obj.bits()[1] & 0x80) != 0) {
  ------------------
  |  Branch (795:13): [True: 153, False: 7.51k]
  |  Branch (795:38): [True: 7, False: 146]
  ------------------
  796|      7|            throw BER_Decoding_Error("Detected non-minimal INTEGER encoding in DER structure");
  797|      7|         }
  798|  7.67k|      }
  799|  13.4k|   }
  800|       |
  801|  15.4k|   out = ASN1::integer_from_contents(obj.data());
  802|       |
  803|  15.4k|   return (*this);
  804|  15.5k|}
_ZN5Botan4ASN121integer_from_contentsENSt3__14spanIKhLm18446744073709551615EEE:
  806|  14.1k|BigInt ASN1::integer_from_contents(std::span<const uint8_t> contents) {
  807|  14.1k|   if(contents.empty()) {
  ------------------
  |  Branch (807:7): [True: 0, False: 14.1k]
  ------------------
  808|      0|      throw BER_Decoding_Error("INTEGER encoding has no content octets");
  809|      0|   }
  810|       |
  811|  14.1k|   BigInt out;
  812|       |
  813|  14.1k|   const bool negative = (contents[0] & 0x80) == 0x80;
  814|       |
  815|  14.1k|   if(negative) {
  ------------------
  |  Branch (815:7): [True: 1.67k, False: 12.4k]
  ------------------
  816|  1.67k|      secure_vector<uint8_t> vec(contents.begin(), contents.end());
  817|  2.10k|      for(size_t i = vec.size(); i > 0; --i) {
  ------------------
  |  Branch (817:34): [True: 2.10k, False: 0]
  ------------------
  818|  2.10k|         const bool gt0 = (vec[i - 1] > 0);
  819|  2.10k|         vec[i - 1] -= 1;
  820|  2.10k|         if(gt0) {
  ------------------
  |  Branch (820:13): [True: 1.67k, False: 429]
  ------------------
  821|  1.67k|            break;
  822|  1.67k|         }
  823|  2.10k|      }
  824|  20.4k|      for(auto& byte : vec) {
  ------------------
  |  Branch (824:22): [True: 20.4k, False: 1.67k]
  ------------------
  825|  20.4k|         byte = ~byte;
  826|  20.4k|      }
  827|  1.67k|      out._assign_from_bytes(vec);
  828|  1.67k|      out.set_sign(BigInt::Negative);
  829|  12.4k|   } else {
  830|  12.4k|      out._assign_from_bytes(contents);
  831|  12.4k|   }
  832|       |
  833|  14.1k|   return out;
  834|  14.1k|}
_ZN5Botan11BER_Decoder6decodeERNSt3__16vectorIhNS1_9allocatorIhEEEENS_9ASN1_TypeES7_NS_10ASN1_ClassE:
 1038|  14.0k|                                 ASN1_Class class_tag) {
 1039|  14.0k|   if(real_type != ASN1_Type::OctetString && real_type != ASN1_Type::BitString) {
  ------------------
  |  Branch (1039:7): [True: 0, False: 14.0k]
  |  Branch (1039:46): [True: 0, False: 0]
  ------------------
 1040|      0|      throw BER_Bad_Tag("Bad tag for {BIT,OCTET} STRING", static_cast<uint32_t>(real_type));
 1041|      0|   }
 1042|       |
 1043|  14.0k|   asn1_decode_binary_string(buffer, get_next_object(), real_type, type_tag, class_tag, m_limits);
 1044|  14.0k|   return (*this);
 1045|  14.0k|}
_ZN5Botan11BER_Decoder16decode_bitstringERNS_14ASN1_BitStringENS_9ASN1_TypeENS_10ASN1_ClassE:
 1047|  2.80k|BER_Decoder& BER_Decoder::decode_bitstring(ASN1_BitString& out, ASN1_Type type_tag, ASN1_Class class_tag) {
 1048|  2.80k|   const BER_Object obj = get_next_object();
 1049|       |
 1050|  2.80k|   std::vector<uint8_t> bits;
 1051|  2.80k|   uint8_t unused_bits = 0;
 1052|       |
 1053|  2.80k|   if(is_constructed(obj.class_tag())) {
  ------------------
  |  Branch (1053:7): [True: 3, False: 2.80k]
  ------------------
 1054|      3|      obj.assert_is_a(type_tag, class_tag | ASN1_Class::Constructed);
 1055|      3|      if(m_limits.require_der_encoding()) {
  ------------------
  |  Branch (1055:10): [True: 1, False: 2]
  ------------------
 1056|      1|         throw BER_Decoding_Error("Detected constructed string encoding in DER structure");
 1057|      1|      }
 1058|      2|      bits.reserve(obj.length());  // upper possible bound on the output size
 1059|      2|      unused_bits = asn1_concat_constructed_bit_string(bits, obj, m_limits, 0);
 1060|  2.80k|   } else {
 1061|  2.80k|      unused_bits = asn1_bitstring_unused_bits(obj, type_tag, class_tag, m_limits.require_der_encoding());
 1062|  2.80k|      bits.assign(obj.bits() + 1, obj.bits() + obj.length());
 1063|  2.80k|   }
 1064|       |
 1065|  2.80k|   if(unused_bits > 0 && !bits.empty()) {
  ------------------
  |  Branch (1065:7): [True: 12, False: 2.79k]
  |  Branch (1065:26): [True: 12, False: 0]
  ------------------
 1066|     12|      bits.back() &= static_cast<uint8_t>(0xFF << unused_bits);
 1067|     12|   }
 1068|       |
 1069|  2.80k|   out = ASN1_BitString(std::move(bits), unused_bits);
 1070|  2.80k|   return (*this);
 1071|  2.80k|}
_ZN5Botan11BER_Decoder22decode_named_bitstringERmmNS_9ASN1_TypeENS_10ASN1_ClassE:
 1076|     42|                                                 ASN1_Class class_tag) {
 1077|     42|   if(width > 64) {
  ------------------
  |  Branch (1077:7): [True: 0, False: 42]
  ------------------
 1078|      0|      throw Invalid_Argument("BER_Decoder: Named BIT STRING width is too large");
 1079|      0|   }
 1080|       |
 1081|     42|   ASN1_BitString bits;
 1082|     42|   decode_bitstring(bits, type_tag, class_tag);
 1083|       |
 1084|     42|   if(bits.bit_length() > width) {
  ------------------
  |  Branch (1084:7): [True: 9, False: 33]
  ------------------
 1085|      9|      throw BER_Decoding_Error("Named BIT STRING exceeds declared width");
 1086|      9|   }
 1087|       |
 1088|     33|   if(m_limits.require_der_encoding() && bits.bit_length() > 0 && !bits.bit_at(bits.bit_length() - 1)) {
  ------------------
  |  Branch (1088:7): [True: 24, False: 9]
  |  Branch (1088:42): [True: 19, False: 5]
  |  Branch (1088:67): [True: 5, False: 14]
  ------------------
 1089|      5|      throw BER_Decoding_Error("Named BIT STRING is not minimally encoded");
 1090|      5|   }
 1091|       |
 1092|     28|   uint64_t decoded = 0;
 1093|    113|   for(size_t bit = 0; bit != bits.bit_length(); ++bit) {
  ------------------
  |  Branch (1093:24): [True: 85, False: 28]
  ------------------
 1094|     85|      if(bits.bit_at(bit)) {
  ------------------
  |  Branch (1094:10): [True: 57, False: 28]
  ------------------
 1095|     57|         decoded |= uint64_t(1) << (width - 1 - bit);
 1096|     57|      }
 1097|     85|   }
 1098|       |
 1099|     28|   out = decoded;
 1100|     28|   return (*this);
 1101|     33|}
_ZN5Botan4ASN120is_single_der_objectENSt3__14spanIKhLm18446744073709551615EEENS_9ASN1_TypeENS_10ASN1_ClassE:
 1105|    623|bool is_single_der_object(std::span<const uint8_t> bytes, ASN1_Type expected_type, ASN1_Class expected_class) {
 1106|    623|   if(bytes.empty()) {
  ------------------
  |  Branch (1106:7): [True: 0, False: 623]
  ------------------
 1107|      0|      return false;
 1108|      0|   }
 1109|       |
 1110|    623|   try {
 1111|    623|      DataSource_Span src(bytes);
 1112|       |
 1113|    623|      ASN1_Type type_tag = ASN1_Type::NoObject;
 1114|    623|      ASN1_Class class_tag = ASN1_Class::NoObject;
 1115|    623|      const size_t tag_bytes = decode_tag(&src, type_tag, class_tag);
 1116|       |
 1117|    623|      if(type_tag != expected_type || class_tag != expected_class) {
  ------------------
  |  Branch (1117:10): [True: 464, False: 159]
  |  Branch (1117:39): [True: 9, False: 150]
  ------------------
 1118|    425|         return false;
 1119|    425|      }
 1120|       |
 1121|    198|      const auto dl = decode_length(&src, /*allow_indef=*/0, /*der_mode=*/true, is_constructed(expected_class));
 1122|       |
 1123|    198|      const size_t header_bytes = tag_bytes + dl.field_length();
 1124|    198|      if(header_bytes > bytes.size()) {
  ------------------
  |  Branch (1124:10): [True: 0, False: 198]
  ------------------
 1125|      0|         return false;
 1126|      0|      }
 1127|    198|      return dl.content_length() == bytes.size() - header_bytes;
 1128|    198|   } catch(Decoding_Error&) {
 1129|     54|      return false;
 1130|     54|   }
 1131|    623|}
_ZN5Botan4ASN122is_der_sequence_headerENSt3__14spanIKhLm18446744073709551615EEE:
 1133|    239|bool is_der_sequence_header(std::span<const uint8_t> bytes) {
 1134|    239|   return is_single_der_object(bytes, ASN1_Type::Sequence, ASN1_Class::Universal | ASN1_Class::Constructed);
 1135|    239|}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_110decode_tagEPNS_10DataSourceERNS_9ASN1_TypeERNS_10ASN1_ClassE:
   29|   136k|size_t decode_tag(DataSource* ber, ASN1_Type& type_tag, ASN1_Class& class_tag) {
   30|   136k|   auto b = ber->read_byte();
   31|       |
   32|   136k|   if(!b) {
  ------------------
  |  Branch (32:7): [True: 258, False: 136k]
  ------------------
   33|    258|      type_tag = ASN1_Type::NoObject;
   34|    258|      class_tag = ASN1_Class::NoObject;
   35|    258|      return 0;
   36|    258|   }
   37|       |
   38|   136k|   if((*b & 0x1F) != 0x1F) {
  ------------------
  |  Branch (38:7): [True: 135k, False: 1.04k]
  ------------------
   39|   135k|      type_tag = ASN1_Type(*b & 0x1F);
   40|   135k|      class_tag = ASN1_Class(*b & 0xE0);
   41|       |      // The EOC marker is primitive; a constructed universal tag 0 has no
   42|       |      // valid meaning and would otherwise bypass the EOC handling, which
   43|       |      // matches on (Eoc, Universal) exactly
   44|   135k|      if(type_tag == ASN1_Type::Eoc && class_tag == ASN1_Class::Constructed) {
  ------------------
  |  Branch (44:10): [True: 3.48k, False: 132k]
  |  Branch (44:40): [True: 25, False: 3.46k]
  ------------------
   45|     25|         throw BER_Decoding_Error("EOC tag with constructed encoding");
   46|     25|      }
   47|   135k|      return 1;
   48|   135k|   }
   49|       |
   50|  1.04k|   size_t tag_bytes = 1;
   51|  1.04k|   class_tag = ASN1_Class(*b & 0xE0);
   52|       |
   53|  1.04k|   uint32_t tag_buf = 0;
   54|  3.43k|   while(true) {
  ------------------
  |  Branch (54:10): [True: 3.43k, Folded]
  ------------------
   55|  3.43k|      b = ber->read_byte();
   56|  3.43k|      if(!b) {
  ------------------
  |  Branch (56:10): [True: 36, False: 3.39k]
  ------------------
   57|     36|         throw BER_Decoding_Error("Long-form tag truncated");
   58|     36|      }
   59|       |      // Reject if shifting in another 7 bits would overflow the uint32_t tag
   60|  3.39k|      if((tag_buf >> 25) != 0) {
  ------------------
  |  Branch (60:10): [True: 46, False: 3.34k]
  ------------------
   61|     46|         throw BER_Decoding_Error("Long-form tag overflowed 32 bits");
   62|     46|      }
   63|       |      // This is required even by BER (see X.690 section 8.1.2.4.2 sentence c).
   64|       |      // Bits 7-1 of the first subsequent octet must not be all zero; this rules
   65|       |      // out both 0x80 (continuation with no data) and 0x00 (a long-form encoding
   66|       |      // of tag value 0, which collides with the EOC marker).
   67|  3.34k|      if(tag_bytes == 1 && (*b & 0x7F) == 0) {
  ------------------
  |  Branch (67:10): [True: 1.02k, False: 2.32k]
  |  Branch (67:28): [True: 46, False: 983]
  ------------------
   68|     46|         throw BER_Decoding_Error("Long form tag with leading zero");
   69|     46|      }
   70|  3.30k|      ++tag_bytes;
   71|  3.30k|      tag_buf = (tag_buf << 7) | (*b & 0x7F);
   72|  3.30k|      if((*b & 0x80) == 0) {
  ------------------
  |  Branch (72:10): [True: 914, False: 2.38k]
  ------------------
   73|    914|         break;
   74|    914|      }
   75|  3.30k|   }
   76|       |   // Per X.690 8.1.2.2, tag values 0-30 shall be encoded in the short form.
   77|       |   // Long-form encoding is reserved for tag values >= 31 (X.690 8.1.2.3).
   78|       |   // This is unconditional and applies to BER as well as DER.
   79|    914|   if(tag_buf <= 30) {
  ------------------
  |  Branch (79:7): [True: 39, False: 875]
  ------------------
   80|     39|      throw BER_Decoding_Error("Long-form tag encoding used for small tag value");
   81|     39|   }
   82|       |
   83|    875|   if(tag_buf == static_cast<uint32_t>(ASN1_Type::NoObject)) {
  ------------------
  |  Branch (83:7): [True: 4, False: 871]
  ------------------
   84|      4|      throw BER_Decoding_Error("Tag value collides with internal sentinel");
   85|      4|   }
   86|       |
   87|       |   // NOLINTNEXTLINE(clang-analyzer-optin.core.EnumCastOutOfRange)
   88|    871|   type_tag = ASN1_Type(tag_buf);
   89|    871|   return tag_bytes;
   90|    875|}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_113decode_lengthEPNS_10DataSourceEmbb:
  135|   136k|BerDecodedLength decode_length(DataSource* ber, size_t allow_indef, bool der_mode, bool constructed) {
  136|   136k|   uint8_t b = 0;
  137|   136k|   if(ber->read_byte(b) == 0) {
  ------------------
  |  Branch (137:7): [True: 150, False: 135k]
  ------------------
  138|    150|      throw BER_Decoding_Error("Length field not found");
  139|    150|   }
  140|   135k|   if((b & 0x80) == 0) {
  ------------------
  |  Branch (140:7): [True: 125k, False: 9.89k]
  ------------------
  141|   125k|      return BerDecodedLength(b, 1);
  142|   125k|   }
  143|       |
  144|  9.89k|   const size_t num_length_bytes = (b & 0x7F);
  145|  9.89k|   if(num_length_bytes > 4) {
  ------------------
  |  Branch (145:7): [True: 303, False: 9.58k]
  ------------------
  146|    303|      throw BER_Decoding_Error("Length field is too large");
  147|    303|   }
  148|       |
  149|  9.58k|   const size_t field_size = 1 + num_length_bytes;
  150|       |
  151|  9.58k|   if(num_length_bytes == 0) {
  ------------------
  |  Branch (151:7): [True: 25, False: 9.56k]
  ------------------
  152|     25|      if(der_mode) {
  ------------------
  |  Branch (152:10): [True: 25, False: 0]
  ------------------
  153|     25|         throw BER_Decoding_Error("Detected indefinite-length encoding in DER structure");
  154|     25|      } else if(!constructed) {
  ------------------
  |  Branch (154:17): [True: 0, False: 0]
  ------------------
  155|       |         // Indefinite length is only valid for constructed types (X.690 8.1.3.2)
  156|      0|         throw BER_Decoding_Error("Indefinite-length encoding used with non-constructed type");
  157|      0|      } else if(allow_indef == 0) {
  ------------------
  |  Branch (157:17): [True: 0, False: 0]
  ------------------
  158|      0|         throw BER_Decoding_Error("Nested EOC markers too deep, rejecting to avoid stack exhaustion");
  159|      0|      } else {
  160|       |         // find_eoc returns bytes up to and including the EOC marker.
  161|       |         // Return the content length; the caller consumes the EOC separately.
  162|      0|         const size_t eoc_len = find_eoc(ber, /*base_offset=*/0, allow_indef - 1);
  163|      0|         if(eoc_len < 2) {
  ------------------
  |  Branch (163:13): [True: 0, False: 0]
  ------------------
  164|      0|            throw BER_Decoding_Error("Invalid EOC encoding");
  165|      0|         }
  166|      0|         return BerDecodedLength::indefinite(eoc_len - 2, field_size);
  167|      0|      }
  168|     25|   }
  169|       |
  170|  9.56k|   size_t length = 0;
  171|       |
  172|  27.9k|   for(size_t i = 0; i != num_length_bytes; ++i) {
  ------------------
  |  Branch (172:22): [True: 18.4k, False: 9.52k]
  ------------------
  173|  18.4k|      if(ber->read_byte(b) == 0) {
  ------------------
  |  Branch (173:10): [True: 44, False: 18.4k]
  ------------------
  174|     44|         throw BER_Decoding_Error("Corrupted length field");
  175|     44|      }
  176|       |      // Can't overflow since we already checked that num_length_bytes <= 4
  177|  18.4k|      length = (length << 8) | b;
  178|  18.4k|   }
  179|       |
  180|       |   // DER requires shortest possible length encoding
  181|  9.52k|   if(der_mode) {
  ------------------
  |  Branch (181:7): [True: 9.52k, False: 0]
  ------------------
  182|  9.52k|      if(length < 128) {
  ------------------
  |  Branch (182:10): [True: 39, False: 9.48k]
  ------------------
  183|     39|         throw BER_Decoding_Error("Detected non-canonical length encoding in DER structure");
  184|     39|      }
  185|  9.48k|      if(num_length_bytes > 1 && length < (size_t(1) << ((num_length_bytes - 1) * 8))) {
  ------------------
  |  Branch (185:10): [True: 8.65k, False: 824]
  |  Branch (185:34): [True: 3, False: 8.65k]
  ------------------
  186|      3|         throw BER_Decoding_Error("Detected non-canonical length encoding in DER structure");
  187|      3|      }
  188|  9.48k|   }
  189|       |
  190|  9.47k|   return BerDecodedLength(length, field_size);
  191|  9.52k|}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_116BerDecodedLengthC2Emm:
  108|   135k|            BerDecodedLength(content_length, field_length, false) {}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_116BerDecodedLengthC2Emmb:
  125|   135k|            m_content_length(content_length), m_field_length(field_length), m_indefinite(indefinite) {}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_18peek_tagEPNS_10DataSourceEmRNS_9ASN1_TypeERNS_10ASN1_ClassE:
  197|  4.25k|size_t peek_tag(DataSource* src, size_t offset, ASN1_Type& type_tag, ASN1_Class& class_tag) {
  198|  4.25k|   uint8_t b = 0;
  199|  4.25k|   if(src->peek(&b, 1, offset) == 0) {
  ------------------
  |  Branch (199:7): [True: 0, False: 4.25k]
  ------------------
  200|      0|      type_tag = ASN1_Type::NoObject;
  201|      0|      class_tag = ASN1_Class::NoObject;
  202|      0|      return 0;
  203|      0|   }
  204|       |
  205|  4.25k|   if((b & 0x1F) != 0x1F) {
  ------------------
  |  Branch (205:7): [True: 4.05k, False: 200]
  ------------------
  206|  4.05k|      type_tag = ASN1_Type(b & 0x1F);
  207|  4.05k|      class_tag = ASN1_Class(b & 0xE0);
  208|       |      // The EOC marker is primitive; a constructed universal tag 0 has no
  209|       |      // valid meaning and would otherwise bypass the EOC handling, which
  210|       |      // matches on (Eoc, Universal) exactly
  211|  4.05k|      if(type_tag == ASN1_Type::Eoc && class_tag == ASN1_Class::Constructed) {
  ------------------
  |  Branch (211:10): [True: 775, False: 3.27k]
  |  Branch (211:40): [True: 5, False: 770]
  ------------------
  212|      5|         throw BER_Decoding_Error("EOC tag with constructed encoding");
  213|      5|      }
  214|  4.04k|      return 1;
  215|  4.05k|   }
  216|       |
  217|    200|   class_tag = ASN1_Class(b & 0xE0);
  218|    200|   size_t tag_bytes = 1;
  219|    200|   uint32_t tag_buf = 0;
  220|       |
  221|    544|   while(true) {
  ------------------
  |  Branch (221:10): [True: 544, Folded]
  ------------------
  222|    544|      if(src->peek(&b, 1, offset + tag_bytes) == 0) {
  ------------------
  |  Branch (222:10): [True: 7, False: 537]
  ------------------
  223|      7|         throw BER_Decoding_Error("Long-form tag truncated");
  224|      7|      }
  225|       |      // Reject if shifting in another 7 bits would overflow the uint32_t tag
  226|    537|      if((tag_buf >> 25) != 0) {
  ------------------
  |  Branch (226:10): [True: 11, False: 526]
  ------------------
  227|     11|         throw BER_Decoding_Error("Long-form tag overflowed 32 bits");
  228|     11|      }
  229|       |      // Required even by BER (X.690 section 8.1.2.4.2 sentence c).
  230|       |      // Bits 7-1 of the first subsequent octet must not be all zero; this rules
  231|       |      // out both 0x80 (continuation with no data) and 0x00 (a long-form encoding
  232|       |      // of tag value 0, which collides with the EOC marker).
  233|    526|      if(tag_bytes == 1 && (b & 0x7F) == 0) {
  ------------------
  |  Branch (233:10): [True: 198, False: 328]
  |  Branch (233:28): [True: 3, False: 195]
  ------------------
  234|      3|         throw BER_Decoding_Error("Long form tag with leading zero");
  235|      3|      }
  236|    523|      ++tag_bytes;
  237|    523|      tag_buf = (tag_buf << 7) | (b & 0x7F);
  238|    523|      if((b & 0x80) == 0) {
  ------------------
  |  Branch (238:10): [True: 179, False: 344]
  ------------------
  239|    179|         break;
  240|    179|      }
  241|    523|   }
  242|       |
  243|       |   // Per X.690 8.1.2.2, tag values 0-30 shall be encoded in the short form.
  244|       |   // Long-form encoding is reserved for tag values >= 31 (X.690 8.1.2.3).
  245|       |   // This is unconditional and applies to BER as well as DER.
  246|    179|   if(tag_buf <= 30) {
  ------------------
  |  Branch (246:7): [True: 7, False: 172]
  ------------------
  247|      7|      throw BER_Decoding_Error("Long-form tag encoding used for small tag value");
  248|      7|   }
  249|       |
  250|    172|   if(tag_buf == static_cast<uint32_t>(ASN1_Type::NoObject)) {
  ------------------
  |  Branch (250:7): [True: 1, False: 171]
  ------------------
  251|      1|      throw BER_Decoding_Error("Tag value collides with internal sentinel");
  252|      1|   }
  253|       |
  254|       |   // NOLINTNEXTLINE(clang-analyzer-optin.core.EnumCastOutOfRange)
  255|    171|   type_tag = ASN1_Type(tag_buf);
  256|    171|   return tag_bytes;
  257|    172|}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_111peek_lengthEPNS_10DataSourceEmRmmbb:
  265|  4.21k|   DataSource* src, size_t offset, size_t& field_size, size_t allow_indef, bool constructed, bool der_mode) {
  266|  4.21k|   uint8_t b = 0;
  267|  4.21k|   if(src->peek(&b, 1, offset) == 0) {
  ------------------
  |  Branch (267:7): [True: 7, False: 4.20k]
  ------------------
  268|      7|      throw BER_Decoding_Error("Length field not found");
  269|      7|   }
  270|       |
  271|  4.20k|   field_size = 1;
  272|  4.20k|   if((b & 0x80) == 0) {
  ------------------
  |  Branch (272:7): [True: 4.11k, False: 96]
  ------------------
  273|  4.11k|      return b;
  274|  4.11k|   }
  275|       |
  276|     96|   const size_t num_length_bytes = (b & 0x7F);
  277|     96|   field_size += num_length_bytes;
  278|     96|   if(field_size > 5) {
  ------------------
  |  Branch (278:7): [True: 18, False: 78]
  ------------------
  279|     18|      throw BER_Decoding_Error("Length field is too large");
  280|     18|   }
  281|       |
  282|     78|   if(num_length_bytes == 0) {
  ------------------
  |  Branch (282:7): [True: 4, False: 74]
  ------------------
  283|       |      // Indefinite length is not allowed in DER
  284|      4|      if(der_mode) {
  ------------------
  |  Branch (284:10): [True: 4, False: 0]
  ------------------
  285|      4|         throw BER_Decoding_Error("Detected indefinite-length encoding in DER structure");
  286|      4|      }
  287|       |      // Indefinite length is only valid for constructed types (X.690 8.1.3.2)
  288|      0|      if(!constructed) {
  ------------------
  |  Branch (288:10): [True: 0, False: 0]
  ------------------
  289|      0|         throw BER_Decoding_Error("Indefinite-length encoding used with non-constructed type");
  290|      0|      }
  291|      0|      if(allow_indef == 0) {
  ------------------
  |  Branch (291:10): [True: 0, False: 0]
  ------------------
  292|      0|         throw BER_Decoding_Error("Nested EOC markers too deep, rejecting to avoid stack exhaustion");
  293|      0|      }
  294|      0|      return find_eoc(src, offset + 1, allow_indef - 1);
  295|      0|   }
  296|       |
  297|     74|   size_t length = 0;
  298|    266|   for(size_t i = 0; i < num_length_bytes; ++i) {
  ------------------
  |  Branch (298:22): [True: 202, False: 64]
  ------------------
  299|    202|      if(src->peek(&b, 1, offset + 1 + i) == 0) {
  ------------------
  |  Branch (299:10): [True: 10, False: 192]
  ------------------
  300|     10|         throw BER_Decoding_Error("Corrupted length field");
  301|     10|      }
  302|    192|      if(get_byte<0>(length) != 0) {
  ------------------
  |  Branch (302:10): [True: 0, False: 192]
  ------------------
  303|      0|         throw BER_Decoding_Error("Field length overflow");
  304|      0|      }
  305|    192|      length = (length << 8) | b;
  306|    192|   }
  307|     64|   return length;
  308|     74|}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_114is_constructedENS_10ASN1_ClassE:
   22|   159k|bool is_constructed(ASN1_Class class_tag) {
   23|   159k|   return (static_cast<uint32_t>(class_tag) & static_cast<uint32_t>(ASN1_Class::Constructed)) != 0;
   24|   159k|}
ber_dec.cpp:_ZNK5Botan12_GLOBAL__N_116BerDecodedLength14content_lengthEv:
  114|   538k|      size_t content_length() const { return m_content_length; }
ber_dec.cpp:_ZNK5Botan12_GLOBAL__N_116BerDecodedLength17indefinite_lengthEv:
  121|   134k|      bool indefinite_length() const { return m_indefinite; }
ber_dec.cpp:_ZNK5Botan12_GLOBAL__N_116BerDecodedLength12total_lengthEv:
  117|   135k|      size_t total_length() const { return m_indefinite ? m_content_length + 2 : m_content_length; }
  ------------------
  |  Branch (117:44): [True: 0, False: 135k]
  ------------------
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_120verify_set_is_sortedENSt3__14spanIKhLm18446744073709551615EEE:
  426|  2.91k|void verify_set_is_sorted(std::span<const uint8_t> content) {
  427|  2.91k|   DataSource_Span src(content);
  428|  2.91k|   size_t offset = 0;
  429|  2.91k|   std::optional<std::span<const uint8_t>> prev;
  430|       |
  431|  7.02k|   while(offset < content.size()) {
  ------------------
  |  Branch (431:10): [True: 4.25k, False: 2.77k]
  ------------------
  432|  4.25k|      ASN1_Type type_tag = ASN1_Type::NoObject;
  433|  4.25k|      ASN1_Class class_tag = ASN1_Class::NoObject;
  434|  4.25k|      const size_t tag_size = peek_tag(&src, offset, type_tag, class_tag);
  435|       |
  436|  4.25k|      size_t length_size = 0;
  437|  4.25k|      const size_t item_size =
  438|  4.25k|         peek_length(&src, offset + tag_size, length_size, /*allow_indef=*/0, is_constructed(class_tag), true);
  439|       |
  440|  4.25k|      const auto end = checked_add(offset, tag_size, length_size, item_size);
  441|  4.25k|      if(!end || *end > content.size()) {
  ------------------
  |  Branch (441:10): [True: 73, False: 4.17k]
  |  Branch (441:18): [True: 75, False: 4.10k]
  ------------------
  442|     75|         throw BER_Decoding_Error("SET element exceeds available data");
  443|     75|      }
  444|       |
  445|  4.17k|      const auto elem = content.subspan(offset, *end - offset);
  446|  4.17k|      if(prev && std::lexicographical_compare(elem.begin(), elem.end(), prev->begin(), prev->end())) {
  ------------------
  |  Branch (446:10): [True: 1.22k, False: 2.95k]
  |  Branch (446:18): [True: 64, False: 1.16k]
  ------------------
  447|     64|         throw BER_Decoding_Error("Detected unsorted SET in DER structure");
  448|     64|      }
  449|  4.11k|      prev = elem;
  450|  4.11k|      offset = *end;
  451|  4.11k|   }
  452|  2.91k|}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_126asn1_bitstring_unused_bitsERKNS_10BER_ObjectENS_9ASN1_TypeENS_10ASN1_ClassEb:
  990|  2.79k|uint8_t asn1_bitstring_unused_bits(const BER_Object& obj, ASN1_Type type_tag, ASN1_Class class_tag, bool require_der) {
  991|  2.79k|   obj.assert_is_a(type_tag, class_tag);
  992|  2.79k|   BOTAN_ASSERT_NOMSG(!is_constructed(obj));
  ------------------
  |  |   84|  2.79k|   do {                                                                     \
  |  |   85|  2.79k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|  2.79k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 2.79k]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|  2.79k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 2.79k]
  |  |  ------------------
  ------------------
  993|       |
  994|  2.79k|   if(obj.length() == 0) {
  ------------------
  |  Branch (994:7): [True: 3, False: 2.79k]
  ------------------
  995|      3|      throw BER_Decoding_Error("Invalid BIT STRING");
  996|      3|   }
  997|       |
  998|  2.79k|   const uint8_t unused_bits = obj.bits()[0];
  999|       |
 1000|  2.79k|   if(unused_bits >= 8) {
  ------------------
  |  Branch (1000:7): [True: 8, False: 2.78k]
  ------------------
 1001|      8|      throw BER_Decoding_Error("Invalid number of unused bits in BIT STRING");
 1002|      8|   }
 1003|       |
 1004|  2.78k|   if(obj.length() == 1 && unused_bits != 0) {
  ------------------
  |  Branch (1004:7): [True: 16, False: 2.76k]
  |  Branch (1004:28): [True: 5, False: 11]
  ------------------
 1005|      5|      throw BER_Decoding_Error("Invalid BIT STRING");
 1006|      5|   }
 1007|       |
 1008|  2.77k|   if(require_der && unused_bits > 0) {
  ------------------
  |  Branch (1008:7): [True: 2.73k, False: 38]
  |  Branch (1008:22): [True: 21, False: 2.71k]
  ------------------
 1009|     21|      const uint8_t last_byte = obj.bits()[obj.length() - 1];
 1010|     21|      if((last_byte & ((1 << unused_bits) - 1)) != 0) {
  ------------------
  |  Branch (1010:10): [True: 9, False: 12]
  ------------------
 1011|      9|         throw BER_Decoding_Error("Detected non-zero padding bits in BIT STRING in DER structure");
 1012|      9|      }
 1013|     21|   }
 1014|       |
 1015|  2.76k|   return unused_bits;
 1016|  2.77k|}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_114is_constructedERKNS_10BER_ObjectE:
  838|  16.8k|bool is_constructed(const BER_Object& obj) {
  839|  16.8k|   return is_constructed(obj.class_tag());
  840|  16.8k|}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_115DataSource_SpanC2ENSt3__14spanIKhLm18446744073709551615EEE:
  414|  3.53k|      explicit DataSource_Span(std::span<const uint8_t> buf) : m_buf(buf) {}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_115DataSource_Span4readEPhm:
  392|  1.25k|      size_t read(uint8_t out[], size_t length) override {
  393|  1.25k|         const size_t got = std::min(m_buf.size() - m_offset, length);
  394|  1.25k|         copy_mem(out, m_buf.data() + m_offset, got);
  395|  1.25k|         m_offset += got;
  396|  1.25k|         return got;
  397|  1.25k|      }
ber_dec.cpp:_ZNK5Botan12_GLOBAL__N_115DataSource_Span4peekEPhmm:
  399|  9.21k|      size_t peek(uint8_t out[], size_t length, size_t peek_offset) const override {
  400|  9.21k|         if(peek_offset >= m_buf.size() - m_offset) {
  ------------------
  |  Branch (400:13): [True: 24, False: 9.18k]
  ------------------
  401|     24|            return 0;
  402|     24|         }
  403|  9.18k|         const size_t got = std::min(m_buf.size() - m_offset - peek_offset, length);
  404|  9.18k|         copy_mem(out, m_buf.data() + m_offset + peek_offset, got);
  405|  9.18k|         return got;
  406|  9.21k|      }
ber_dec.cpp:_ZNK5Botan12_GLOBAL__N_116BerDecodedLength12field_lengthEv:
  119|    144|      size_t field_length() const { return m_field_length; }
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_120DataSource_BERObjectC2EONS_10BER_ObjectE:
  379|  54.3k|      explicit DataSource_BERObject(BER_Object&& obj) : m_obj(std::move(obj)) {}
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_120DataSource_BERObject4readEPhm:
  349|   349k|      size_t read(uint8_t out[], size_t length) override {
  350|   349k|         BOTAN_ASSERT_NOMSG(m_offset <= m_obj.length());
  ------------------
  |  |   84|   349k|   do {                                                                     \
  |  |   85|   349k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|   349k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 349k]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|   349k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 349k]
  |  |  ------------------
  ------------------
  351|   349k|         const size_t got = std::min<size_t>(m_obj.length() - m_offset, length);
  352|   349k|         copy_mem(out, m_obj.bits() + m_offset, got);
  353|   349k|         m_offset += got;
  354|   349k|         return got;
  355|   349k|      }
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_120DataSource_BERObject15check_availableEm:
  370|  97.4k|      bool check_available(size_t n) override {
  371|  97.4k|         BOTAN_ASSERT_NOMSG(m_offset <= m_obj.length());
  ------------------
  |  |   84|  97.4k|   do {                                                                     \
  |  |   85|  97.4k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|  97.4k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 97.4k]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|  97.4k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 97.4k]
  |  |  ------------------
  ------------------
  372|  97.4k|         return (n <= (m_obj.length() - m_offset));
  373|  97.4k|      }
ber_dec.cpp:_ZNK5Botan12_GLOBAL__N_120DataSource_BERObject11end_of_dataEv:
  375|  89.3k|      bool end_of_data() const override { return get_bytes_read() == m_obj.length(); }
ber_dec.cpp:_ZNK5Botan12_GLOBAL__N_120DataSource_BERObject14get_bytes_readEv:
  377|  89.3k|      size_t get_bytes_read() const override { return m_offset; }
ber_dec.cpp:_ZN5Botan12_GLOBAL__N_125asn1_decode_binary_stringINSt3__19allocatorIhEEEEvRNS2_6vectorIhT_EERKNS_10BER_ObjectENS_9ASN1_TypeESC_NS_10ASN1_ClassERKNS_11BER_Decoder6LimitsE:
  932|  14.0k|                               const BER_Decoder::Limits& limits) {
  933|       |   // DER requires BIT STRING and OCTET STRING to use primitive encoding;
  934|       |   // in BER the constructed (fragmented) form is decoded by concatenation
  935|  14.0k|   if(is_constructed(obj)) {
  ------------------
  |  Branch (935:7): [True: 10, False: 14.0k]
  ------------------
  936|     10|      obj.assert_is_a(type_tag, class_tag | ASN1_Class::Constructed);
  937|       |
  938|     10|      if(limits.require_der_encoding()) {
  ------------------
  |  Branch (938:10): [True: 1, False: 9]
  ------------------
  939|      1|         throw BER_Decoding_Error("Detected constructed string encoding in DER structure");
  940|      1|      }
  941|       |
  942|       |      // Concatenate into a temporary so a failed decode leaves buffer unmodified
  943|      9|      std::vector<uint8_t, Alloc> concat;
  944|      9|      concat.reserve(obj.length());  // upper possible bound on the output size
  945|      9|      if(real_type == ASN1_Type::OctetString) {
  ------------------
  |  Branch (945:10): [True: 0, False: 9]
  ------------------
  946|      0|         asn1_concat_constructed_octet_string(concat, obj, limits, 0);
  947|      9|      } else {
  948|      9|         asn1_concat_constructed_bit_string(concat, obj, limits, 0);
  949|      9|      }
  950|      9|      buffer = std::move(concat);
  951|      9|      return;
  952|     10|   }
  953|       |
  954|  14.0k|   obj.assert_is_a(type_tag, class_tag);
  955|       |
  956|  14.0k|   if(real_type == ASN1_Type::OctetString) {
  ------------------
  |  Branch (956:7): [True: 14.0k, False: 24]
  ------------------
  957|  14.0k|      buffer.assign(obj.bits(), obj.bits() + obj.length());
  958|  14.0k|   } else {
  959|     24|      if(obj.length() == 0) {
  ------------------
  |  Branch (959:10): [True: 0, False: 24]
  ------------------
  960|      0|         throw BER_Decoding_Error("Invalid BIT STRING");
  961|      0|      }
  962|       |
  963|     24|      const uint8_t unused_bits = obj.bits()[0];
  964|       |
  965|     24|      if(unused_bits >= 8) {
  ------------------
  |  Branch (965:10): [True: 0, False: 24]
  ------------------
  966|      0|         throw BER_Decoding_Error("Bad number of unused bits in BIT STRING");
  967|      0|      }
  968|       |
  969|       |      // Empty BIT STRING with unused bits > 0 ...
  970|     24|      if(unused_bits > 0 && obj.length() < 2) {
  ------------------
  |  Branch (970:10): [True: 0, False: 24]
  |  Branch (970:29): [True: 0, False: 0]
  ------------------
  971|      0|         throw BER_Decoding_Error("Invalid BIT STRING");
  972|      0|      }
  973|       |
  974|       |      // DER requires unused bits in BIT STRING to be zero (X.690 section 11.2.2)
  975|     24|      if(limits.require_der_encoding() && unused_bits > 0) {
  ------------------
  |  Branch (975:10): [True: 0, False: 24]
  |  Branch (975:43): [True: 0, False: 0]
  ------------------
  976|      0|         const uint8_t last_byte = obj.bits()[obj.length() - 1];
  977|      0|         if((last_byte & ((1 << unused_bits) - 1)) != 0) {
  ------------------
  |  Branch (977:13): [True: 0, False: 0]
  ------------------
  978|      0|            throw BER_Decoding_Error("Detected non-zero padding bits in BIT STRING in DER structure");
  979|      0|         }
  980|      0|      }
  981|       |
  982|     24|      buffer.resize(obj.length() - 1);
  983|       |
  984|     24|      if(obj.length() > 1) {
  ------------------
  |  Branch (984:10): [True: 0, False: 24]
  ------------------
  985|      0|         copy_mem(buffer.data(), obj.bits() + 1, obj.length() - 1);
  986|      0|      }
  987|     24|   }
  988|  14.0k|}

_ZN5Botan11DER_EncoderC2ERNSt3__16vectorIhNS1_9allocatorIhEEEE:
   89|  3.27k|DER_Encoder::DER_Encoder(std::vector<uint8_t>& vec) {
   90|  3.27k|   m_append_output = [&vec](const uint8_t b[], size_t l) {
   91|  3.27k|      if(l > 0) {
   92|  3.27k|         vec.insert(vec.end(), b, b + l);
   93|  3.27k|      }
   94|  3.27k|   };
   95|  3.27k|}
_ZN5Botan11DER_Encoder12DER_Sequence13push_contentsERS0_:
  100|    191|void DER_Encoder::DER_Sequence::push_contents(DER_Encoder& der) {
  101|    191|   const auto real_class_tag = m_class_tag | ASN1_Class::Constructed;
  102|       |
  103|    191|   if(m_sort_contents) {
  ------------------
  |  Branch (103:7): [True: 0, False: 191]
  ------------------
  104|      0|      std::sort(m_set_contents.begin(), m_set_contents.end());
  105|      0|      for(const auto& set_elem : m_set_contents) {
  ------------------
  |  Branch (105:32): [True: 0, False: 0]
  ------------------
  106|      0|         m_contents += set_elem;
  107|      0|      }
  108|      0|      m_set_contents.clear();
  109|      0|   }
  110|       |
  111|    191|   der.add_object(m_type_tag, real_class_tag, m_contents.data(), m_contents.size());
  112|    191|   m_contents.clear();
  113|    191|}
_ZN5Botan11DER_Encoder12DER_Sequence9add_bytesEPKhmS3_m:
  130|    191|void DER_Encoder::DER_Sequence::add_bytes(const uint8_t hdr[], size_t hdr_len, const uint8_t val[], size_t val_len) {
  131|    191|   if(m_sort_contents) {
  ------------------
  |  Branch (131:7): [True: 0, False: 191]
  ------------------
  132|      0|      secure_vector<uint8_t> m;
  133|      0|      m.reserve(hdr_len + val_len);
  134|      0|      m += std::make_pair(hdr, hdr_len);
  135|      0|      m += std::make_pair(val, val_len);
  136|      0|      m_set_contents.push_back(std::move(m));
  137|    191|   } else {
  138|    191|      m_contents += std::make_pair(hdr, hdr_len);
  139|    191|      m_contents += std::make_pair(val, val_len);
  140|    191|   }
  141|    191|}
_ZN5Botan11DER_Encoder12DER_SequenceC2ENS_9ASN1_TypeENS_10ASN1_ClassEb:
  154|    191|      m_type_tag(type_tag),
  155|    191|      m_class_tag(class_tag),
  156|    191|      m_sort_contents(sort_contents || (type_tag == ASN1_Type::Set && class_tag == ASN1_Class::Universal)) {}
  ------------------
  |  Branch (156:23): [True: 0, False: 191]
  |  Branch (156:41): [True: 0, False: 191]
  |  Branch (156:71): [True: 0, False: 0]
  ------------------
_ZN5Botan11DER_Encoder10start_consENS_9ASN1_TypeENS_10ASN1_ClassE:
  192|    191|DER_Encoder& DER_Encoder::start_cons(ASN1_Type type_tag, ASN1_Class class_tag) {
  193|    191|   return start_cons(type_tag, class_tag, false);
  194|    191|}
_ZN5Botan11DER_Encoder10start_consENS_9ASN1_TypeENS_10ASN1_ClassEb:
  200|    191|DER_Encoder& DER_Encoder::start_cons(ASN1_Type type_tag, ASN1_Class class_tag, bool sort_contents) {
  201|    191|   m_subsequences.push_back(DER_Sequence(type_tag, class_tag, sort_contents));
  202|    191|   return (*this);
  203|    191|}
_ZN5Botan11DER_Encoder8end_consEv:
  208|    191|DER_Encoder& DER_Encoder::end_cons() {
  209|    191|   if(m_subsequences.empty()) {
  ------------------
  |  Branch (209:7): [True: 0, False: 191]
  ------------------
  210|      0|      throw Invalid_State("DER_Encoder::end_cons: No such sequence");
  211|      0|   }
  212|       |
  213|    191|   DER_Sequence last_seq = std::move(m_subsequences[m_subsequences.size() - 1]);
  214|    191|   m_subsequences.pop_back();
  215|    191|   last_seq.push_contents(*this);
  216|       |
  217|    191|   return (*this);
  218|    191|}
_ZN5Botan11DER_Encoder10add_objectENS_9ASN1_TypeENS_10ASN1_ClassEPKhm:
  285|  3.46k|DER_Encoder& DER_Encoder::add_object(ASN1_Type type_tag, ASN1_Class class_tag, const uint8_t rep[], size_t length) {
  286|  3.46k|   std::vector<uint8_t> hdr;
  287|  3.46k|   encode_tag(hdr, type_tag, class_tag);
  288|  3.46k|   encode_length(hdr, length);
  289|       |
  290|  3.46k|   if(!m_subsequences.empty()) {
  ------------------
  |  Branch (290:7): [True: 191, False: 3.27k]
  ------------------
  291|    191|      m_subsequences[m_subsequences.size() - 1].add_bytes(hdr.data(), hdr.size(), rep, length);
  292|  3.27k|   } else if(m_append_output) {
  ------------------
  |  Branch (292:14): [True: 3.26k, False: 3]
  ------------------
  293|  3.26k|      m_append_output(hdr.data(), hdr.size());
  294|  3.26k|      m_append_output(rep, length);
  295|  3.26k|   } else {
  296|      3|      m_default_outbuf += hdr;
  297|      3|      m_default_outbuf += std::make_pair(rep, length);
  298|      3|   }
  299|       |
  300|  3.46k|   return (*this);
  301|  3.46k|}
_ZN5Botan4ASN116integer_contentsERKNS_6BigIntE:
  356|  8.96k|std::vector<uint8_t> ASN1::integer_contents(const BigInt& n) {
  357|  8.96k|   if(n == 0) {
  ------------------
  |  Branch (357:7): [True: 250, False: 8.71k]
  ------------------
  358|    250|      return {0x00};
  359|    250|   }
  360|       |
  361|       |   // Serialize magnitude with one extra leading byte
  362|  8.71k|   auto contents = n.serialize(n.bytes() + 1);
  363|       |
  364|  8.71k|   if(n.signum() < 0) {
  ------------------
  |  Branch (364:7): [True: 759, False: 7.95k]
  ------------------
  365|       |      // Two's complement: bitwise NOT then increment
  366|  9.87k|      for(auto& byte : contents) {
  ------------------
  |  Branch (366:22): [True: 9.87k, False: 759]
  ------------------
  367|  9.87k|         byte = ~byte;
  368|  9.87k|      }
  369|  1.02k|      for(size_t i = contents.size(); i > 0; --i) {
  ------------------
  |  Branch (369:39): [True: 1.02k, False: 0]
  ------------------
  370|  1.02k|         if(++contents[i - 1] != 0) {
  ------------------
  |  Branch (370:13): [True: 759, False: 266]
  ------------------
  371|    759|            break;
  372|    759|         }
  373|  1.02k|      }
  374|    759|   }
  375|       |
  376|       |   /*
  377|       |   * DER requires the leading byte be emitted only if it required
  378|       |   */
  379|  8.71k|   BOTAN_ASSERT_NOMSG(contents.size() >= 2);
  ------------------
  |  |   84|  8.71k|   do {                                                                     \
  |  |   85|  8.71k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|  8.71k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 8.71k]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|  8.71k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 8.71k]
  |  |  ------------------
  ------------------
  380|  8.71k|   const bool leading_byte_redundant =
  381|  8.71k|      (contents[0] == 0x00 && (contents[1] & 0x80) == 0) || (contents[0] == 0xFF && (contents[1] & 0x80) != 0);
  ------------------
  |  Branch (381:8): [True: 7.95k, False: 759]
  |  Branch (381:31): [True: 7.68k, False: 272]
  |  Branch (381:62): [True: 759, False: 272]
  |  Branch (381:85): [True: 644, False: 115]
  ------------------
  382|       |
  383|  8.71k|   if(leading_byte_redundant) {
  ------------------
  |  Branch (383:7): [True: 8.32k, False: 387]
  ------------------
  384|  8.32k|      contents.erase(contents.begin());
  385|  8.32k|   }
  386|  8.71k|   return contents;
  387|  8.96k|}
der_enc.cpp:_ZN5Botan12_GLOBAL__N_110encode_tagERNSt3__16vectorIhNS1_9allocatorIhEEEENS_9ASN1_TypeENS_10ASN1_ClassE:
   26|  3.46k|void encode_tag(std::vector<uint8_t>& encoded_tag, ASN1_Type type_tag_e, ASN1_Class class_tag_e) {
   27|  3.46k|   const uint32_t type_tag = static_cast<uint32_t>(type_tag_e);
   28|  3.46k|   const uint32_t class_tag = static_cast<uint32_t>(class_tag_e);
   29|       |
   30|  3.46k|   if((class_tag | 0xE0) != 0xE0) {
  ------------------
  |  Branch (30:7): [True: 3, False: 3.45k]
  ------------------
   31|      3|      throw Encoding_Error(fmt("DER_Encoder: Invalid class tag {}", std::to_string(class_tag)));
   32|      3|   }
   33|       |
   34|  3.45k|   if(type_tag <= 30) {
  ------------------
  |  Branch (34:7): [True: 3.34k, False: 117]
  ------------------
   35|  3.34k|      encoded_tag.push_back(static_cast<uint8_t>(type_tag | class_tag));
   36|  3.34k|   } else {
   37|    117|      size_t blocks = high_bit(static_cast<uint32_t>(type_tag)) + 6;
   38|    117|      blocks = (blocks - (blocks % 7)) / 7;
   39|       |
   40|    117|      BOTAN_ASSERT_NOMSG(blocks > 0);
  ------------------
  |  |   84|    117|   do {                                                                     \
  |  |   85|    117|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|    117|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 117]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|    117|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 117]
  |  |  ------------------
  ------------------
   41|       |
   42|    117|      encoded_tag.push_back(static_cast<uint8_t>(class_tag | 0x1F));
   43|    422|      for(size_t i = 0; i != blocks - 1; ++i) {
  ------------------
  |  Branch (43:25): [True: 305, False: 117]
  ------------------
   44|    305|         encoded_tag.push_back(0x80 | ((type_tag >> 7 * (blocks - i - 1)) & 0x7F));
   45|    305|      }
   46|    117|      encoded_tag.push_back(type_tag & 0x7F);
   47|    117|   }
   48|  3.45k|}
der_enc.cpp:_ZN5Botan12_GLOBAL__N_113encode_lengthERNSt3__16vectorIhNS1_9allocatorIhEEEEm:
   53|  3.45k|void encode_length(std::vector<uint8_t>& encoded_length, size_t length) {
   54|  3.45k|   if(length <= 127) {
  ------------------
  |  Branch (54:7): [True: 3.45k, False: 0]
  ------------------
   55|  3.45k|      encoded_length.push_back(static_cast<uint8_t>(length));
   56|  3.45k|   } else {
   57|      0|      const size_t bytes_needed = significant_bytes(length);
   58|       |
   59|      0|      encoded_length.push_back(static_cast<uint8_t>(0x80 | bytes_needed));
   60|       |
   61|      0|      for(size_t i = sizeof(length) - bytes_needed; i < sizeof(length); ++i) {
  ------------------
  |  Branch (61:53): [True: 0, False: 0]
  ------------------
   62|      0|         encoded_length.push_back(get_byte_var(i, length));
   63|      0|      }
   64|      0|   }
   65|  3.45k|}
der_enc.cpp:_ZZN5Botan11DER_EncoderC1ERNSt3__16vectorIhNS1_9allocatorIhEEEEENK3$_0clEPKhm:
   90|  6.53k|   m_append_output = [&vec](const uint8_t b[], size_t l) {
   91|  6.53k|      if(l > 0) {
  ------------------
  |  Branch (91:10): [True: 6.49k, False: 44]
  ------------------
   92|  6.49k|         vec.insert(vec.end(), b, b + l);
   93|  6.49k|      }
   94|  6.53k|   };

_ZN5Botan7OID_MapC2Ev:
   11|      1|OID_Map::OID_Map() {
   12|      1|   m_str2oid = OID_Map::load_str2oid_map();
   13|      1|   m_oid2str = OID_Map::load_oid2str_map();
   14|      1|}
_ZN5Botan7OID_Map15global_registryEv:
   16|    891|OID_Map& OID_Map::global_registry() {
   17|    891|   static OID_Map g_map;
   18|    891|   return g_map;
   19|    891|}
_ZN5Botan7OID_Map7str2oidENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
   88|    891|OID OID_Map::str2oid(std::string_view str) {
   89|    891|   if(auto oid = lookup_static_oid_name(str)) {
  ------------------
  |  Branch (89:12): [True: 891, False: 0]
  ------------------
   90|    891|      return std::move(*oid);
   91|    891|   }
   92|       |
   93|      0|   const lock_guard_type<mutex_type> lock(m_mutex);
   94|      0|   auto i = m_str2oid.find(std::string(str));
   95|      0|   if(i != m_str2oid.end()) {
  ------------------
  |  Branch (95:7): [True: 0, False: 0]
  ------------------
   96|      0|      return i->second;
   97|      0|   }
   98|       |
   99|      0|   return OID();
  100|      0|}

_ZN5Botan7OID_Map22lookup_static_oid_nameENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
  744|    891|std::optional<OID> OID_Map::lookup_static_oid_name(std::string_view req) {
  745|    891|   const uint32_t hc = hash_oid_name(req);
  746|       |
  747|    891|   switch(hc) {
  748|      0|      case 0x00545:
  ------------------
  |  Branch (748:7): [True: 0, False: 891]
  ------------------
  749|      0|         return if_match(req, "Twofish/GCM", {1, 3, 6, 1, 4, 1, 25258, 3, 102});
  750|      0|      case 0x00CF3:
  ------------------
  |  Branch (750:7): [True: 0, False: 891]
  ------------------
  751|      0|         return if_match(req, "SphincsPlus-sha2-192f-r3.1", {1, 3, 6, 1, 4, 1, 25258, 1, 12, 2, 4});
  752|      0|      case 0x015FE:
  ------------------
  |  Branch (752:7): [True: 0, False: 891]
  ------------------
  753|      0|         return if_match(req, "FrodoKEM-640-SHAKE", {1, 3, 6, 1, 4, 1, 25258, 1, 14, 1});
  754|      0|      case 0x01F9E:
  ------------------
  |  Branch (754:7): [True: 0, False: 891]
  ------------------
  755|      0|         return if_match(req, "MD5", {1, 2, 840, 113549, 2, 5});
  756|      0|      case 0x02293:
  ------------------
  |  Branch (756:7): [True: 0, False: 891]
  ------------------
  757|      0|         return if_match(req, "SphincsPlus-shake-192f-r3.1", {1, 3, 6, 1, 4, 1, 25258, 1, 12, 1, 4});
  758|      0|      case 0x02B93:
  ------------------
  |  Branch (758:7): [True: 0, False: 891]
  ------------------
  759|      0|         return if_match(req, "Microsoft SmartcardLogon", {1, 3, 6, 1, 4, 1, 311, 20, 2, 2});
  760|      0|      case 0x041D5:
  ------------------
  |  Branch (760:7): [True: 0, False: 891]
  ------------------
  761|      0|         return if_match(req, "secp160k1", {1, 3, 132, 0, 9});
  762|      0|      case 0x044B3:
  ------------------
  |  Branch (762:7): [True: 0, False: 891]
  ------------------
  763|      0|         return if_match(req, "Camellia-256/SIV", {1, 3, 6, 1, 4, 1, 25258, 3, 4, 8});
  764|      0|      case 0x048B2:
  ------------------
  |  Branch (764:7): [True: 0, False: 891]
  ------------------
  765|      0|         return if_match(req, "secp160r1", {1, 3, 132, 0, 8});
  766|      0|      case 0x048B3:
  ------------------
  |  Branch (766:7): [True: 0, False: 891]
  ------------------
  767|      0|         return if_match(req, "secp160r2", {1, 3, 132, 0, 30});
  768|      0|      case 0x05CDA:
  ------------------
  |  Branch (768:7): [True: 0, False: 891]
  ------------------
  769|      0|         return if_match(req, "X520.Country", {2, 5, 4, 6});
  770|      0|      case 0x07783:
  ------------------
  |  Branch (770:7): [True: 0, False: 891]
  ------------------
  771|      0|         return if_match(req, "PKIX.ServerAuth", {1, 3, 6, 1, 5, 5, 7, 3, 1});
  772|      0|      case 0x086C7:
  ------------------
  |  Branch (772:7): [True: 0, False: 891]
  ------------------
  773|      0|         return if_match(req, "numsp384d1", {1, 3, 6, 1, 4, 1, 25258, 4, 2});
  774|      0|      case 0x08A92:
  ------------------
  |  Branch (774:7): [True: 0, False: 891]
  ------------------
  775|      0|         return if_match(req, "RSA/PKCS1v15(SHA-1)", {1, 2, 840, 113549, 1, 1, 5});
  776|      0|      case 0x09EA0:
  ------------------
  |  Branch (776:7): [True: 0, False: 891]
  ------------------
  777|      0|         return if_match(req, "DES/CBC", {1, 3, 14, 3, 2, 7});
  778|      0|      case 0x0B2D6:
  ------------------
  |  Branch (778:7): [True: 0, False: 891]
  ------------------
  779|      0|         return if_match(req, "ECDSA/SHA-3(512)", {2, 16, 840, 1, 101, 3, 4, 3, 12});
  780|      0|      case 0x0BA72:
  ------------------
  |  Branch (780:7): [True: 0, False: 891]
  ------------------
  781|      0|         return if_match(req, "SphincsPlus-sha2-128s-r3.1", {1, 3, 6, 1, 4, 1, 25258, 1, 12, 2, 1});
  782|      0|      case 0x0BE23:
  ------------------
  |  Branch (782:7): [True: 0, False: 891]
  ------------------
  783|      0|         return if_match(req, "ECGDSA", {1, 3, 36, 3, 3, 2, 5, 2, 1});
  784|      0|      case 0x0C109:
  ------------------
  |  Branch (784:7): [True: 0, False: 891]
  ------------------
  785|      0|         return if_match(req, "PKCS9.FriendlyName", {1, 2, 840, 113549, 1, 9, 20});
  786|      0|      case 0x0D012:
  ------------------
  |  Branch (786:7): [True: 0, False: 891]
  ------------------
  787|      0|         return if_match(req, "SphincsPlus-shake-128s-r3.1", {1, 3, 6, 1, 4, 1, 25258, 1, 12, 1, 1});
  788|      0|      case 0x0DCE9:
  ------------------
  |  Branch (788:7): [True: 0, False: 891]
  ------------------
  789|      0|         return if_match(req, "ClassicMcEliece_8192128f", {1, 3, 6, 1, 4, 1, 22554, 5, 1, 10});
  790|      0|      case 0x0E52A:
  ------------------
  |  Branch (790:7): [True: 0, False: 891]
  ------------------
  791|      0|         return if_match(req, "numsp512d1", {1, 3, 6, 1, 4, 1, 25258, 4, 3});
  792|      0|      case 0x0F9CC:
  ------------------
  |  Branch (792:7): [True: 0, False: 891]
  ------------------
  793|      0|         return if_match(req, "PKCS9.UnstructuredName", {1, 2, 840, 113549, 1, 9, 2});
  794|      0|      case 0x0FF45:
  ------------------
  |  Branch (794:7): [True: 0, False: 891]
  ------------------
  795|      0|         return if_match(req, "Camellia-256/GCM", {0, 3, 4401, 5, 3, 1, 9, 46});
  796|      0|      case 0x1033D:
  ------------------
  |  Branch (796:7): [True: 0, False: 891]
  ------------------
  797|      0|         return if_match(req, "DSA/SHA-3(384)", {2, 16, 840, 1, 101, 3, 4, 3, 7});
  798|      0|      case 0x1139D:
  ------------------
  |  Branch (798:7): [True: 0, False: 891]
  ------------------
  799|      0|         return if_match(req, "secp192k1", {1, 3, 132, 0, 31});
  800|      0|      case 0x113D6:
  ------------------
  |  Branch (800:7): [True: 0, False: 891]
  ------------------
  801|      0|         return if_match(req, "X520.DNQualifier", {2, 5, 4, 46});
  802|      0|      case 0x11A7A:
  ------------------
  |  Branch (802:7): [True: 0, False: 891]
  ------------------
  803|      0|         return if_match(req, "secp192r1", {1, 2, 840, 10045, 3, 1, 1});
  804|      0|      case 0x12096:
  ------------------
  |  Branch (804:7): [True: 0, False: 891]
  ------------------
  805|      0|         return if_match(req, "SM2_Kex", {1, 2, 156, 10197, 1, 301, 2});
  806|      0|      case 0x13FC1:
  ------------------
  |  Branch (806:7): [True: 0, False: 891]
  ------------------
  807|      0|         return if_match(req, "X520.GenerationalQualifier", {2, 5, 4, 44});
  808|      0|      case 0x1445B:
  ------------------
  |  Branch (808:7): [True: 0, False: 891]
  ------------------
  809|      0|         return if_match(req, "PKCS5.PBKDF2", {1, 2, 840, 113549, 1, 5, 12});
  810|      0|      case 0x1495D:
  ------------------
  |  Branch (810:7): [True: 0, False: 891]
  ------------------
  811|      0|         return if_match(req, "eFrodoKEM-1344-AES", {1, 3, 6, 1, 4, 1, 25258, 1, 17, 3});
  812|      0|      case 0x14E30:
  ------------------
  |  Branch (812:7): [True: 0, False: 891]
  ------------------
  813|      0|         return if_match(req, "ClassicMcEliece_460896", {1, 3, 6, 1, 4, 1, 22554, 5, 1, 3});
  814|      0|      case 0x14FB1:
  ------------------
  |  Branch (814:7): [True: 0, False: 891]
  ------------------
  815|      0|         return if_match(req, "XMSS-draft12", {1, 3, 6, 1, 4, 1, 25258, 1, 8});
  816|      0|      case 0x156E3:
  ------------------
  |  Branch (816:7): [True: 0, False: 891]
  ------------------
  817|      0|         return if_match(req, "Compression.Zlib", {1, 2, 840, 113549, 1, 9, 16, 3, 8});
  818|      0|      case 0x1579E:
  ------------------
  |  Branch (818:7): [True: 0, False: 891]
  ------------------
  819|      0|         return if_match(req, "Streebog-512", {1, 2, 643, 7, 1, 1, 2, 3});
  820|      0|      case 0x1701A:
  ------------------
  |  Branch (820:7): [True: 0, False: 891]
  ------------------
  821|      0|         return if_match(req, "X509v3.AnyExtendedKeyUsage", {2, 5, 29, 37, 0});
  822|      0|      case 0x175EF:
  ------------------
  |  Branch (822:7): [True: 0, False: 891]
  ------------------
  823|      0|         return if_match(req, "Kyber-1024-90s-r3", {1, 3, 6, 1, 4, 1, 25258, 1, 11, 3});
  824|      0|      case 0x17709:
  ------------------
  |  Branch (824:7): [True: 0, False: 891]
  ------------------
  825|      0|         return if_match(req, "X520.GivenName", {2, 5, 4, 42});
  826|      0|      case 0x17AD9:
  ------------------
  |  Branch (826:7): [True: 0, False: 891]
  ------------------
  827|      0|         return if_match(req, "RSA/PKCS1v15(SM3)", {1, 2, 156, 10197, 1, 504});
  828|      0|      case 0x17CE2:
  ------------------
  |  Branch (828:7): [True: 0, False: 891]
  ------------------
  829|      0|         return if_match(req, "SLH-DSA-SHA2-256f", {2, 16, 840, 1, 101, 3, 4, 3, 25});
  830|      0|      case 0x17CEF:
  ------------------
  |  Branch (830:7): [True: 0, False: 891]
  ------------------
  831|      0|         return if_match(req, "SLH-DSA-SHA2-256s", {2, 16, 840, 1, 101, 3, 4, 3, 24});
  832|      0|      case 0x18618:
  ------------------
  |  Branch (832:7): [True: 0, False: 891]
  ------------------
  833|      0|         return if_match(req, "FrodoKEM-976-AES", {1, 3, 6, 1, 4, 1, 25258, 1, 15, 2});
  834|      0|      case 0x19480:
  ------------------
  |  Branch (834:7): [True: 0, False: 891]
  ------------------
  835|      0|         return if_match(req, "eFrodoKEM-1344-SHAKE", {1, 3, 6, 1, 4, 1, 25258, 1, 16, 3});
  836|      0|      case 0x1958A:
  ------------------
  |  Branch (836:7): [True: 0, False: 891]
  ------------------
  837|      0|         return if_match(req, "X509v3.InvalidityDate", {2, 5, 29, 24});
  838|      0|      case 0x19851:
  ------------------
  |  Branch (838:7): [True: 0, False: 891]
  ------------------
  839|      0|         return if_match(req, "DSA/SHA-1", {1, 2, 840, 10040, 4, 3});
  840|      0|      case 0x1B2E7:
  ------------------
  |  Branch (840:7): [True: 0, False: 891]
  ------------------
  841|      0|         return if_match(req, "KeyWrap.AES-128", {2, 16, 840, 1, 101, 3, 4, 1, 5});
  842|      0|      case 0x1B9BE:
  ------------------
  |  Branch (842:7): [True: 0, False: 891]
  ------------------
  843|      0|         return if_match(req, "KeyWrap.AES-192", {2, 16, 840, 1, 101, 3, 4, 1, 25});
  844|      0|      case 0x1D439:
  ------------------
  |  Branch (844:7): [True: 0, False: 891]
  ------------------
  845|      0|         return if_match(req, "SphincsPlus-haraka-192f-r3.1", {1, 3, 6, 1, 4, 1, 25258, 1, 12, 3, 4});
  846|      0|      case 0x2065B:
  ------------------
  |  Branch (846:7): [True: 0, False: 891]
  ------------------
  847|      0|         return if_match(req, "KeyWrap.CAST-128", {1, 2, 840, 113533, 7, 66, 15});
  848|      0|      case 0x216A0:
  ------------------
  |  Branch (848:7): [True: 0, False: 891]
  ------------------
  849|      0|         return if_match(req, "ML-KEM-512", {2, 16, 840, 1, 101, 3, 4, 4, 1});
  850|      0|      case 0x2216B:
  ------------------
  |  Branch (850:7): [True: 0, False: 891]
  ------------------
  851|      0|         return if_match(req, "GOST-34.10-2012-512", {1, 2, 643, 7, 1, 1, 1, 2});
  852|      0|      case 0x22C2C:
  ------------------
  |  Branch (852:7): [True: 0, False: 891]
  ------------------
  853|      0|         return if_match(req, "ElGamal", {1, 3, 6, 1, 4, 1, 3029, 1, 2, 1});
  854|      0|      case 0x2559A:
  ------------------
  |  Branch (854:7): [True: 0, False: 891]
  ------------------
  855|      0|         return if_match(req, "X520.Initials", {2, 5, 4, 43});
  856|      0|      case 0x271AC:
  ------------------
  |  Branch (856:7): [True: 0, False: 891]
  ------------------
  857|      0|         return if_match(req, "PKIX.AutonomousSysIds", {1, 3, 6, 1, 5, 5, 7, 1, 8});
  858|      0|      case 0x2808B:
  ------------------
  |  Branch (858:7): [True: 0, False: 891]
  ------------------
  859|      0|         return if_match(req, "PKCS7.Data", {1, 2, 840, 113549, 1, 7, 1});
  860|      0|      case 0x281B8:
  ------------------
  |  Branch (860:7): [True: 0, False: 891]
  ------------------
  861|      0|         return if_match(req, "SphincsPlus-haraka-128s-r3.1", {1, 3, 6, 1, 4, 1, 25258, 1, 12, 3, 1});
  862|      0|      case 0x282FE:
  ------------------
  |  Branch (862:7): [True: 0, False: 891]
  ------------------
  863|      0|         return if_match(req, "PKIX.OCSP.Nonce", {1, 3, 6, 1, 5, 5, 7, 48, 1, 2});
  864|      0|      case 0x29999:
  ------------------
  |  Branch (864:7): [True: 0, False: 891]
  ------------------
  865|      0|         return if_match(req, "DSA/SHA-3(256)", {2, 16, 840, 1, 101, 3, 4, 3, 6});
  866|      0|      case 0x2A83D:
  ------------------
  |  Branch (866:7): [True: 0, False: 891]
  ------------------
  867|      0|         return if_match(req, "SHA-224", {2, 16, 840, 1, 101, 3, 4, 2, 4});
  868|      0|      case 0x2AB30:
  ------------------
  |  Branch (868:7): [True: 0, False: 891]
  ------------------
  869|      0|         return if_match(req, "SHA-256", {2, 16, 840, 1, 101, 3, 4, 2, 1});
  870|      0|      case 0x2ABEF:
  ------------------
  |  Branch (870:7): [True: 0, False: 891]
  ------------------
  871|      0|         return if_match(req, "KeyWrap.AES-256", {2, 16, 840, 1, 101, 3, 4, 1, 45});
  872|      0|      case 0x2BAEF:
  ------------------
  |  Branch (872:7): [True: 0, False: 891]
  ------------------
  873|      0|         return if_match(req, "SM2_Sig/SM3", {1, 2, 156, 10197, 1, 501});
  874|      0|      case 0x2C39A:
  ------------------
  |  Branch (874:7): [True: 0, False: 891]
  ------------------
  875|      0|         return if_match(req, "ECGDSA/RIPEMD-160", {1, 3, 36, 3, 3, 2, 5, 4, 1});
  876|      0|      case 0x2C54F:
  ------------------
  |  Branch (876:7): [True: 0, False: 891]
  ------------------
  877|      0|         return if_match(req, "ECDSA/SHA-3(224)", {2, 16, 840, 1, 101, 3, 4, 3, 9});
  878|      0|      case 0x2EEA6:
  ------------------
  |  Branch (878:7): [True: 0, False: 891]
  ------------------
  879|      0|         return if_match(req, "RSA/PKCS1v15(RIPEMD-160)", {1, 3, 36, 3, 3, 1, 2});
  880|      0|      case 0x2EFBA:
  ------------------
  |  Branch (880:7): [True: 0, False: 891]
  ------------------
  881|      0|         return if_match(req, "Kyber-512-r3", {1, 3, 6, 1, 4, 1, 25258, 1, 7, 1});
  882|      0|      case 0x2F0AD:
  ------------------
  |  Branch (882:7): [True: 0, False: 891]
  ------------------
  883|      0|         return if_match(req, "PKCS7.EncryptedData", {1, 2, 840, 113549, 1, 7, 6});
  884|      0|      case 0x2F219:
  ------------------
  |  Branch (884:7): [True: 0, False: 891]
  ------------------
  885|      0|         return if_match(req, "PBE-SHA1-2DES", {1, 2, 840, 113549, 1, 12, 1, 4});
  886|      0|      case 0x3133E:
  ------------------
  |  Branch (886:7): [True: 0, False: 891]
  ------------------
  887|      0|         return if_match(req, "SLH-DSA-SHA2-128f", {2, 16, 840, 1, 101, 3, 4, 3, 21});
  888|      0|      case 0x3134B:
  ------------------
  |  Branch (888:7): [True: 0, False: 891]
  ------------------
  889|      0|         return if_match(req, "SLH-DSA-SHA2-128s", {2, 16, 840, 1, 101, 3, 4, 3, 20});
  890|      0|      case 0x3160D:
  ------------------
  |  Branch (890:7): [True: 0, False: 891]
  ------------------
  891|      0|         return if_match(req, "RSA/PKCS1v15(SHA-3(224))", {2, 16, 840, 1, 101, 3, 4, 3, 13});
  892|      0|      case 0x319E0:
  ------------------
  |  Branch (892:7): [True: 0, False: 891]
  ------------------
  893|      0|         return if_match(req, "GOST-34.10-2012-256/Streebog-256", {1, 2, 643, 7, 1, 1, 3, 2});
  894|      0|      case 0x31B3D:
  ------------------
  |  Branch (894:7): [True: 0, False: 891]
  ------------------
  895|      0|         return if_match(req, "HMAC(SHA-512)", {1, 2, 840, 113549, 2, 11});
  896|      0|      case 0x31C6D:
  ------------------
  |  Branch (896:7): [True: 0, False: 891]
  ------------------
  897|      0|         return if_match(req, "secp384r1", {1, 3, 132, 0, 34});
  898|      0|      case 0x32899:
  ------------------
  |  Branch (898:7): [True: 0, False: 891]
  ------------------
  899|      0|         return if_match(req, "TripleDES/CBC", {1, 2, 840, 113549, 3, 7});
  900|    745|      case 0x33C9C:
  ------------------
  |  Branch (900:7): [True: 745, False: 146]
  ------------------
  901|    745|         return if_match(req, "PKIX.SmtpUTF8Mailbox", {1, 3, 6, 1, 5, 5, 7, 8, 9});
  902|      0|      case 0x33D04:
  ------------------
  |  Branch (902:7): [True: 0, False: 891]
  ------------------
  903|      0|         return if_match(req, "PKCS12.SecretBag", {1, 2, 840, 113549, 1, 12, 10, 1, 5});
  904|      0|      case 0x3615D:
  ------------------
  |  Branch (904:7): [True: 0, False: 891]
  ------------------
  905|      0|         return if_match(req, "FrodoKEM-976-SHAKE", {1, 3, 6, 1, 4, 1, 25258, 1, 14, 2});
  906|      0|      case 0x361B8:
  ------------------
  |  Branch (906:7): [True: 0, False: 891]
  ------------------
  907|      0|         return if_match(req, "Ed25519", {1, 3, 101, 112});
  908|      0|      case 0x3649D:
  ------------------
  |  Branch (908:7): [True: 0, False: 891]
  ------------------
  909|      0|         return if_match(req, "SHAKE-128", {2, 16, 840, 1, 101, 3, 4, 2, 11});
  910|      0|      case 0x36693:
  ------------------
  |  Branch (910:7): [True: 0, False: 891]
  ------------------
  911|      0|         return if_match(req, "ClassicMcEliece_348864", {1, 3, 6, 1, 4, 1, 22554, 5, 1, 1});
  912|      0|      case 0x373C7:
  ------------------
  |  Branch (912:7): [True: 0, False: 891]
  ------------------
  913|      0|         return if_match(req, "ML-DSA-4x4", {2, 16, 840, 1, 101, 3, 4, 3, 17});
  914|      0|      case 0x3750B:
  ------------------
  |  Branch (914:7): [True: 0, False: 891]
  ------------------
  915|      0|         return if_match(req, "ClassicMcEliece_8192128", {1, 3, 6, 1, 4, 1, 22554, 5, 1, 9});
  916|      0|      case 0x39890:
  ------------------
  |  Branch (916:7): [True: 0, False: 891]
  ------------------
  917|      0|         return if_match(req, "Ed448", {1, 3, 101, 113});
  918|      0|      case 0x3A438:
  ------------------
  |  Branch (918:7): [True: 0, False: 891]
  ------------------
  919|      0|         return if_match(req, "SHA-384", {2, 16, 840, 1, 101, 3, 4, 2, 2});
  920|      0|      case 0x3A963:
  ------------------
  |  Branch (920:7): [True: 0, False: 891]
  ------------------
  921|      0|         return if_match(req, "DH", {1, 2, 840, 10046, 2, 1});
  922|      0|      case 0x3AC83:
  ------------------
  |  Branch (922:7): [True: 0, False: 891]
  ------------------
  923|      0|         return if_match(req, "MGF1", {1, 2, 840, 113549, 1, 1, 8});
  924|      0|      case 0x3ACBA:
  ------------------
  |  Branch (924:7): [True: 0, False: 891]
  ------------------
  925|      0|         return if_match(req, "X509v3.IssuerAlternativeName", {2, 5, 29, 18});
  926|      0|      case 0x3B273:
  ------------------
  |  Branch (926:7): [True: 0, False: 891]
  ------------------
  927|      0|         return if_match(req, "KeyWrap.TripleDES", {1, 2, 840, 113549, 1, 9, 16, 3, 6});
  928|      0|      case 0x3B91E:
  ------------------
  |  Branch (928:7): [True: 0, False: 891]
  ------------------
  929|      0|         return if_match(req, "X509v3.PrivateKeyUsagePeriod", {2, 5, 29, 16});
  930|      0|      case 0x3BC8A:
  ------------------
  |  Branch (930:7): [True: 0, False: 891]
  ------------------
  931|      0|         return if_match(req, "SLH-DSA-SHAKE-192f", {2, 16, 840, 1, 101, 3, 4, 3, 29});
  932|      0|      case 0x3BC97:
  ------------------
  |  Branch (932:7): [True: 0, False: 891]
  ------------------
  933|      0|         return if_match(req, "SLH-DSA-SHAKE-192s", {2, 16, 840, 1, 101, 3, 4, 3, 28});
  934|      0|      case 0x3D127:
  ------------------
  |  Branch (934:7): [True: 0, False: 891]
  ------------------
  935|      0|         return if_match(req, "DSA", {1, 2, 840, 10040, 4, 1});
  936|      0|      case 0x3E249:
  ------------------
  |  Branch (936:7): [True: 0, False: 891]
  ------------------
  937|      0|         return if_match(req, "HSS-LMS", {1, 2, 840, 113549, 1, 9, 16, 3, 17});
  938|      0|      case 0x3E7D5:
  ------------------
  |  Branch (938:7): [True: 0, False: 891]
  ------------------
  939|      0|         return if_match(req, "RSA/PKCS1v15(SHA-3(256))", {2, 16, 840, 1, 101, 3, 4, 3, 14});
  940|      0|      case 0x3F748:
  ------------------
  |  Branch (940:7): [True: 0, False: 891]
  ------------------
  941|      0|         return if_match(req, "GOST.OGRN", {1, 2, 643, 100, 1});
  942|      0|      case 0x3F99F:
  ------------------
  |  Branch (942:7): [True: 0, False: 891]
  ------------------
  943|      0|         return if_match(req, "X509v3.BasicConstraints", {2, 5, 29, 19});
  944|      0|      case 0x40726:
  ------------------
  |  Branch (944:7): [True: 0, False: 891]
  ------------------
  945|      0|         return if_match(req, "SHA-3(512)", {2, 16, 840, 1, 101, 3, 4, 2, 10});
  946|      0|      case 0x407BF:
  ------------------
  |  Branch (946:7): [True: 0, False: 891]
  ------------------
  947|      0|         return if_match(req, "ML-KEM-768", {2, 16, 840, 1, 101, 3, 4, 4, 2});
  948|      0|      case 0x41334:
  ------------------
  |  Branch (948:7): [True: 0, False: 891]
  ------------------
  949|      0|         return if_match(req, "ECDSA/SHA-3(384)", {2, 16, 840, 1, 101, 3, 4, 3, 11});
  950|      0|      case 0x42DF3:
  ------------------
  |  Branch (950:7): [True: 0, False: 891]
  ------------------
  951|      0|         return if_match(req, "X509v3.CRLDistributionPoints", {2, 5, 29, 31});
  952|      0|      case 0x437FB:
  ------------------
  |  Branch (952:7): [True: 0, False: 891]
  ------------------
  953|      0|         return if_match(req, "brainpool160r1", {1, 3, 36, 3, 3, 2, 8, 1, 1, 1});
  954|      0|      case 0x441F5:
  ------------------
  |  Branch (954:7): [True: 0, False: 891]
  ------------------
  955|      0|         return if_match(req, "gost_256A", {1, 2, 643, 7, 1, 2, 1, 1, 1});
  956|      0|      case 0x441F6:
  ------------------
  |  Branch (956:7): [True: 0, False: 891]
  ------------------
  957|      0|         return if_match(req, "gost_256B", {1, 2, 643, 7, 1, 2, 1, 1, 2});
  958|      0|      case 0x44221:
  ------------------
  |  Branch (958:7): [True: 0, False: 891]
  ------------------
  959|      0|         return if_match(req, "GOST-34.10-2012-512/Streebog-512", {1, 2, 643, 7, 1, 1, 3, 3});
  960|      0|      case 0x44322:
  ------------------
  |  Branch (960:7): [True: 0, False: 891]
  ------------------
  961|      0|         return if_match(req, "ClassicMcEliece_6960119pc", {1, 3, 6, 1, 4, 1, 25258, 1, 18, 3});
  962|      0|      case 0x44973:
  ------------------
  |  Branch (962:7): [True: 0, False: 891]
  ------------------
  963|      0|         return if_match(req, "Kyber-512-90s-r3", {1, 3, 6, 1, 4, 1, 25258, 1, 11, 1});
  964|      0|      case 0x45C27:
  ------------------
  |  Branch (964:7): [True: 0, False: 891]
  ------------------
  965|      0|         return if_match(req, "RSA/PKCS1v15(SHA-512-256)", {1, 2, 840, 113549, 1, 1, 16});
  966|      0|      case 0x45C85:
  ------------------
  |  Branch (966:7): [True: 0, False: 891]
  ------------------
  967|      0|         return if_match(req, "X509v3.ReasonCode", {2, 5, 29, 21});
  968|      0|      case 0x45DA5:
  ------------------
  |  Branch (968:7): [True: 0, False: 891]
  ------------------
  969|      0|         return if_match(req, "SHAKE-256", {2, 16, 840, 1, 101, 3, 4, 2, 12});
  970|      0|      case 0x4663C:
  ------------------
  |  Branch (970:7): [True: 0, False: 891]
  ------------------
  971|      0|         return if_match(req, "X509v3.PolicyConstraints", {2, 5, 29, 36});
  972|      0|      case 0x480F7:
  ------------------
  |  Branch (972:7): [True: 0, False: 891]
  ------------------
  973|      0|         return if_match(req, "Serpent/OCB", {1, 3, 6, 1, 4, 1, 25258, 3, 2, 4});
  974|      0|      case 0x48627:
  ------------------
  |  Branch (974:7): [True: 0, False: 891]
  ------------------
  975|      0|         return if_match(req, "Dilithium-4x4-AES-r3", {1, 3, 6, 1, 4, 1, 25258, 1, 10, 1});
  976|      0|      case 0x48861:
  ------------------
  |  Branch (976:7): [True: 0, False: 891]
  ------------------
  977|      0|         return if_match(req, "ChaCha20Poly1305", {1, 2, 840, 113549, 1, 9, 16, 3, 18});
  978|      0|      case 0x4A292:
  ------------------
  |  Branch (978:7): [True: 0, False: 891]
  ------------------
  979|      0|         return if_match(req, "frp256v1", {1, 2, 250, 1, 223, 101, 256, 1});
  980|      0|      case 0x4A9EE:
  ------------------
  |  Branch (980:7): [True: 0, False: 891]
  ------------------
  981|      0|         return if_match(req, "ClassicMcEliece_6960119f", {1, 3, 6, 1, 4, 1, 22554, 5, 1, 8});
  982|      0|      case 0x4BF87:
  ------------------
  |  Branch (982:7): [True: 0, False: 891]
  ------------------
  983|      0|         return if_match(req, "PKIX.TNAuthList", {1, 3, 6, 1, 5, 5, 7, 1, 26});
  984|      0|      case 0x4C088:
  ------------------
  |  Branch (984:7): [True: 0, False: 891]
  ------------------
  985|      0|         return if_match(req, "eFrodoKEM-976-AES", {1, 3, 6, 1, 4, 1, 25258, 1, 17, 2});
  986|      0|      case 0x4C513:
  ------------------
  |  Branch (986:7): [True: 0, False: 891]
  ------------------
  987|      0|         return if_match(req, "DSA/SHA-224", {2, 16, 840, 1, 101, 3, 4, 3, 1});
  988|      0|      case 0x4C806:
  ------------------
  |  Branch (988:7): [True: 0, False: 891]
  ------------------
  989|      0|         return if_match(req, "DSA/SHA-256", {2, 16, 840, 1, 101, 3, 4, 3, 2});
  990|      0|      case 0x4D740:
  ------------------
  |  Branch (990:7): [True: 0, False: 891]
  ------------------
  991|      0|         return if_match(req, "X509v3.AnyPolicy", {2, 5, 29, 32, 0});
  992|      0|      case 0x4DE49:
  ------------------
  |  Branch (992:7): [True: 0, False: 891]
  ------------------
  993|      0|         return if_match(req, "RSA/PKCS1v15(SHA-512)", {1, 2, 840, 113549, 1, 1, 13});
  994|      0|      case 0x4ED5D:
  ------------------
  |  Branch (994:7): [True: 0, False: 891]
  ------------------
  995|      0|         return if_match(req, "CAST-128/CBC", {1, 2, 840, 113533, 7, 66, 10});
  996|      0|      case 0x4FCDC:
  ------------------
  |  Branch (996:7): [True: 0, False: 891]
  ------------------
  997|      0|         return if_match(req, "RSA", {1, 2, 840, 113549, 1, 1, 1});
  998|      0|      case 0x501CB:
  ------------------
  |  Branch (998:7): [True: 0, False: 891]
  ------------------
  999|      0|         return if_match(req, "ECDSA/SHA-224", {1, 2, 840, 10045, 4, 3, 1});
 1000|      0|      case 0x50395:
  ------------------
  |  Branch (1000:7): [True: 0, False: 891]
  ------------------
 1001|      0|         return if_match(req, "GOST-34.10/GOST-R-34.11-94", {1, 2, 643, 2, 2, 3});
 1002|      0|      case 0x504BE:
  ------------------
  |  Branch (1002:7): [True: 0, False: 891]
  ------------------
 1003|      0|         return if_match(req, "ECDSA/SHA-256", {1, 2, 840, 10045, 4, 3, 2});
 1004|      0|      case 0x509C3:
  ------------------
  |  Branch (1004:7): [True: 0, False: 891]
  ------------------
 1005|      0|         return if_match(req, "brainpool192r1", {1, 3, 36, 3, 3, 2, 8, 1, 1, 3});
 1006|      0|      case 0x509F9:
  ------------------
  |  Branch (1006:7): [True: 0, False: 891]
  ------------------
 1007|      0|         return if_match(req, "PKCS9.ContentType", {1, 2, 840, 113549, 1, 9, 3});
 1008|      0|      case 0x50B26:
  ------------------
  |  Branch (1008:7): [True: 0, False: 891]
  ------------------
 1009|      0|         return if_match(req, "FrodoKEM-640-AES", {1, 3, 6, 1, 4, 1, 25258, 1, 15, 1});
 1010|      0|      case 0x50D78:
  ------------------
  |  Branch (1010:7): [True: 0, False: 891]
  ------------------
 1011|      0|         return if_match(req, "x962_p192v2", {1, 2, 840, 10045, 3, 1, 2});
 1012|      0|      case 0x50D79:
  ------------------
  |  Branch (1012:7): [True: 0, False: 891]
  ------------------
 1013|      0|         return if_match(req, "x962_p192v3", {1, 2, 840, 10045, 3, 1, 3});
 1014|      0|      case 0x51DC6:
  ------------------
  |  Branch (1014:7): [True: 0, False: 891]
  ------------------
 1015|      0|         return if_match(req, "AES-128/OCB", {1, 3, 6, 1, 4, 1, 25258, 3, 2, 1});
 1016|      0|      case 0x52DB6:
  ------------------
  |  Branch (1016:7): [True: 0, False: 891]
  ------------------
 1017|      0|         return if_match(req, "HMAC(SHA-224)", {1, 2, 840, 113549, 2, 8});
 1018|      0|      case 0x53E11:
  ------------------
  |  Branch (1018:7): [True: 0, False: 891]
  ------------------
 1019|      0|         return if_match(req, "FrodoKEM-1344-SHAKE", {1, 3, 6, 1, 4, 1, 25258, 1, 14, 3});
 1020|      0|      case 0x54012:
  ------------------
  |  Branch (1020:7): [True: 0, False: 891]
  ------------------
 1021|      0|         return if_match(req, "PKIX.TimeStamping", {1, 3, 6, 1, 5, 5, 7, 3, 8});
 1022|      0|      case 0x5407A:
  ------------------
  |  Branch (1022:7): [True: 0, False: 891]
  ------------------
 1023|      0|         return if_match(req, "Serpent/CBC", {1, 3, 6, 1, 4, 1, 25258, 3, 1});
 1024|      0|      case 0x5576D:
  ------------------
  |  Branch (1024:7): [True: 0, False: 891]
  ------------------
 1025|      0|         return if_match(req, "SphincsPlus-sha2-128f-r3.1", {1, 3, 6, 1, 4, 1, 25258, 1, 12, 2, 2});
 1026|      0|      case 0x55EF6:
  ------------------
  |  Branch (1026:7): [True: 0, False: 891]
  ------------------
 1027|      0|         return if_match(req, "AES-192/OCB", {1, 3, 6, 1, 4, 1, 25258, 3, 2, 2});
 1028|      0|      case 0x55FFA:
  ------------------
  |  Branch (1028:7): [True: 0, False: 891]
  ------------------
 1029|      0|         return if_match(req, "ML-DSA-6x5", {2, 16, 840, 1, 101, 3, 4, 3, 18});
 1030|      0|      case 0x56826:
  ------------------
  |  Branch (1030:7): [True: 0, False: 891]
  ------------------
 1031|      0|         return if_match(req, "brainpool320r1", {1, 3, 36, 3, 3, 2, 8, 1, 1, 9});
 1032|      0|      case 0x56D0D:
  ------------------
  |  Branch (1032:7): [True: 0, False: 891]
  ------------------
 1033|      0|         return if_match(req, "SphincsPlus-shake-128f-r3.1", {1, 3, 6, 1, 4, 1, 25258, 1, 12, 1, 2});
 1034|      0|      case 0x57077:
  ------------------
  |  Branch (1034:7): [True: 0, False: 891]
  ------------------
 1035|      0|         return if_match(req, "XMSS-draft6", {1, 3, 6, 1, 4, 1, 25258, 1, 5});
 1036|      0|      case 0x5818B:
  ------------------
  |  Branch (1036:7): [True: 0, False: 891]
  ------------------
 1037|      0|         return if_match(req, "ECGDSA/SHA-224", {1, 3, 36, 3, 3, 2, 5, 4, 3});
 1038|      0|      case 0x5847E:
  ------------------
  |  Branch (1038:7): [True: 0, False: 891]
  ------------------
 1039|      0|         return if_match(req, "ECGDSA/SHA-256", {1, 3, 36, 3, 3, 2, 5, 4, 4});
 1040|      0|      case 0x5898B:
  ------------------
  |  Branch (1040:7): [True: 0, False: 891]
  ------------------
 1041|      0|         return if_match(req, "SHA-512", {2, 16, 840, 1, 101, 3, 4, 2, 3});
 1042|      0|      case 0x58991:
  ------------------
  |  Branch (1042:7): [True: 0, False: 891]
  ------------------
 1043|      0|         return if_match(req, "PKIX.OCSP.NoCheck", {1, 3, 6, 1, 5, 5, 7, 48, 1, 5});
 1044|      0|      case 0x59717:
  ------------------
  |  Branch (1044:7): [True: 0, False: 891]
  ------------------
 1045|      0|         return if_match(req, "X509v3.SubjectKeyIdentifier", {2, 5, 29, 14});
 1046|      0|      case 0x5A1E1:
  ------------------
  |  Branch (1046:7): [True: 0, False: 891]
  ------------------
 1047|      0|         return if_match(req, "PKCS12.KeyBag", {1, 2, 840, 113549, 1, 12, 10, 1, 1});
 1048|      0|      case 0x5A570:
  ------------------
  |  Branch (1048:7): [True: 0, False: 891]
  ------------------
 1049|      0|         return if_match(req, "X520.CommonName", {2, 5, 4, 3});
 1050|      0|      case 0x5A990:
  ------------------
  |  Branch (1050:7): [True: 0, False: 891]
  ------------------
 1051|      0|         return if_match(req, "ECDSA/SHA-3(256)", {2, 16, 840, 1, 101, 3, 4, 3, 10});
 1052|      0|      case 0x5AB0E:
  ------------------
  |  Branch (1052:7): [True: 0, False: 891]
  ------------------
 1053|      0|         return if_match(req, "SphincsPlus-sha2-256s-r3.1", {1, 3, 6, 1, 4, 1, 25258, 1, 12, 2, 5});
 1054|      0|      case 0x5AC4A:
  ------------------
  |  Branch (1054:7): [True: 0, False: 891]
  ------------------
 1055|      0|         return if_match(req, "X520.Surname", {2, 5, 4, 4});
 1056|      0|      case 0x5AF2C:
  ------------------
  |  Branch (1056:7): [True: 0, False: 891]
  ------------------
 1057|      0|         return if_match(req, "ClassicMcEliece_8192128pc", {1, 3, 6, 1, 4, 1, 25258, 1, 18, 5});
 1058|      0|      case 0x5BC39:
  ------------------
  |  Branch (1058:7): [True: 0, False: 891]
  ------------------
 1059|      0|         return if_match(req, "X509v3.KeyUsage", {2, 5, 29, 15});
 1060|      0|      case 0x5BDDB:
  ------------------
  |  Branch (1060:7): [True: 0, False: 891]
  ------------------
 1061|      0|         return if_match(req, "numsp256d1", {1, 3, 6, 1, 4, 1, 25258, 4, 1});
 1062|      0|      case 0x5C0AE:
  ------------------
  |  Branch (1062:7): [True: 0, False: 891]
  ------------------
 1063|      0|         return if_match(req, "SphincsPlus-shake-256s-r3.1", {1, 3, 6, 1, 4, 1, 25258, 1, 12, 1, 5});
 1064|      0|      case 0x5C10E:
  ------------------
  |  Branch (1064:7): [True: 0, False: 891]
  ------------------
 1065|      0|         return if_match(req, "DSA/SHA-384", {2, 16, 840, 1, 101, 3, 4, 3, 3});
 1066|      0|      case 0x5CFE5:
  ------------------
  |  Branch (1066:7): [True: 0, False: 891]
  ------------------
 1067|      0|         return if_match(req, "PKCS9.X509Certificate", {1, 2, 840, 113549, 1, 9, 22, 1});
 1068|      0|      case 0x5D1CF:
  ------------------
  |  Branch (1068:7): [True: 0, False: 891]
  ------------------
 1069|      0|         return if_match(req, "X520.SerialNumber", {2, 5, 4, 5});
 1070|      0|      case 0x5D375:
  ------------------
  |  Branch (1070:7): [True: 0, False: 891]
  ------------------
 1071|      0|         return if_match(req, "SM4/OCB", {1, 2, 156, 10197, 1, 104, 100});
 1072|      0|      case 0x5DD49:
  ------------------
  |  Branch (1072:7): [True: 0, False: 891]
  ------------------
 1073|      0|         return if_match(req, "AES-128/CBC", {2, 16, 840, 1, 101, 3, 4, 1, 2});
 1074|      0|      case 0x5DE4E:
  ------------------
  |  Branch (1074:7): [True: 0, False: 891]
  ------------------
 1075|      0|         return if_match(req, "AES-128/CCM", {2, 16, 840, 1, 101, 3, 4, 1, 7});
 1076|      0|      case 0x5DF23:
  ------------------
  |  Branch (1076:7): [True: 0, False: 891]
  ------------------
 1077|      0|         return if_match(req, "HMAC(SHA-512-256)", {1, 2, 840, 113549, 2, 13});
 1078|      0|      case 0x5ED04:
  ------------------
  |  Branch (1078:7): [True: 0, False: 891]
  ------------------
 1079|      0|         return if_match(req, "SM2", {1, 2, 156, 10197, 1, 301, 1});
 1080|      0|      case 0x5ED05:
  ------------------
  |  Branch (1080:7): [True: 0, False: 891]
  ------------------
 1081|      0|         return if_match(req, "SM3", {1, 2, 156, 10197, 1, 401});
 1082|      0|      case 0x5FDC6:
  ------------------
  |  Branch (1082:7): [True: 0, False: 891]
  ------------------
 1083|      0|         return if_match(req, "ECDSA/SHA-384", {1, 2, 840, 10045, 4, 3, 3});
 1084|      0|      case 0x6199F:
  ------------------
  |  Branch (1084:7): [True: 0, False: 891]
  ------------------
 1085|      0|         return if_match(req, "SHA-3(224)", {2, 16, 840, 1, 101, 3, 4, 2, 7});
 1086|      0|      case 0x61E79:
  ------------------
  |  Branch (1086:7): [True: 0, False: 891]
  ------------------
 1087|      0|         return if_match(req, "AES-192/CBC", {2, 16, 840, 1, 101, 3, 4, 1, 22});
 1088|      0|      case 0x61F7E:
  ------------------
  |  Branch (1088:7): [True: 0, False: 891]
  ------------------
 1089|      0|         return if_match(req, "AES-192/CCM", {2, 16, 840, 1, 101, 3, 4, 1, 27});
 1090|      0|      case 0x64947:
  ------------------
  |  Branch (1090:7): [True: 0, False: 891]
  ------------------
 1091|      0|         return if_match(req, "OpenPGP.Ed25519", {1, 3, 6, 1, 4, 1, 11591, 15, 1});
 1092|      0|      case 0x652E7:
  ------------------
  |  Branch (1092:7): [True: 0, False: 891]
  ------------------
 1093|      0|         return if_match(req, "sm2p256v1", {1, 2, 156, 10197, 1, 301});
 1094|      0|      case 0x6697B:
  ------------------
  |  Branch (1094:7): [True: 0, False: 891]
  ------------------
 1095|      0|         return if_match(req, "FrodoKEM-1344-AES", {1, 3, 6, 1, 4, 1, 25258, 1, 15, 3});
 1096|      0|      case 0x67B2C:
  ------------------
  |  Branch (1096:7): [True: 0, False: 891]
  ------------------
 1097|      0|         return if_match(req, "X520.State", {2, 5, 4, 8});
 1098|      0|      case 0x67B9B:
  ------------------
  |  Branch (1098:7): [True: 0, False: 891]
  ------------------
 1099|      0|         return if_match(req, "HMAC(SHA-384)", {1, 2, 840, 113549, 2, 10});
 1100|      0|      case 0x67D86:
  ------------------
  |  Branch (1100:7): [True: 0, False: 891]
  ------------------
 1101|      0|         return if_match(req, "ECGDSA/SHA-384", {1, 3, 36, 3, 3, 2, 5, 4, 5});
 1102|      0|      case 0x68A0B:
  ------------------
  |  Branch (1102:7): [True: 0, False: 891]
  ------------------
 1103|      0|         return if_match(req, "Camellia-128/OCB", {1, 3, 6, 1, 4, 1, 25258, 3, 2, 6});
 1104|      0|      case 0x68E33:
  ------------------
  |  Branch (1104:7): [True: 0, False: 891]
  ------------------
 1105|      0|         return if_match(req, "PKCS9.ExtensionRequest", {1, 2, 840, 113549, 1, 9, 14});
 1106|      0|      case 0x69126:
  ------------------
  |  Branch (1106:7): [True: 0, False: 891]
  ------------------
 1107|      0|         return if_match(req, "X509v3.SubjectAlternativeName", {2, 5, 29, 17});
 1108|      0|      case 0x692F8:
  ------------------
  |  Branch (1108:7): [True: 0, False: 891]
  ------------------
 1109|      0|         return if_match(req, "SM4/CBC", {1, 2, 156, 10197, 1, 104, 2});
 1110|      0|      case 0x695E1:
  ------------------
  |  Branch (1110:7): [True: 0, False: 891]
  ------------------
 1111|      0|         return if_match(req, "Dilithium-4x4-r3", {1, 3, 6, 1, 4, 1, 25258, 1, 9, 1});
 1112|      0|      case 0x696DC:
  ------------------
  |  Branch (1112:7): [True: 0, False: 891]
  ------------------
 1113|      0|         return if_match(req, "PKIX.IpAddrBlocks", {1, 3, 6, 1, 5, 5, 7, 1, 7});
 1114|      0|      case 0x6A7CA:
  ------------------
  |  Branch (1114:7): [True: 0, False: 891]
  ------------------
 1115|      0|         return if_match(req, "ECDSA", {1, 2, 840, 10045, 2, 1});
 1116|      0|      case 0x6BD26:
  ------------------
  |  Branch (1116:7): [True: 0, False: 891]
  ------------------
 1117|      0|         return if_match(req, "GOST.INN", {1, 2, 643, 3, 131, 1, 1});
 1118|      0|      case 0x6CB3B:
  ------------------
  |  Branch (1118:7): [True: 0, False: 891]
  ------------------
 1119|      0|         return if_match(req, "Camellia-192/OCB", {1, 3, 6, 1, 4, 1, 25258, 3, 2, 7});
 1120|      0|      case 0x6E602:
  ------------------
  |  Branch (1120:7): [True: 0, False: 891]
  ------------------
 1121|      0|         return if_match(req, "Dilithium-8x7-r3", {1, 3, 6, 1, 4, 1, 25258, 1, 9, 3});
 1122|      0|      case 0x6F0C2:
  ------------------
  |  Branch (1122:7): [True: 0, False: 891]
  ------------------
 1123|      0|         return if_match(req, "RSA/PKCS1v15(SHA-224)", {1, 2, 840, 113549, 1, 1, 14});
 1124|      0|      case 0x6F9F8:
  ------------------
  |  Branch (1124:7): [True: 0, False: 891]
  ------------------
 1125|      0|         return if_match(req, "PKCS12.SafeContentsBag", {1, 2, 840, 113549, 1, 12, 10, 1, 6});
 1126|      0|      case 0x6FB26:
  ------------------
  |  Branch (1126:7): [True: 0, False: 891]
  ------------------
 1127|      0|         return if_match(req, "PKIX.AuthorityInformationAccess", {1, 3, 6, 1, 5, 5, 7, 1, 1});
 1128|      0|      case 0x70BB6:
  ------------------
  |  Branch (1128:7): [True: 0, False: 891]
  ------------------
 1129|      0|         return if_match(req, "brainpool384r1", {1, 3, 36, 3, 3, 2, 8, 1, 1, 11});
 1130|      0|      case 0x70EA6:
  ------------------
  |  Branch (1130:7): [True: 0, False: 891]
  ------------------
 1131|      0|         return if_match(req, "PKCS12.PKCS8ShroudedKeyBag", {1, 2, 840, 113549, 1, 12, 10, 1, 2});
 1132|      0|      case 0x71EB3:
  ------------------
  |  Branch (1132:7): [True: 0, False: 891]
  ------------------
 1133|      0|         return if_match(req, "SphincsPlus-haraka-128f-r3.1", {1, 3, 6, 1, 4, 1, 25258, 1, 12, 3, 2});
 1134|      0|      case 0x7382C:
  ------------------
  |  Branch (1134:7): [True: 0, False: 891]
  ------------------
 1135|      0|         return if_match(req, "ML-KEM-1024", {2, 16, 840, 1, 101, 3, 4, 4, 3});
 1136|      0|      case 0x743BD:
  ------------------
  |  Branch (1136:7): [True: 0, False: 891]
  ------------------
 1137|      0|         return if_match(req, "AES-256/OCB", {1, 3, 6, 1, 4, 1, 25258, 3, 2, 3});
 1138|      0|      case 0x7498E:
  ------------------
  |  Branch (1138:7): [True: 0, False: 891]
  ------------------
 1139|      0|         return if_match(req, "Camellia-128/CBC", {1, 2, 392, 200011, 61, 1, 1, 1, 2});
 1140|      0|      case 0x74C2E:
  ------------------
  |  Branch (1140:7): [True: 0, False: 891]
  ------------------
 1141|      0|         return if_match(req, "ML-DSA-8x7", {2, 16, 840, 1, 101, 3, 4, 3, 19});
 1142|      0|      case 0x7505F:
  ------------------
  |  Branch (1142:7): [True: 0, False: 891]
  ------------------
 1143|      0|         return if_match(req, "PKIX.XMPPAddr", {1, 3, 6, 1, 5, 5, 7, 8, 5});
 1144|      0|      case 0x7517A:
  ------------------
  |  Branch (1144:7): [True: 0, False: 891]
  ------------------
 1145|      0|         return if_match(req, "RSA/PKCS1v15(MD2)", {1, 2, 840, 113549, 1, 1, 2});
 1146|      0|      case 0x7546B:
  ------------------
  |  Branch (1146:7): [True: 0, False: 891]
  ------------------
 1147|      0|         return if_match(req, "RSA/PKCS1v15(MD5)", {1, 2, 840, 113549, 1, 1, 4});
 1148|      0|      case 0x75921:
  ------------------
  |  Branch (1148:7): [True: 0, False: 891]
  ------------------
 1149|      0|         return if_match(req, "ClassicMcEliece_348864f", {1, 3, 6, 1, 4, 1, 22554, 5, 1, 2});
 1150|      0|      case 0x76784:
  ------------------
  |  Branch (1150:7): [True: 0, False: 891]
  ------------------
 1151|      0|         return if_match(req, "SHA-3(384)", {2, 16, 840, 1, 101, 3, 4, 2, 9});
 1152|      0|      case 0x768FD:
  ------------------
  |  Branch (1152:7): [True: 0, False: 891]
  ------------------
 1153|      0|         return if_match(req, "PKCS9.LocalKeyId", {1, 2, 840, 113549, 1, 9, 21});
 1154|      0|      case 0x76A19:
  ------------------
  |  Branch (1154:7): [True: 0, False: 891]
  ------------------
 1155|      0|         return if_match(req, "brainpool512r1", {1, 3, 36, 3, 3, 2, 8, 1, 1, 13});
 1156|      0|      case 0x77254:
  ------------------
  |  Branch (1156:7): [True: 0, False: 891]
  ------------------
 1157|      0|         return if_match(req, "SphincsPlus-haraka-256s-r3.1", {1, 3, 6, 1, 4, 1, 25258, 1, 12, 3, 5});
 1158|      0|      case 0x77ADC:
  ------------------
  |  Branch (1158:7): [True: 0, False: 891]
  ------------------
 1159|      0|         return if_match(req, "secp224k1", {1, 3, 132, 0, 32});
 1160|      0|      case 0x781B9:
  ------------------
  |  Branch (1160:7): [True: 0, False: 891]
  ------------------
 1161|      0|         return if_match(req, "secp224r1", {1, 3, 132, 0, 33});
 1162|      0|      case 0x78ABE:
  ------------------
  |  Branch (1162:7): [True: 0, False: 891]
  ------------------
 1163|      0|         return if_match(req, "Camellia-192/CBC", {1, 2, 392, 200011, 61, 1, 1, 1, 3});
 1164|      0|      case 0x792F2:
  ------------------
  |  Branch (1164:7): [True: 0, False: 891]
  ------------------
 1165|      0|         return if_match(req, "ClassicMcEliece_6688128pc", {1, 3, 6, 1, 4, 1, 25258, 1, 18, 1});
 1166|      0|      case 0x7A661:
  ------------------
  |  Branch (1166:7): [True: 0, False: 891]
  ------------------
 1167|      0|         return if_match(req, "DSA/SHA-512", {2, 16, 840, 1, 101, 3, 4, 3, 4});
 1168|      0|      case 0x7A977:
  ------------------
  |  Branch (1168:7): [True: 0, False: 891]
  ------------------
 1169|      0|         return if_match(req, "X509v3.ExtendedKeyUsage", {2, 5, 29, 37});
 1170|      0|      case 0x7AE67:
  ------------------
  |  Branch (1170:7): [True: 0, False: 891]
  ------------------
 1171|      0|         return if_match(req, "SM2_Enc", {1, 2, 156, 10197, 1, 301, 3});
 1172|      0|      case 0x7B602:
  ------------------
  |  Branch (1172:7): [True: 0, False: 891]
  ------------------
 1173|      0|         return if_match(req, "Twofish/OCB", {1, 3, 6, 1, 4, 1, 25258, 3, 2, 5});
 1174|      0|      case 0x7B9A1:
  ------------------
  |  Branch (1174:7): [True: 0, False: 891]
  ------------------
 1175|      0|         return if_match(req, "SphincsPlus-sha2-192s-r3.1", {1, 3, 6, 1, 4, 1, 25258, 1, 12, 2, 3});
 1176|      0|      case 0x7BB0A:
  ------------------
  |  Branch (1176:7): [True: 0, False: 891]
  ------------------
 1177|      0|         return if_match(req, "SLH-DSA-SHAKE-256f", {2, 16, 840, 1, 101, 3, 4, 3, 31});
 1178|      0|      case 0x7BB17:
  ------------------
  |  Branch (1178:7): [True: 0, False: 891]
  ------------------
 1179|      0|         return if_match(req, "SLH-DSA-SHAKE-256s", {2, 16, 840, 1, 101, 3, 4, 3, 30});
 1180|      0|      case 0x7BCF3:
  ------------------
  |  Branch (1180:7): [True: 0, False: 891]
  ------------------
 1181|      0|         return if_match(req, "PKIX.EmailProtection", {1, 3, 6, 1, 5, 5, 7, 3, 4});
 1182|      0|      case 0x7CC2C:
  ------------------
  |  Branch (1182:7): [True: 0, False: 891]
  ------------------
 1183|      0|         return if_match(req, "SHA-512-256", {2, 16, 840, 1, 101, 3, 4, 2, 6});
 1184|      0|      case 0x7CF41:
  ------------------
  |  Branch (1184:7): [True: 0, False: 891]
  ------------------
 1185|      0|         return if_match(req, "SphincsPlus-shake-192s-r3.1", {1, 3, 6, 1, 4, 1, 25258, 1, 12, 1, 3});
 1186|      0|      case 0x7DB91:
  ------------------
  |  Branch (1186:7): [True: 0, False: 891]
  ------------------
 1187|      0|         return if_match(req, "GOST-34.10", {1, 2, 643, 2, 2, 19});
 1188|      0|      case 0x7E319:
  ------------------
  |  Branch (1188:7): [True: 0, False: 891]
  ------------------
 1189|      0|         return if_match(req, "ECDSA/SHA-512", {1, 2, 840, 10045, 4, 3, 4});
 1190|      0|      case 0x7E874:
  ------------------
  |  Branch (1190:7): [True: 0, False: 891]
  ------------------
 1191|      0|         return if_match(req, "ClassicMcEliece_6688128f", {1, 3, 6, 1, 4, 1, 22554, 5, 1, 6});
 1192|      0|      case 0x7EAAF:
  ------------------
  |  Branch (1192:7): [True: 0, False: 891]
  ------------------
 1193|      0|         return if_match(req, "eFrodoKEM-640-SHAKE", {1, 3, 6, 1, 4, 1, 25258, 1, 16, 1});
 1194|      0|      case 0x7F51F:
  ------------------
  |  Branch (1194:7): [True: 0, False: 891]
  ------------------
 1195|      0|         return if_match(req, "PKIX.IPsecTunnel", {1, 3, 6, 1, 5, 5, 7, 3, 6});
 1196|      0|      case 0x80272:
  ------------------
  |  Branch (1196:7): [True: 0, False: 891]
  ------------------
 1197|      0|         return if_match(req, "X520.Organization", {2, 5, 4, 10});
 1198|      0|      case 0x80340:
  ------------------
  |  Branch (1198:7): [True: 0, False: 891]
  ------------------
 1199|      0|         return if_match(req, "AES-256/CBC", {2, 16, 840, 1, 101, 3, 4, 1, 42});
 1200|      0|      case 0x80445:
  ------------------
  |  Branch (1200:7): [True: 0, False: 891]
  ------------------
 1201|      0|         return if_match(req, "AES-256/CCM", {2, 16, 840, 1, 101, 3, 4, 1, 47});
 1202|      0|      case 0x811F7:
  ------------------
  |  Branch (1202:7): [True: 0, False: 891]
  ------------------
 1203|      0|         return if_match(req, "HMAC(SHA-256)", {1, 2, 840, 113549, 2, 9});
 1204|      0|      case 0x82434:
  ------------------
  |  Branch (1204:7): [True: 0, False: 891]
  ------------------
 1205|      0|         return if_match(req, "PKCS9.X509CRL", {1, 2, 840, 113549, 1, 9, 23, 1});
 1206|      0|      case 0x82B47:
  ------------------
  |  Branch (1206:7): [True: 0, False: 891]
  ------------------
 1207|      0|         return if_match(req, "Threefish-512/CBC", {1, 3, 6, 1, 4, 1, 25258, 3, 2});
 1208|      0|      case 0x83EA7:
  ------------------
  |  Branch (1208:7): [True: 0, False: 891]
  ------------------
 1209|      0|         return if_match(req, "RSA/PKCS1v15(SHA-384)", {1, 2, 840, 113549, 1, 1, 12});
 1210|      0|      case 0x84596:
  ------------------
  |  Branch (1210:7): [True: 0, False: 891]
  ------------------
 1211|      0|         return if_match(req, "eFrodoKEM-640-AES", {1, 3, 6, 1, 4, 1, 25258, 1, 17, 1});
 1212|      0|      case 0x8469F:
  ------------------
  |  Branch (1212:7): [True: 0, False: 891]
  ------------------
 1213|      0|         return if_match(req, "ClassicMcEliece_6960119pcf", {1, 3, 6, 1, 4, 1, 25258, 1, 18, 4});
 1214|      0|      case 0x84CA4:
  ------------------
  |  Branch (1214:7): [True: 0, False: 891]
  ------------------
 1215|      0|         return if_match(req, "secp256k1", {1, 3, 132, 0, 10});
 1216|      0|      case 0x85381:
  ------------------
  |  Branch (1216:7): [True: 0, False: 891]
  ------------------
 1217|      0|         return if_match(req, "secp256r1", {1, 2, 840, 10045, 3, 1, 7});
 1218|      0|      case 0x854FC:
  ------------------
  |  Branch (1218:7): [True: 0, False: 891]
  ------------------
 1219|      0|         return if_match(req, "PKIX.IPsecUser", {1, 3, 6, 1, 5, 5, 7, 3, 7});
 1220|      0|      case 0x85F51:
  ------------------
  |  Branch (1220:7): [True: 0, False: 891]
  ------------------
 1221|      0|         return if_match(req, "Serpent/SIV", {1, 3, 6, 1, 4, 1, 25258, 3, 4, 4});
 1222|      0|      case 0x862D9:
  ------------------
  |  Branch (1222:7): [True: 0, False: 891]
  ------------------
 1223|      0|         return if_match(req, "ECGDSA/SHA-512", {1, 3, 36, 3, 3, 2, 5, 4, 6});
 1224|      0|      case 0x87585:
  ------------------
  |  Branch (1224:7): [True: 0, False: 891]
  ------------------
 1225|      0|         return if_match(req, "Twofish/CBC", {1, 3, 6, 1, 4, 1, 25258, 3, 3});
 1226|      0|      case 0x877D1:
  ------------------
  |  Branch (1226:7): [True: 0, False: 891]
  ------------------
 1227|      0|         return if_match(req, "PKCS9.EmailAddress", {1, 2, 840, 113549, 1, 9, 1});
 1228|     73|      case 0x87D27:
  ------------------
  |  Branch (1228:7): [True: 73, False: 818]
  ------------------
 1229|     73|         return if_match(req, "PKIX.CertificateAuthorityIssuers", {1, 3, 6, 1, 5, 5, 7, 48, 2});
 1230|      0|      case 0x87E42:
  ------------------
  |  Branch (1230:7): [True: 0, False: 891]
  ------------------
 1231|      0|         return if_match(req, "X509v3.AuthorityKeyIdentifier", {2, 5, 29, 35});
 1232|      0|      case 0x889B1:
  ------------------
  |  Branch (1232:7): [True: 0, False: 891]
  ------------------
 1233|      0|         return if_match(req, "ECDSA/SHA-1", {1, 2, 840, 10045, 4, 1});
 1234|      0|      case 0x89658:
  ------------------
  |  Branch (1234:7): [True: 0, False: 891]
  ------------------
 1235|      0|         return if_match(req, "PBE-PKCS5v20", {1, 2, 840, 113549, 1, 5, 13});
 1236|      0|      case 0x8976D:
  ------------------
  |  Branch (1236:7): [True: 0, False: 891]
  ------------------
 1237|      0|         return if_match(req, "PKCS9.MessageDigest", {1, 2, 840, 113549, 1, 9, 4});
 1238|      0|      case 0x8B002:
  ------------------
  |  Branch (1238:7): [True: 0, False: 891]
  ------------------
 1239|      0|         return if_match(req, "Camellia-256/OCB", {1, 3, 6, 1, 4, 1, 25258, 3, 2, 8});
 1240|      0|      case 0x8B935:
  ------------------
  |  Branch (1240:7): [True: 0, False: 891]
  ------------------
 1241|      0|         return if_match(req, "ClassicMcEliece_6688128", {1, 3, 6, 1, 4, 1, 22554, 5, 1, 5});
 1242|      0|      case 0x8BB11:
  ------------------
  |  Branch (1242:7): [True: 0, False: 891]
  ------------------
 1243|      0|         return if_match(req, "X509v3.NoRevocationAvailable", {2, 5, 29, 56});
 1244|      0|      case 0x8CE3D:
  ------------------
  |  Branch (1244:7): [True: 0, False: 891]
  ------------------
 1245|      0|         return if_match(req, "PKCS9.ChallengePassword", {1, 2, 840, 113549, 1, 9, 7});
 1246|      0|      case 0x8D45C:
  ------------------
  |  Branch (1246:7): [True: 0, False: 891]
  ------------------
 1247|      0|         return if_match(req, "ECKCDSA", {1, 0, 14888, 3, 0, 5});
 1248|      0|      case 0x8E0C1:
  ------------------
  |  Branch (1248:7): [True: 0, False: 891]
  ------------------
 1249|      0|         return if_match(req, "X509v3.CertificatePolicies", {2, 5, 29, 32});
 1250|      0|      case 0x8E39A:
  ------------------
  |  Branch (1250:7): [True: 0, False: 891]
  ------------------
 1251|      0|         return if_match(req, "HSS-LMS-Private-Key", {1, 3, 6, 1, 4, 1, 25258, 1, 13});
 1252|      0|      case 0x8EC51:
  ------------------
  |  Branch (1252:7): [True: 0, False: 891]
  ------------------
 1253|      0|         return if_match(req, "Kyber-768-r3", {1, 3, 6, 1, 4, 1, 25258, 1, 7, 2});
 1254|      0|      case 0x8F94A:
  ------------------
  |  Branch (1254:7): [True: 0, False: 891]
  ------------------
 1255|      0|         return if_match(req, "Dilithium-6x5-r3", {1, 3, 6, 1, 4, 1, 25258, 1, 9, 2});
 1256|      0|      case 0x8FC20:
  ------------------
  |  Branch (1256:7): [True: 0, False: 891]
  ------------------
 1257|      0|         return if_match(req, "AES-128/SIV", {1, 3, 6, 1, 4, 1, 25258, 3, 4, 1});
 1258|      0|      case 0x8FDE0:
  ------------------
  |  Branch (1258:7): [True: 0, False: 891]
  ------------------
 1259|      0|         return if_match(req, "SHA-3(256)", {2, 16, 840, 1, 101, 3, 4, 2, 8});
 1260|      0|      case 0x919E3:
  ------------------
  |  Branch (1260:7): [True: 0, False: 891]
  ------------------
 1261|      0|         return if_match(req, "Serpent/GCM", {1, 3, 6, 1, 4, 1, 25258, 3, 101});
 1262|      0|      case 0x91C1A:
  ------------------
  |  Branch (1262:7): [True: 0, False: 891]
  ------------------
 1263|      0|         return if_match(req, "X25519", {1, 3, 101, 110});
 1264|      0|      case 0x91DC4:
  ------------------
  |  Branch (1264:7): [True: 0, False: 891]
  ------------------
 1265|      0|         return if_match(req, "McEliece", {1, 3, 6, 1, 4, 1, 25258, 1, 3});
 1266|      0|      case 0x93467:
  ------------------
  |  Branch (1266:7): [True: 0, False: 891]
  ------------------
 1267|      0|         return if_match(req, "Dilithium-6x5-AES-r3", {1, 3, 6, 1, 4, 1, 25258, 1, 10, 2});
 1268|      0|      case 0x93D50:
  ------------------
  |  Branch (1268:7): [True: 0, False: 891]
  ------------------
 1269|      0|         return if_match(req, "AES-192/SIV", {1, 3, 6, 1, 4, 1, 25258, 3, 4, 2});
 1270|      0|      case 0x95166:
  ------------------
  |  Branch (1270:7): [True: 0, False: 891]
  ------------------
 1271|      0|         return if_match(req, "SLH-DSA-SHAKE-128f", {2, 16, 840, 1, 101, 3, 4, 3, 27});
 1272|      0|      case 0x95173:
  ------------------
  |  Branch (1272:7): [True: 0, False: 891]
  ------------------
 1273|      0|         return if_match(req, "SLH-DSA-SHAKE-128s", {2, 16, 840, 1, 101, 3, 4, 3, 26});
 1274|     73|      case 0x952D6:
  ------------------
  |  Branch (1274:7): [True: 73, False: 818]
  ------------------
 1275|     73|         return if_match(req, "PKIX.OCSP", {1, 3, 6, 1, 5, 5, 7, 48, 1});
 1276|      0|      case 0x959B9:
  ------------------
  |  Branch (1276:7): [True: 0, False: 891]
  ------------------
 1277|      0|         return if_match(req, "PKIX.IPsecEndSystem", {1, 3, 6, 1, 5, 5, 7, 3, 5});
 1278|      0|      case 0x96F85:
  ------------------
  |  Branch (1278:7): [True: 0, False: 891]
  ------------------
 1279|      0|         return if_match(req, "Camellia-256/CBC", {1, 2, 392, 200011, 61, 1, 1, 1, 4});
 1280|      0|      case 0x97D5E:
  ------------------
  |  Branch (1280:7): [True: 0, False: 891]
  ------------------
 1281|      0|         return if_match(req, "HMAC(SHA-1)", {1, 2, 840, 113549, 2, 7});
 1282|      0|      case 0x9805C:
  ------------------
  |  Branch (1282:7): [True: 0, False: 891]
  ------------------
 1283|      0|         return if_match(req, "SEED/CBC", {1, 2, 410, 200004, 1, 4});
 1284|      0|      case 0x980E7:
  ------------------
  |  Branch (1284:7): [True: 0, False: 891]
  ------------------
 1285|      0|         return if_match(req, "SphincsPlus-haraka-192s-r3.1", {1, 3, 6, 1, 4, 1, 25258, 1, 12, 3, 3});
 1286|      0|      case 0x980F5:
  ------------------
  |  Branch (1286:7): [True: 0, False: 891]
  ------------------
 1287|      0|         return if_match(req, "GOST.SubjectSigningTool", {1, 2, 643, 100, 111});
 1288|      0|      case 0x98B03:
  ------------------
  |  Branch (1288:7): [True: 0, False: 891]
  ------------------
 1289|      0|         return if_match(req, "XMSS", {0, 4, 0, 127, 0, 15, 1, 1, 13, 0});
 1290|      0|      case 0x9A6B2:
  ------------------
  |  Branch (1290:7): [True: 0, False: 891]
  ------------------
 1291|      0|         return if_match(req, "ECKCDSA/SHA-1", {1, 2, 410, 200004, 1, 100, 4, 3});
 1292|      0|      case 0x9B1CF:
  ------------------
  |  Branch (1292:7): [True: 0, False: 891]
  ------------------
 1293|      0|         return if_match(req, "SM4/SIV", {1, 3, 6, 1, 4, 1, 25258, 3, 4, 9});
 1294|      0|      case 0x9B6B2:
  ------------------
  |  Branch (1294:7): [True: 0, False: 891]
  ------------------
 1295|      0|         return if_match(req, "AES-128/GCM", {2, 16, 840, 1, 101, 3, 4, 1, 6});
 1296|      0|      case 0x9B6BB:
  ------------------
  |  Branch (1296:7): [True: 0, False: 891]
  ------------------
 1297|      0|         return if_match(req, "X520.OrganizationalUnit", {2, 5, 4, 11});
 1298|      0|      case 0x9B851:
  ------------------
  |  Branch (1298:7): [True: 0, False: 891]
  ------------------
 1299|      0|         return if_match(req, "OpenPGP.Curve25519", {1, 3, 6, 1, 4, 1, 3029, 1, 5, 1});
 1300|      0|      case 0x9C80B:
  ------------------
  |  Branch (1300:7): [True: 0, False: 891]
  ------------------
 1301|      0|         return if_match(req, "SLH-DSA-SHA2-192f", {2, 16, 840, 1, 101, 3, 4, 3, 23});
 1302|      0|      case 0x9C818:
  ------------------
  |  Branch (1302:7): [True: 0, False: 891]
  ------------------
 1303|      0|         return if_match(req, "SLH-DSA-SHA2-192s", {2, 16, 840, 1, 101, 3, 4, 3, 22});
 1304|      0|      case 0x9CD2B:
  ------------------
  |  Branch (1304:7): [True: 0, False: 891]
  ------------------
 1305|      0|         return if_match(req, "Scrypt", {1, 3, 6, 1, 4, 1, 11591, 4, 11});
 1306|      0|      case 0x9CDE1:
  ------------------
  |  Branch (1306:7): [True: 0, False: 891]
  ------------------
 1307|      0|         return if_match(req, "GOST-34.10-2012-256/SHA-256", {1, 3, 6, 1, 4, 1, 25258, 1, 6, 1});
 1308|      0|      case 0x9CF73:
  ------------------
  |  Branch (1308:7): [True: 0, False: 891]
  ------------------
 1309|      0|         return if_match(req, "ClassicMcEliece_460896f", {1, 3, 6, 1, 4, 1, 22554, 5, 1, 4});
 1310|      0|      case 0x9D354:
  ------------------
  |  Branch (1310:7): [True: 0, False: 891]
  ------------------
 1311|      0|         return if_match(req, "RIPEMD-160", {1, 3, 36, 3, 2, 1});
 1312|      0|      case 0x9D503:
  ------------------
  |  Branch (1312:7): [True: 0, False: 891]
  ------------------
 1313|      0|         return if_match(req, "RSA/PKCS1v15(SHA-256)", {1, 2, 840, 113549, 1, 1, 11});
 1314|      0|      case 0x9EC88:
  ------------------
  |  Branch (1314:7): [True: 0, False: 891]
  ------------------
 1315|      0|         return if_match(req, "DSA/SHA-3(512)", {2, 16, 840, 1, 101, 3, 4, 3, 8});
 1316|      0|      case 0x9EF36:
  ------------------
  |  Branch (1316:7): [True: 0, False: 891]
  ------------------
 1317|      0|         return if_match(req, "ClassicMcEliece_6960119", {1, 3, 6, 1, 4, 1, 22554, 5, 1, 7});
 1318|      0|      case 0x9F764:
  ------------------
  |  Branch (1318:7): [True: 0, False: 891]
  ------------------
 1319|      0|         return if_match(req, "X448", {1, 3, 101, 111});
 1320|      0|      case 0x9F7E2:
  ------------------
  |  Branch (1320:7): [True: 0, False: 891]
  ------------------
 1321|      0|         return if_match(req, "AES-192/GCM", {2, 16, 840, 1, 101, 3, 4, 1, 26});
 1322|      0|      case 0x9F9C5:
  ------------------
  |  Branch (1322:7): [True: 0, False: 891]
  ------------------
 1323|      0|         return if_match(req, "ClassicMcEliece_6688128pcf", {1, 3, 6, 1, 4, 1, 25258, 1, 18, 2});
 1324|      0|      case 0xA0805:
  ------------------
  |  Branch (1324:7): [True: 0, False: 891]
  ------------------
 1325|      0|         return if_match(req, "PKCS9.SDSICertificate", {1, 2, 840, 113549, 1, 9, 22, 2});
 1326|      0|      case 0xA2B5B:
  ------------------
  |  Branch (1326:7): [True: 0, False: 891]
  ------------------
 1327|      0|         return if_match(req, "X509v3.CRLNumber", {2, 5, 29, 20});
 1328|      0|      case 0xA3005:
  ------------------
  |  Branch (1328:7): [True: 0, False: 891]
  ------------------
 1329|      0|         return if_match(req, "X520.Title", {2, 5, 4, 12});
 1330|      0|      case 0xA323F:
  ------------------
  |  Branch (1330:7): [True: 0, False: 891]
  ------------------
 1331|      0|         return if_match(req, "X509v3.NameConstraints", {2, 5, 29, 30});
 1332|      0|      case 0xA3C55:
  ------------------
  |  Branch (1332:7): [True: 0, False: 891]
  ------------------
 1333|      0|         return if_match(req, "X520.Pseudonym", {2, 5, 4, 65});
 1334|      0|      case 0xA4809:
  ------------------
  |  Branch (1334:7): [True: 0, False: 891]
  ------------------
 1335|      0|         return if_match(req, "SphincsPlus-sha2-256f-r3.1", {1, 3, 6, 1, 4, 1, 25258, 1, 12, 2, 6});
 1336|      0|      case 0xA57AF:
  ------------------
  |  Branch (1336:7): [True: 0, False: 891]
  ------------------
 1337|      0|         return if_match(req, "secp521r1", {1, 3, 132, 0, 35});
 1338|      0|      case 0xA5DA9:
  ------------------
  |  Branch (1338:7): [True: 0, False: 891]
  ------------------
 1339|      0|         return if_match(req, "SphincsPlus-shake-256f-r3.1", {1, 3, 6, 1, 4, 1, 25258, 1, 12, 1, 6});
 1340|      0|      case 0xA6865:
  ------------------
  |  Branch (1340:7): [True: 0, False: 891]
  ------------------
 1341|      0|         return if_match(req, "Camellia-128/SIV", {1, 3, 6, 1, 4, 1, 25258, 3, 4, 6});
 1342|      0|      case 0xA6C61:
  ------------------
  |  Branch (1342:7): [True: 0, False: 891]
  ------------------
 1343|      0|         return if_match(req, "SM4/GCM", {1, 2, 156, 10197, 1, 104, 8});
 1344|      0|      case 0xA8439:
  ------------------
  |  Branch (1344:7): [True: 0, False: 891]
  ------------------
 1345|      0|         return if_match(req, "PKCS12.CertBag", {1, 2, 840, 113549, 1, 12, 10, 1, 3});
 1346|      0|      case 0xA9061:
  ------------------
  |  Branch (1346:7): [True: 0, False: 891]
  ------------------
 1347|      0|         return if_match(req, "Kyber-768-90s-r3", {1, 3, 6, 1, 4, 1, 25258, 1, 11, 2});
 1348|      0|      case 0xAA995:
  ------------------
  |  Branch (1348:7): [True: 0, False: 891]
  ------------------
 1349|      0|         return if_match(req, "Camellia-192/SIV", {1, 3, 6, 1, 4, 1, 25258, 3, 4, 7});
 1350|      0|      case 0xAAE2B:
  ------------------
  |  Branch (1350:7): [True: 0, False: 891]
  ------------------
 1351|      0|         return if_match(req, "Dilithium-8x7-AES-r3", {1, 3, 6, 1, 4, 1, 25258, 1, 10, 3});
 1352|      0|      case 0xABCED:
  ------------------
  |  Branch (1352:7): [True: 0, False: 891]
  ------------------
 1353|      0|         return if_match(req, "GOST.IssuerSigningTool", {1, 2, 643, 100, 112});
 1354|      0|      case 0xABD24:
  ------------------
  |  Branch (1354:7): [True: 0, False: 891]
  ------------------
 1355|      0|         return if_match(req, "RSA/OAEP", {1, 2, 840, 113549, 1, 1, 7});
 1356|      0|      case 0xAC2EC:
  ------------------
  |  Branch (1356:7): [True: 0, False: 891]
  ------------------
 1357|      0|         return if_match(req, "Streebog-256", {1, 2, 643, 7, 1, 1, 2, 2});
 1358|      0|      case 0xAC3DD:
  ------------------
  |  Branch (1358:7): [True: 0, False: 891]
  ------------------
 1359|      0|         return if_match(req, "Certificate Comment", {2, 16, 840, 1, 113730, 1, 13});
 1360|      0|      case 0xAC511:
  ------------------
  |  Branch (1360:7): [True: 0, False: 891]
  ------------------
 1361|      0|         return if_match(req, "PBE-SHA1-3DES", {1, 2, 840, 113549, 1, 12, 1, 3});
 1362|      0|      case 0xAE6FE:
  ------------------
  |  Branch (1362:7): [True: 0, False: 891]
  ------------------
 1363|      0|         return if_match(req, "PKIX.ClientAuth", {1, 3, 6, 1, 5, 5, 7, 3, 2});
 1364|      0|      case 0xAE8D3:
  ------------------
  |  Branch (1364:7): [True: 0, False: 891]
  ------------------
 1365|      0|         return if_match(req, "ClassicMcEliece_8192128pcf", {1, 3, 6, 1, 4, 1, 25258, 1, 18, 6});
 1366|      0|      case 0xAF476:
  ------------------
  |  Branch (1366:7): [True: 0, False: 891]
  ------------------
 1367|      0|         return if_match(req, "ECDH", {1, 3, 132, 1, 12});
 1368|      0|      case 0xAFA6A:
  ------------------
  |  Branch (1368:7): [True: 0, False: 891]
  ------------------
 1369|      0|         return if_match(req, "RSA/PKCS1v15(SHA-3(384))", {2, 16, 840, 1, 101, 3, 4, 3, 15});
 1370|      0|      case 0xB2217:
  ------------------
  |  Branch (1370:7): [True: 0, False: 891]
  ------------------
 1371|      0|         return if_match(req, "AES-256/SIV", {1, 3, 6, 1, 4, 1, 25258, 3, 4, 3});
 1372|      0|      case 0xB22F7:
  ------------------
  |  Branch (1372:7): [True: 0, False: 891]
  ------------------
 1373|      0|         return if_match(req, "Camellia-128/GCM", {0, 3, 4401, 5, 3, 1, 9, 6});
 1374|      0|      case 0xB23DE:
  ------------------
  |  Branch (1374:7): [True: 0, False: 891]
  ------------------
 1375|      0|         return if_match(req, "X520.Locality", {2, 5, 4, 7});
 1376|      0|      case 0xB2FBD:
  ------------------
  |  Branch (1376:7): [True: 0, False: 891]
  ------------------
 1377|      0|         return if_match(req, "ECKCDSA/SHA-224", {1, 2, 410, 200004, 1, 100, 4, 4});
 1378|      0|      case 0xB32B0:
  ------------------
  |  Branch (1378:7): [True: 0, False: 891]
  ------------------
 1379|      0|         return if_match(req, "ECKCDSA/SHA-256", {1, 2, 410, 200004, 1, 100, 4, 5});
 1380|      0|      case 0xB360E:
  ------------------
  |  Branch (1380:7): [True: 0, False: 891]
  ------------------
 1381|      0|         return if_match(req, "eFrodoKEM-976-SHAKE", {1, 3, 6, 1, 4, 1, 25258, 1, 16, 2});
 1382|      0|      case 0xB4368:
  ------------------
  |  Branch (1382:7): [True: 0, False: 891]
  ------------------
 1383|      0|         return if_match(req, "ECGDSA/SHA-1", {1, 3, 36, 3, 3, 2, 5, 4, 2});
 1384|      0|      case 0xB58CD:
  ------------------
  |  Branch (1384:7): [True: 0, False: 891]
  ------------------
 1385|      0|         return if_match(req, "RSA/PKCS1v15(SHA-3(512))", {2, 16, 840, 1, 101, 3, 4, 3, 16});
 1386|      0|      case 0xB6427:
  ------------------
  |  Branch (1386:7): [True: 0, False: 891]
  ------------------
 1387|      0|         return if_match(req, "Camellia-192/GCM", {0, 3, 4401, 5, 3, 1, 9, 26});
 1388|      0|      case 0xB7102:
  ------------------
  |  Branch (1388:7): [True: 0, False: 891]
  ------------------
 1389|      0|         return if_match(req, "brainpool224r1", {1, 3, 36, 3, 3, 2, 8, 1, 1, 5});
 1390|      0|      case 0xB710D:
  ------------------
  |  Branch (1390:7): [True: 0, False: 891]
  ------------------
 1391|      0|         return if_match(req, "X509v3.CRLIssuingDistributionPoint", {2, 5, 29, 28});
 1392|      0|      case 0xB72D4:
  ------------------
  |  Branch (1392:7): [True: 0, False: 891]
  ------------------
 1393|      0|         return if_match(req, "Microsoft UPN", {1, 3, 6, 1, 4, 1, 311, 20, 2, 3});
 1394|      0|      case 0xB73A5:
  ------------------
  |  Branch (1394:7): [True: 0, False: 891]
  ------------------
 1395|      0|         return if_match(req, "RSA/PSS", {1, 2, 840, 113549, 1, 1, 10});
 1396|      0|      case 0xB84B3:
  ------------------
  |  Branch (1396:7): [True: 0, False: 891]
  ------------------
 1397|      0|         return if_match(req, "PKIX.CodeSigning", {1, 3, 6, 1, 5, 5, 7, 3, 3});
 1398|      0|      case 0xB8CB9:
  ------------------
  |  Branch (1398:7): [True: 0, False: 891]
  ------------------
 1399|      0|         return if_match(req, "GOST-34.10-2012-256", {1, 2, 643, 7, 1, 1, 1, 1});
 1400|      0|      case 0xB945C:
  ------------------
  |  Branch (1400:7): [True: 0, False: 891]
  ------------------
 1401|      0|         return if_match(req, "Twofish/SIV", {1, 3, 6, 1, 4, 1, 25258, 3, 4, 5});
 1402|      0|      case 0xB94E4:
  ------------------
  |  Branch (1402:7): [True: 0, False: 891]
  ------------------
 1403|      0|         return if_match(req, "gost_512A", {1, 2, 643, 7, 1, 2, 1, 2, 1});
 1404|      0|      case 0xB94E5:
  ------------------
  |  Branch (1404:7): [True: 0, False: 891]
  ------------------
 1405|      0|         return if_match(req, "gost_512B", {1, 2, 643, 7, 1, 2, 1, 2, 2});
 1406|      0|      case 0xBA1D8:
  ------------------
  |  Branch (1406:7): [True: 0, False: 891]
  ------------------
 1407|      0|         return if_match(req, "X520.StreetAddress", {2, 5, 4, 9});
 1408|      0|      case 0xBCB45:
  ------------------
  |  Branch (1408:7): [True: 0, False: 891]
  ------------------
 1409|      0|         return if_match(req, "PKCS12.CRLBag", {1, 2, 840, 113549, 1, 12, 10, 1, 4});
 1410|      0|      case 0xBCC82:
  ------------------
  |  Branch (1410:7): [True: 0, False: 891]
  ------------------
 1411|      0|         return if_match(req, "x962_p239v1", {1, 2, 840, 10045, 3, 1, 4});
 1412|      0|      case 0xBCC83:
  ------------------
  |  Branch (1412:7): [True: 0, False: 891]
  ------------------
 1413|      0|         return if_match(req, "x962_p239v2", {1, 2, 840, 10045, 3, 1, 5});
 1414|      0|      case 0xBCC84:
  ------------------
  |  Branch (1414:7): [True: 0, False: 891]
  ------------------
 1415|      0|         return if_match(req, "x962_p239v3", {1, 2, 840, 10045, 3, 1, 6});
 1416|      0|      case 0xBD92B:
  ------------------
  |  Branch (1416:7): [True: 0, False: 891]
  ------------------
 1417|      0|         return if_match(req, "X509v3.HoldInstructionCode", {2, 5, 29, 23});
 1418|      0|      case 0xBDCA9:
  ------------------
  |  Branch (1418:7): [True: 0, False: 891]
  ------------------
 1419|      0|         return if_match(req, "AES-256/GCM", {2, 16, 840, 1, 101, 3, 4, 1, 46});
 1420|      0|      case 0xBE48D:
  ------------------
  |  Branch (1420:7): [True: 0, False: 891]
  ------------------
 1421|      0|         return if_match(req, "PKIX.OCSP.BasicResponse", {1, 3, 6, 1, 5, 5, 7, 48, 1, 1});
 1422|      0|      case 0xBF71E:
  ------------------
  |  Branch (1422:7): [True: 0, False: 891]
  ------------------
 1423|      0|         return if_match(req, "Kyber-1024-r3", {1, 3, 6, 1, 4, 1, 25258, 1, 7, 3});
 1424|      0|      case 0xBFF01:
  ------------------
  |  Branch (1424:7): [True: 0, False: 891]
  ------------------
 1425|      0|         return if_match(req, "DSA/SHA-3(224)", {2, 16, 840, 1, 101, 3, 4, 3, 5});
 1426|      0|      case 0xC0F4F:
  ------------------
  |  Branch (1426:7): [True: 0, False: 891]
  ------------------
 1427|      0|         return if_match(req, "SphincsPlus-haraka-256f-r3.1", {1, 3, 6, 1, 4, 1, 25258, 1, 12, 3, 6});
 1428|      0|      case 0xC1875:
  ------------------
  |  Branch (1428:7): [True: 0, False: 891]
  ------------------
 1429|      0|         return if_match(req, "SHA-1", {1, 3, 14, 3, 2, 26});
 1430|      0|      case 0xC28D1:
  ------------------
  |  Branch (1430:7): [True: 0, False: 891]
  ------------------
 1431|      0|         return if_match(req, "PKIX.OCSPSigning", {1, 3, 6, 1, 5, 5, 7, 3, 9});
 1432|      0|      case 0xC42CA:
  ------------------
  |  Branch (1432:7): [True: 0, False: 891]
  ------------------
 1433|      0|         return if_match(req, "brainpool256r1", {1, 3, 36, 3, 3, 2, 8, 1, 1, 7});
 1434|      0|      default:
  ------------------
  |  Branch (1434:7): [True: 0, False: 891]
  ------------------
 1435|      0|         return {};
 1436|    891|   }
 1437|    891|}
_ZN5Botan7OID_Map16load_oid2str_mapEv:
 1439|      1|std::unordered_map<OID, std::string> OID_Map::load_oid2str_map() {
 1440|      1|   return {
 1441|      1|      {OID{2, 5, 8, 1, 1}, "RSA"},
 1442|      1|      {OID{1, 3, 6, 1, 4, 1, 8301, 3, 1, 2, 9, 0, 38}, "secp521r1"},
 1443|      1|      {OID{1, 2, 643, 2, 2, 35, 1}, "gost_256A"},
 1444|      1|      {OID{1, 2, 643, 2, 2, 36, 0}, "gost_256A"},
 1445|      1|   };
 1446|      1|}
_ZN5Botan7OID_Map16load_str2oid_mapEv:
 1448|      1|std::unordered_map<std::string, OID> OID_Map::load_str2oid_map() {
 1449|      1|   return {
 1450|      1|      {"Curve25519", OID{1, 3, 101, 110}},
 1451|      1|      {"SM2_Sig", OID{1, 2, 156, 10197, 1, 301, 1}},
 1452|      1|      {"RSA/EMSA3(MD2)", OID{1, 2, 840, 113549, 1, 1, 2}},
 1453|      1|      {"RSA/EMSA3(MD5)", OID{1, 2, 840, 113549, 1, 1, 4}},
 1454|      1|      {"RSA/EMSA3(SHA-1)", OID{1, 2, 840, 113549, 1, 1, 5}},
 1455|      1|      {"RSA/EMSA3(SHA-256)", OID{1, 2, 840, 113549, 1, 1, 11}},
 1456|      1|      {"RSA/EMSA3(SHA-384)", OID{1, 2, 840, 113549, 1, 1, 12}},
 1457|      1|      {"RSA/EMSA3(SHA-512)", OID{1, 2, 840, 113549, 1, 1, 13}},
 1458|      1|      {"RSA/EMSA3(SHA-224)", OID{1, 2, 840, 113549, 1, 1, 14}},
 1459|      1|      {"RSA/EMSA3(SHA-512-256)", OID{1, 2, 840, 113549, 1, 1, 16}},
 1460|      1|      {"RSA/EMSA3(SHA-3(224))", OID{2, 16, 840, 1, 101, 3, 4, 3, 13}},
 1461|      1|      {"RSA/EMSA3(SHA-3(256))", OID{2, 16, 840, 1, 101, 3, 4, 3, 14}},
 1462|      1|      {"RSA/EMSA3(SHA-3(384))", OID{2, 16, 840, 1, 101, 3, 4, 3, 15}},
 1463|      1|      {"RSA/EMSA3(SHA-3(512))", OID{2, 16, 840, 1, 101, 3, 4, 3, 16}},
 1464|      1|      {"RSA/EMSA3(SM3)", OID{1, 2, 156, 10197, 1, 504}},
 1465|      1|      {"RSA/EMSA3(RIPEMD-160)", OID{1, 3, 36, 3, 3, 1, 2}},
 1466|      1|      {"RSA/EMSA4", OID{1, 2, 840, 113549, 1, 1, 10}},
 1467|      1|      {"PBES2", OID{1, 2, 840, 113549, 1, 5, 13}},
 1468|      1|   };
 1469|      1|}
static_oids.cpp:_ZN5Botan12_GLOBAL__N_113hash_oid_nameENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
   34|    891|uint32_t hash_oid_name(std::string_view s) {
   35|    891|   uint64_t hash = 0x8188B31879A4879A;
   36|       |
   37|  17.8k|   for(const char c : s) {
  ------------------
  |  Branch (37:21): [True: 17.8k, False: 891]
  ------------------
   38|  17.8k|      hash *= 251;
   39|  17.8k|      hash += c;
   40|  17.8k|   }
   41|       |
   42|    891|   return static_cast<uint32_t>(hash % 805289);
   43|    891|}
static_oids.cpp:_ZN5Botan12_GLOBAL__N_18if_matchENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEES5_St16initializer_listIjE:
   26|    891|std::optional<OID> if_match(std::string_view req, std::string_view actual, std::initializer_list<uint32_t> oid) {
   27|    891|   if(req == actual) {
  ------------------
  |  Branch (27:7): [True: 891, False: 0]
  ------------------
   28|    891|      return OID(oid);
   29|    891|   } else {
   30|      0|      return {};
   31|      0|   }
   32|    891|}

_ZN5Botan13base64_decodeEPKcmb:
  189|    185|secure_vector<uint8_t> base64_decode(const char input[], size_t input_length, bool ignore_ws) {
  190|    185|   return base_decode_to_vec<secure_vector<uint8_t>>(Base64(), input, input_length, ignore_ws);
  191|    185|}
base64.cpp:_ZN5Botan12_GLOBAL__N_16Base6417decode_max_outputEm:
   43|    370|      static constexpr size_t decode_max_output(size_t input_length) {
   44|       |         // Divide before multiply to avoid overflow; round_up makes the division exact.
   45|    370|         return (round_up(input_length, m_encoding_bytes_out) / m_encoding_bytes_out) * m_encoding_bytes_in;
   46|    370|      }
base64.cpp:_ZN5Botan12_GLOBAL__N_16Base6413bits_consumedEv:
   34|     33|      static constexpr size_t bits_consumed() noexcept { return m_encoding_bits; }
base64.cpp:_ZN5Botan12_GLOBAL__N_16Base6419lookup_binary_valueEc:
  112|  49.5k|uint8_t Base64::lookup_binary_value(char input) noexcept {
  113|  49.5k|   auto has_zero_byte = [](uint64_t v) { return ((v - 0x0101010101010101) & ~(v) & 0x8080808080808080); };
  114|       |
  115|       |   // Assumes each byte is either 0x00 or 0x80
  116|  49.5k|   auto index_of_first_set_byte = [](uint64_t v) {
  117|  49.5k|      return ((((v - 1) & 0x0101010101010101) * 0x0101010101010101) >> 56) - 1;
  118|  49.5k|   };
  119|       |
  120|  49.5k|   constexpr uint64_t lo = 0x0101010101010101;
  121|       |
  122|  49.5k|   const uint8_t x = static_cast<uint8_t>(input);
  123|       |
  124|  49.5k|   const uint64_t x8 = x * lo;
  125|       |
  126|       |   // Defines the valid ASCII ranges of base64, except the special chars (below)
  127|  49.5k|   constexpr uint64_t val_l = make_uint64(0, 0, 0, 0, 0, 'A', 'a', '0');
  128|  49.5k|   constexpr uint64_t val_u = make_uint64(0, 0, 0, 0, 0, 26, 26, 10);
  129|       |
  130|       |   // If x is in one of the ranges return a mask. Otherwise we xor in at the
  131|       |   // high word which will be our invalid marker
  132|  49.5k|   auto v_mask = swar_in_range<uint64_t>(x8, val_l, val_u) ^ 0x80000000;
  133|       |
  134|       |   // This is the offset added to x to get the value
  135|  49.5k|   const uint64_t val_v = 0xbfb904 ^ (0xFF000000 - (x << 24));
  136|       |
  137|  49.5k|   const uint8_t z = x + static_cast<uint8_t>(val_v >> (8 * index_of_first_set_byte(v_mask)));
  138|       |
  139|       |   // Valid base64 special characters, and some whitespace chars
  140|  49.5k|   constexpr uint64_t specials_i = make_uint64(0, '+', '/', '=', ' ', '\n', '\t', '\r');
  141|       |
  142|  49.5k|   const uint64_t specials_v = 0x3e3f8180808080 ^ (static_cast<uint64_t>(z) << 56);
  143|       |
  144|  49.5k|   const uint64_t smask = has_zero_byte(x8 ^ specials_i) ^ 0x8000000000000000;
  145|       |
  146|  49.5k|   return static_cast<uint8_t>(specials_v >> (8 * index_of_first_set_byte(smask)));
  147|  49.5k|}
base64.cpp:_ZZN5Botan12_GLOBAL__N_16Base6419lookup_binary_valueEcENK3$_0clEm:
  116|  99.1k|   auto index_of_first_set_byte = [](uint64_t v) {
  117|  99.1k|      return ((((v - 1) & 0x0101010101010101) * 0x0101010101010101) >> 56) - 1;
  118|  99.1k|   };
base64.cpp:_ZZN5Botan12_GLOBAL__N_16Base6419lookup_binary_valueEcENK3$_1clEm:
  113|  49.5k|   auto has_zero_byte = [](uint64_t v) { return ((v - 0x0101010101010101) & ~(v) & 0x8080808080808080); };
base64.cpp:_ZN5Botan12_GLOBAL__N_16Base6414check_bad_charEhcb:
  150|  36.9k|bool Base64::check_bad_char(uint8_t bin, char input, bool ignore_ws) {
  151|  36.9k|   if(bin <= 0x3F) {
  ------------------
  |  Branch (151:7): [True: 11.9k, False: 25.0k]
  ------------------
  152|  11.9k|      return true;
  153|  25.0k|   } else if(!(bin == 0x81 || (bin == 0x80 && ignore_ws))) {
  ------------------
  |  Branch (153:16): [True: 219, False: 24.8k]
  |  Branch (153:32): [True: 24.8k, False: 49]
  |  Branch (153:47): [True: 24.8k, False: 0]
  ------------------
  154|     49|      throw Invalid_Argument(fmt("base64_decode: invalid character '{}'", format_char_for_display(input)));
  155|     49|   }
  156|  25.0k|   return false;
  157|  36.9k|}
base64.cpp:_ZN5Botan12_GLOBAL__N_16Base644nameEv:
   24|     34|      static std::string name() { return "base64"; }
base64.cpp:_ZN5Botan12_GLOBAL__N_16Base646decodeEPhPKh:
   54|  2.98k|      static void decode(uint8_t* out_ptr, const uint8_t decode_buf[4]) {
   55|  2.98k|         out_ptr[0] = (decode_buf[0] << 2) | (decode_buf[1] >> 4);
   56|  2.98k|         out_ptr[1] = (decode_buf[1] << 4) | (decode_buf[2] >> 2);
   57|  2.98k|         out_ptr[2] = (decode_buf[2] << 6) | decode_buf[3];
   58|  2.98k|      }
base64.cpp:_ZN5Botan12_GLOBAL__N_16Base6415bytes_to_removeEm:
   60|    127|      static size_t bytes_to_remove(size_t final_truncate) { return final_truncate; }

_ZNK5Botan6BigInt7byte_atEm:
  117|  16.7k|uint8_t BigInt::byte_at(size_t n) const {
  118|  16.7k|   return get_byte_var(sizeof(word) - (n % sizeof(word)) - 1, word_at(n / sizeof(word)));
  119|  16.7k|}
_ZNK5Botan6BigInt8cmp_wordEm:
  121|  8.96k|int32_t BigInt::cmp_word(word other) const {
  122|  8.96k|   if(signum() < 0) {
  ------------------
  |  Branch (122:7): [True: 759, False: 8.20k]
  ------------------
  123|    759|      return -1;  // other is positive ...
  124|    759|   }
  125|       |
  126|  8.20k|   const size_t sw = this->sig_words();
  127|  8.20k|   if(sw > 1) {
  ------------------
  |  Branch (127:7): [True: 1.61k, False: 6.59k]
  ------------------
  128|  1.61k|      return 1;  // must be larger since other is just one word ...
  129|  1.61k|   }
  130|       |
  131|  6.59k|   return bigint_cmp(this->_data(), sw, &other, 1);
  132|  8.20k|}
_ZN5Botan6BigInt4Data11set_to_zeroEv:
  190|  14.1k|void BigInt::Data::set_to_zero() {
  191|  14.1k|   m_reg.resize(m_reg.capacity());
  192|  14.1k|   clear_mem(m_reg.data(), m_reg.size());
  193|  14.1k|   m_sig_words = 0;
  194|  14.1k|}
_ZNK5Botan6BigInt4Data14calc_sig_wordsEv:
  214|  14.1k|size_t BigInt::Data::calc_sig_words() const {
  215|  14.1k|   const size_t sz = m_reg.size();
  216|  14.1k|   size_t sig = sz;
  217|       |
  218|  14.1k|   word sub = 1;
  219|       |
  220|   129k|   for(size_t i = 0; i != sz; ++i) {
  ------------------
  |  Branch (220:22): [True: 115k, False: 14.1k]
  ------------------
  221|   115k|      const word w = m_reg[sz - i - 1];
  222|   115k|      sub &= ct_is_zero(w);
  223|   115k|      sig -= sub;
  224|   115k|   }
  225|       |
  226|       |   /*
  227|       |   * This depends on the data so is poisoned, but unpoison it here as
  228|       |   * later conditionals are made on the size.
  229|       |   */
  230|  14.1k|   CT::unpoison(sig);
  231|       |
  232|  14.1k|   return sig;
  233|  14.1k|}
_ZNK5Botan6BigInt5bytesEv:
  293|  18.8k|size_t BigInt::bytes() const {
  294|  18.8k|   return round_up(bits(), 8) / 8;
  295|  18.8k|}
_ZNK5Botan6BigInt13top_bits_freeEv:
  297|  23.0k|size_t BigInt::top_bits_free() const {
  298|  23.0k|   const size_t words = sig_words();
  299|       |
  300|  23.0k|   const word top_word = word_at(words - 1);
  301|  23.0k|   const size_t bits_used = high_bit(CT::value_barrier(top_word));
  302|  23.0k|   CT::unpoison(bits_used);
  303|  23.0k|   return WordInfo<word>::bits - bits_used;
  304|  23.0k|}
_ZNK5Botan6BigInt4bitsEv:
  306|  23.1k|size_t BigInt::bits() const {
  307|  23.1k|   const size_t words = sig_words();
  308|       |
  309|  23.1k|   if(words == 0) {
  ------------------
  |  Branch (309:7): [True: 75, False: 23.0k]
  ------------------
  310|     75|      return 0;
  311|     75|   }
  312|       |
  313|  23.0k|   const size_t full_words = (words - 1) * WordInfo<word>::bits;
  314|  23.0k|   const size_t top_bits = WordInfo<word>::bits - top_bits_free();
  315|       |
  316|  23.0k|   return full_words + top_bits;
  317|  23.1k|}
_ZNK5Botan6BigInt12serialize_toENSt3__14spanIhLm18446744073709551615EEE:
  394|  9.43k|void BigInt::serialize_to(std::span<uint8_t> output) const {
  395|  9.43k|   BOTAN_ARG_CHECK(this->bytes() <= output.size(), "Insufficient output space");
  ------------------
  |  |   35|  9.43k|   do {                                                          \
  |  |   36|  9.43k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */              \
  |  |   37|  9.43k|      if(!(expr)) {                                              \
  |  |  ------------------
  |  |  |  Branch (37:10): [True: 0, False: 9.43k]
  |  |  ------------------
  |  |   38|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */     \
  |  |   39|      0|         Botan::throw_invalid_argument(msg, __func__, __FILE__); \
  |  |   40|      0|      }                                                          \
  |  |   41|  9.43k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (41:12): [Folded, False: 9.43k]
  |  |  ------------------
  ------------------
  396|       |
  397|  9.43k|   this->binary_encode(output.data(), output.size());
  398|  9.43k|}
_ZNK5Botan6BigInt13binary_encodeEPhm:
  403|  9.43k|void BigInt::binary_encode(uint8_t output[], size_t len) const {
  404|  9.43k|   const size_t full_words = len / sizeof(word);
  405|  9.43k|   const size_t extra_bytes = len % sizeof(word);
  406|       |
  407|  14.6k|   for(size_t i = 0; i != full_words; ++i) {
  ------------------
  |  Branch (407:22): [True: 5.23k, False: 9.43k]
  ------------------
  408|  5.23k|      const word w = word_at(i);
  409|  5.23k|      store_be(w, output + (len - (i + 1) * sizeof(word)));
  410|  5.23k|   }
  411|       |
  412|  9.43k|   if(extra_bytes > 0) {
  ------------------
  |  Branch (412:7): [True: 9.29k, False: 142]
  ------------------
  413|  9.29k|      const word w = word_at(full_words);
  414|       |
  415|  33.7k|      for(size_t i = 0; i != extra_bytes; ++i) {
  ------------------
  |  Branch (415:25): [True: 24.4k, False: 9.29k]
  ------------------
  416|  24.4k|         output[extra_bytes - i - 1] = get_byte_var(sizeof(word) - i - 1, w);
  417|  24.4k|      }
  418|  9.29k|   }
  419|  9.43k|}
_ZN5Botan6BigInt17assign_from_bytesENSt3__14spanIKhLm18446744073709551615EEE:
  424|  14.1k|void BigInt::assign_from_bytes(std::span<const uint8_t> bytes) {
  425|  14.1k|   clear();
  426|       |
  427|  14.1k|   const size_t length = bytes.size();
  428|  14.1k|   const size_t full_words = length / sizeof(word);
  429|  14.1k|   const size_t extra_bytes = length % sizeof(word);
  430|       |
  431|  14.1k|   secure_vector<word> reg((round_up(full_words + (extra_bytes > 0 ? 1 : 0), 8)));
  ------------------
  |  Branch (431:52): [True: 12.3k, False: 1.83k]
  ------------------
  432|       |
  433|  21.0k|   for(size_t i = 0; i != full_words; ++i) {
  ------------------
  |  Branch (433:22): [True: 6.92k, False: 14.1k]
  ------------------
  434|  6.92k|      reg[i] = load_be<word>(bytes.last<sizeof(word)>());
  435|  6.92k|      bytes = bytes.first(bytes.size() - sizeof(word));
  436|  6.92k|   }
  437|       |
  438|  14.1k|   if(!bytes.empty()) {
  ------------------
  |  Branch (438:7): [True: 12.3k, False: 1.83k]
  ------------------
  439|  12.3k|      BOTAN_ASSERT_NOMSG(extra_bytes == bytes.size());
  ------------------
  |  |   84|  12.3k|   do {                                                                     \
  |  |   85|  12.3k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|  12.3k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 12.3k]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|  12.3k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 12.3k]
  |  |  ------------------
  ------------------
  440|  12.3k|      std::array<uint8_t, sizeof(word)> last_partial_word = {0};
  441|  12.3k|      copy_mem(std::span{last_partial_word}.last(extra_bytes), bytes);
  442|  12.3k|      reg[full_words] = load_be<word>(last_partial_word);
  443|  12.3k|   }
  444|       |
  445|  14.1k|   m_data.swap(reg);
  446|  14.1k|}
_ZNK5Botan6BigInt20_const_time_unpoisonEv:
  558|  29.7k|void BigInt::_const_time_unpoison() const {
  559|  29.7k|   CT::unpoison(m_data.const_data(), m_data.size());
  560|  29.7k|}

_ZN5Botan8PEM_Code6decodeERNS_10DataSourceERNSt3__112basic_stringIcNS3_11char_traitsIcEENS3_9allocatorIcEEEE:
   64|    351|secure_vector<uint8_t> decode(DataSource& source, std::string& label) {
   65|    351|   const size_t RANDOM_CHAR_LIMIT = 8;
   66|       |
   67|    351|   label.clear();
   68|       |
   69|    351|   const std::string PEM_HEADER1 = "-----BEGIN ";
   70|    351|   const std::string PEM_HEADER2 = "-----";
   71|    351|   size_t position = 0;
   72|       |
   73|  34.2k|   while(position != PEM_HEADER1.length()) {
  ------------------
  |  Branch (73:10): [True: 33.9k, False: 306]
  ------------------
   74|  33.9k|      auto b = source.read_byte();
   75|       |
   76|  33.9k|      if(!b) {
  ------------------
  |  Branch (76:10): [True: 44, False: 33.9k]
  ------------------
   77|     44|         throw Decoding_Error("PEM: No PEM header found");
   78|     44|      }
   79|  33.9k|      if(static_cast<char>(*b) == PEM_HEADER1[position]) {
  ------------------
  |  Branch (79:10): [True: 3.61k, False: 30.2k]
  ------------------
   80|  3.61k|         ++position;
   81|  30.2k|      } else if(position >= RANDOM_CHAR_LIMIT) {
  ------------------
  |  Branch (81:17): [True: 1, False: 30.2k]
  ------------------
   82|      1|         throw Decoding_Error("PEM: Malformed PEM header");
   83|  30.2k|      } else {
   84|  30.2k|         position = 0;
   85|  30.2k|      }
   86|  33.9k|   }
   87|    306|   position = 0;
   88|  4.75k|   while(position != PEM_HEADER2.length()) {
  ------------------
  |  Branch (88:10): [True: 4.49k, False: 260]
  ------------------
   89|  4.49k|      auto b = source.read_byte();
   90|       |
   91|  4.49k|      if(!b) {
  ------------------
  |  Branch (91:10): [True: 42, False: 4.44k]
  ------------------
   92|     42|         throw Decoding_Error("PEM: No PEM header found");
   93|     42|      }
   94|  4.44k|      if(static_cast<char>(*b) == PEM_HEADER2[position]) {
  ------------------
  |  Branch (94:10): [True: 1.31k, False: 3.13k]
  ------------------
   95|  1.31k|         ++position;
   96|  3.13k|      } else if(position > 0) {
  ------------------
  |  Branch (96:17): [True: 3, False: 3.13k]
  ------------------
   97|      3|         throw Decoding_Error("PEM: Malformed PEM header");
   98|      3|      }
   99|       |
  100|  4.44k|      if(position == 0) {
  ------------------
  |  Branch (100:10): [True: 3.13k, False: 1.31k]
  ------------------
  101|  3.13k|         if(label.size() >= 128) {
  ------------------
  |  Branch (101:13): [True: 1, False: 3.12k]
  ------------------
  102|      1|            throw Decoding_Error("PEM: Label too long");
  103|      1|         }
  104|  3.12k|         label += static_cast<char>(*b);
  105|  3.12k|      }
  106|  4.44k|   }
  107|       |
  108|    260|   std::vector<char> b64;
  109|       |
  110|    260|   const std::string PEM_TRAILER = fmt("-----END {}-----", label);
  111|    260|   position = 0;
  112|  81.2k|   while(position != PEM_TRAILER.length()) {
  ------------------
  |  Branch (112:10): [True: 81.1k, False: 185]
  ------------------
  113|  81.1k|      auto b = source.read_byte();
  114|       |
  115|  81.1k|      if(!b) {
  ------------------
  |  Branch (115:10): [True: 67, False: 81.0k]
  ------------------
  116|     67|         throw Decoding_Error("PEM: No PEM trailer found");
  117|     67|      }
  118|  81.0k|      if(static_cast<char>(*b) == PEM_TRAILER[position]) {
  ------------------
  |  Branch (118:10): [True: 3.64k, False: 77.3k]
  ------------------
  119|  3.64k|         ++position;
  120|  77.3k|      } else if(position > 0) {
  ------------------
  |  Branch (120:17): [True: 8, False: 77.3k]
  ------------------
  121|      8|         throw Decoding_Error("PEM: Malformed PEM trailer");
  122|      8|      }
  123|       |
  124|  81.0k|      if(position == 0) {
  ------------------
  |  Branch (124:10): [True: 77.3k, False: 3.64k]
  ------------------
  125|  77.3k|         b64.push_back(*b);
  126|  77.3k|      }
  127|  81.0k|   }
  128|       |
  129|    185|   return base64_decode(b64.data(), b64.size());
  130|    260|}
_ZN5Botan8PEM_Code7matchesERNS_10DataSourceENSt3__117basic_string_viewIcNS3_11char_traitsIcEEEEm:
  145|  3.50k|bool matches(DataSource& source, std::string_view extra, size_t search_range) {
  146|  3.50k|   const std::string PEM_HEADER = fmt("-----BEGIN {}", extra);
  147|       |
  148|  3.50k|   std::array<uint8_t, 4096> stack_buf{};
  149|  3.50k|   std::vector<uint8_t> heap_buf;
  150|  3.50k|   uint8_t* search_buf = stack_buf.data();
  151|  3.50k|   if(search_range > stack_buf.size()) {
  ------------------
  |  Branch (151:7): [True: 0, False: 3.50k]
  ------------------
  152|      0|      heap_buf.resize(search_range);
  153|      0|      search_buf = heap_buf.data();
  154|      0|   }
  155|       |
  156|  3.50k|   const size_t got = source.peek(search_buf, search_range, 0);
  157|       |
  158|  3.50k|   if(got < PEM_HEADER.length()) {
  ------------------
  |  Branch (158:7): [True: 459, False: 3.04k]
  ------------------
  159|    459|      return false;
  160|    459|   }
  161|       |
  162|  3.04k|   return std::search(search_buf, search_buf + got, PEM_HEADER.begin(), PEM_HEADER.end()) != search_buf + got;
  163|  3.50k|}

_ZN5Botan15allocate_memoryEmm:
   21|  34.3k|BOTAN_MALLOC_FN void* allocate_memory(size_t elems, size_t elem_size) {
   22|  34.3k|   if(elems == 0 || elem_size == 0) {
  ------------------
  |  Branch (22:7): [True: 0, False: 34.3k]
  |  Branch (22:21): [True: 0, False: 34.3k]
  ------------------
   23|      0|      return nullptr;
   24|      0|   }
   25|       |
   26|       |   // Some calloc implementations do not check for overflow (?!?)
   27|  34.3k|   if(!checked_mul(elems, elem_size).has_value()) {
  ------------------
  |  Branch (27:7): [True: 0, False: 34.3k]
  ------------------
   28|      0|      throw std::bad_alloc();
   29|      0|   }
   30|       |
   31|       |#if defined(BOTAN_HAS_LOCKING_ALLOCATOR)
   32|       |   // NOLINTNEXTLINE(*-const-correctness) bug in clang-tidy
   33|       |   if(void* p = mlock_allocator::instance().allocate(elems, elem_size)) {
   34|       |      return p;
   35|       |   }
   36|       |#endif
   37|       |
   38|       |#if defined(BOTAN_TARGET_OS_HAS_ALLOC_CONCEAL)
   39|       |   void* ptr = ::calloc_conceal(elems, elem_size);
   40|       |#else
   41|       |   // NOLINTNEXTLINE(*-const-correctness) bug in clang-tidy
   42|  34.3k|   void* ptr = std::calloc(elems, elem_size);  // NOLINT(*-no-malloc,*-owning-memory)
   43|  34.3k|#endif
   44|  34.3k|   if(ptr == nullptr) {
  ------------------
  |  Branch (44:7): [True: 0, False: 34.3k]
  ------------------
   45|      0|      [[unlikely]] throw std::bad_alloc();
   46|      0|   }
   47|  34.3k|   return ptr;
   48|  34.3k|}
_ZN5Botan17deallocate_memoryEPvmm:
   50|  34.3k|void deallocate_memory(void* p, size_t elems, size_t elem_size) {
   51|  34.3k|   if(p == nullptr) {
  ------------------
  |  Branch (51:7): [True: 0, False: 34.3k]
  ------------------
   52|      0|      [[unlikely]] return;
   53|      0|   }
   54|       |
   55|  34.3k|   secure_scrub_memory(p, elems * elem_size);
   56|       |
   57|       |#if defined(BOTAN_HAS_LOCKING_ALLOCATOR)
   58|       |   if(mlock_allocator::instance().deallocate(p, elems, elem_size)) {
   59|       |      return;
   60|       |   }
   61|       |#endif
   62|       |
   63|  34.3k|   std::free(p);  // NOLINT(*-no-malloc,*-owning-memory)
   64|  34.3k|}

_ZN5Botan22throw_invalid_argumentEPKcS1_S1_:
   23|     42|void throw_invalid_argument(const char* message, const char* func, const char* file) {
   24|     42|   throw Invalid_Argument(fmt("{} in {}:{}", message, func, file));
   25|     42|}

_ZN5Botan19next_utf8_codepointENSt3__117basic_string_viewIcNS0_11char_traitsIcEEEERm:
   53|  15.3k|uint32_t next_utf8_codepoint(std::string_view utf8, size_t& pos) {
   54|  15.3k|   auto read_continuation = [&]() -> uint32_t {
   55|  15.3k|      if(pos >= utf8.size()) {
   56|  15.3k|         throw Decoding_Error("Invalid UTF-8 sequence");
   57|  15.3k|      }
   58|  15.3k|      const uint8_t b = static_cast<uint8_t>(utf8[pos++]);
   59|  15.3k|      if((b & 0xC0) != 0x80) {
   60|  15.3k|         throw Decoding_Error("Invalid UTF-8 sequence");
   61|  15.3k|      }
   62|  15.3k|      return b & 0x3F;
   63|  15.3k|   };
   64|       |
   65|  15.3k|   if(pos >= utf8.size()) {
  ------------------
  |  Branch (65:7): [True: 0, False: 15.3k]
  ------------------
   66|      0|      throw Decoding_Error("Invalid UTF-8 sequence");
   67|      0|   }
   68|  15.3k|   const uint8_t lead = static_cast<uint8_t>(utf8[pos++]);
   69|  15.3k|   uint32_t c = 0;
   70|       |
   71|  15.3k|   if(lead <= 0x7F) {
  ------------------
  |  Branch (71:7): [True: 14.9k, False: 397]
  ------------------
   72|  14.9k|      c = lead;
   73|  14.9k|   } else if((lead & 0xE0) == 0xC0) {
  ------------------
  |  Branch (73:14): [True: 144, False: 253]
  ------------------
   74|    144|      c = (lead & 0x1F) << 6;
   75|    144|      c |= read_continuation();
   76|    144|      if(c < 0x80) {
  ------------------
  |  Branch (76:10): [True: 20, False: 124]
  ------------------
   77|     20|         throw Decoding_Error("Overlong UTF-8 sequence");
   78|     20|      }
   79|    253|   } else if((lead & 0xF0) == 0xE0) {
  ------------------
  |  Branch (79:14): [True: 101, False: 152]
  ------------------
   80|    101|      c = (lead & 0x0F) << 12;
   81|    101|      c |= read_continuation() << 6;
   82|    101|      c |= read_continuation();
   83|    101|      if(c < 0x800) {
  ------------------
  |  Branch (83:10): [True: 8, False: 93]
  ------------------
   84|      8|         throw Decoding_Error("Overlong UTF-8 sequence");
   85|      8|      }
   86|    152|   } else if((lead & 0xF8) == 0xF0) {
  ------------------
  |  Branch (86:14): [True: 96, False: 56]
  ------------------
   87|     96|      c = (lead & 0x07) << 18;
   88|     96|      c |= read_continuation() << 12;
   89|     96|      c |= read_continuation() << 6;
   90|     96|      c |= read_continuation();
   91|     96|      if(c < 0x10000) {
  ------------------
  |  Branch (91:10): [True: 4, False: 92]
  ------------------
   92|      4|         throw Decoding_Error("Overlong UTF-8 sequence");
   93|      4|      }
   94|     96|   } else {
   95|     56|      throw Decoding_Error("Invalid UTF-8 sequence");
   96|     56|   }
   97|       |
   98|  15.2k|   if(c > 0x10FFFF) {
  ------------------
  |  Branch (98:7): [True: 3, False: 15.2k]
  ------------------
   99|      3|      throw Decoding_Error("UTF-8 sequence encodes value outside Unicode range");
  100|      3|   }
  101|  15.2k|   if(c >= 0xD800 && c < 0xE000) {
  ------------------
  |  Branch (101:7): [True: 94, False: 15.1k]
  |  Branch (101:22): [True: 6, False: 88]
  ------------------
  102|      6|      throw Decoding_Error("UTF-8 sequence encodes surrogate code point");
  103|      6|   }
  104|       |
  105|  15.2k|   return c;
  106|  15.2k|}
_ZN5Botan13is_valid_utf8ENSt3__117basic_string_viewIcNS0_11char_traitsIcEEEE:
  108|  1.99k|bool is_valid_utf8(std::string_view utf8) {
  109|  1.99k|   try {
  110|  1.99k|      size_t pos = 0;
  111|  17.3k|      while(pos < utf8.size()) {
  ------------------
  |  Branch (111:13): [True: 15.3k, False: 1.99k]
  ------------------
  112|  15.3k|         const uint32_t c = next_utf8_codepoint(utf8, pos);
  113|  15.3k|         BOTAN_UNUSED(c);
  ------------------
  |  |  151|  15.3k|#define BOTAN_UNUSED Botan::ignore_params
  ------------------
  114|  15.3k|      }
  115|  1.99k|   } catch(Decoding_Error&) {
  116|    148|      return false;
  117|    148|   }
  118|  1.84k|   return true;
  119|  1.99k|}
_ZN5Botan12ucs2_to_utf8ENSt3__14spanIKhLm18446744073709551615EEE:
  121|    286|std::string ucs2_to_utf8(std::span<const uint8_t> ucs2) {
  122|    286|   if(ucs2.size() % 2 != 0) {
  ------------------
  |  Branch (122:7): [True: 3, False: 283]
  ------------------
  123|      3|      throw Decoding_Error("Invalid length for UCS-2 string");
  124|      3|   }
  125|       |
  126|    283|   const size_t chars = ucs2.size() / 2;
  127|       |
  128|    283|   std::string s;
  129|  1.35k|   for(size_t i = 0; i != chars; ++i) {
  ------------------
  |  Branch (129:22): [True: 1.06k, False: 283]
  ------------------
  130|  1.06k|      const uint32_t c = load_be<uint16_t>(ucs2.data(), i);
  131|  1.06k|      append_utf8_for(s, c);
  132|  1.06k|   }
  133|       |
  134|    283|   return s;
  135|    286|}
_ZN5Botan12ucs4_to_utf8ENSt3__14spanIKhLm18446744073709551615EEE:
  155|     96|std::string ucs4_to_utf8(std::span<const uint8_t> ucs4) {
  156|     96|   if(ucs4.size() % 4 != 0) {
  ------------------
  |  Branch (156:7): [True: 5, False: 91]
  ------------------
  157|      5|      throw Decoding_Error("Invalid length for UCS-4 string");
  158|      5|   }
  159|       |
  160|     91|   const size_t chars = ucs4.size() / 4;
  161|       |
  162|     91|   std::string s;
  163|    256|   for(size_t i = 0; i != chars; ++i) {
  ------------------
  |  Branch (163:22): [True: 165, False: 91]
  ------------------
  164|    165|      const uint32_t c = load_be<uint32_t>(ucs4.data(), i);
  165|    165|      append_utf8_for(s, c);
  166|    165|   }
  167|       |
  168|     91|   return s;
  169|     96|}
_ZN5Botan14latin1_to_utf8ENSt3__14spanIKhLm18446744073709551615EEE:
  190|    246|std::string latin1_to_utf8(std::span<const uint8_t> chars) {
  191|    246|   std::string s;
  192|  4.33k|   for(const uint8_t b : chars) {
  ------------------
  |  Branch (192:24): [True: 4.33k, False: 246]
  ------------------
  193|  4.33k|      append_utf8_for(s, static_cast<uint32_t>(b));
  194|  4.33k|   }
  195|    246|   return s;
  196|    246|}
_ZN5Botan21is_ascii_control_charEc:
  198|     49|bool is_ascii_control_char(char c) {
  199|     49|   const uint8_t b = static_cast<uint8_t>(c);
  200|     49|   return b < 0x20 || b == 0x7F;
  ------------------
  |  Branch (200:11): [True: 16, False: 33]
  |  Branch (200:23): [True: 1, False: 32]
  ------------------
  201|     49|}
_ZN5Botan23format_char_for_displayEc:
  243|     49|std::string format_char_for_display(char c) {
  244|     49|   std::string out;
  245|     49|   out += '\'';
  246|       |
  247|     49|   if(c == '\t') {
  ------------------
  |  Branch (247:7): [True: 0, False: 49]
  ------------------
  248|      0|      out += "\\t";
  249|     49|   } else if(c == '\n') {
  ------------------
  |  Branch (249:14): [True: 0, False: 49]
  ------------------
  250|      0|      out += "\\n";
  251|     49|   } else if(c == '\r') {
  ------------------
  |  Branch (251:14): [True: 0, False: 49]
  ------------------
  252|      0|      out += "\\r";
  253|     49|   } else if(is_ascii_control_char(c) || static_cast<uint8_t>(c) >= 0x80) {
  ------------------
  |  Branch (253:14): [True: 17, False: 32]
  |  Branch (253:42): [True: 23, False: 9]
  ------------------
  254|     40|      const auto b = static_cast<uint8_t>(c);
  255|     40|      out += "\\x";
  256|     40|      out += nibble_to_hex(b >> 4);
  257|     40|      out += nibble_to_hex(b);
  258|     40|   } else {
  259|      9|      out += c;
  260|      9|   }
  261|       |
  262|     49|   out += '\'';
  263|       |
  264|     49|   return out;
  265|     49|}
charset.cpp:_ZZN5Botan19next_utf8_codepointENSt3__117basic_string_viewIcNS0_11char_traitsIcEEEERmENK3$_0clEv:
   54|    614|   auto read_continuation = [&]() -> uint32_t {
   55|    614|      if(pos >= utf8.size()) {
  ------------------
  |  Branch (55:10): [True: 16, False: 598]
  ------------------
   56|     16|         throw Decoding_Error("Invalid UTF-8 sequence");
   57|     16|      }
   58|    598|      const uint8_t b = static_cast<uint8_t>(utf8[pos++]);
   59|    598|      if((b & 0xC0) != 0x80) {
  ------------------
  |  Branch (59:10): [True: 35, False: 563]
  ------------------
   60|     35|         throw Decoding_Error("Invalid UTF-8 sequence");
   61|     35|      }
   62|    563|      return b & 0x3F;
   63|    598|   };
charset.cpp:_ZN5Botan12_GLOBAL__N_115append_utf8_forERNSt3__112basic_stringIcNS1_11char_traitsIcEENS1_9allocatorIcEEEEj:
   17|  5.57k|void append_utf8_for(std::string& s, uint32_t c) {
   18|  5.57k|   if(c >= 0xD800 && c < 0xE000) {
  ------------------
  |  Branch (18:7): [True: 335, False: 5.23k]
  |  Branch (18:22): [True: 16, False: 319]
  ------------------
   19|     16|      throw Decoding_Error("Invalid Unicode character");
   20|     16|   }
   21|       |
   22|  5.55k|   if(c <= 0x7F) {
  ------------------
  |  Branch (22:7): [True: 2.96k, False: 2.59k]
  ------------------
   23|  2.96k|      const uint8_t b0 = static_cast<uint8_t>(c);
   24|  2.96k|      s.push_back(static_cast<char>(b0));
   25|  2.96k|   } else if(c <= 0x7FF) {
  ------------------
  |  Branch (25:14): [True: 1.70k, False: 882]
  ------------------
   26|  1.70k|      const uint8_t b0 = 0xC0 | static_cast<uint8_t>(c >> 6);
   27|  1.70k|      const uint8_t b1 = 0x80 | static_cast<uint8_t>(c & 0x3F);
   28|  1.70k|      s.push_back(static_cast<char>(b0));
   29|  1.70k|      s.push_back(static_cast<char>(b1));
   30|  1.70k|   } else if(c <= 0xFFFF) {
  ------------------
  |  Branch (30:14): [True: 733, False: 149]
  ------------------
   31|    733|      const uint8_t b0 = 0xE0 | static_cast<uint8_t>(c >> 12);
   32|    733|      const uint8_t b1 = 0x80 | static_cast<uint8_t>((c >> 6) & 0x3F);
   33|    733|      const uint8_t b2 = 0x80 | static_cast<uint8_t>(c & 0x3F);
   34|    733|      s.push_back(static_cast<char>(b0));
   35|    733|      s.push_back(static_cast<char>(b1));
   36|    733|      s.push_back(static_cast<char>(b2));
   37|    733|   } else if(c <= 0x10FFFF) {
  ------------------
  |  Branch (37:14): [True: 95, False: 54]
  ------------------
   38|     95|      const uint8_t b0 = 0xF0 | static_cast<uint8_t>(c >> 18);
   39|     95|      const uint8_t b1 = 0x80 | static_cast<uint8_t>((c >> 12) & 0x3F);
   40|     95|      const uint8_t b2 = 0x80 | static_cast<uint8_t>((c >> 6) & 0x3F);
   41|     95|      const uint8_t b3 = 0x80 | static_cast<uint8_t>(c & 0x3F);
   42|     95|      s.push_back(static_cast<char>(b0));
   43|     95|      s.push_back(static_cast<char>(b1));
   44|     95|      s.push_back(static_cast<char>(b2));
   45|     95|      s.push_back(static_cast<char>(b3));
   46|     95|   } else {
   47|     54|      throw Decoding_Error("Invalid Unicode character");
   48|     54|   }
   49|  5.55k|}

_ZN5Botan10DataSource9read_byteERh:
   27|   154k|size_t DataSource::read_byte(uint8_t& out) {
   28|   154k|   return read(&out, 1);
   29|   154k|}
_ZN5Botan10DataSource9read_byteEv:
   34|   259k|std::optional<uint8_t> DataSource::read_byte() {
   35|   259k|   uint8_t b = 0;
   36|   259k|   if(this->read(&b, 1) == 1) {
  ------------------
  |  Branch (36:7): [True: 259k, False: 447]
  ------------------
   37|   259k|      return b;
   38|   259k|   } else {
   39|    447|      return {};
   40|    447|   }
   41|   259k|}
_ZNK5Botan10DataSource9peek_byteERh:
   46|  3.84k|size_t DataSource::peek_byte(uint8_t& out) const {
   47|  3.84k|   return peek(&out, 1, 0);
   48|  3.84k|}
_ZN5Botan17DataSource_Memory4readEPhm:
   73|   245k|size_t DataSource_Memory::read(uint8_t out[], size_t length) {
   74|   245k|   const size_t got = std::min<size_t>(m_source.size() - m_offset, length);
   75|   245k|   copy_mem(out, m_source.data() + m_offset, got);
   76|   245k|   m_offset += got;
   77|   245k|   return got;
   78|   245k|}
_ZN5Botan17DataSource_Memory15check_availableEm:
   80|  37.7k|bool DataSource_Memory::check_available(size_t n) {
   81|  37.7k|   return (n <= (m_source.size() - m_offset));
   82|  37.7k|}
_ZNK5Botan17DataSource_Memory4peekEPhmm:
   87|  7.35k|size_t DataSource_Memory::peek(uint8_t out[], size_t length, size_t peek_offset) const {
   88|  7.35k|   const size_t bytes_left = m_source.size() - m_offset;
   89|  7.35k|   if(peek_offset >= bytes_left) {
  ------------------
  |  Branch (89:7): [True: 0, False: 7.35k]
  ------------------
   90|      0|      return 0;
   91|      0|   }
   92|       |
   93|  7.35k|   const size_t got = std::min(bytes_left - peek_offset, length);
   94|  7.35k|   copy_mem(out, &m_source[m_offset + peek_offset], got);
   95|  7.35k|   return got;
   96|  7.35k|}
_ZNK5Botan17DataSource_Memory11end_of_dataEv:
  101|  18.1k|bool DataSource_Memory::end_of_data() const {
  102|  18.1k|   return (m_offset == m_source.size());
  103|  18.1k|}

_ZN5Botan7DNSName11from_stringENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
  134|  1.31k|std::optional<DNSName> DNSName::from_string(std::string_view name) {
  135|  1.31k|   if(auto canon = check_and_canonicalize_dns_name(name)) {
  ------------------
  |  Branch (135:12): [True: 1.18k, False: 131]
  ------------------
  136|       |      // TODO(C++23) std::string::contains
  137|  1.18k|      if(canon->find('*') != std::string::npos) {
  ------------------
  |  Branch (137:10): [True: 14, False: 1.17k]
  ------------------
  138|     14|         return {};
  139|     14|      }
  140|  1.17k|      return DNSName(std::move(*canon));
  141|  1.18k|   } else {
  142|    131|      return {};
  143|    131|   }
  144|  1.31k|}
_ZN5Botan7DNSName15from_san_stringENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
  147|    687|std::optional<DNSName> DNSName::from_san_string(std::string_view name) {
  148|    687|   if(auto canon = check_and_canonicalize_dns_name(name)) {
  ------------------
  |  Branch (148:12): [True: 649, False: 38]
  ------------------
  149|       |      /*
  150|       |      Validate the wildcard shape: at most one "*", and if present it must be in
  151|       |      the leftmost label (no "." before it). This matches the RFC 6125 6.4.3
  152|       |      form that host_wildcard_match accepts and rejects eg "*.*.example.com" or
  153|       |      "foo.*.example.com"
  154|       |      */
  155|    649|      const auto first_star = canon->find('*');
  156|    649|      if(first_star != std::string::npos) {
  ------------------
  |  Branch (156:10): [True: 55, False: 594]
  ------------------
  157|     55|         if(canon->find('*', first_star + 1) != std::string::npos) {
  ------------------
  |  Branch (157:13): [True: 9, False: 46]
  ------------------
  158|      9|            return std::nullopt;
  159|      9|         }
  160|     46|         const auto first_dot = canon->find('.');
  161|     46|         if(first_dot != std::string::npos && first_dot < first_star) {
  ------------------
  |  Branch (161:13): [True: 32, False: 14]
  |  Branch (161:47): [True: 8, False: 24]
  ------------------
  162|      8|            return std::nullopt;
  163|      8|         }
  164|       |         /*
  165|       |         RFC 6125 6.4.3: "the client SHOULD NOT attempt to match a presented
  166|       |         identifier where the wildcard character is embedded within an
  167|       |         A-label or U-label"
  168|       |         */
  169|     38|         if(canon->starts_with("xn--")) {
  ------------------
  |  Branch (169:13): [True: 3, False: 35]
  ------------------
  170|      3|            return std::nullopt;
  171|      3|         }
  172|       |         // A wildcard match requires at least three labels, so shorter
  173|       |         // patterns ("*", "*.com") could never match any host
  174|     35|         if(std::count(canon->begin(), canon->end(), '.') < 2) {
  ------------------
  |  Branch (174:13): [True: 21, False: 14]
  ------------------
  175|     21|            return std::nullopt;
  176|     21|         }
  177|     35|      }
  178|    608|      return DNSName(std::move(*canon));
  179|    649|   } else {
  180|     38|      return {};
  181|     38|   }
  182|    687|}
dns_name.cpp:_ZN5Botan12_GLOBAL__N_131check_and_canonicalize_dns_nameENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
   21|  2.00k|std::optional<std::string> check_and_canonicalize_dns_name(std::string_view name) {
   22|       |   /*
   23|       |   * RFC 1035 limits names to "255 octets or less", but that is in the wire
   24|       |   * encoding, which includes a length octet per label plus the root label.
   25|       |   * In presentation form (without a trailing dot) the limit is 253.
   26|       |   */
   27|  2.00k|   if(name.size() > 253) {
  ------------------
  |  Branch (27:7): [True: 0, False: 2.00k]
  ------------------
   28|      0|      return {};
   29|      0|   }
   30|       |
   31|       |   // DNS names are not empty
   32|  2.00k|   if(name.empty()) {
  ------------------
  |  Branch (32:7): [True: 0, False: 2.00k]
  ------------------
   33|      0|      return {};
   34|      0|   }
   35|       |
   36|       |   // DNS names do not start with or end with a dot
   37|  2.00k|   if(name.starts_with(".") || name.ends_with(".")) {
  ------------------
  |  Branch (37:7): [True: 7, False: 1.99k]
  |  Branch (37:32): [True: 4, False: 1.99k]
  ------------------
   38|     11|      return {};
   39|     11|   }
   40|       |
   41|       |   /*
   42|       |   * Table mapping uppercase to lowercase and only including values valid for
   43|       |   * DNS names: A-Z, a-z, 0-9, '-', '.', plus '*' for wildcarding (RFC 1035)
   44|       |   */
   45|       |   // clang-format off
   46|  1.99k|   constexpr uint8_t DNS_CHAR_MAPPING[128] = {
   47|  1.99k|      '\0', '\0', '\0', '\0', '\0', '\0', '\0', '\0', '\0', '\0', '\0', '\0', '\0', '\0', '\0', '\0', '\0', '\0', '\0',
   48|  1.99k|      '\0', '\0', '\0', '\0', '\0', '\0', '\0', '\0', '\0', '\0', '\0', '\0', '\0', '\0', '\0', '\0', '\0', '\0', '\0',
   49|  1.99k|      '\0', '\0', '\0', '\0',  '*', '\0', '\0',  '-',  '.', '\0',  '0',  '1',  '2',  '3',  '4',  '5',  '6',  '7',  '8',
   50|  1.99k|       '9', '\0', '\0', '\0', '\0', '\0', '\0', '\0',  'a',  'b',  'c',  'd',  'e',  'f',  'g',  'h',  'i',  'j',  'k',
   51|  1.99k|       'l',  'm',  'n',  'o',  'p',  'q',  'r',  's',  't',  'u',  'v',  'w',  'x',  'y',  'z', '\0', '\0', '\0', '\0',
   52|  1.99k|       '\0', '\0',  'a',  'b',  'c',  'd',  'e',  'f',  'g',  'h',  'i',  'j',  'k',  'l',  'm',  'n',  'o',  'p',  'q',
   53|  1.99k|       'r',  's',  't',  'u',  'v',  'w',  'x',  'y',  'z', '\0', '\0', '\0', '\0', '\0',
   54|  1.99k|   };
   55|       |   // clang-format on
   56|       |
   57|  1.99k|   std::string canon;
   58|  1.99k|   canon.reserve(name.size());
   59|       |
   60|       |   // RFC 1035: DNS labels must not exceed 63 characters
   61|  1.99k|   size_t current_label_length = 0;
   62|       |
   63|       |   // Tracks if the name consists only of digits and dots
   64|  1.99k|   bool all_numeric = true;
   65|       |
   66|  15.7k|   for(size_t i = 0; i != name.size(); ++i) {
  ------------------
  |  Branch (66:22): [True: 13.8k, False: 1.85k]
  ------------------
   67|  13.8k|      const char c = name[i];
   68|       |
   69|  13.8k|      if(c == '.') {
  ------------------
  |  Branch (69:10): [True: 428, False: 13.4k]
  ------------------
   70|       |         // Sequential dot (.) characters are not allowed
   71|    428|         if(i > 0 && name[i - 1] == '.') {
  ------------------
  |  Branch (71:13): [True: 428, False: 0]
  |  Branch (71:22): [True: 5, False: 423]
  ------------------
   72|      5|            return {};
   73|      5|         }
   74|       |
   75|       |         // Empty labels are not allowed
   76|    423|         if(current_label_length == 0) {
  ------------------
  |  Branch (76:13): [True: 0, False: 423]
  ------------------
   77|      0|            return {};
   78|      0|         }
   79|    423|         current_label_length = 0;  // Reset for next label
   80|  13.4k|      } else {
   81|  13.4k|         current_label_length++;
   82|       |
   83|       |         // Labels cannot exceed maximum DNS label length
   84|  13.4k|         if(current_label_length > 63) {
  ------------------
  |  Branch (84:13): [True: 5, False: 13.4k]
  ------------------
   85|      5|            return {};
   86|      5|         }
   87|  13.4k|      }
   88|       |
   89|  13.8k|      const uint8_t cu = static_cast<uint8_t>(c);
   90|       |      // DNS names are not allowed to include any high-bit set characters
   91|  13.8k|      if(cu >= 128) {
  ------------------
  |  Branch (91:10): [True: 45, False: 13.8k]
  ------------------
   92|     45|         return {};
   93|     45|      }
   94|  13.8k|      const uint8_t mapped = DNS_CHAR_MAPPING[cu];
   95|       |      // DNS names are from a restricted character set
   96|  13.8k|      if(mapped == 0) {
  ------------------
  |  Branch (96:10): [True: 71, False: 13.7k]
  ------------------
   97|     71|         return {};
   98|     71|      }
   99|       |
  100|  13.7k|      if(mapped != '.' && (mapped < '0' || mapped > '9')) {
  ------------------
  |  Branch (100:10): [True: 13.3k, False: 423]
  |  Branch (100:28): [True: 506, False: 12.8k]
  |  Branch (100:44): [True: 7.65k, False: 5.17k]
  ------------------
  101|  8.16k|         all_numeric = false;
  102|  8.16k|      }
  103|       |
  104|  13.7k|      if(mapped == '-') {
  ------------------
  |  Branch (104:10): [True: 422, False: 13.3k]
  ------------------
  105|       |         // DNS labels are not allowed to include a leading or trailing hyphen
  106|    422|         if(i == 0 || (i > 0 && name[i - 1] == '.')) {
  ------------------
  |  Branch (106:13): [True: 4, False: 418]
  |  Branch (106:24): [True: 418, False: 0]
  |  Branch (106:33): [True: 4, False: 414]
  ------------------
  107|      8|            return {};  // leading hyphen
  108|      8|         }
  109|       |
  110|    414|         if(i == name.size() - 1 || (i < name.size() - 1 && name[i + 1] == '.')) {
  ------------------
  |  Branch (110:13): [True: 4, False: 410]
  |  Branch (110:38): [True: 410, False: 0]
  |  Branch (110:61): [True: 5, False: 405]
  ------------------
  111|      9|            return {};  // trailing hyphen
  112|      9|         }
  113|    414|      }
  114|  13.7k|      canon.push_back(static_cast<char>(mapped));
  115|  13.7k|   }
  116|       |
  117|       |   // This should never be hit, due to earlier validation steps
  118|  1.85k|   if(current_label_length == 0) {
  ------------------
  |  Branch (118:7): [True: 0, False: 1.85k]
  ------------------
  119|      0|      return {};
  120|      0|   }
  121|       |
  122|       |   // An entirely numeric name ("1.2.3.4") is either a misplaced IP address
  123|       |   // or an attempt at confusing some other system; reject outright
  124|  1.85k|   if(all_numeric) {
  ------------------
  |  Branch (124:7): [True: 15, False: 1.83k]
  ------------------
  125|     15|      return {};
  126|     15|   }
  127|       |
  128|  1.83k|   return canon;
  129|  1.85k|}

_ZN5Botan12EmailAddress11from_stringENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
   78|    648|std::optional<EmailAddress> EmailAddress::from_string(std::string_view addr) {
   79|    648|   auto parsed = parse_email_address(addr);
   80|       |
   81|    648|   if(parsed) {
  ------------------
  |  Branch (81:7): [True: 488, False: 160]
  ------------------
   82|       |      // Verify the local-part is all ASCII
   83|  1.61k|      for(const char c : parsed->first) {
  ------------------
  |  Branch (83:24): [True: 1.61k, False: 483]
  ------------------
   84|  1.61k|         if(static_cast<uint8_t>(c) >= 0x80) {
  ------------------
  |  Branch (84:13): [True: 5, False: 1.61k]
  ------------------
   85|      5|            return {};
   86|      5|         }
   87|  1.61k|      }
   88|    483|      return EmailAddress(std::move(parsed->first), std::move(parsed->second));
   89|    488|   } else {
   90|    160|      return {};
   91|    160|   }
   92|    648|}
email.cpp:_ZN5Botan12_GLOBAL__N_119parse_email_addressENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
   16|    648|std::optional<std::pair<std::string, DNSName>> parse_email_address(std::string_view addr) {
   17|       |   /*
   18|       |   * RFC 5322 atext: ALPHA / DIGIT plus "!#$%&'*+-/=?^_`{|}~" (plus ".")
   19|       |   *
   20|       |   * Anything outside this set in the local part requires quoting,
   21|       |   * which we deliberately don't accept.
   22|       |   */
   23|    648|   constexpr auto is_atext_or_dot = CharacterValidityTable::alpha_numeric_plus(".!#$%&'*+-/=?^_`{|}~");
   24|       |
   25|    648|   if(addr.empty() || !is_valid_utf8(addr)) {
  ------------------
  |  Branch (25:7): [True: 0, False: 648]
  |  Branch (25:23): [True: 55, False: 593]
  ------------------
   26|     55|      return {};
   27|     55|   }
   28|       |
   29|    593|   const auto at = addr.find('@');
   30|       |
   31|       |   // Must be one (and only one) @ sign
   32|    593|   if(at == std::string_view::npos || addr.find('@', at + 1) != std::string_view::npos) {
  ------------------
  |  Branch (32:7): [True: 16, False: 577]
  |  Branch (32:39): [True: 10, False: 567]
  ------------------
   33|     26|      return {};
   34|     26|   }
   35|       |
   36|       |   // Split at the @ sign and verify both halves are non-empty
   37|    567|   const std::string_view local = addr.substr(0, at);
   38|    567|   const std::string_view domain = addr.substr(at + 1);
   39|       |
   40|    567|   if(local.empty() || domain.empty()) {
  ------------------
  |  Branch (40:7): [True: 3, False: 564]
  |  Branch (40:24): [True: 5, False: 559]
  ------------------
   41|      8|      return {};
   42|      8|   }
   43|       |
   44|       |   // RFC 3696 section 3:
   45|       |   //
   46|       |   //  period (".") may also appear [in an email address local-part],
   47|       |   //  but may not be used to start or end the local part, nor may two
   48|       |   //  or more consecutive periods appear.
   49|       |
   50|       |   // TODO(C++23): use std::string::contains
   51|    559|   if(local.starts_with('.') || local.ends_with('.') || local.find("..") != std::string_view::npos) {
  ------------------
  |  Branch (51:7): [True: 3, False: 556]
  |  Branch (51:33): [True: 5, False: 551]
  |  Branch (51:57): [True: 10, False: 541]
  ------------------
   52|     18|      return {};
   53|     18|   }
   54|       |
   55|       |   // RFC 5322 dot-atom. This intentionally omits support for quoting
   56|  2.37k|   for(const char c : local) {
  ------------------
  |  Branch (56:21): [True: 2.37k, False: 521]
  ------------------
   57|       |      // Here we accept high bit for UTF-8 for SmtpUtf8Mailbox
   58|  2.37k|      if(!is_atext_or_dot(c) && static_cast<uint8_t>(c) < 0x80) {
  ------------------
  |  Branch (58:10): [True: 56, False: 2.31k]
  |  Branch (58:33): [True: 20, False: 36]
  ------------------
   59|     20|         return {};
   60|     20|      }
   61|  2.37k|   }
   62|       |
   63|    521|   auto parsed_domain = DNSName::from_string(domain);
   64|    521|   if(!parsed_domain.has_value()) {
  ------------------
  |  Branch (64:7): [True: 33, False: 488]
  ------------------
   65|     33|      return {};
   66|     33|   }
   67|       |
   68|    488|   return std::make_pair(std::string(local), parsed_domain.value());
   69|    521|}

_ZN5Botan9ExceptionC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
   71|  9.41k|Exception::Exception(std::string_view msg) : m_msg(msg) {}
_ZN5Botan9ExceptionC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEERKSt9exception:
   73|  3.72k|Exception::Exception(std::string_view msg, const std::exception& e) : m_msg(fmt("{} failed with {}", msg, e.what())) {}
_ZN5Botan9ExceptionC2EPKcNSt3__117basic_string_viewIcNS3_11char_traitsIcEEEE:
   75|      3|Exception::Exception(const char* prefix, std::string_view msg) : m_msg(fmt("{} {}", prefix, msg)) {}
_ZN5Botan16Invalid_ArgumentC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
   77|    529|Invalid_Argument::Invalid_Argument(std::string_view msg) : Exception(msg) {}
_ZN5Botan14Encoding_ErrorC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
  123|      3|Encoding_Error::Encoding_Error(std::string_view name) : Exception("Encoding error:", name) {}
_ZN5Botan14Decoding_ErrorC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
  125|  8.88k|Decoding_Error::Decoding_Error(std::string_view name) : Exception(name) {}
_ZN5Botan14Decoding_ErrorC2ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEERKSt9exception:
  130|  3.72k|Decoding_Error::Decoding_Error(std::string_view msg, const std::exception& e) : Exception(msg, e) {}

_ZN5Botan11IPv4Address11from_stringENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
   90|    891|std::optional<IPv4Address> IPv4Address::from_string(std::string_view str) {
   91|    891|   if(auto ipv4 = string_to_ipv4(str)) {
  ------------------
  |  Branch (91:12): [True: 87, False: 804]
  ------------------
   92|     87|      return IPv4Address(*ipv4);
   93|    804|   } else {
   94|    804|      return {};
   95|    804|   }
   96|    891|}
ipv4_address.cpp:_ZN5Botan12_GLOBAL__N_114string_to_ipv4ENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
   21|    891|std::optional<uint32_t> string_to_ipv4(std::string_view str) {
   22|       |   // At least 3 dots + 4 1-digit integers
   23|       |   // At most 3 dots + 4 3-digit integers
   24|    891|   if(str.size() < 3 + 4 * 1 || str.size() > 3 + 4 * 3) {
  ------------------
  |  Branch (24:7): [True: 498, False: 393]
  |  Branch (24:33): [True: 132, False: 261]
  ------------------
   25|    630|      return {};
   26|    630|   }
   27|       |
   28|       |   // the final result
   29|    261|   uint32_t ip = 0;
   30|       |   // the number of '.' seen so far
   31|    261|   size_t dots = 0;
   32|       |   // accumulates one quad (range 0-255)
   33|    261|   uint32_t accum = 0;
   34|       |   // # of digits pushed to accum since last dot
   35|    261|   size_t cur_digits = 0;
   36|       |
   37|  1.44k|   for(const char c : str) {
  ------------------
  |  Branch (37:21): [True: 1.44k, False: 90]
  ------------------
   38|  1.44k|      if(c == '.') {
  ------------------
  |  Branch (38:10): [True: 381, False: 1.06k]
  ------------------
   39|       |         // . without preceding digit is invalid
   40|    381|         if(cur_digits == 0) {
  ------------------
  |  Branch (40:13): [True: 3, False: 378]
  ------------------
   41|      3|            return {};
   42|      3|         }
   43|    378|         dots += 1;
   44|       |         // too many dots
   45|    378|         if(dots > 3) {
  ------------------
  |  Branch (45:13): [True: 4, False: 374]
  ------------------
   46|      4|            return {};
   47|      4|         }
   48|       |
   49|    374|         cur_digits = 0;
   50|    374|         ip = (ip << 8) | accum;
   51|    374|         accum = 0;
   52|  1.06k|      } else if(c >= '0' && c <= '9') {
  ------------------
  |  Branch (52:17): [True: 1.03k, False: 26]
  |  Branch (52:29): [True: 949, False: 88]
  ------------------
   53|    949|         const auto d = static_cast<uint8_t>(c - '0');
   54|       |
   55|       |         // prohibit leading zero in quad (used for octal)
   56|    949|         if(cur_digits > 0 && accum == 0) {
  ------------------
  |  Branch (56:13): [True: 387, False: 562]
  |  Branch (56:31): [True: 13, False: 374]
  ------------------
   57|     13|            return {};
   58|     13|         }
   59|    936|         accum = (accum * 10) + d;
   60|       |
   61|    936|         if(accum > 255) {
  ------------------
  |  Branch (61:13): [True: 37, False: 899]
  ------------------
   62|     37|            return {};
   63|     37|         }
   64|       |
   65|    899|         cur_digits++;
   66|    899|         BOTAN_ASSERT_NOMSG(cur_digits <= 3);
  ------------------
  |  |   84|    899|   do {                                                                     \
  |  |   85|    899|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|    899|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 899]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|    899|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 899]
  |  |  ------------------
  ------------------
   67|    899|      } else {
   68|    114|         return {};
   69|    114|      }
   70|  1.44k|   }
   71|       |
   72|       |   // no trailing digits?
   73|     90|   if(cur_digits == 0) {
  ------------------
  |  Branch (73:7): [True: 0, False: 90]
  ------------------
   74|      0|      return {};
   75|      0|   }
   76|       |
   77|       |   // insufficient # of dots
   78|     90|   if(dots != 3) {
  ------------------
  |  Branch (78:7): [True: 3, False: 87]
  ------------------
   79|      3|      return {};
   80|      3|   }
   81|       |
   82|     87|   ip = (ip << 8) | accum;
   83|       |
   84|     87|   return ip;
   85|     90|}

_ZN5Botan11IPv6AddressC2ENSt3__14spanIKhLm16EEE:
   17|    144|IPv6Address::IPv6Address(std::span<const uint8_t, 16> ip) : m_ip{} {
   18|  2.44k|   for(size_t i = 0; i != 16; ++i) {
  ------------------
  |  Branch (18:22): [True: 2.30k, False: 144]
  ------------------
   19|  2.30k|      m_ip[i] = ip[i];
   20|  2.30k|   }
   21|    144|}
_ZN5Botan11IPv6Address11from_stringENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
   24|    119|std::optional<IPv6Address> IPv6Address::from_string(std::string_view str) {
   25|    119|   if(str.empty()) {
  ------------------
  |  Branch (25:7): [True: 0, False: 119]
  ------------------
   26|      0|      return {};
   27|      0|   }
   28|       |
   29|       |   // Parsed hex groups, split by whether they appeared before or after a "::".
   30|       |   // If no "::" appears, only `pre` is populated and must reach exactly 8 groups.
   31|    119|   std::array<uint16_t, 8> pre{};
   32|    119|   std::array<uint16_t, 8> post{};
   33|    119|   size_t pre_count = 0;
   34|    119|   size_t post_count = 0;
   35|    119|   bool seen_double_colon = false;
   36|       |
   37|    119|   auto hex_value = [](char c) -> std::optional<uint8_t> {
   38|    119|      if(c >= '0' && c <= '9') {
   39|    119|         return c - '0';
   40|    119|      } else if(c >= 'a' && c <= 'f') {
   41|    119|         return 10 + (c - 'a');
   42|    119|      } else if(c >= 'A' && c <= 'F') {
   43|    119|         return 10 + (c - 'A');
   44|    119|      } else {
   45|    119|         return {};
   46|    119|      }
   47|    119|   };
   48|       |
   49|    119|   size_t idx = 0;
   50|    119|   bool expect_group = true;  // set after any separator, cleared after a group
   51|       |
   52|    977|   while(idx < str.size()) {
  ------------------
  |  Branch (52:10): [True: 945, False: 32]
  ------------------
   53|    945|      if(str[idx] == ':') {
  ------------------
  |  Branch (53:10): [True: 409, False: 536]
  ------------------
   54|    409|         if(idx + 1 < str.size() && str[idx + 1] == ':') {
  ------------------
  |  Branch (54:13): [True: 404, False: 5]
  |  Branch (54:37): [True: 52, False: 352]
  ------------------
   55|     52|            if(seen_double_colon) {
  ------------------
  |  Branch (55:16): [True: 4, False: 48]
  ------------------
   56|      4|               return {};  // at most one "::"
   57|      4|            }
   58|     48|            seen_double_colon = true;
   59|     48|            idx += 2;
   60|     48|            expect_group = (idx < str.size());
   61|     48|            continue;
   62|     52|         }
   63|       |         // single ':' separator between groups, only valid after a group
   64|    357|         if(expect_group) {
  ------------------
  |  Branch (64:13): [True: 4, False: 353]
  ------------------
   65|      4|            return {};
   66|      4|         }
   67|    353|         expect_group = true;
   68|    353|         idx += 1;
   69|    353|         continue;
   70|    357|      }
   71|       |
   72|       |      // Parse a hex group of 1..4 digits
   73|    536|      const size_t group_start = idx;
   74|    536|      uint32_t group = 0;
   75|    536|      size_t hex_chars = 0;
   76|  1.83k|      while(idx < str.size() && hex_chars < 4) {
  ------------------
  |  Branch (76:13): [True: 1.80k, False: 25]
  |  Branch (76:33): [True: 1.64k, False: 159]
  ------------------
   77|  1.64k|         const auto digit = hex_value(str[idx]);
   78|  1.64k|         if(digit.has_value() == false) {
  ------------------
  |  Branch (78:13): [True: 352, False: 1.29k]
  ------------------
   79|    352|            break;
   80|    352|         }
   81|  1.29k|         group = (group << 4) | static_cast<uint32_t>(digit.value());
   82|  1.29k|         idx += 1;
   83|  1.29k|         hex_chars += 1;
   84|  1.29k|      }
   85|    536|      if(hex_chars == 0) {
  ------------------
  |  Branch (85:10): [True: 46, False: 490]
  ------------------
   86|     46|         return {};
   87|     46|      }
   88|       |      // If a 5th hex digit follows, the group is oversized.
   89|    490|      if(hex_chars == 4 && idx < str.size() && hex_value(str[idx]).has_value()) {
  ------------------
  |  Branch (89:10): [True: 166, False: 324]
  |  Branch (89:10): [True: 19, False: 471]
  |  Branch (89:28): [True: 159, False: 7]
  |  Branch (89:48): [True: 19, False: 140]
  ------------------
   90|     19|         return {};
   91|     19|      }
   92|       |
   93|       |      /*
   94|       |      RFC 4291 2.2 allows the final 32 bits in dotted decimal, eg
   95|       |      "::ffff:1.2.3.4". The dotted quad must consume the remainder of the
   96|       |      input, and accounts for two 16-bit groups.
   97|       |      */
   98|    471|      if(idx < str.size() && str[idx] == '.') {
  ------------------
  |  Branch (98:10): [True: 446, False: 25]
  |  Branch (98:30): [True: 7, False: 439]
  ------------------
   99|      7|         const auto ipv4 = IPv4Address::from_string(str.substr(group_start));
  100|      7|         if(!ipv4.has_value()) {
  ------------------
  |  Branch (100:13): [True: 7, False: 0]
  ------------------
  101|      7|            return {};
  102|      7|         }
  103|      0|         const uint32_t v4 = ipv4->address();
  104|      0|         const std::array<uint16_t, 2> v4_groups{static_cast<uint16_t>(v4 >> 16), static_cast<uint16_t>(v4 & 0xFFFF)};
  105|      0|         for(const auto g : v4_groups) {
  ------------------
  |  Branch (105:27): [True: 0, False: 0]
  ------------------
  106|      0|            if(seen_double_colon) {
  ------------------
  |  Branch (106:16): [True: 0, False: 0]
  ------------------
  107|      0|               if(post_count >= 8) {
  ------------------
  |  Branch (107:19): [True: 0, False: 0]
  ------------------
  108|      0|                  return {};
  109|      0|               }
  110|      0|               post[post_count++] = g;
  111|      0|            } else {
  112|      0|               if(pre_count >= 8) {
  ------------------
  |  Branch (112:19): [True: 0, False: 0]
  ------------------
  113|      0|                  return {};
  114|      0|               }
  115|      0|               pre[pre_count++] = g;
  116|      0|            }
  117|      0|         }
  118|      0|         idx = str.size();
  119|      0|         expect_group = false;
  120|      0|         continue;
  121|      0|      }
  122|       |
  123|    464|      if(seen_double_colon) {
  ------------------
  |  Branch (123:10): [True: 176, False: 288]
  ------------------
  124|    176|         if(post_count >= 8) {
  ------------------
  |  Branch (124:13): [True: 3, False: 173]
  ------------------
  125|      3|            return {};
  126|      3|         }
  127|    173|         post[post_count++] = static_cast<uint16_t>(group);
  128|    288|      } else {
  129|    288|         if(pre_count >= 8) {
  ------------------
  |  Branch (129:13): [True: 4, False: 284]
  ------------------
  130|      4|            return {};
  131|      4|         }
  132|    284|         pre[pre_count++] = static_cast<uint16_t>(group);
  133|    284|      }
  134|    457|      expect_group = false;
  135|    457|   }
  136|       |
  137|       |   // Trailing single ':' is invalid
  138|     32|   if(expect_group) {
  ------------------
  |  Branch (138:7): [True: 3, False: 29]
  ------------------
  139|      3|      return {};
  140|      3|   }
  141|       |
  142|     29|   const size_t total_groups = pre_count + post_count;
  143|     29|   if(seen_double_colon) {
  ------------------
  |  Branch (143:7): [True: 20, False: 9]
  ------------------
  144|       |      // "::" has to cover at least one zero group
  145|     20|      if(total_groups > 7) {
  ------------------
  |  Branch (145:10): [True: 4, False: 16]
  ------------------
  146|      4|         return {};
  147|      4|      }
  148|     20|   } else {
  149|      9|      if(total_groups != 8) {
  ------------------
  |  Branch (149:10): [True: 6, False: 3]
  ------------------
  150|      6|         return {};
  151|      6|      }
  152|      9|   }
  153|       |
  154|     19|   std::array<uint8_t, 16> out{};
  155|     63|   for(size_t i = 0; i != pre_count; ++i) {
  ------------------
  |  Branch (155:22): [True: 44, False: 19]
  ------------------
  156|     44|      out[2 * i] = get_byte<0>(pre[i]);
  157|     44|      out[2 * i + 1] = get_byte<1>(pre[i]);
  158|     44|   }
  159|     19|   const size_t gap = 8 - total_groups;
  160|     48|   for(size_t i = 0; i != post_count; ++i) {
  ------------------
  |  Branch (160:22): [True: 29, False: 19]
  ------------------
  161|     29|      const size_t target = pre_count + gap + i;
  162|     29|      out[2 * target] = get_byte<0>(post[i]);
  163|     29|      out[2 * target + 1] = get_byte<1>(post[i]);
  164|     29|   }
  165|     19|   return IPv6Address(out);
  166|     29|}
ipv6_address.cpp:_ZZN5Botan11IPv6Address11from_stringENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEEENK3$_0clEc:
   37|  1.80k|   auto hex_value = [](char c) -> std::optional<uint8_t> {
   38|  1.80k|      if(c >= '0' && c <= '9') {
  ------------------
  |  Branch (38:10): [True: 1.75k, False: 55]
  |  Branch (38:22): [True: 383, False: 1.36k]
  ------------------
   39|    383|         return c - '0';
   40|  1.42k|      } else if(c >= 'a' && c <= 'f') {
  ------------------
  |  Branch (40:17): [True: 504, False: 920]
  |  Branch (40:29): [True: 478, False: 26]
  ------------------
   41|    478|         return 10 + (c - 'a');
   42|    946|      } else if(c >= 'A' && c <= 'F') {
  ------------------
  |  Branch (42:17): [True: 491, False: 455]
  |  Branch (42:29): [True: 454, False: 37]
  ------------------
   43|    454|         return 10 + (c - 'A');
   44|    492|      } else {
   45|    492|         return {};
   46|    492|      }
   47|  1.80k|   };

_ZN5Botan19secure_scrub_memoryEPvm:
   24|   336k|void secure_scrub_memory(void* ptr, size_t n) {
   25|   336k|   return secure_zeroize_buffer(ptr, n);
   26|   336k|}
_ZN5Botan21secure_zeroize_bufferEPvm:
   28|   336k|void secure_zeroize_buffer(void* ptr, size_t n) {
   29|   336k|   if(n == 0) {
  ------------------
  |  Branch (29:7): [True: 170k, False: 165k]
  ------------------
   30|   170k|      return;
   31|   170k|   }
   32|       |
   33|       |#if defined(BOTAN_TARGET_OS_HAS_RTLSECUREZEROMEMORY)
   34|       |   ::RtlSecureZeroMemory(ptr, n);
   35|       |
   36|       |#elif defined(BOTAN_TARGET_OS_HAS_EXPLICIT_BZERO)
   37|   165k|   ::explicit_bzero(ptr, n);
   38|       |
   39|       |#elif defined(BOTAN_TARGET_OS_HAS_EXPLICIT_MEMSET)
   40|       |   (void)::explicit_memset(ptr, 0, n);
   41|       |
   42|       |#else
   43|       |   /*
   44|       |   * Call memset through a static volatile pointer, which the compiler should
   45|       |   * not elide. This construct should be safe in conforming compilers, but who
   46|       |   * knows. This has been checked to generate the expected code, which saves the
   47|       |   * memset address in the data segment and unconditionally loads and jumps to
   48|       |   * that address, with the following targets:
   49|       |   *
   50|       |   * x86-64: Clang 19, GCC 6, 11, 13, 14
   51|       |   * riscv64: GCC 14
   52|       |   * aarch64: GCC 14
   53|       |   * armv7: GCC 14
   54|       |   *
   55|       |   * Actually all of them generated the expected jump even without marking the
   56|       |   * function pointer as volatile. However this seems worth including as an
   57|       |   * additional precaution.
   58|       |   */
   59|       |   static void* (*const volatile memset_ptr)(void*, int, size_t) = std::memset;
   60|       |   (memset_ptr)(ptr, 0, n);
   61|       |#endif
   62|   165k|}

_ZN5Botan9parse_u16ENSt3__117basic_string_viewIcNS0_11char_traitsIcEEEEb:
   59|     93|std::optional<uint16_t> parse_u16(std::string_view input, bool require_canonical) {
   60|     93|   return parse_decimal_integer<uint16_t>(input, require_canonical);
   61|     93|}
_ZN5Botan9parse_u32ENSt3__117basic_string_viewIcNS0_11char_traitsIcEEEEb:
   63|  68.6k|std::optional<uint32_t> parse_u32(std::string_view input, bool require_canonical) {
   64|  68.6k|   return parse_decimal_integer<uint32_t>(input, require_canonical);
   65|  68.6k|}
_ZN5Botan9to_u32bitENSt3__117basic_string_viewIcNS0_11char_traitsIcEEEE:
   75|  68.6k|uint32_t to_u32bit(std::string_view input) {
   76|  68.6k|   if(const auto parsed = parse_u32(input)) {
  ------------------
  |  Branch (76:18): [True: 68.6k, False: 30]
  ------------------
   77|  68.6k|      return *parsed;
   78|  68.6k|   } else {
   79|     30|      throw Invalid_Argument(fmt("Failed to parse input '{}' as a 32-bit integer", input));
   80|     30|   }
   81|  68.6k|}
_ZN5Botan14tolower_stringENSt3__117basic_string_viewIcNS0_11char_traitsIcEEEE:
  182|  2.00k|std::string tolower_string(std::string_view str) {
  183|       |   // Locale-independent ASCII fold; the only callers (DNS name canonicalization
  184|       |   // for SAN/name-constraints) work on ASCII strings per RFC 1035.
  185|  2.00k|   std::string lower(str);
  186|  5.40k|   for(char& c : lower) {
  ------------------
  |  Branch (186:16): [True: 5.40k, False: 2.00k]
  ------------------
  187|  5.40k|      if(c >= 'A' && c <= 'Z') {
  ------------------
  |  Branch (187:10): [True: 5.00k, False: 399]
  |  Branch (187:22): [True: 4.46k, False: 537]
  ------------------
  188|  4.46k|         c = static_cast<char>(c + ('a' - 'A'));
  189|  4.46k|      }
  190|  5.40k|   }
  191|  2.00k|   return lower;
  192|  2.00k|}
parsing.cpp:_ZN5Botan12_GLOBAL__N_121parse_decimal_integerITkNSt3__117unsigned_integralEtEENS2_8optionalIT_EENS2_17basic_string_viewIcNS2_11char_traitsIcEEEEb:
   31|     93|std::optional<T> parse_decimal_integer(std::string_view input, bool require_canonical) {
   32|     93|   if(input.empty() || input.size() > (std::numeric_limits<T>::digits10 + 1)) {
  ------------------
  |  Branch (32:7): [True: 0, False: 93]
  |  Branch (32:24): [True: 11, False: 82]
  ------------------
   33|     11|      return {};
   34|     11|   }
   35|       |
   36|       |   // The canonical encoding of zero is "0"; no other value starts with a zero
   37|     82|   if(require_canonical && input.size() > 1 && input.front() == '0') {
  ------------------
  |  Branch (37:7): [True: 82, False: 0]
  |  Branch (37:28): [True: 50, False: 32]
  |  Branch (37:48): [True: 3, False: 47]
  ------------------
   38|      3|      return {};
   39|      3|   }
   40|       |
   41|     79|   T accum = 0;
   42|       |
   43|    173|   for(const char c : input) {
  ------------------
  |  Branch (43:21): [True: 173, False: 60]
  ------------------
   44|    173|      if(const auto digit = digit_from_ascii(c)) {
  ------------------
  |  Branch (44:21): [True: 158, False: 15]
  ------------------
   45|    158|         if(accum > (std::numeric_limits<T>::max() - static_cast<T>(*digit)) / 10) {
  ------------------
  |  Branch (45:13): [True: 4, False: 154]
  ------------------
   46|      4|            return {};
   47|      4|         }
   48|    154|         accum = accum * 10 + static_cast<T>(*digit);
   49|    154|      } else {
   50|     15|         return {};
   51|     15|      }
   52|    173|   }
   53|       |
   54|     60|   return accum;
   55|     79|}
parsing.cpp:_ZN5Botan12_GLOBAL__N_116digit_from_asciiEc:
   22|   139k|std::optional<size_t> digit_from_ascii(char c) {
   23|   139k|   if(c >= '0' && c <= '9') {
  ------------------
  |  Branch (23:7): [True: 139k, False: 30]
  |  Branch (23:19): [True: 139k, False: 15]
  ------------------
   24|   139k|      return c - '0';
   25|   139k|   } else {
   26|     45|      return {};
   27|     45|   }
   28|   139k|}
parsing.cpp:_ZN5Botan12_GLOBAL__N_121parse_decimal_integerITkNSt3__117unsigned_integralEjEENS2_8optionalIT_EENS2_17basic_string_viewIcNS2_11char_traitsIcEEEEb:
   31|  68.6k|std::optional<T> parse_decimal_integer(std::string_view input, bool require_canonical) {
   32|  68.6k|   if(input.empty() || input.size() > (std::numeric_limits<T>::digits10 + 1)) {
  ------------------
  |  Branch (32:7): [True: 0, False: 68.6k]
  |  Branch (32:24): [True: 0, False: 68.6k]
  ------------------
   33|      0|      return {};
   34|      0|   }
   35|       |
   36|       |   // The canonical encoding of zero is "0"; no other value starts with a zero
   37|  68.6k|   if(require_canonical && input.size() > 1 && input.front() == '0') {
  ------------------
  |  Branch (37:7): [True: 0, False: 68.6k]
  |  Branch (37:28): [True: 0, False: 0]
  |  Branch (37:48): [True: 0, False: 0]
  ------------------
   38|      0|      return {};
   39|      0|   }
   40|       |
   41|  68.6k|   T accum = 0;
   42|       |
   43|   139k|   for(const char c : input) {
  ------------------
  |  Branch (43:21): [True: 139k, False: 68.6k]
  ------------------
   44|   139k|      if(const auto digit = digit_from_ascii(c)) {
  ------------------
  |  Branch (44:21): [True: 139k, False: 30]
  ------------------
   45|   139k|         if(accum > (std::numeric_limits<T>::max() - static_cast<T>(*digit)) / 10) {
  ------------------
  |  Branch (45:13): [True: 0, False: 139k]
  ------------------
   46|      0|            return {};
   47|      0|         }
   48|   139k|         accum = accum * 10 + static_cast<T>(*digit);
   49|   139k|      } else {
   50|     30|         return {};
   51|     30|      }
   52|   139k|   }
   53|       |
   54|  68.6k|   return accum;
   55|  68.6k|}

_ZNK5Botan3URIssERKS0_:
  114|  2.56k|std::strong_ordering URI::operator<=>(const URI& other) const {
  115|  2.56k|   const bool has_authority = raw_authority().has_value();
  116|  2.56k|   const bool other_has_authority = other.raw_authority().has_value();
  117|       |
  118|  2.56k|   return std::tie(m_scheme, has_authority, m_authority, m_path, m_query, m_fragment) <=>
  119|  2.56k|          std::tie(
  120|  2.56k|             other.m_scheme, other_has_authority, other.m_authority, other.m_path, other.m_query, other.m_fragment);
  121|  2.56k|}
_ZNK5Botan3URI13raw_authorityEv:
  129|  5.12k|std::optional<std::string_view> URI::raw_authority() const {
  130|  5.12k|   const auto colon = m_raw.find(':');
  131|  5.12k|   BOTAN_ASSERT_NOMSG(colon != std::string::npos);
  ------------------
  |  |   84|  5.12k|   do {                                                                     \
  |  |   85|  5.12k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|  5.12k|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 5.12k]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|  5.12k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 5.12k]
  |  |  ------------------
  ------------------
  132|       |
  133|  5.12k|   const size_t rest_offset = colon + 1;
  134|  5.12k|   if(m_raw.size() < rest_offset + 2 || m_raw[rest_offset] != '/' || m_raw[rest_offset + 1] != '/') {
  ------------------
  |  Branch (134:7): [True: 495, False: 4.62k]
  |  Branch (134:41): [True: 1.57k, False: 3.05k]
  |  Branch (134:70): [True: 815, False: 2.23k]
  ------------------
  135|  2.88k|      return std::nullopt;
  136|  2.88k|   }
  137|       |
  138|  2.23k|   const size_t authority_start = rest_offset + 2;
  139|  2.23k|   const auto authority_end = m_raw.find_first_of("/?#", authority_start);
  140|  2.23k|   const size_t authority_len =
  141|  2.23k|      (authority_end == std::string::npos) ? std::string::npos : authority_end - authority_start;
  ------------------
  |  Branch (141:7): [True: 924, False: 1.31k]
  ------------------
  142|  2.23k|   return std::string_view(m_raw).substr(authority_start, authority_len);
  143|  5.12k|}
_ZNK5Botan3URI9AuthorityssERKS1_:
  145|    806|std::strong_ordering URI::Authority::operator<=>(const URI::Authority& other) const {
  146|       |   /*
  147|       |   Userinfo is compared without normalization; RFC 3986 6.2.2.1:
  148|       |      When a URI uses components of the generic syntax, the component
  149|       |      syntax equivalence rules always apply; namely, that the scheme
  150|       |      and host are case-insensitive and therefore should be normalized
  151|       |      to lowercase. ... The other generic syntax components are assumed
  152|       |      to be case-sensitive unless specifically defined otherwise by the
  153|       |      scheme.
  154|       |   */
  155|    806|   return std::tie(m_userinfo, m_host, m_port) <=> std::tie(other.m_userinfo, other.m_host, other.m_port);
  156|    806|}
_ZN5Botan3URI11from_stringENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
  163|  2.07k|std::optional<URI> URI::from_string(std::string_view raw) {
  164|       |   // Empty string is not a valid URI
  165|  2.07k|   if(raw.empty()) {
  ------------------
  |  Branch (165:7): [True: 0, False: 2.07k]
  ------------------
  166|      0|      return {};
  167|      0|   }
  168|       |
  169|       |   // RFC 3986:
  170|       |   // scheme = ALPHA *( ALPHA / DIGIT / "+" / "-" / "." )
  171|  2.07k|   constexpr auto is_scheme_cont_char = CharacterValidityTable::alpha_numeric_plus("+-.");
  172|       |
  173|  2.07k|   const auto is_ascii_alpha = [](char c) -> bool { return (c >= 'a' && c <= 'z') || (c >= 'A' && c <= 'Z'); };
  174|       |
  175|       |   // Check the first scheme character
  176|  2.07k|   if(!is_ascii_alpha(raw.front())) {
  ------------------
  |  Branch (176:7): [True: 28, False: 2.04k]
  ------------------
  177|     28|      return {};
  178|     28|   }
  179|       |
  180|       |   // Scan the rest of the scheme
  181|  2.04k|   size_t i = 1;
  182|  5.79k|   while(i < raw.size() && is_scheme_cont_char(raw[i])) {
  ------------------
  |  Branch (182:10): [True: 5.79k, False: 4]
  |  Branch (182:28): [True: 3.74k, False: 2.04k]
  ------------------
  183|  3.74k|      ++i;
  184|  3.74k|   }
  185|       |   // Scheme wasn't followed by ':' -> invalid
  186|  2.04k|   if(i >= raw.size() || raw[i] != ':') {
  ------------------
  |  Branch (186:7): [True: 4, False: 2.04k]
  |  Branch (186:26): [True: 43, False: 2.00k]
  ------------------
  187|     47|      return {};
  188|     47|   }
  189|       |
  190|       |   // Canonicalize the scheme
  191|  2.00k|   const std::string scheme = tolower_string(raw.substr(0, i));
  192|       |
  193|  2.00k|   auto rest = raw.substr(i + 1);
  194|       |
  195|  2.00k|   std::optional<Authority> parsed_authority;
  196|  2.00k|   std::string_view path_query_fragment;
  197|       |
  198|  2.00k|   if(rest.starts_with("//")) {
  ------------------
  |  Branch (198:7): [True: 1.19k, False: 809]
  ------------------
  199|  1.19k|      rest.remove_prefix(2);  // Strip off the '//'
  200|       |
  201|       |      // Authority runs to the first '/', '?' or '#'. The remaining is `path ? query # fragment`,
  202|       |      // which is validated against the RFC 3986 character set.
  203|  1.19k|      const auto end = rest.find_first_of("/?#");
  204|  1.19k|      const auto authority = (end == std::string_view::npos) ? rest : rest.substr(0, end);
  ------------------
  |  Branch (204:30): [True: 424, False: 767]
  ------------------
  205|  1.19k|      path_query_fragment = (end == std::string_view::npos) ? std::string_view{} : rest.substr(end);
  ------------------
  |  Branch (205:29): [True: 424, False: 767]
  ------------------
  206|       |
  207|       |      // Parse and validate non-empty authority strings (hostname, IPv4, or IPv6 address)
  208|  1.19k|      if(!authority.empty()) {
  ------------------
  |  Branch (208:10): [True: 1.13k, False: 55]
  ------------------
  209|  1.13k|         parsed_authority = Authority::from_string(authority);
  210|  1.13k|         if(!parsed_authority.has_value()) {
  ------------------
  |  Branch (210:13): [True: 382, False: 754]
  ------------------
  211|    382|            return {};
  212|    382|         }
  213|  1.13k|      }
  214|  1.19k|   } else {
  215|    809|      path_query_fragment = rest;
  216|    809|   }
  217|       |
  218|       |   // Validate any `path ? query # fragment` portions of the URL
  219|  1.61k|   if(!validate_path_query_fragment(path_query_fragment)) {
  ------------------
  |  Branch (219:7): [True: 159, False: 1.45k]
  ------------------
  220|    159|      return {};
  221|    159|   }
  222|       |
  223|       |   // Split into path / query / fragment. Validation above guarantees at most
  224|       |   // one '#', so the first '#' is the fragment delimiter, and within the
  225|       |   // pre-fragment portion the first '?' (if any) is the query delimiter.
  226|  1.45k|   const auto hash = path_query_fragment.find('#');
  227|  1.45k|   const auto pre_fragment =
  228|  1.45k|      (hash == std::string_view::npos) ? path_query_fragment : path_query_fragment.substr(0, hash);
  ------------------
  |  Branch (228:7): [True: 1.11k, False: 342]
  ------------------
  229|  1.45k|   std::optional<std::string> fragment;
  230|  1.45k|   if(hash != std::string_view::npos) {
  ------------------
  |  Branch (230:7): [True: 342, False: 1.11k]
  ------------------
  231|    342|      fragment = std::string(path_query_fragment.substr(hash + 1));
  232|    342|   }
  233|       |
  234|  1.45k|   const auto qmark = pre_fragment.find('?');
  235|  1.45k|   const auto path = (qmark == std::string_view::npos) ? pre_fragment : pre_fragment.substr(0, qmark);
  ------------------
  |  Branch (235:22): [True: 1.06k, False: 391]
  ------------------
  236|  1.45k|   std::optional<std::string> query;
  237|  1.45k|   if(qmark != std::string_view::npos) {
  ------------------
  |  Branch (237:7): [True: 391, False: 1.06k]
  ------------------
  238|    391|      query = std::string(pre_fragment.substr(qmark + 1));
  239|    391|   }
  240|       |
  241|       |   // Accept
  242|  1.45k|   return URI(
  243|  1.45k|      std::string(raw), scheme, std::move(parsed_authority), std::string(path), std::move(query), std::move(fragment));
  244|  1.61k|}
_ZN5Botan3URI9Authority11from_stringENSt3__117basic_string_viewIcNS2_11char_traitsIcEEEE:
  247|  1.13k|std::optional<URI::Authority> URI::Authority::from_string(std::string_view raw) {
  248|  1.13k|   if(raw.empty()) {
  ------------------
  |  Branch (248:7): [True: 0, False: 1.13k]
  ------------------
  249|      0|      return {};
  250|      0|   }
  251|       |
  252|       |   // Capture the full input now; the userinfo prefix is stripped from
  253|       |   // `raw` below, and m_raw must reflect the original
  254|  1.13k|   const std::string original_input(raw);
  255|       |
  256|       |   /*
  257|       |   RFC 3986
  258|       |     userinfo = *( unreserved / pct-encoded / sub-delims / ":" )
  259|       |
  260|       |   Thus a unencoded '@' is not allowed inside userinfo, and the single '@' splits the
  261|       |   username from the authority. The @ being present at all is significant; an empty
  262|       |   userinfo ("https://@example.com/") is distinct from no userinfo at all.
  263|       |   */
  264|  1.13k|   std::optional<std::string> userinfo;
  265|  1.13k|   const auto first_at = raw.find('@');
  266|  1.13k|   if(first_at != std::string_view::npos) {
  ------------------
  |  Branch (266:7): [True: 650, False: 486]
  ------------------
  267|    650|      if(raw.find('@', first_at + 1) != std::string_view::npos) {
  ------------------
  |  Branch (267:10): [True: 12, False: 638]
  ------------------
  268|     12|         return {};
  269|     12|      }
  270|    638|      const auto userinfo_view = raw.substr(0, first_at);
  271|    638|      if(!validate_userinfo(userinfo_view)) {
  ------------------
  |  Branch (271:10): [True: 70, False: 568]
  ------------------
  272|     70|         return {};
  273|     70|      }
  274|    568|      userinfo = std::string(userinfo_view);
  275|    568|      raw.remove_prefix(first_at + 1);
  276|    568|   }
  277|       |
  278|  1.05k|   std::string_view host_view;
  279|  1.05k|   std::string_view port_str;
  280|  1.05k|   std::optional<Host> host;
  281|       |
  282|  1.05k|   if(!raw.empty() && raw.front() == '[') {
  ------------------
  |  Branch (282:7): [True: 1.04k, False: 6]
  |  Branch (282:23): [True: 146, False: 902]
  ------------------
  283|       |      // Bracketed IPv6 literal.
  284|    146|      const auto close = raw.find(']');
  285|    146|      if(close == std::string_view::npos) {
  ------------------
  |  Branch (285:10): [True: 10, False: 136]
  ------------------
  286|     10|         return {};
  287|     10|      }
  288|    136|      host_view = raw.substr(1, close - 1);
  289|    136|      if(host_view.empty()) {
  ------------------
  |  Branch (289:10): [True: 4, False: 132]
  ------------------
  290|      4|         return {};
  291|      4|      }
  292|    132|      const auto after = raw.substr(close + 1);
  293|    132|      if(!after.empty()) {
  ------------------
  |  Branch (293:10): [True: 33, False: 99]
  ------------------
  294|     33|         if(after.front() != ':') {
  ------------------
  |  Branch (294:13): [True: 13, False: 20]
  ------------------
  295|     13|            return {};
  296|     13|         }
  297|     20|         port_str = after.substr(1);
  298|     20|      }
  299|    119|      auto ipv6 = IPv6Address::from_string(host_view);
  300|    119|      if(!ipv6.has_value()) {
  ------------------
  |  Branch (300:10): [True: 100, False: 19]
  ------------------
  301|    100|         return {};
  302|    100|      }
  303|     19|      host = *ipv6;
  304|    908|   } else {
  305|       |      // host[:port] with no brackets. Only one ':' is allowed (port).
  306|    908|      const auto colon = raw.find(':');
  307|    908|      if(colon == std::string_view::npos) {
  ------------------
  |  Branch (307:10): [True: 789, False: 119]
  ------------------
  308|    789|         host_view = raw;
  309|    789|      } else {
  310|    119|         host_view = raw.substr(0, colon);
  311|    119|         port_str = raw.substr(colon + 1);
  312|       |
  313|       |         // Verify the `:` char is the only one that appears
  314|    119|         if(port_str.find(':') != std::string::npos) {
  ------------------
  |  Branch (314:13): [True: 14, False: 105]
  ------------------
  315|     14|            return {};
  316|     14|         }
  317|    119|      }
  318|       |
  319|    894|      if(host_view.empty()) {
  ------------------
  |  Branch (319:10): [True: 6, False: 888]
  ------------------
  320|      6|         return {};
  321|      6|      }
  322|       |
  323|       |      // Technically valid per RFC 3986 but likely not something we want to support
  324|    888|      if(host_view.ends_with('.')) {
  ------------------
  |  Branch (324:10): [True: 4, False: 884]
  ------------------
  325|      4|         return {};
  326|      4|      }
  327|       |
  328|    884|      if(auto ipv4 = IPv4Address::from_string(host_view)) {
  ------------------
  |  Branch (328:15): [True: 87, False: 797]
  ------------------
  329|     87|         host = *ipv4;
  330|    797|      } else if(auto dns = DNSName::from_string(host_view)) {
  ------------------
  |  Branch (330:22): [True: 685, False: 112]
  ------------------
  331|    685|         host = std::move(*dns);
  332|    685|      } else {
  333|    112|         return {};
  334|    112|      }
  335|    884|   }
  336|       |
  337|    791|   std::optional<uint16_t> port;
  338|       |
  339|    791|   if(!port_str.empty()) {
  ------------------
  |  Branch (339:7): [True: 93, False: 698]
  ------------------
  340|     93|      port = parse_port(port_str);
  341|     93|      if(!port.has_value()) {
  ------------------
  |  Branch (341:10): [True: 37, False: 56]
  ------------------
  342|     37|         return {};
  343|     37|      }
  344|     93|   }
  345|       |
  346|    754|   return Authority(original_input, std::move(userinfo), std::move(*host), port);
  347|    791|}
uri.cpp:_ZZN5Botan3URI11from_stringENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEEENK3$_0clEc:
  173|  2.07k|   const auto is_ascii_alpha = [](char c) -> bool { return (c >= 'a' && c <= 'z') || (c >= 'A' && c <= 'Z'); };
  ------------------
  |  Branch (173:61): [True: 90, False: 1.98k]
  |  Branch (173:73): [True: 87, False: 3]
  |  Branch (173:87): [True: 1.96k, False: 24]
  |  Branch (173:99): [True: 1.96k, False: 4]
  ------------------
uri.cpp:_ZN5Botan12_GLOBAL__N_128validate_path_query_fragmentENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
   45|  1.61k|bool validate_path_query_fragment(std::string_view tail) {
   46|       |   /*
   47|       |   * RFC 3986 syntax for the path/query/fragment of a URI:
   48|       |   *
   49|       |   *   URI           = scheme ":" hier-part [ "?" query ] [ "#" fragment ]
   50|       |   *   pchar         = unreserved / pct-encoded / sub-delims / ":" / "@"
   51|       |   *   segment       = *pchar
   52|       |   *   path-abempty  = *( "/" segment )
   53|       |   *   query         = *( pchar / "/" / "?" )
   54|       |   *   fragment     =  *( pchar / "/" / "?" )
   55|       |   */
   56|       |
   57|  1.61k|   constexpr auto is_pchar_or_slash = CharacterValidityTable::alpha_numeric_plus("-._~!$&'()*+,;=:@/");
   58|       |
   59|  1.61k|   enum class State : uint8_t { Path, Query, Fragment };
   60|  1.61k|   State state = State::Path;
   61|       |
   62|  19.5k|   for(size_t i = 0; i < tail.size(); ++i) {
  ------------------
  |  Branch (62:22): [True: 18.0k, False: 1.45k]
  ------------------
   63|  18.0k|      const char c = tail[i];
   64|  18.0k|      if(c == '%') {
  ------------------
  |  Branch (64:10): [True: 389, False: 17.6k]
  ------------------
   65|    389|         if(i + 2 >= tail.size() || !is_valid_percent_escape(tail[i + 1], tail[i + 2])) {
  ------------------
  |  Branch (65:13): [True: 5, False: 384]
  |  Branch (65:37): [True: 61, False: 323]
  ------------------
   66|     66|            return false;
   67|     66|         }
   68|    323|         i += 2;
   69|    323|         continue;
   70|    389|      }
   71|  17.6k|      if(c == '?') {
  ------------------
  |  Branch (71:10): [True: 944, False: 16.7k]
  ------------------
   72|       |         // First '?' transitions from path to query, any further '?' are literal
   73|    944|         if(state == State::Path) {
  ------------------
  |  Branch (73:13): [True: 419, False: 525]
  ------------------
   74|    419|            state = State::Query;
   75|    419|         }
   76|    944|         continue;
   77|    944|      }
   78|  16.7k|      if(c == '#') {
  ------------------
  |  Branch (78:10): [True: 365, False: 16.3k]
  ------------------
   79|       |         // There is only one '#' fragment delimiter, second '#' is invalid
   80|    365|         if(state == State::Fragment) {
  ------------------
  |  Branch (80:13): [True: 5, False: 360]
  ------------------
   81|      5|            return false;
   82|      5|         }
   83|    360|         state = State::Fragment;
   84|    360|         continue;
   85|    365|      }
   86|  16.3k|      if(!is_pchar_or_slash(c)) {
  ------------------
  |  Branch (86:10): [True: 88, False: 16.2k]
  ------------------
   87|     88|         return false;
   88|     88|      }
   89|  16.3k|   }
   90|  1.45k|   return true;
   91|  1.61k|}
uri.cpp:_ZN5Botan12_GLOBAL__N_123is_valid_percent_escapeEcc:
   28|    845|bool is_valid_percent_escape(char c1, char c2) {
   29|    845|   auto is_hex_digit = [](char c) {
   30|    845|      return (c >= '0' && c <= '9') || (c >= 'a' && c <= 'f') || (c >= 'A' && c <= 'F');
   31|    845|   };
   32|       |
   33|    845|   if(!is_hex_digit(c1) || !is_hex_digit(c2)) {
  ------------------
  |  Branch (33:7): [True: 59, False: 786]
  |  Branch (33:28): [True: 48, False: 738]
  ------------------
   34|    107|      return false;
   35|    107|   }
   36|       |
   37|       |   // Proactively reject embedded null (%00)
   38|    738|   if(c1 == '0' && c2 == '0') {
  ------------------
  |  Branch (38:7): [True: 54, False: 684]
  |  Branch (38:20): [True: 6, False: 48]
  ------------------
   39|      6|      return false;
   40|      6|   }
   41|       |
   42|    732|   return true;
   43|    738|}
uri.cpp:_ZZN5Botan12_GLOBAL__N_123is_valid_percent_escapeEccENK3$_0clEc:
   29|  1.63k|   auto is_hex_digit = [](char c) {
   30|  1.63k|      return (c >= '0' && c <= '9') || (c >= 'a' && c <= 'f') || (c >= 'A' && c <= 'F');
  ------------------
  |  Branch (30:15): [True: 1.57k, False: 52]
  |  Branch (30:27): [True: 381, False: 1.19k]
  |  Branch (30:41): [True: 602, False: 648]
  |  Branch (30:53): [True: 577, False: 25]
  |  Branch (30:67): [True: 610, False: 63]
  |  Branch (30:79): [True: 566, False: 44]
  ------------------
   31|  1.63k|   };
uri.cpp:_ZN5Botan12_GLOBAL__N_117validate_userinfoENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
   93|    638|bool validate_userinfo(std::string_view userinfo) {
   94|    638|   constexpr auto is_valid_userinfo_char = CharacterValidityTable::alpha_numeric_plus("-._~!$&'()*+,;=:");
   95|       |
   96|  4.63k|   for(size_t i = 0; i < userinfo.size(); ++i) {
  ------------------
  |  Branch (96:22): [True: 4.07k, False: 568]
  ------------------
   97|  4.07k|      const char c = userinfo[i];
   98|  4.07k|      if(c == '%') {
  ------------------
  |  Branch (98:10): [True: 465, False: 3.60k]
  ------------------
   99|    465|         if(i + 2 >= userinfo.size() || !is_valid_percent_escape(userinfo[i + 1], userinfo[i + 2])) {
  ------------------
  |  Branch (99:13): [True: 4, False: 461]
  |  Branch (99:41): [True: 52, False: 409]
  ------------------
  100|     56|            return false;
  101|     56|         }
  102|    409|         i += 2;
  103|    409|         continue;
  104|    465|      }
  105|  3.60k|      if(!is_valid_userinfo_char(c)) {
  ------------------
  |  Branch (105:10): [True: 14, False: 3.59k]
  ------------------
  106|     14|         return false;
  107|     14|      }
  108|  3.60k|   }
  109|    568|   return true;
  110|    638|}
uri.cpp:_ZN5Botan12_GLOBAL__N_110parse_portENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
   17|     93|std::optional<uint16_t> parse_port(std::string_view s) {
   18|       |   // RFC 3986 port is "*DIGIT" but we reject leading zeros ("host:0080")
   19|     93|   if(const auto port = parse_u16(s, /*require_canonical=*/true)) {
  ------------------
  |  Branch (19:18): [True: 60, False: 33]
  ------------------
   20|     60|      if(*port > 0) {
  ------------------
  |  Branch (20:10): [True: 56, False: 4]
  ------------------
   21|     56|         return port;
   22|     56|      }
   23|     60|   }
   24|       |
   25|     37|   return {};
   26|     93|}

_ZN5Botan15AlternativeName7add_uriENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
   17|  2.18k|void AlternativeName::add_uri(std::string_view uri) {
   18|  2.18k|   if(uri.empty()) {
  ------------------
  |  Branch (18:7): [True: 119, False: 2.06k]
  ------------------
   19|    119|      return;
   20|    119|   }
   21|  2.06k|   if(auto parsed = URI::from_string(uri)) {
  ------------------
  |  Branch (21:12): [True: 1.45k, False: 616]
  ------------------
   22|  1.45k|      add_uri(std::move(*parsed));
   23|  1.45k|   } else {
   24|    616|      throw Decoding_Error("Invalid URI in SubjectAlternativeName");
   25|    616|   }
   26|  2.06k|}
_ZN5Botan15AlternativeName7add_uriENS_3URIE:
   28|  1.45k|void AlternativeName::add_uri(URI uri) {
   29|  1.45k|   m_uri.insert(std::move(uri));
   30|  1.45k|}
_ZN5Botan15AlternativeName9add_emailENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
   40|    689|void AlternativeName::add_email(std::string_view addr) {
   41|    689|   if(addr.empty()) {
  ------------------
  |  Branch (41:7): [True: 41, False: 648]
  ------------------
   42|     41|      return;
   43|     41|   }
   44|    648|   if(auto parsed = EmailAddress::from_string(addr)) {
  ------------------
  |  Branch (44:12): [True: 483, False: 165]
  ------------------
   45|    483|      add_email(std::move(*parsed));
   46|    483|   } else {
   47|    165|      throw Decoding_Error("Invalid email address in SubjectAlternativeName");
   48|    165|   }
   49|    648|}
_ZN5Botan15AlternativeName9add_emailENS_12EmailAddressE:
   51|    483|void AlternativeName::add_email(EmailAddress addr) {
   52|    483|   m_email.insert(std::move(addr));
   53|    483|}
_ZN5Botan15AlternativeName7add_dnsENSt3__117basic_string_viewIcNS1_11char_traitsIcEEEE:
   63|    722|void AlternativeName::add_dns(std::string_view dns) {
   64|    722|   if(dns.empty()) {
  ------------------
  |  Branch (64:7): [True: 35, False: 687]
  ------------------
   65|     35|      return;
   66|     35|   }
   67|    687|   if(auto parsed = DNSName::from_san_string(dns)) {
  ------------------
  |  Branch (67:12): [True: 608, False: 79]
  ------------------
   68|    608|      add_dns(std::move(*parsed));
   69|    608|   } else {
   70|     79|      throw Decoding_Error("Invalid DNS name in SubjectAlternativeName");
   71|     79|   }
   72|    687|}
_ZN5Botan15AlternativeName7add_dnsENS_7DNSNameE:
   74|    608|void AlternativeName::add_dns(DNSName dns) {
   75|    608|   m_dns.insert(std::move(dns));
   76|    608|}
_ZN5Botan15AlternativeName17add_registered_idERKNS_3OIDE:
   97|    213|void AlternativeName::add_registered_id(const OID& oid) {
   98|    213|   m_registered_ids.insert(oid);
   99|    213|}
_ZN5Botan15AlternativeName6add_dnERKNS_7X509_DNE:
  101|    197|void AlternativeName::add_dn(const X509_DN& dn) {
  102|    197|   m_dn_names.insert(dn);
  103|    197|}
_ZN5Botan15AlternativeName16add_ipv4_addressERKNS_11IPv4AddressE:
  105|    521|void AlternativeName::add_ipv4_address(const IPv4Address& ip) {
  106|    521|   m_ipv4_addrs.insert(ip);
  107|    521|}
_ZN5Botan15AlternativeName16add_ipv6_addressERKNS_11IPv6AddressE:
  109|    144|void AlternativeName::add_ipv6_address(const IPv6Address& ip) {
  110|    144|   m_ipv6_addrs.insert(ip);
  111|    144|}
_ZNK5Botan15AlternativeName5countEv:
  113|    152|size_t AlternativeName::count() const {
  114|    152|   const auto sum = checked_add(m_dns.size(),
  115|    152|                                m_uri.size(),
  116|    152|                                m_email.size(),
  117|    152|                                m_ipv4_addrs.size(),
  118|    152|                                m_ipv6_addrs.size(),
  119|    152|                                m_dn_names.size(),
  120|    152|                                m_other_name_values.size(),
  121|    152|                                m_registered_ids.size());
  122|       |
  123|    152|   BOTAN_ASSERT_NOMSG(sum.has_value());
  ------------------
  |  |   84|    152|   do {                                                                     \
  |  |   85|    152|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */                         \
  |  |   86|    152|      if(!(expr)) {                                                         \
  |  |  ------------------
  |  |  |  Branch (86:10): [True: 0, False: 152]
  |  |  ------------------
  |  |   87|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                \
  |  |   88|      0|         Botan::assertion_failure(#expr, "", __func__, __FILE__, __LINE__); \
  |  |   89|      0|      }                                                                     \
  |  |   90|    152|   } while(0)
  |  |  ------------------
  |  |  |  Branch (90:12): [Folded, False: 152]
  |  |  ------------------
  ------------------
  124|    152|   return sum.value();
  125|    152|}
_ZNK5Botan15AlternativeName9has_itemsEv:
  127|    152|bool AlternativeName::has_items() const {
  128|    152|   return this->count() > 0;
  129|    152|}
_ZN5Botan15AlternativeName11decode_fromERNS_11BER_DecoderE:
  198|  2.15k|void AlternativeName::decode_from(BER_Decoder& source) {
  199|  2.15k|   BER_Decoder names = source.start_sequence();
  200|       |
  201|  7.94k|   while(names.more_items()) {
  ------------------
  |  Branch (201:10): [True: 6.51k, False: 1.43k]
  ------------------
  202|  6.51k|      const BER_Object obj = names.get_next_object();
  203|       |
  204|  6.51k|      if(obj.is_a(0, ASN1_Class::ExplicitContextSpecific)) {
  ------------------
  |  Branch (204:10): [True: 807, False: 5.70k]
  ------------------
  205|    807|         BER_Decoder othername(obj, names.limits());
  206|       |
  207|    807|         OID oid;
  208|    807|         othername.decode(oid);
  209|    807|         const BER_Object othername_value_outer = othername.get_next_object();
  210|    807|         othername.verify_end();
  211|       |
  212|    807|         if(!othername_value_outer.is_a(0, ASN1_Class::ExplicitContextSpecific)) {
  ------------------
  |  Branch (212:13): [True: 4, False: 803]
  ------------------
  213|      4|            throw Decoding_Error("Invalid tags on otherName value");
  214|      4|         }
  215|       |
  216|    803|         BER_Decoder othername_value_inner(othername_value_outer, names.limits());
  217|       |
  218|    803|         const BER_Object value = othername_value_inner.get_next_object();
  219|    803|         othername_value_inner.verify_end();
  220|       |
  221|       |         // Capture the inner ANY value verbatim so applications can retrieve
  222|       |         // it regardless of its ASN.1 form.
  223|    803|         std::vector<uint8_t> raw_value;
  224|    803|         DER_Encoder(raw_value).add_object(value.type_tag(), value.class_tag(), value.data());
  225|    803|         m_other_name_values.insert(OtherNameValue{oid, std::move(raw_value)});
  226|       |
  227|       |         // Populate old string view for compatibility
  228|    803|         if(ASN1_String::is_string_type(value.type()) && value.get_class() == ASN1_Class::Universal) {
  ------------------
  |  Branch (228:13): [True: 609, False: 194]
  |  Branch (228:58): [True: 571, False: 38]
  ------------------
  229|    571|            try {
  230|    571|               m_othernames.insert(std::make_pair(oid, ASN1_String(ASN1::to_string(value), value.type())));
  231|    571|            } catch(const Invalid_Argument&) {  // NOLINT(*-empty-catch)
  232|    333|            }
  233|    571|         }
  234|       |
  235|    803|         if(oid == OID::from_string("PKIX.SmtpUTF8Mailbox")) {
  ------------------
  |  Branch (235:13): [True: 0, False: 803]
  ------------------
  236|      0|            if(!value.is_a(ASN1_Type::Utf8String, ASN1_Class::Universal)) {
  ------------------
  |  Branch (236:16): [True: 0, False: 0]
  ------------------
  237|      0|               throw Decoding_Error("SmtpUTF8Mailbox otherName must contain a UTF8String");
  238|      0|            }
  239|      0|            auto parsed_mailbox = SmtpUtf8Mailbox::from_string(ASN1::to_string(value));
  240|      0|            if(!parsed_mailbox.has_value()) {
  ------------------
  |  Branch (240:16): [True: 0, False: 0]
  ------------------
  241|      0|               throw Decoding_Error("Invalid SmtpUTF8Mailbox encoding");
  242|      0|            }
  243|      0|            m_smtp_utf8_mailboxes.insert(std::move(*parsed_mailbox));
  244|      0|         }
  245|  5.70k|      } else if(obj.is_a(1, ASN1_Class::ContextSpecific)) {
  ------------------
  |  Branch (245:17): [True: 689, False: 5.01k]
  ------------------
  246|    689|         add_email(ASN1::to_string(obj));
  247|  5.01k|      } else if(obj.is_a(2, ASN1_Class::ContextSpecific)) {
  ------------------
  |  Branch (247:17): [True: 722, False: 4.29k]
  ------------------
  248|    722|         add_dns(ASN1::to_string(obj));
  249|  4.29k|      } else if(obj.is_a(3, ASN1_Class::ContextSpecific | ASN1_Class::Constructed)) {
  ------------------
  |  Branch (249:17): [True: 56, False: 4.24k]
  ------------------
  250|       |         // x400Address not supported but it is a SEQUENCE so we know it cannot be empty
  251|     56|         if(obj.length() == 0) {
  ------------------
  |  Branch (251:13): [True: 4, False: 52]
  ------------------
  252|      4|            throw Decoding_Error("Invalid x400Address field");
  253|      4|         }
  254|  4.24k|      } else if(obj.is_a(4, ASN1_Class::ContextSpecific | ASN1_Class::Constructed)) {
  ------------------
  |  Branch (254:17): [True: 344, False: 3.89k]
  ------------------
  255|    344|         BER_Decoder dec(obj, names.limits());
  256|    344|         X509_DN dn;
  257|    344|         dec.decode(dn).verify_end();
  258|    344|         this->add_dn(dn);
  259|  3.89k|      } else if(obj.is_a(5, ASN1_Class::ContextSpecific | ASN1_Class::Constructed)) {
  ------------------
  |  Branch (259:17): [True: 110, False: 3.78k]
  ------------------
  260|       |         // ediPartyName not supported but it is a SEQUENCE so we know it cannot be empty
  261|    110|         if(obj.length() == 0) {
  ------------------
  |  Branch (261:13): [True: 4, False: 106]
  ------------------
  262|      4|            throw Decoding_Error("Invalid ediPartyName field");
  263|      4|         }
  264|  3.78k|      } else if(obj.is_a(6, ASN1_Class::ContextSpecific)) {
  ------------------
  |  Branch (264:17): [True: 2.18k, False: 1.60k]
  ------------------
  265|  2.18k|         this->add_uri(ASN1::to_string(obj));
  266|  2.18k|      } else if(obj.is_a(7, ASN1_Class::ContextSpecific)) {
  ------------------
  |  Branch (266:17): [True: 683, False: 917]
  ------------------
  267|    683|         if(obj.length() == 4) {
  ------------------
  |  Branch (267:13): [True: 521, False: 162]
  ------------------
  268|    521|            const uint32_t ip = load_be<uint32_t>(obj.bits(), 0);
  269|    521|            this->add_ipv4_address(ip);
  270|    521|         } else if(obj.length() == 16) {
  ------------------
  |  Branch (270:20): [True: 144, False: 18]
  ------------------
  271|    144|            const IPv6Address ip(std::span<const uint8_t, 16>{obj.bits(), 16});
  272|    144|            this->add_ipv6_address(ip);
  273|    144|         } else {
  274|     18|            throw Decoding_Error("Invalid IP constraint neither IPv4 or IPv6");
  275|     18|         }
  276|    917|      } else if(obj.is_a(8, ASN1_Class::ContextSpecific)) {
  ------------------
  |  Branch (276:17): [True: 224, False: 693]
  ------------------
  277|       |         // [8] registeredID is IMPLICIT OBJECT IDENTIFIER.
  278|    224|         OID oid;
  279|    224|         names.decode_implicit(obj, oid, ASN1_Type::ObjectId, ASN1_Class::Universal);
  280|    224|         this->add_registered_id(oid);
  281|    693|      } else {
  282|    693|         throw Decoding_Error(fmt("Unknown GeneralName tag {}/class {}",
  283|    693|                                  static_cast<uint32_t>(obj.type_tag()),
  284|    693|                                  static_cast<uint32_t>(obj.class_tag())));
  285|    693|      }
  286|  6.51k|   }
  287|  2.15k|}

_ZN5Botan9CRL_Entry11decode_fromERNS_11BER_DecoderE:
   88|  9.01k|void CRL_Entry::decode_from(BER_Decoder& source) {
   89|  9.01k|   auto data = std::make_unique<CRL_Entry_Data>();
   90|       |
   91|  9.01k|   BER_Decoder entry = source.start_sequence();
   92|       |
   93|  9.01k|   entry.decode(data->m_serial);
   94|  9.01k|   entry.decode(data->m_time);
   95|       |
   96|  9.01k|   data->m_serial_bits = data->m_serial.magnitude();
   97|       |
   98|  9.01k|   if(entry.more_items()) {
  ------------------
  |  Branch (98:7): [True: 7.31k, False: 1.69k]
  ------------------
   99|  7.31k|      data->m_extensions.decode_from(entry, Extension_Context::CRL_Entry);
  100|       |
  101|       |      // TODO(Botan4) start checking that CRLEntry extensions is not empty
  102|       |      // Extensions  ::=  SEQUENCE SIZE (1..MAX) OF Extension
  103|       |
  104|  7.31k|      if(const auto* ext = data->m_extensions.get_extension_object_as<Cert_Extension::CRL_ReasonCode>()) {
  ------------------
  |  Branch (104:22): [True: 1.26k, False: 6.05k]
  ------------------
  105|  1.26k|         const auto reason = ext->get_reason();
  106|       |
  107|       |         /*
  108|       |         * This reason code only makes sense in the context of delta CRL processing, which
  109|       |         * we do not currently support. Seeing it in a regular CRL suggests that something
  110|       |         * has gone very wrong (eg we are somehow processing a delta CRL, though that
  111|       |         * shouldn't happen since the delta CRL indicator extension should be a critical
  112|       |         * extension which we will reject.)
  113|       |         */
  114|  1.26k|         if(reason == CRL_Code::RemoveFromCrl) {
  ------------------
  |  Branch (114:13): [True: 1, False: 1.26k]
  ------------------
  115|      1|            throw Decoding_Error("CRL entry ReasonCode extension included invalid RemoveFromCrl");
  116|      1|         }
  117|  1.26k|         data->m_reason = reason;
  118|  6.05k|      } else {
  119|  6.05k|         data->m_reason = CRL_Code::Unspecified;
  120|  6.05k|      }
  121|  7.31k|   }
  122|       |
  123|  9.00k|   entry.end_cons();
  124|       |
  125|  9.00k|   m_data = std::move(data);
  126|  9.00k|}
_ZNK5Botan9CRL_Entry4dataEv:
  128|  12.0k|const CRL_Entry_Data& CRL_Entry::data() const {
  129|  12.0k|   if(!m_data) {
  ------------------
  |  Branch (129:7): [True: 0, False: 12.0k]
  ------------------
  130|      0|      throw Invalid_State("CRL_Entry_Data uninitialized");
  131|      0|   }
  132|       |
  133|  12.0k|   return *m_data;
  134|  12.0k|}
_ZNK5Botan9CRL_Entry6serialEv:
  140|  3.03k|const X509_Serial_Number& CRL_Entry::serial() const {
  141|  3.03k|   return data().m_serial;
  142|  3.03k|}
_ZNK5Botan9CRL_Entry10extensionsEv:
  152|  9.04k|const Extensions& CRL_Entry::extensions() const {
  153|  9.04k|   return data().m_extensions;
  154|  9.04k|}
_ZN5Botan14CRL_Entry_DataC2Ev:
   31|  9.01k|      CRL_Entry_Data() = default;

_ZNK5Botan8X509_CRL9PEM_labelEv:
   62|  3.92k|std::string X509_CRL::PEM_label() const {
   63|  3.92k|   return "X509 CRL";
   64|  3.92k|}
_ZNK5Botan8X509_CRL20alternate_PEM_labelsEv:
   66|     98|std::vector<std::string> X509_CRL::alternate_PEM_labels() const {
   67|     98|   return {"CRL"};
   68|     98|}
_ZN5Botan8X509_CRLC2ERNS_10DataSourceE:
   70|  3.84k|X509_CRL::X509_CRL(DataSource& src) {
   71|  3.84k|   load_data(src);
   72|  3.84k|}
_ZN5Botan8X509_CRL12force_decodeEv:
  242|  2.67k|void X509_CRL::force_decode() {
  243|  2.67k|   m_data.reset(decode_crl_body(signed_body(), signature_algorithm()).release());
  244|  2.67k|}
x509_crl.cpp:_ZN5Botan12_GLOBAL__N_115decode_crl_bodyERKNSt3__16vectorIhNS1_9allocatorIhEEEERKNS_19AlgorithmIdentifierE:
  130|  2.67k|std::unique_ptr<CRL_Data> decode_crl_body(const std::vector<uint8_t>& body, const AlgorithmIdentifier& sig_algo) {
  131|  2.67k|   auto data = std::make_unique<CRL_Data>();
  132|       |
  133|  2.67k|   BER_Decoder tbs_crl(body, BER_Decoder::Limits::DER());
  134|       |
  135|  2.67k|   tbs_crl.decode_optional(data->m_version, ASN1_Type::Integer, ASN1_Class::Universal);
  136|  2.67k|   data->m_version += 1;  // wire-format is 0-based
  137|       |
  138|  2.67k|   if(data->m_version != 1 && data->m_version != 2) {
  ------------------
  |  Branch (138:7): [True: 2.36k, False: 313]
  |  Branch (138:31): [True: 40, False: 2.32k]
  ------------------
  139|     40|      throw Decoding_Error("Unknown X.509 CRL version " + std::to_string(data->m_version));
  140|     40|   }
  141|       |
  142|       |   // Extensions are only defined for v2 CRLs
  143|  2.63k|   const bool supports_extensions = data->m_version > 1;
  144|       |
  145|  2.63k|   AlgorithmIdentifier sig_algo_inner;
  146|  2.63k|   tbs_crl.decode(sig_algo_inner);
  147|       |
  148|  2.63k|   if(sig_algo != sig_algo_inner) {
  ------------------
  |  Branch (148:7): [True: 95, False: 2.53k]
  ------------------
  149|     95|      throw Decoding_Error("Algorithm identifier mismatch in CRL");
  150|     95|   }
  151|       |
  152|  2.53k|   tbs_crl.decode(data->m_issuer).decode(data->m_this_update);
  153|       |
  154|       |   // According to RFC 5280 Section 5.1, nextUpdate is OPTIONAL and may be
  155|       |   // encoded as either a UTCTime or a GeneralizedTime. Section 5.1.2.5
  156|       |   // further states that "[c]onforming CRL issuers MUST include the nextUpdate
  157|       |   // field in all CRLs". Obviously, not everyone complies...
  158|       |   //
  159|       |   // See https://github.com/randombit/botan/issues/4722 for more details.
  160|  2.53k|   {
  161|  2.53k|      const auto& next_update = tbs_crl.peek_next_object();
  162|  2.53k|      if(next_update.is_a(ASN1_Type::UtcTime, ASN1_Class::Universal) ||
  ------------------
  |  Branch (162:10): [True: 1.54k, False: 998]
  ------------------
  163|    998|         next_update.is_a(ASN1_Type::GeneralizedTime, ASN1_Class::Universal)) {
  ------------------
  |  Branch (163:10): [True: 5, False: 993]
  ------------------
  164|    820|         tbs_crl.decode(data->m_next_update);
  165|    820|      }
  166|  2.53k|   }
  167|       |
  168|  2.53k|   BER_Object next = tbs_crl.get_next_object();
  169|       |
  170|  2.53k|   if(next.is_a(ASN1_Type::Sequence, ASN1_Class::Constructed)) {
  ------------------
  |  Branch (170:7): [True: 319, False: 2.22k]
  ------------------
  171|    319|      BER_Decoder cert_list(next, tbs_crl.limits());
  172|       |
  173|  9.32k|      while(cert_list.more_items()) {
  ------------------
  |  Branch (173:13): [True: 9.01k, False: 317]
  ------------------
  174|  9.01k|         CRL_Entry entry;
  175|  9.01k|         cert_list.decode(entry);
  176|       |
  177|  9.01k|         if(entry.extensions().has_unknown_critical_extension()) {
  ------------------
  |  Branch (177:13): [True: 1, False: 9.00k]
  ------------------
  178|      1|            data->m_has_unknown_critical_extension = true;
  179|      1|         }
  180|       |
  181|  9.01k|         if(!supports_extensions && entry.extensions().count() > 0) {
  ------------------
  |  Branch (181:13): [True: 315, False: 8.69k]
  |  Branch (181:37): [True: 2, False: 313]
  ------------------
  182|      2|            throw Decoding_Error("X509 CRL included extensions in a version that doesn't support them");
  183|      2|         }
  184|       |
  185|  9.00k|         data->m_entries.push_back(std::move(entry));
  186|  9.00k|      }
  187|       |
  188|       |      /*
  189|       |      RFC 5280 Section 5.1.2.6
  190|       |         When there are no revoked certificates, the revoked certificates list MUST be absent.
  191|       |
  192|       |      So strictly speaking we should be checking that m_entries is not empty. But practically,
  193|       |      it seems nearly all implementations accept a present-but-empty SEQUENCE as equivalent
  194|       |      to an absent one, and several major ones (including GnuTLS) will emit it. Considering
  195|       |      this situation, and the benign nature of the deviation, accept the non-conforming encoding.
  196|       |      */
  197|       |
  198|    317|      next = tbs_crl.get_next_object();
  199|    317|   }
  200|       |
  201|  2.53k|   if(next.is_a(0, ASN1_Class::Constructed | ASN1_Class::ContextSpecific)) {
  ------------------
  |  Branch (201:7): [True: 1.47k, False: 1.06k]
  ------------------
  202|  1.47k|      if(!supports_extensions) {
  ------------------
  |  Branch (202:10): [True: 1, False: 1.47k]
  ------------------
  203|      1|         throw Decoding_Error("X509 CRL included extensions in a version that doesn't support them");
  204|      1|      }
  205|  1.47k|      BER_Decoder crl_options(next, tbs_crl.limits());
  206|  1.47k|      data->m_extensions.decode_from(crl_options, Extension_Context::CRL);
  207|  1.47k|      crl_options.verify_end();
  208|  1.47k|      if(data->m_extensions.has_unknown_critical_extension()) {
  ------------------
  |  Branch (208:10): [True: 0, False: 1.47k]
  ------------------
  209|      0|         data->m_has_unknown_critical_extension = true;
  210|      0|      }
  211|       |
  212|  1.47k|      if(tbs_crl.get_next_object().is_set()) {
  ------------------
  |  Branch (212:10): [True: 14, False: 1.45k]
  ------------------
  213|     14|         throw Decoding_Error("Unknown tag following extensions in CRL");
  214|     14|      }
  215|  1.47k|   }
  216|       |
  217|  2.52k|   tbs_crl.verify_end("Unexpected trailing data after CRL");
  218|       |
  219|       |   // Now cache some fields from the extensions
  220|  2.52k|   if(const auto* ext = data->m_extensions.get_extension_object_as<Cert_Extension::CRL_Number>()) {
  ------------------
  |  Branch (220:19): [True: 12, False: 2.51k]
  ------------------
  221|     12|      data->m_crl_number = ext->crl_number();
  222|     12|   }
  223|  2.52k|   if(const auto* ext = data->m_extensions.get_extension_object_as<Cert_Extension::Authority_Key_ID>()) {
  ------------------
  |  Branch (223:19): [True: 4, False: 2.51k]
  ------------------
  224|      4|      data->m_auth_key_id = ext->get_key_id();
  225|      4|   }
  226|  2.52k|   if(const auto* ext = data->m_extensions.get_extension_object_as<Cert_Extension::CRL_Issuing_Distribution_Point>()) {
  ------------------
  |  Branch (226:19): [True: 0, False: 2.52k]
  ------------------
  227|      0|      const auto& dpn = ext->distribution_point_name();
  228|      0|      if(dpn.has_value() && dpn->full_name().has_value()) {
  ------------------
  |  Branch (228:10): [True: 0, False: 0]
  |  Branch (228:29): [True: 0, False: 0]
  ------------------
  229|      0|         for(const auto& uri : dpn->full_name()->uri_names()) {
  ------------------
  |  Branch (229:30): [True: 0, False: 0]
  ------------------
  230|      0|            data->m_idp_urls.push_back(uri);
  231|      0|         }
  232|      0|      }
  233|      0|   }
  234|       |
  235|  2.52k|   data->update_index();
  236|       |
  237|  2.52k|   return data;
  238|  2.53k|}
_ZN5Botan8CRL_DataC2Ev:
   34|  2.67k|      CRL_Data() = default;
_ZN5Botan8CRL_Data12update_indexEv:
   36|     43|      void update_index() {
   37|     43|         m_revoked_serials.clear();
   38|  3.03k|         for(const auto& entry : m_entries) {
  ------------------
  |  Branch (38:32): [True: 3.03k, False: 43]
  ------------------
   39|  3.03k|            m_revoked_serials.insert(entry.serial());
   40|  3.03k|         }
   41|     43|      }

_ZN5BotanltERKNS_7X509_DNES2_:
  353|    191|bool operator<(const X509_DN& dn1, const X509_DN& dn2) {
  354|    191|   return dn1._canonical_bytes() < dn2._canonical_bytes();
  355|    191|}
_ZN5Botan7X509_DN11decode_fromERNS_11BER_DecoderE:
  407|  2.67k|void X509_DN::decode_from(BER_Decoder& source) {
  408|  2.67k|   std::vector<uint8_t> bits;
  409|       |
  410|  2.67k|   source.start_sequence().raw_bytes(bits).end_cons();
  411|       |
  412|  2.67k|   BER_Decoder sequence(bits, source.limits());
  413|       |
  414|  2.67k|   std::vector<std::vector<std::pair<OID, ASN1_String>>> rdns;
  415|       |
  416|       |   // Cap AVAs per RDN to bound work for downstream set-based matching.
  417|       |   // No legitimate cert has anywhere near this many AVAs in a single RDN.
  418|  2.67k|   constexpr size_t MAX_AVAS_PER_RDN = 32;
  419|       |
  420|  5.61k|   while(sequence.more_items()) {
  ------------------
  |  Branch (420:10): [True: 2.94k, False: 2.67k]
  ------------------
  421|  2.94k|      BER_Decoder rdn_decoder = sequence.start_set();
  422|       |
  423|  2.94k|      std::vector<std::pair<OID, ASN1_String>> rdn;
  424|  5.65k|      while(rdn_decoder.more_items()) {
  ------------------
  |  Branch (424:13): [True: 2.70k, False: 2.94k]
  ------------------
  425|  2.70k|         OID oid;
  426|  2.70k|         ASN1_String str;
  427|       |
  428|  2.70k|         rdn_decoder.start_sequence()
  429|  2.70k|            .decode(oid)
  430|  2.70k|            .decode(str)  // TODO support Any
  431|  2.70k|            .end_cons();
  432|       |
  433|  2.70k|         rdn.emplace_back(std::move(oid), std::move(str));
  434|       |
  435|  2.70k|         if(rdn.size() > MAX_AVAS_PER_RDN) {
  ------------------
  |  Branch (435:13): [True: 0, False: 2.70k]
  ------------------
  436|      0|            throw Decoding_Error("X.500 RDN has too many attribute-value assertions");
  437|      0|         }
  438|  2.70k|      }
  439|       |
  440|       |      /*
  441|       |      RFC 5280 4.1.2.4:
  442|       |         RelativeDistinguishedName ::=
  443|       |           SET SIZE (1..MAX) OF AttributeTypeAndValue
  444|       |      */
  445|  2.94k|      if(rdn.empty()) {
  ------------------
  |  Branch (445:10): [True: 3, False: 2.93k]
  ------------------
  446|      3|         throw Decoding_Error("X.500 RDN must contain at least one attribute-value assertion");
  447|      3|      }
  448|  2.93k|      rdns.push_back(std::move(rdn));
  449|  2.93k|   }
  450|       |
  451|  2.67k|   auto canonical_bits = canonicalize_dn(rdns);
  452|       |
  453|  2.67k|   m_rdn = std::move(rdns);
  454|  2.67k|   m_dn_bits = std::move(bits);
  455|  2.67k|   m_canonical_dn_bits = std::move(canonical_bits);
  456|  2.67k|}
x509_dn.cpp:_ZN5Botan12_GLOBAL__N_115canonicalize_dnERKNSt3__16vectorINS2_INS1_4pairINS_3OIDENS_11ASN1_StringEEENS1_9allocatorIS6_EEEENS7_IS9_EEEE:
  310|  2.18k|std::vector<uint8_t> canonicalize_dn(const std::vector<std::vector<std::pair<OID, ASN1_String>>>& rdns) {
  311|  2.18k|   auto append_canonical_data = []<typename T>(std::vector<uint8_t>& out, const T& data) {
  312|  2.18k|      const std::array<uint8_t, 8> data_len = store_le(static_cast<uint64_t>(data.size()));
  313|  2.18k|      out.insert(out.end(), data_len.begin(), data_len.end());
  314|  2.18k|      out.insert(out.end(), data.begin(), data.end());
  315|  2.18k|   };
  316|       |
  317|  2.18k|   std::vector<uint8_t> canonical_bits;
  318|       |
  319|  2.32k|   for(const auto& rdn : rdns) {
  ------------------
  |  Branch (319:24): [True: 2.32k, False: 2.18k]
  ------------------
  320|  2.32k|      std::vector<uint8_t> rdn_bits;
  321|       |
  322|  2.33k|      for(const auto& [oid, value] : canonicalize_rdn(rdn)) {
  ------------------
  |  Branch (322:36): [True: 2.33k, False: 2.32k]
  ------------------
  323|  2.33k|         append_canonical_data(rdn_bits, oid.BER_encode());
  324|  2.33k|         append_canonical_data(rdn_bits, value);
  325|  2.33k|      }
  326|       |
  327|  2.32k|      append_canonical_data(canonical_bits, rdn_bits);
  328|  2.32k|   }
  329|       |
  330|  2.18k|   return canonical_bits;
  331|  2.18k|}
x509_dn.cpp:_ZN5Botan12_GLOBAL__N_116canonicalize_rdnERKNSt3__16vectorINS1_4pairINS_3OIDENS_11ASN1_StringEEENS1_9allocatorIS6_EEEE:
  298|  2.32k|std::vector<std::pair<OID, std::string>> canonicalize_rdn(const std::vector<std::pair<OID, ASN1_String>>& rdn) {
  299|  2.32k|   std::vector<std::pair<OID, std::string>> result;
  300|  2.32k|   result.reserve(rdn.size());
  301|  2.33k|   for(const auto& ava : rdn) {
  ------------------
  |  Branch (301:24): [True: 2.33k, False: 2.32k]
  ------------------
  302|  2.33k|      result.emplace_back(ava.first, X500_Char_Iterator::canonicalize(ava.second.value()));
  303|  2.33k|   }
  304|  2.32k|   if(result.size() != 1) {
  ------------------
  |  Branch (304:7): [True: 3, False: 2.32k]
  ------------------
  305|      3|      std::sort(result.begin(), result.end());
  306|      3|   }
  307|  2.32k|   return result;
  308|  2.32k|}
x509_dn.cpp:_ZN5Botan12_GLOBAL__N_118X500_Char_Iterator12canonicalizeENSt3__117basic_string_viewIcNS2_11char_traitsIcEEEE:
  114|  2.33k|      static std::string canonicalize(std::string_view name) {
  115|  2.33k|         std::string result;
  116|  2.33k|         result.reserve(name.size());
  117|       |
  118|  2.33k|         X500_Char_Iterator it(name);
  119|  19.7k|         while(auto c = it.next()) {
  ------------------
  |  Branch (119:21): [True: 17.4k, False: 2.33k]
  ------------------
  120|  17.4k|            result += *c;
  121|  17.4k|         }
  122|       |
  123|  2.33k|         return result;
  124|  2.33k|      }
x509_dn.cpp:_ZN5Botan12_GLOBAL__N_118X500_Char_IteratorC2ENSt3__117basic_string_viewIcNS2_11char_traitsIcEEEE:
   81|  2.33k|      explicit X500_Char_Iterator(std::string_view s) : m_str(s), m_pos(0) {
   82|       |         // Skip leading whitespace
   83|  2.54k|         while(m_pos < m_str.size() && is_space(m_str[m_pos])) {
  ------------------
  |  Branch (83:16): [True: 2.53k, False: 15]
  |  Branch (83:40): [True: 216, False: 2.31k]
  ------------------
   84|    216|            ++m_pos;
   85|    216|         }
   86|  2.33k|      }
x509_dn.cpp:_ZN5Botan12_GLOBAL__N_118X500_Char_Iterator4nextEv:
   89|  19.7k|      std::optional<char> next() {
   90|  19.7k|         if(m_pos >= m_str.size()) {
  ------------------
  |  Branch (90:13): [True: 2.27k, False: 17.4k]
  ------------------
   91|  2.27k|            return std::nullopt;
   92|  2.27k|         }
   93|       |
   94|  17.4k|         if(is_space(m_str[m_pos])) {
  ------------------
  |  Branch (94:13): [True: 503, False: 16.9k]
  ------------------
   95|       |            // Skip the entire whitespace run
   96|  1.32k|            while(m_pos < m_str.size() && is_space(m_str[m_pos])) {
  ------------------
  |  Branch (96:19): [True: 1.26k, False: 60]
  |  Branch (96:43): [True: 821, False: 443]
  ------------------
   97|    821|               ++m_pos;
   98|    821|            }
   99|       |            // Emit a single space only if more content follows (strip trailing ws)
  100|    503|            if(m_pos < m_str.size()) {
  ------------------
  |  Branch (100:16): [True: 443, False: 60]
  ------------------
  101|    443|               return ' ';
  102|    443|            }
  103|     60|            return std::nullopt;
  104|    503|         }
  105|       |
  106|  16.9k|         const char c = m_str[m_pos++];
  107|       |         // Locale-independent ASCII fold; RFC 5280 DN matching does not depend on libc locale
  108|  16.9k|         if(c >= 'A' && c <= 'Z') {
  ------------------
  |  Branch (108:13): [True: 7.90k, False: 9.07k]
  |  Branch (108:25): [True: 6.05k, False: 1.84k]
  ------------------
  109|  6.05k|            return static_cast<char>(c + ('a' - 'A'));
  110|  6.05k|         }
  111|  10.9k|         return c;
  112|  16.9k|      }
x509_dn.cpp:_ZZN5Botan12_GLOBAL__N_115canonicalize_dnERKNSt3__16vectorINS2_INS1_4pairINS_3OIDENS_11ASN1_StringEEENS1_9allocatorIS6_EEEENS7_IS9_EEEEENK3$_0clINS2_IhNS7_IhEEEEEEDaRSH_RKT_:
  311|  4.66k|   auto append_canonical_data = []<typename T>(std::vector<uint8_t>& out, const T& data) {
  312|  4.66k|      const std::array<uint8_t, 8> data_len = store_le(static_cast<uint64_t>(data.size()));
  313|  4.66k|      out.insert(out.end(), data_len.begin(), data_len.end());
  314|  4.66k|      out.insert(out.end(), data.begin(), data.end());
  315|  4.66k|   };
x509_dn.cpp:_ZZN5Botan12_GLOBAL__N_115canonicalize_dnERKNSt3__16vectorINS2_INS1_4pairINS_3OIDENS_11ASN1_StringEEENS1_9allocatorIS6_EEEENS7_IS9_EEEEENK3$_0clINS1_12basic_stringIcNS1_11char_traitsIcEENS7_IcEEEEEEDaRNS2_IhNS7_IhEEEERKT_:
  311|  2.33k|   auto append_canonical_data = []<typename T>(std::vector<uint8_t>& out, const T& data) {
  312|  2.33k|      const std::array<uint8_t, 8> data_len = store_le(static_cast<uint64_t>(data.size()));
  313|  2.33k|      out.insert(out.end(), data_len.begin(), data_len.end());
  314|  2.33k|      out.insert(out.end(), data.begin(), data.end());
  315|  2.33k|   };
x509_dn.cpp:_ZN5Botan12_GLOBAL__N_18is_spaceEc:
   26|  21.2k|bool is_space(char c) {
   27|  21.2k|   return c == ' ' || c == '\t';
  ------------------
  |  Branch (27:11): [True: 951, False: 20.3k]
  |  Branch (27:23): [True: 589, False: 19.7k]
  ------------------
   28|  21.2k|}

_ZN5Botan10Extensions15create_extn_objERKNS_3OIDEbRKNSt3__16vectorIhNS4_9allocatorIhEEEENS4_8optionalINS_17Extension_ContextEEE:
  148|  13.9k|                                                                   std::optional<Extension_Context> context) {
  149|  13.9k|   auto extn = extension_from_oid(oid);
  150|       |
  151|  13.9k|   if(!extn) {
  ------------------
  |  Branch (151:7): [True: 7.57k, False: 6.39k]
  ------------------
  152|       |      // some other unknown extension type
  153|  7.57k|      extn = std::make_unique<Cert_Extension::Unknown_Extension>(oid, critical);
  154|  7.57k|   } else {
  155|  6.39k|      if(context.has_value() && !extn->is_appropriate_context(*context)) {
  ------------------
  |  Branch (155:10): [True: 6.39k, False: 0]
  |  Branch (155:33): [True: 23, False: 6.37k]
  ------------------
  156|     23|         throw Decoding_Error(fmt("Extension {} is not allowed in this context", extn->oid_name()));
  157|     23|      }
  158|       |
  159|  6.37k|      try {
  160|  6.37k|         extn->decode_inner(body);
  161|  6.37k|         return extn;
  162|  6.37k|      } catch(const Exception&) {
  163|       |         // OID was recognized but contents failed to decode
  164|  4.96k|         extn = std::make_unique<Cert_Extension::Unknown_Extension>(oid, critical, /*failed_to_decode=*/true);
  165|  4.96k|      }
  166|  6.37k|   }
  167|       |
  168|       |   // This is always Unknown_Extension:
  169|  12.5k|   extn->decode_inner(body);
  170|  12.5k|   return extn;
  171|  13.9k|}
_ZNK5Botan10Extensions15Extensions_Info3objEv:
  173|  4.06k|const Certificate_Extension& Extensions::Extensions_Info::obj() const {
  174|  4.06k|   BOTAN_ASSERT_NONNULL(m_obj.get());
  ------------------
  |  |  123|  4.06k|   do {                                                                                   \
  |  |  124|  4.06k|      if((ptr) == nullptr) {                                                              \
  |  |  ------------------
  |  |  |  Branch (124:10): [True: 0, False: 4.06k]
  |  |  ------------------
  |  |  125|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */                              \
  |  |  126|      0|         Botan::assertion_failure(#ptr " is not null", "", __func__, __FILE__, __LINE__); \
  |  |  127|      0|      }                                                                                   \
  |  |  128|  4.06k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (128:12): [Folded, False: 4.06k]
  |  |  ------------------
  ------------------
  175|  4.06k|   return *m_obj;
  176|  4.06k|}
_ZNK5Botan10Extensions20get_extension_objectERKNS_3OIDE:
  256|  7.39k|const Certificate_Extension* Extensions::get_extension_object(const OID& oid) const {
  257|  7.39k|   auto extn = m_extension_info.find(oid);
  258|  7.39k|   if(extn == m_extension_info.end()) {
  ------------------
  |  Branch (258:7): [True: 3.33k, False: 4.06k]
  ------------------
  259|  3.33k|      return nullptr;
  260|  3.33k|   }
  261|       |
  262|  4.06k|   return &extn->second.obj();
  263|  7.39k|}
_ZN5Botan10Extensions11decode_fromERNS_11BER_DecoderENSt3__18optionalINS_17Extension_ContextEEE:
  326|  8.78k|void Extensions::decode_from(BER_Decoder& from_source, std::optional<Extension_Context> context) {
  327|  8.78k|   m_extension_oids.clear();
  328|  8.78k|   m_extension_info.clear();
  329|  8.78k|   m_has_unknown_critical_extension = false;
  330|       |
  331|  8.78k|   BER_Decoder sequence = from_source.start_sequence();
  332|       |
  333|  22.4k|   while(sequence.more_items()) {
  ------------------
  |  Branch (333:10): [True: 14.5k, False: 7.88k]
  ------------------
  334|  14.5k|      OID oid;
  335|  14.5k|      bool critical = false;
  336|  14.5k|      std::vector<uint8_t> bits;
  337|       |
  338|  14.5k|      sequence.start_sequence()
  339|  14.5k|         .decode(oid)
  340|  14.5k|         .decode_optional(critical, ASN1_Type::Boolean, ASN1_Class::Universal, false)
  341|  14.5k|         .decode(bits, ASN1_Type::OctetString)
  342|  14.5k|         .end_cons();
  343|       |
  344|  14.5k|      auto obj = create_extn_obj(oid, critical, bits, context);
  345|       |      // Unknown_Extension is the only Certificate_Extension with an empty oid_name
  346|  14.5k|      if(critical && obj->oid_name().empty()) {
  ------------------
  |  Branch (346:10): [True: 2, False: 14.5k]
  |  Branch (346:10): [True: 2, False: 14.5k]
  |  Branch (346:22): [True: 2, False: 0]
  ------------------
  347|      2|         m_has_unknown_critical_extension = true;
  348|      2|      }
  349|  14.5k|      Extensions_Info info(critical, std::move(bits), std::move(obj));
  350|       |
  351|  14.5k|      m_extension_oids.push_back(oid);
  352|       |
  353|       |      // RFC 5280 4.2: "A certificate MUST NOT include more than one
  354|       |      // instance of a particular extension."
  355|  14.5k|      if(!m_extension_info.emplace(std::move(oid), std::move(info)).second) {
  ------------------
  |  Branch (355:10): [True: 897, False: 13.6k]
  ------------------
  356|    897|         throw Decoding_Error("Duplicate certificate extension encountered");
  357|    897|      }
  358|  14.5k|   }
  359|  7.88k|   sequence.verify_end();
  360|  7.88k|}
_ZNK5Botan14Cert_Extension17Basic_Constraints22is_appropriate_contextENS_17Extension_ContextE:
  364|      1|bool Basic_Constraints::is_appropriate_context(Extension_Context context) const {
  365|      1|   return context == Extension_Context::Certificate;
  366|      1|}
_ZNK5Botan14Cert_Extension9Key_Usage22is_appropriate_contextENS_17Extension_ContextE:
  368|      1|bool Key_Usage::is_appropriate_context(Extension_Context context) const {
  369|      1|   return context == Extension_Context::Certificate;
  370|      1|}
_ZNK5Botan14Cert_Extension14Subject_Key_ID22is_appropriate_contextENS_17Extension_ContextE:
  372|      3|bool Subject_Key_ID::is_appropriate_context(Extension_Context context) const {
  373|      3|   return context == Extension_Context::Certificate;
  374|      3|}
_ZNK5Botan14Cert_Extension16Authority_Key_ID22is_appropriate_contextENS_17Extension_ContextE:
  376|    106|bool Authority_Key_ID::is_appropriate_context(Extension_Context context) const {
  377|    106|   return context == Extension_Context::Certificate || context == Extension_Context::CRL;
  ------------------
  |  Branch (377:11): [True: 0, False: 106]
  |  Branch (377:56): [True: 105, False: 1]
  ------------------
  378|    106|}
_ZNK5Botan14Cert_Extension24Subject_Alternative_Name22is_appropriate_contextENS_17Extension_ContextE:
  380|      1|bool Subject_Alternative_Name::is_appropriate_context(Extension_Context context) const {
  381|      1|   return context == Extension_Context::Certificate;
  382|      1|}
_ZNK5Botan14Cert_Extension23Issuer_Alternative_Name22is_appropriate_contextENS_17Extension_ContextE:
  384|  1.92k|bool Issuer_Alternative_Name::is_appropriate_context(Extension_Context context) const {
  385|  1.92k|   return context == Extension_Context::Certificate || context == Extension_Context::CRL;
  ------------------
  |  Branch (385:11): [True: 0, False: 1.92k]
  |  Branch (385:56): [True: 1.92k, False: 1]
  ------------------
  386|  1.92k|}
_ZNK5Botan14Cert_Extension18Extended_Key_Usage22is_appropriate_contextENS_17Extension_ContextE:
  388|      1|bool Extended_Key_Usage::is_appropriate_context(Extension_Context context) const {
  389|      1|   return context == Extension_Context::Certificate;
  390|      1|}
_ZNK5Botan14Cert_Extension16Name_Constraints22is_appropriate_contextENS_17Extension_ContextE:
  392|      1|bool Name_Constraints::is_appropriate_context(Extension_Context context) const {
  393|      1|   return context == Extension_Context::Certificate;
  394|      1|}
_ZNK5Botan14Cert_Extension20Certificate_Policies22is_appropriate_contextENS_17Extension_ContextE:
  396|      2|bool Certificate_Policies::is_appropriate_context(Extension_Context context) const {
  397|      2|   return context == Extension_Context::Certificate;
  398|      2|}
_ZNK5Botan14Cert_Extension28Authority_Information_Access22is_appropriate_contextENS_17Extension_ContextE:
  400|     74|bool Authority_Information_Access::is_appropriate_context(Extension_Context context) const {
  401|     74|   return context == Extension_Context::Certificate || context == Extension_Context::CRL;
  ------------------
  |  Branch (401:11): [True: 0, False: 74]
  |  Branch (401:56): [True: 74, False: 0]
  ------------------
  402|     74|}
_ZNK5Botan14Cert_Extension10CRL_Number22is_appropriate_contextENS_17Extension_ContextE:
  404|     39|bool CRL_Number::is_appropriate_context(Extension_Context context) const {
  405|     39|   return context == Extension_Context::CRL;
  406|     39|}
_ZNK5Botan14Cert_Extension14CRL_ReasonCode22is_appropriate_contextENS_17Extension_ContextE:
  408|  4.03k|bool CRL_ReasonCode::is_appropriate_context(Extension_Context context) const {
  409|       |   // RFC 6960 4.4.5: "All the extensions specified as CRL entry extensions
  410|       |   // -- in Section 5.3 of [RFC5280] -- are also supported as singleExtensions."
  411|  4.03k|   return context == Extension_Context::CRL_Entry || context == Extension_Context::OCSP_Response;
  ------------------
  |  Branch (411:11): [True: 4.03k, False: 2]
  |  Branch (411:54): [True: 0, False: 2]
  ------------------
  412|  4.03k|}
_ZNK5Botan14Cert_Extension23CRL_Distribution_Points22is_appropriate_contextENS_17Extension_ContextE:
  414|      2|bool CRL_Distribution_Points::is_appropriate_context(Extension_Context context) const {
  415|      2|   return context == Extension_Context::Certificate;
  416|      2|}
_ZNK5Botan14Cert_Extension30CRL_Issuing_Distribution_Point22is_appropriate_contextENS_17Extension_ContextE:
  418|    198|bool CRL_Issuing_Distribution_Point::is_appropriate_context(Extension_Context context) const {
  419|    198|   return context == Extension_Context::CRL;
  420|    198|}
_ZNK5Botan14Cert_Extension21NoRevocationAvailable22is_appropriate_contextENS_17Extension_ContextE:
  426|      1|bool NoRevocationAvailable::is_appropriate_context(Extension_Context context) const {
  427|      1|   return context == Extension_Context::Certificate;
  428|      1|}
_ZNK5Botan14Cert_Extension10TNAuthList22is_appropriate_contextENS_17Extension_ContextE:
  430|      1|bool TNAuthList::is_appropriate_context(Extension_Context context) const {
  431|      1|   return context == Extension_Context::Certificate;
  432|      1|}
_ZNK5Botan14Cert_Extension15IPAddressBlocks22is_appropriate_contextENS_17Extension_ContextE:
  434|      1|bool IPAddressBlocks::is_appropriate_context(Extension_Context context) const {
  435|      1|   return context == Extension_Context::Certificate;
  436|      1|}
_ZNK5Botan14Cert_Extension8ASBlocks22is_appropriate_contextENS_17Extension_ContextE:
  438|      1|bool ASBlocks::is_appropriate_context(Extension_Context context) const {
  439|      1|   return context == Extension_Context::Certificate;
  440|      1|}
_ZN5Botan14Cert_Extension17Basic_ConstraintsC2Ebm:
  447|      1|      Basic_Constraints(is_ca, is_ca ? std::optional<size_t>(path_length_constraint) : std::nullopt) {}
  ------------------
  |  Branch (447:32): [True: 0, False: 1]
  ------------------
_ZN5Botan14Cert_Extension17Basic_ConstraintsC2EbNSt3__18optionalImEE:
  450|      1|      m_is_ca(is_ca), m_path_length_constraint(path_length_constraint) {
  451|      1|   if(!m_is_ca && m_path_length_constraint.has_value()) {
  ------------------
  |  Branch (451:7): [True: 1, False: 0]
  |  Branch (451:19): [True: 0, False: 1]
  ------------------
  452|       |      // RFC 5280 Sec 4.2.1.9 "CAs MUST NOT include the pathLenConstraint field unless the cA boolean is asserted"
  453|      0|      throw Invalid_Argument(
  454|      0|         "Basic_Constraints nonsensical to set a path length constraint for a non-CA basicConstraints");
  455|      0|   }
  456|      1|}
_ZN5Botan14Cert_Extension16Authority_Key_ID12decode_innerERKNSt3__16vectorIhNS2_9allocatorIhEEEE:
  625|    105|void Authority_Key_ID::decode_inner(const std::vector<uint8_t>& in) {
  626|       |   /*
  627|       |   * RFC 5280 Section 4.2.1.1
  628|       |   *
  629|       |   * AuthorityKeyIdentifier ::= SEQUENCE {
  630|       |   *    keyIdentifier             [0] KeyIdentifier           OPTIONAL,
  631|       |   *    authorityCertIssuer       [1] GeneralNames            OPTIONAL,
  632|       |   *    authorityCertSerialNumber [2] CertificateSerialNumber OPTIONAL }
  633|       |   */
  634|    105|   BER_Decoder ber(in, BER_Decoder::Limits::DER());
  635|    105|   BER_Decoder seq = ber.start_sequence();
  636|       |
  637|    105|   m_key_id.clear();
  638|    105|   m_authority_cert.reset();
  639|       |
  640|    105|   bool key_id_present = false;
  641|    105|   std::optional<AlternativeName> authority_cert_issuer;
  642|    105|   std::optional<X509_Serial_Number> authority_cert_serial;
  643|       |
  644|    105|   seq.decode_optional_field(0,
  645|    105|                             ASN1_Class::ContextSpecific,
  646|    105|                             [&](BER_Decoder& d) {
  647|    105|                                d.decode(m_key_id, ASN1_Type::OctetString, ASN1_Type(0), ASN1_Class::ContextSpecific);
  648|    105|                                key_id_present = true;
  649|    105|                             })
  650|    105|      .decode_optional_field(1,
  651|    105|                             ASN1_Class::ContextSpecific | ASN1_Class::Constructed,
  652|    105|                             [&](BER_Decoder& d) {
  653|    105|                                AlternativeName names;
  654|    105|                                d.decode_implicit(names,
  655|    105|                                                  ASN1_Type(1),
  656|    105|                                                  ASN1_Class::ContextSpecific | ASN1_Class::Constructed,
  657|    105|                                                  ASN1_Type::Sequence,
  658|    105|                                                  ASN1_Class::Constructed);
  659|    105|                                authority_cert_issuer = std::move(names);
  660|    105|                             })
  661|    105|      .decode_optional_field(2, ASN1_Class::ContextSpecific, [&](BER_Decoder& d) {
  662|    105|         X509_Serial_Number serial;
  663|    105|         d.decode_implicit(
  664|    105|            serial, ASN1_Type(2), ASN1_Class::ContextSpecific, ASN1_Type::Integer, ASN1_Class::Universal);
  665|    105|         authority_cert_serial = std::move(serial);
  666|    105|      });
  667|       |
  668|    105|   seq.end_cons();
  669|    105|   ber.verify_end();
  670|       |
  671|    105|   if(key_id_present) {
  ------------------
  |  Branch (671:7): [True: 12, False: 93]
  ------------------
  672|     12|      if(m_key_id.empty()) {
  ------------------
  |  Branch (672:10): [True: 0, False: 12]
  ------------------
  673|      0|         throw Decoding_Error("AuthorityKeyIdentifier keyIdentifier must not be empty");
  674|      0|      }
  675|     12|      if(m_key_id.size() > MaximumKeyIdentifierLength) {
  ------------------
  |  Branch (675:10): [True: 3, False: 9]
  ------------------
  676|      3|         throw Decoding_Error(fmt("AuthorityKeyIdentifier keyIdentifier length {} exceeds limit of {} bytes",
  677|      3|                                  m_key_id.size(),
  678|      3|                                  MaximumKeyIdentifierLength));
  679|      3|      }
  680|     12|   }
  681|       |
  682|       |   // RFC 5280 4.2.1.6: GeneralNames ::= SEQUENCE SIZE (1..MAX) OF GeneralName
  683|    102|   if(authority_cert_issuer.has_value() && authority_cert_issuer->is_empty()) {
  ------------------
  |  Branch (683:7): [True: 0, False: 102]
  |  Branch (683:44): [True: 0, False: 0]
  ------------------
  684|      0|      throw Decoding_Error("AuthorityKeyIdentifier authorityCertIssuer must contain at least one GeneralName");
  685|      0|   }
  686|       |
  687|       |   /*
  688|       |   * RFC 5280 Appendix A.2:
  689|       |   *
  690|       |   *    authorityCertIssuer and authorityCertSerialNumber MUST both be
  691|       |   *    present or both be absent
  692|       |   */
  693|    102|   if(authority_cert_issuer.has_value() != authority_cert_serial.has_value()) {
  ------------------
  |  Branch (693:7): [True: 5, False: 97]
  ------------------
  694|      5|      throw Decoding_Error(
  695|      5|         "AuthorityKeyIdentifier authorityCertIssuer and authorityCertSerialNumber must both be present or absent");
  696|      5|   }
  697|       |
  698|     97|   if(authority_cert_issuer.has_value()) {
  ------------------
  |  Branch (698:7): [True: 0, False: 97]
  ------------------
  699|      0|      m_authority_cert =
  700|      0|         Authority_Cert_Identifier{std::move(*authority_cert_issuer), std::move(*authority_cert_serial)};
  701|      0|   }
  702|     97|}
_ZN5Botan14Cert_Extension23Issuer_Alternative_Name12decode_innerERKNSt3__16vectorIhNS2_9allocatorIhEEEE:
  737|  1.92k|void Issuer_Alternative_Name::decode_inner(const std::vector<uint8_t>& in) {
  738|       |   /* RFC 5280 Section 4.2.1.7 - IssuerAltName ::= GeneralNames
  739|       |   *  GeneralNames ::= SEQUENCE SIZE (1..MAX) OF GeneralName */
  740|  1.92k|   BER_Decoder(in, BER_Decoder::Limits::DER()).decode(m_alt_name).verify_end();
  741|  1.92k|   if(!m_alt_name.has_items()) {
  ------------------
  |  Branch (741:7): [True: 3, False: 1.92k]
  ------------------
  742|      3|      throw Decoding_Error("IssuerAlternativeName extension must contain at least one GeneralName");
  743|      3|   }
  744|  1.92k|}
_ZN5Botan14Cert_Extension28Authority_Information_Access12decode_innerERKNSt3__16vectorIhNS2_9allocatorIhEEEE:
 1135|     74|void Authority_Information_Access::decode_inner(const std::vector<uint8_t>& in) {
 1136|       |   /*
 1137|       |   * RFC 5280 Section 4.2.2.1
 1138|       |   *
 1139|       |   * AuthorityInfoAccessSyntax ::= SEQUENCE SIZE (1..MAX) OF AccessDescription
 1140|       |   * AccessDescription ::= SEQUENCE {
 1141|       |   *    accessMethod          OBJECT IDENTIFIER,
 1142|       |   *    accessLocation        GeneralName }
 1143|       |   */
 1144|     74|   BER_Decoder outer(in, BER_Decoder::Limits::DER());
 1145|     74|   BER_Decoder ber = outer.start_sequence();
 1146|       |
 1147|     74|   const OID ocsp_responder = OID::from_string("PKIX.OCSP");
 1148|     74|   const OID ca_issuer = OID::from_string("PKIX.CertificateAuthorityIssuers");
 1149|       |
 1150|     74|   m_access_descriptions.clear();
 1151|     74|   m_ocsp_responders.clear();
 1152|     74|   m_ca_issuers.clear();
 1153|       |
 1154|    288|   while(ber.more_items()) {
  ------------------
  |  Branch (1154:10): [True: 216, False: 72]
  ------------------
 1155|    216|      OID oid;
 1156|       |
 1157|    216|      BER_Decoder info = ber.start_sequence();
 1158|       |
 1159|    216|      info.decode(oid);
 1160|    216|      const BER_Object name = info.get_next_object();
 1161|       |
 1162|       |      /* RFC 5280 4.2.2.1:
 1163|       |      *    AccessDescription  ::=  SEQUENCE {
 1164|       |      *         accessMethod          OBJECT IDENTIFIER,
 1165|       |      *         accessLocation        GeneralName  }
 1166|       |      */
 1167|    216|      if(!name.is_set()) {
  ------------------
  |  Branch (1167:10): [True: 2, False: 214]
  ------------------
 1168|      2|         throw Decoding_Error("AuthorityInformationAccess AccessDescription missing accessLocation");
 1169|      2|      }
 1170|    214|      validate_general_name_encoding(name.type_tag(), name.get_class(), name.data());
 1171|    214|      info.end_cons();
 1172|       |
 1173|    214|      m_access_descriptions.emplace_back(
 1174|    214|         oid, name.type_tag(), name.get_class(), std::vector<uint8_t>(name.data().begin(), name.data().end()));
 1175|       |
 1176|    214|      if(name.is_a(6, ASN1_Class::ContextSpecific)) {
  ------------------
  |  Branch (1176:10): [True: 41, False: 173]
  ------------------
 1177|     41|         if(oid == ocsp_responder) {
  ------------------
  |  Branch (1177:13): [True: 5, False: 36]
  ------------------
 1178|      5|            if(auto parsed = URI::from_string(ASN1::to_string(name))) {
  ------------------
  |  Branch (1178:21): [True: 5, False: 0]
  ------------------
 1179|      5|               m_ocsp_responders.push_back(std::move(*parsed));
 1180|      5|            } else {
 1181|      0|               throw Decoding_Error("Invalid URI in AuthorityInformationAccess OCSP responder");
 1182|      0|            }
 1183|     36|         } else if(oid == ca_issuer) {
  ------------------
  |  Branch (1183:20): [True: 3, False: 33]
  ------------------
 1184|      3|            if(auto parsed = URI::from_string(ASN1::to_string(name))) {
  ------------------
  |  Branch (1184:21): [True: 3, False: 0]
  ------------------
 1185|      3|               m_ca_issuers.push_back(std::move(*parsed));
 1186|      3|            } else {
 1187|      0|               throw Decoding_Error("Invalid URI in AuthorityInformationAccess CA issuers");
 1188|      0|            }
 1189|      3|         }
 1190|     41|      }
 1191|    214|   }
 1192|       |
 1193|     72|   ber.end_cons();
 1194|     72|   outer.verify_end();
 1195|       |
 1196|     72|   if(m_access_descriptions.empty()) {
  ------------------
  |  Branch (1196:7): [True: 0, False: 72]
  ------------------
 1197|      0|      throw Decoding_Error("AuthorityInformationAccess extension must contain at least one AccessDescription");
 1198|      0|   }
 1199|     72|}
_ZNK5Botan14Cert_Extension10CRL_Number10crl_numberEv:
 1205|     12|const BigInt& CRL_Number::crl_number() const {
 1206|       |   // This can only happen via a misuse of the CRL_Number default constructor
 1207|     12|   BOTAN_STATE_CHECK(m_has_value);
  ------------------
  |  |   51|     12|   do {                                                         \
  |  |   52|     12|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */             \
  |  |   53|     12|      if(!(expr)) {                                             \
  |  |  ------------------
  |  |  |  Branch (53:10): [True: 0, False: 12]
  |  |  ------------------
  |  |   54|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */    \
  |  |   55|      0|         Botan::throw_invalid_state(#expr, __func__, __FILE__); \
  |  |   56|      0|      }                                                         \
  |  |   57|     12|   } while(0)
  |  |  ------------------
  |  |  |  Branch (57:12): [Folded, False: 12]
  |  |  ------------------
  ------------------
 1208|     12|   return m_crl_number;
 1209|     12|}
_ZN5Botan14Cert_Extension10CRL_Number12decode_innerERKNSt3__16vectorIhNS2_9allocatorIhEEEE:
 1239|     38|void CRL_Number::decode_inner(const std::vector<uint8_t>& in) {
 1240|       |   /* RFC 5280 Section 5.2.3 - CRLNumber ::= INTEGER (0..MAX) */
 1241|     38|   BER_Decoder(in, BER_Decoder::Limits::DER()).decode(m_crl_number).verify_end();
 1242|     38|   if(m_crl_number.signum() < 0) {
  ------------------
  |  Branch (1242:7): [True: 5, False: 33]
  ------------------
 1243|      5|      throw Decoding_Error("CRL number cannot be negative");
 1244|      5|   }
 1245|     33|   m_has_value = true;
 1246|     33|}
_ZN5Botan14Cert_Extension14CRL_ReasonCode12decode_innerERKNSt3__16vectorIhNS2_9allocatorIhEEEE:
 1260|  4.03k|void CRL_ReasonCode::decode_inner(const std::vector<uint8_t>& in) {
 1261|       |   /*
 1262|       |   * RFC 5280 Section 5.3.1
 1263|       |   *
 1264|       |   * CRLReason ::= ENUMERATED {
 1265|       |   *      unspecified             (0),
 1266|       |   *      keyCompromise           (1),
 1267|       |   *      cACompromise            (2),
 1268|       |   *      affiliationChanged      (3),
 1269|       |   *      superseded              (4),
 1270|       |   *      cessationOfOperation    (5),
 1271|       |   *      certificateHold         (6),
 1272|       |   *           -- value 7 is not used
 1273|       |   *      removeFromCRL           (8),
 1274|       |   *      privilegeWithdrawn      (9),
 1275|       |   *      aACompromise           (10) }
 1276|       |   */
 1277|  4.03k|   size_t reason_code = 0;
 1278|  4.03k|   BER_Decoder(in, BER_Decoder::Limits::DER())
 1279|  4.03k|      .decode(reason_code, ASN1_Type::Enumerated, ASN1_Class::Universal)
 1280|  4.03k|      .verify_end();
 1281|       |
 1282|  4.03k|   if(reason_code == 7 || reason_code > 10) {
  ------------------
  |  Branch (1282:7): [True: 2.24k, False: 1.78k]
  |  Branch (1282:27): [True: 525, False: 1.26k]
  ------------------
 1283|    565|      throw Decoding_Error(fmt("CRLReason has unknown enumeration value {}", reason_code));
 1284|    565|   }
 1285|       |
 1286|  3.47k|   m_reason = static_cast<CRL_Code>(reason_code);
 1287|  3.47k|}
_ZN5Botan14Cert_Extension21DistributionPointName11decode_fromERNS_11BER_DecoderE:
 1356|     39|void DistributionPointName::decode_from(BER_Decoder& ber) {
 1357|     39|   const BER_Object& obj = ber.peek_next_object();
 1358|     39|   if(obj.is_a(0, ASN1_Class::ContextSpecific | ASN1_Class::Constructed)) {
  ------------------
  |  Branch (1358:7): [True: 32, False: 7]
  ------------------
 1359|     32|      AlternativeName full_name;
 1360|     32|      ber.decode_implicit(full_name,
 1361|     32|                          ASN1_Type(0),
 1362|     32|                          ASN1_Class::ContextSpecific | ASN1_Class::Constructed,
 1363|     32|                          ASN1_Type::Sequence,
 1364|     32|                          ASN1_Class::Constructed);
 1365|       |      // RFC 5280 4.2.1.6: GeneralNames ::= SEQUENCE SIZE (1..MAX) OF GeneralName
 1366|     32|      if(!full_name.has_items()) {
  ------------------
  |  Branch (1366:10): [True: 4, False: 28]
  ------------------
 1367|      4|         throw Decoding_Error("DistributionPointName fullName must contain at least one GeneralName");
 1368|      4|      }
 1369|     28|      if(std::ranges::any_of(full_name.directory_names(), [](const X509_DN& dn) { return dn.empty(); })) {
  ------------------
  |  Branch (1369:10): [True: 0, False: 28]
  ------------------
 1370|      0|         throw Decoding_Error("DistributionPointName fullName must not contain an empty directoryName");
 1371|      0|      }
 1372|     28|      m_full_name = std::move(full_name);
 1373|     28|   } else if(obj.is_a(1, ASN1_Class::ContextSpecific | ASN1_Class::Constructed)) {
  ------------------
  |  Branch (1373:14): [True: 3, False: 4]
  ------------------
 1374|      3|      throw Decoding_Error("nameRelativeToCrlIssuer not supported in DistributionPointName");
 1375|      4|   } else {
 1376|      4|      throw Decoding_Error("DistributionPointName CHOICE is neither fullName nor nameRelativeToCRLIssuer");
 1377|      4|   }
 1378|     39|}
_ZN5Botan14Cert_Extension30CRL_Issuing_Distribution_Point12decode_innerERKNSt3__16vectorIhNS2_9allocatorIhEEEE:
 1552|    196|void CRL_Issuing_Distribution_Point::decode_inner(const std::vector<uint8_t>& buf) {
 1553|       |   /*
 1554|       |   * RFC 5280 Section 5.2.5
 1555|       |   *
 1556|       |   * IssuingDistributionPoint ::= SEQUENCE {
 1557|       |   *      distributionPoint          [0] DistributionPointName OPTIONAL,
 1558|       |   *      onlyContainsUserCerts      [1] BOOLEAN DEFAULT FALSE,
 1559|       |   *      onlyContainsCACerts        [2] BOOLEAN DEFAULT FALSE,
 1560|       |   *      onlySomeReasons            [3] ReasonFlags OPTIONAL,
 1561|       |   *      indirectCRL                [4] BOOLEAN DEFAULT FALSE,
 1562|       |   *      onlyContainsAttributeCerts [5] BOOLEAN DEFAULT FALSE }
 1563|       |   */
 1564|    196|   BER_Decoder outer(buf, BER_Decoder::Limits::DER());
 1565|    196|   BER_Decoder seq = outer.start_sequence();
 1566|       |
 1567|    196|   m_dp_name.reset();
 1568|    196|   m_only_contains_user_certs = false;
 1569|    196|   m_only_contains_ca_certs = false;
 1570|    196|   m_only_some_reasons = {};
 1571|    196|   m_indirect_crl = false;
 1572|    196|   m_only_contains_attribute_certs = false;
 1573|       |
 1574|    196|   auto decode_implicit_bool = [&](BER_Decoder& dec, uint32_t tag) -> bool {
 1575|    196|      bool value = false;
 1576|    196|      dec.decode(value, ASN1_Type(tag), ASN1_Class::ContextSpecific);
 1577|    196|      return value;
 1578|    196|   };
 1579|       |
 1580|       |   // DER: these optional fields appear at most once and in increasing tag
 1581|       |   // order. Decoding them in tag order and then rejecting anything left over
 1582|       |   // (see end_cons below) catches out-of-order, duplicate, and unknown fields.
 1583|    196|   seq.decode_optional_field(0,
 1584|    196|                             ASN1_Class::ContextSpecific | ASN1_Class::Constructed,
 1585|    196|                             [&](BER_Decoder& d) {
 1586|    196|                                DistributionPointName name;
 1587|    196|                                d.start_context_specific(0).decode(name).verify_end();
 1588|    196|                                m_dp_name = std::move(name);
 1589|    196|                             })
 1590|    196|      .decode_optional_field(1,
 1591|    196|                             ASN1_Class::ContextSpecific,
 1592|    196|                             [&](BER_Decoder& d) { m_only_contains_user_certs = decode_implicit_bool(d, 1); })
 1593|    196|      .decode_optional_field(
 1594|    196|         2, ASN1_Class::ContextSpecific, [&](BER_Decoder& d) { m_only_contains_ca_certs = decode_implicit_bool(d, 2); })
 1595|    196|      .decode_optional_field(3,
 1596|    196|                             ASN1_Class::ContextSpecific,
 1597|    196|                             [&](BER_Decoder& d) { m_only_some_reasons = decode_reason_flags_implicit(d, 3); })
 1598|    196|      .decode_optional_field(
 1599|    196|         4, ASN1_Class::ContextSpecific, [&](BER_Decoder& d) { m_indirect_crl = decode_implicit_bool(d, 4); })
 1600|    196|      .decode_optional_field(5, ASN1_Class::ContextSpecific, [&](BER_Decoder& d) {
 1601|    196|         m_only_contains_attribute_certs = decode_implicit_bool(d, 5);
 1602|    196|      });
 1603|       |
 1604|    196|   seq.end_cons();
 1605|    196|   outer.verify_end();
 1606|       |
 1607|       |   /* RFC 5280 5.2.5: "Conforming CRLs issuers MUST NOT issue CRLs where the
 1608|       |   * DER encoding of the issuing distribution point extension is an empty
 1609|       |   * sequence." Empty here means none of the fields above were present. */
 1610|    196|   if(!m_dp_name.has_value() && !m_only_contains_user_certs && !m_only_contains_ca_certs &&
  ------------------
  |  Branch (1610:7): [True: 0, False: 196]
  |  Branch (1610:33): [True: 0, False: 0]
  |  Branch (1610:64): [True: 0, False: 0]
  ------------------
 1611|      0|      !m_only_some_reasons.has_value() && !m_indirect_crl && !m_only_contains_attribute_certs) {
  ------------------
  |  Branch (1611:7): [True: 0, False: 0]
  |  Branch (1611:43): [True: 0, False: 0]
  |  Branch (1611:62): [True: 0, False: 0]
  ------------------
 1612|      0|      throw Decoding_Error("IssuingDistributionPoint must contain at least one field");
 1613|      0|   }
 1614|       |
 1615|       |   /* RFC 5280 5.2.5: "at most one of onlyContainsUserCerts,
 1616|       |   * onlyContainsCACerts, and onlyContainsAttributeCerts may be set to TRUE." */
 1617|    196|   const size_t scope_set = static_cast<size_t>(m_only_contains_user_certs) +
 1618|    196|                            static_cast<size_t>(m_only_contains_ca_certs) +
 1619|    196|                            static_cast<size_t>(m_only_contains_attribute_certs);
 1620|    196|   if(scope_set > 1) {
  ------------------
  |  Branch (1620:7): [True: 0, False: 196]
  ------------------
 1621|      0|      throw Decoding_Error(
 1622|      0|         "IssuingDistributionPoint sets more than one of onlyContainsUserCerts/CACerts/AttributeCerts");
 1623|      0|   }
 1624|    196|}
_ZN5Botan14Cert_Extension17Unknown_Extension12decode_innerERKNSt3__16vectorIhNS2_9allocatorIhEEEE:
 2613|  12.5k|void Unknown_Extension::decode_inner(const std::vector<uint8_t>& bytes) {
 2614|       |   // Just treat as an opaque blob at this level
 2615|  12.5k|   m_bytes = bytes;
 2616|  12.5k|}
x509_ext.cpp:_ZN5Botan12_GLOBAL__N_118extension_from_oidERKNS_3OIDE:
   55|  13.9k|std::unique_ptr<Certificate_Extension> extension_from_oid(const OID& oid) {
   56|  13.9k|   if(auto iso_ext = is_sub_element_of(oid, {2, 5, 29})) {
  ------------------
  |  Branch (56:12): [True: 10.7k, False: 3.21k]
  ------------------
   57|       |      // NOLINTNEXTLINE(*-switch-missing-default-case)
   58|  10.7k|      switch(*iso_ext) {
  ------------------
  |  Branch (58:14): [True: 6.32k, False: 4.43k]
  ------------------
   59|      3|         case 14:
  ------------------
  |  Branch (59:10): [True: 3, False: 10.7k]
  ------------------
   60|      3|            return make_extension<Cert_Extension::Subject_Key_ID>(oid);
   61|      1|         case 15:
  ------------------
  |  Branch (61:10): [True: 1, False: 10.7k]
  ------------------
   62|      1|            return make_extension<Cert_Extension::Key_Usage>(oid);
   63|      1|         case 17:
  ------------------
  |  Branch (63:10): [True: 1, False: 10.7k]
  ------------------
   64|      1|            return make_extension<Cert_Extension::Subject_Alternative_Name>(oid);
   65|  1.92k|         case 18:
  ------------------
  |  Branch (65:10): [True: 1.92k, False: 8.83k]
  ------------------
   66|  1.92k|            return make_extension<Cert_Extension::Issuer_Alternative_Name>(oid);
   67|      1|         case 19:
  ------------------
  |  Branch (67:10): [True: 1, False: 10.7k]
  ------------------
   68|      1|            return make_extension<Cert_Extension::Basic_Constraints>(oid);
   69|     39|         case 20:
  ------------------
  |  Branch (69:10): [True: 39, False: 10.7k]
  ------------------
   70|     39|            return make_extension<Cert_Extension::CRL_Number>(oid);
   71|  4.03k|         case 21:
  ------------------
  |  Branch (71:10): [True: 4.03k, False: 6.71k]
  ------------------
   72|  4.03k|            return make_extension<Cert_Extension::CRL_ReasonCode>(oid);
   73|    198|         case 28:
  ------------------
  |  Branch (73:10): [True: 198, False: 10.5k]
  ------------------
   74|    198|            return make_extension<Cert_Extension::CRL_Issuing_Distribution_Point>(oid);
   75|      1|         case 30:
  ------------------
  |  Branch (75:10): [True: 1, False: 10.7k]
  ------------------
   76|      1|            return make_extension<Cert_Extension::Name_Constraints>(oid);
   77|      2|         case 31:
  ------------------
  |  Branch (77:10): [True: 2, False: 10.7k]
  ------------------
   78|      2|            return make_extension<Cert_Extension::CRL_Distribution_Points>(oid);
   79|      2|         case 32:
  ------------------
  |  Branch (79:10): [True: 2, False: 10.7k]
  ------------------
   80|      2|            return make_extension<Cert_Extension::Certificate_Policies>(oid);
   81|    106|         case 35:
  ------------------
  |  Branch (81:10): [True: 106, False: 10.6k]
  ------------------
   82|    106|            return make_extension<Cert_Extension::Authority_Key_ID>(oid);
   83|      1|         case 37:
  ------------------
  |  Branch (83:10): [True: 1, False: 10.7k]
  ------------------
   84|      1|            return make_extension<Cert_Extension::Extended_Key_Usage>(oid);
   85|      1|         case 56:
  ------------------
  |  Branch (85:10): [True: 1, False: 10.7k]
  ------------------
   86|      1|            return make_extension<Cert_Extension::NoRevocationAvailable>(oid);
   87|  10.7k|      }
   88|  10.7k|   }
   89|       |
   90|  7.65k|   if(auto pkix_ext = is_sub_element_of(oid, {1, 3, 6, 1, 5, 5, 7, 1})) {
  ------------------
  |  Branch (90:12): [True: 78, False: 7.57k]
  ------------------
   91|       |      // NOLINTNEXTLINE(*-switch-missing-default-case)
   92|     78|      switch(*pkix_ext) {
  ------------------
  |  Branch (92:14): [True: 77, False: 1]
  ------------------
   93|     74|         case 1:
  ------------------
  |  Branch (93:10): [True: 74, False: 4]
  ------------------
   94|     74|            return make_extension<Cert_Extension::Authority_Information_Access>(oid);
   95|      1|         case 7:
  ------------------
  |  Branch (95:10): [True: 1, False: 77]
  ------------------
   96|      1|            return make_extension<Cert_Extension::IPAddressBlocks>(oid);
   97|      1|         case 8:
  ------------------
  |  Branch (97:10): [True: 1, False: 77]
  ------------------
   98|      1|            return make_extension<Cert_Extension::ASBlocks>(oid);
   99|      1|         case 26:
  ------------------
  |  Branch (99:10): [True: 1, False: 77]
  ------------------
  100|      1|            return make_extension<Cert_Extension::TNAuthList>(oid);
  101|     78|      }
  102|     78|   }
  103|       |
  104|  7.57k|   if(oid == Cert_Extension::OCSP_NoCheck::static_oid()) {
  ------------------
  |  Branch (104:7): [True: 0, False: 7.57k]
  ------------------
  105|      0|      return make_extension<Cert_Extension::OCSP_NoCheck>(oid);
  106|      0|   }
  107|       |
  108|  7.57k|   return nullptr;  // unknown
  109|  7.57k|}
x509_ext.cpp:_ZN5Botan12_GLOBAL__N_114make_extensionITkNSt3__112derived_fromINS_21Certificate_ExtensionEEENS_14Cert_Extension14Subject_Key_IDEEEDaRKNS_3OIDE:
   50|      3|auto make_extension([[maybe_unused]] const OID& oid) {
   51|      3|   BOTAN_DEBUG_ASSERT(oid == T::static_oid());
  ------------------
  |  |  137|      3|      do { /* NOLINT(*-avoid-do-while) */ \
  |  |  138|      3|      } while(0)
  |  |  ------------------
  |  |  |  Branch (138:15): [Folded, False: 3]
  |  |  ------------------
  ------------------
   52|      3|   return std::make_unique<T>();
   53|      3|}
x509_ext.cpp:_ZN5Botan12_GLOBAL__N_114make_extensionITkNSt3__112derived_fromINS_21Certificate_ExtensionEEENS_14Cert_Extension9Key_UsageEEEDaRKNS_3OIDE:
   50|      1|auto make_extension([[maybe_unused]] const OID& oid) {
   51|      1|   BOTAN_DEBUG_ASSERT(oid == T::static_oid());
  ------------------
  |  |  137|      1|      do { /* NOLINT(*-avoid-do-while) */ \
  |  |  138|      1|      } while(0)
  |  |  ------------------
  |  |  |  Branch (138:15): [Folded, False: 1]
  |  |  ------------------
  ------------------
   52|      1|   return std::make_unique<T>();
   53|      1|}
x509_ext.cpp:_ZN5Botan12_GLOBAL__N_114make_extensionITkNSt3__112derived_fromINS_21Certificate_ExtensionEEENS_14Cert_Extension24Subject_Alternative_NameEEEDaRKNS_3OIDE:
   50|      1|auto make_extension([[maybe_unused]] const OID& oid) {
   51|      1|   BOTAN_DEBUG_ASSERT(oid == T::static_oid());
  ------------------
  |  |  137|      1|      do { /* NOLINT(*-avoid-do-while) */ \
  |  |  138|      1|      } while(0)
  |  |  ------------------
  |  |  |  Branch (138:15): [Folded, False: 1]
  |  |  ------------------
  ------------------
   52|      1|   return std::make_unique<T>();
   53|      1|}
x509_ext.cpp:_ZN5Botan12_GLOBAL__N_114make_extensionITkNSt3__112derived_fromINS_21Certificate_ExtensionEEENS_14Cert_Extension23Issuer_Alternative_NameEEEDaRKNS_3OIDE:
   50|  1.92k|auto make_extension([[maybe_unused]] const OID& oid) {
   51|  1.92k|   BOTAN_DEBUG_ASSERT(oid == T::static_oid());
  ------------------
  |  |  137|  1.92k|      do { /* NOLINT(*-avoid-do-while) */ \
  |  |  138|  1.92k|      } while(0)
  |  |  ------------------
  |  |  |  Branch (138:15): [Folded, False: 1.92k]
  |  |  ------------------
  ------------------
   52|  1.92k|   return std::make_unique<T>();
   53|  1.92k|}
x509_ext.cpp:_ZN5Botan12_GLOBAL__N_114make_extensionITkNSt3__112derived_fromINS_21Certificate_ExtensionEEENS_14Cert_Extension17Basic_ConstraintsEEEDaRKNS_3OIDE:
   50|      1|auto make_extension([[maybe_unused]] const OID& oid) {
   51|      1|   BOTAN_DEBUG_ASSERT(oid == T::static_oid());
  ------------------
  |  |  137|      1|      do { /* NOLINT(*-avoid-do-while) */ \
  |  |  138|      1|      } while(0)
  |  |  ------------------
  |  |  |  Branch (138:15): [Folded, False: 1]
  |  |  ------------------
  ------------------
   52|      1|   return std::make_unique<T>();
   53|      1|}
x509_ext.cpp:_ZN5Botan12_GLOBAL__N_114make_extensionITkNSt3__112derived_fromINS_21Certificate_ExtensionEEENS_14Cert_Extension10CRL_NumberEEEDaRKNS_3OIDE:
   50|     39|auto make_extension([[maybe_unused]] const OID& oid) {
   51|     39|   BOTAN_DEBUG_ASSERT(oid == T::static_oid());
  ------------------
  |  |  137|     39|      do { /* NOLINT(*-avoid-do-while) */ \
  |  |  138|     39|      } while(0)
  |  |  ------------------
  |  |  |  Branch (138:15): [Folded, False: 39]
  |  |  ------------------
  ------------------
   52|     39|   return std::make_unique<T>();
   53|     39|}
x509_ext.cpp:_ZN5Botan12_GLOBAL__N_114make_extensionITkNSt3__112derived_fromINS_21Certificate_ExtensionEEENS_14Cert_Extension14CRL_ReasonCodeEEEDaRKNS_3OIDE:
   50|  4.03k|auto make_extension([[maybe_unused]] const OID& oid) {
   51|  4.03k|   BOTAN_DEBUG_ASSERT(oid == T::static_oid());
  ------------------
  |  |  137|  4.03k|      do { /* NOLINT(*-avoid-do-while) */ \
  |  |  138|  4.03k|      } while(0)
  |  |  ------------------
  |  |  |  Branch (138:15): [Folded, False: 4.03k]
  |  |  ------------------
  ------------------
   52|  4.03k|   return std::make_unique<T>();
   53|  4.03k|}
x509_ext.cpp:_ZN5Botan12_GLOBAL__N_114make_extensionITkNSt3__112derived_fromINS_21Certificate_ExtensionEEENS_14Cert_Extension30CRL_Issuing_Distribution_PointEEEDaRKNS_3OIDE:
   50|    198|auto make_extension([[maybe_unused]] const OID& oid) {
   51|    198|   BOTAN_DEBUG_ASSERT(oid == T::static_oid());
  ------------------
  |  |  137|    198|      do { /* NOLINT(*-avoid-do-while) */ \
  |  |  138|    198|      } while(0)
  |  |  ------------------
  |  |  |  Branch (138:15): [Folded, False: 198]
  |  |  ------------------
  ------------------
   52|    198|   return std::make_unique<T>();
   53|    198|}
x509_ext.cpp:_ZN5Botan12_GLOBAL__N_114make_extensionITkNSt3__112derived_fromINS_21Certificate_ExtensionEEENS_14Cert_Extension16Name_ConstraintsEEEDaRKNS_3OIDE:
   50|      1|auto make_extension([[maybe_unused]] const OID& oid) {
   51|      1|   BOTAN_DEBUG_ASSERT(oid == T::static_oid());
  ------------------
  |  |  137|      1|      do { /* NOLINT(*-avoid-do-while) */ \
  |  |  138|      1|      } while(0)
  |  |  ------------------
  |  |  |  Branch (138:15): [Folded, False: 1]
  |  |  ------------------
  ------------------
   52|      1|   return std::make_unique<T>();
   53|      1|}
x509_ext.cpp:_ZN5Botan12_GLOBAL__N_114make_extensionITkNSt3__112derived_fromINS_21Certificate_ExtensionEEENS_14Cert_Extension23CRL_Distribution_PointsEEEDaRKNS_3OIDE:
   50|      2|auto make_extension([[maybe_unused]] const OID& oid) {
   51|      2|   BOTAN_DEBUG_ASSERT(oid == T::static_oid());
  ------------------
  |  |  137|      2|      do { /* NOLINT(*-avoid-do-while) */ \
  |  |  138|      2|      } while(0)
  |  |  ------------------
  |  |  |  Branch (138:15): [Folded, False: 2]
  |  |  ------------------
  ------------------
   52|      2|   return std::make_unique<T>();
   53|      2|}
x509_ext.cpp:_ZN5Botan12_GLOBAL__N_114make_extensionITkNSt3__112derived_fromINS_21Certificate_ExtensionEEENS_14Cert_Extension20Certificate_PoliciesEEEDaRKNS_3OIDE:
   50|      2|auto make_extension([[maybe_unused]] const OID& oid) {
   51|      2|   BOTAN_DEBUG_ASSERT(oid == T::static_oid());
  ------------------
  |  |  137|      2|      do { /* NOLINT(*-avoid-do-while) */ \
  |  |  138|      2|      } while(0)
  |  |  ------------------
  |  |  |  Branch (138:15): [Folded, False: 2]
  |  |  ------------------
  ------------------
   52|      2|   return std::make_unique<T>();
   53|      2|}
x509_ext.cpp:_ZN5Botan12_GLOBAL__N_114make_extensionITkNSt3__112derived_fromINS_21Certificate_ExtensionEEENS_14Cert_Extension16Authority_Key_IDEEEDaRKNS_3OIDE:
   50|    106|auto make_extension([[maybe_unused]] const OID& oid) {
   51|    106|   BOTAN_DEBUG_ASSERT(oid == T::static_oid());
  ------------------
  |  |  137|    106|      do { /* NOLINT(*-avoid-do-while) */ \
  |  |  138|    106|      } while(0)
  |  |  ------------------
  |  |  |  Branch (138:15): [Folded, False: 106]
  |  |  ------------------
  ------------------
   52|    106|   return std::make_unique<T>();
   53|    106|}
x509_ext.cpp:_ZN5Botan12_GLOBAL__N_114make_extensionITkNSt3__112derived_fromINS_21Certificate_ExtensionEEENS_14Cert_Extension18Extended_Key_UsageEEEDaRKNS_3OIDE:
   50|      1|auto make_extension([[maybe_unused]] const OID& oid) {
   51|      1|   BOTAN_DEBUG_ASSERT(oid == T::static_oid());
  ------------------
  |  |  137|      1|      do { /* NOLINT(*-avoid-do-while) */ \
  |  |  138|      1|      } while(0)
  |  |  ------------------
  |  |  |  Branch (138:15): [Folded, False: 1]
  |  |  ------------------
  ------------------
   52|      1|   return std::make_unique<T>();
   53|      1|}
x509_ext.cpp:_ZN5Botan12_GLOBAL__N_114make_extensionITkNSt3__112derived_fromINS_21Certificate_ExtensionEEENS_14Cert_Extension21NoRevocationAvailableEEEDaRKNS_3OIDE:
   50|      1|auto make_extension([[maybe_unused]] const OID& oid) {
   51|      1|   BOTAN_DEBUG_ASSERT(oid == T::static_oid());
  ------------------
  |  |  137|      1|      do { /* NOLINT(*-avoid-do-while) */ \
  |  |  138|      1|      } while(0)
  |  |  ------------------
  |  |  |  Branch (138:15): [Folded, False: 1]
  |  |  ------------------
  ------------------
   52|      1|   return std::make_unique<T>();
   53|      1|}
x509_ext.cpp:_ZN5Botan12_GLOBAL__N_114make_extensionITkNSt3__112derived_fromINS_21Certificate_ExtensionEEENS_14Cert_Extension28Authority_Information_AccessEEEDaRKNS_3OIDE:
   50|     74|auto make_extension([[maybe_unused]] const OID& oid) {
   51|     74|   BOTAN_DEBUG_ASSERT(oid == T::static_oid());
  ------------------
  |  |  137|     74|      do { /* NOLINT(*-avoid-do-while) */ \
  |  |  138|     74|      } while(0)
  |  |  ------------------
  |  |  |  Branch (138:15): [Folded, False: 74]
  |  |  ------------------
  ------------------
   52|     74|   return std::make_unique<T>();
   53|     74|}
x509_ext.cpp:_ZN5Botan12_GLOBAL__N_114make_extensionITkNSt3__112derived_fromINS_21Certificate_ExtensionEEENS_14Cert_Extension15IPAddressBlocksEEEDaRKNS_3OIDE:
   50|      1|auto make_extension([[maybe_unused]] const OID& oid) {
   51|      1|   BOTAN_DEBUG_ASSERT(oid == T::static_oid());
  ------------------
  |  |  137|      1|      do { /* NOLINT(*-avoid-do-while) */ \
  |  |  138|      1|      } while(0)
  |  |  ------------------
  |  |  |  Branch (138:15): [Folded, False: 1]
  |  |  ------------------
  ------------------
   52|      1|   return std::make_unique<T>();
   53|      1|}
x509_ext.cpp:_ZN5Botan12_GLOBAL__N_114make_extensionITkNSt3__112derived_fromINS_21Certificate_ExtensionEEENS_14Cert_Extension8ASBlocksEEEDaRKNS_3OIDE:
   50|      1|auto make_extension([[maybe_unused]] const OID& oid) {
   51|      1|   BOTAN_DEBUG_ASSERT(oid == T::static_oid());
  ------------------
  |  |  137|      1|      do { /* NOLINT(*-avoid-do-while) */ \
  |  |  138|      1|      } while(0)
  |  |  ------------------
  |  |  |  Branch (138:15): [Folded, False: 1]
  |  |  ------------------
  ------------------
   52|      1|   return std::make_unique<T>();
   53|      1|}
x509_ext.cpp:_ZN5Botan12_GLOBAL__N_114make_extensionITkNSt3__112derived_fromINS_21Certificate_ExtensionEEENS_14Cert_Extension10TNAuthListEEEDaRKNS_3OIDE:
   50|      1|auto make_extension([[maybe_unused]] const OID& oid) {
   51|      1|   BOTAN_DEBUG_ASSERT(oid == T::static_oid());
  ------------------
  |  |  137|      1|      do { /* NOLINT(*-avoid-do-while) */ \
  |  |  138|      1|      } while(0)
  |  |  ------------------
  |  |  |  Branch (138:15): [Folded, False: 1]
  |  |  ------------------
  ------------------
   52|      1|   return std::make_unique<T>();
   53|      1|}
x509_ext.cpp:_ZN5Botan14Cert_Extension12_GLOBAL__N_130validate_general_name_encodingENS_9ASN1_TypeENS_10ASN1_ClassENSt3__14spanIKhLm18446744073709551615EEE:
 1024|    191|void validate_general_name_encoding(ASN1_Type tag, ASN1_Class cls, std::span<const uint8_t> value) {
 1025|       |   // AlternativeName decodes GeneralNames; AIA accessLocation is a single GeneralName.
 1026|    191|   std::vector<uint8_t> wrapped_name;
 1027|    191|   DER_Encoder(wrapped_name).start_sequence().add_object(tag, cls, value).end_cons();
 1028|       |
 1029|    191|   AlternativeName decoded_name;
 1030|    191|   BER_Decoder(wrapped_name, BER_Decoder::Limits::DER()).decode(decoded_name).verify_end();
 1031|       |
 1032|    191|   if((tag == ASN1_Type(1) || tag == ASN1_Type(2) || tag == ASN1_Type(6)) && value.empty()) {
  ------------------
  |  Branch (1032:8): [True: 44, False: 147]
  |  Branch (1032:31): [True: 11, False: 136]
  |  Branch (1032:54): [True: 42, False: 94]
  |  Branch (1032:78): [True: 1, False: 53]
  ------------------
 1033|      1|      throw Decoding_Error("GeneralName IA5String value must not be empty");
 1034|      1|   }
 1035|    190|   if(tag == ASN1_Type(4) &&
  ------------------
  |  Branch (1035:7): [True: 2, False: 188]
  ------------------
 1036|      2|      std::ranges::any_of(decoded_name.directory_names(), [](const X509_DN& dn) { return dn.empty(); })) {
  ------------------
  |  Branch (1036:7): [True: 1, False: 1]
  ------------------
 1037|      1|      throw Decoding_Error("GeneralName directoryName must not be empty");
 1038|      1|   }
 1039|    190|}
x509_ext.cpp:_ZZN5Botan14Cert_Extension12_GLOBAL__N_130validate_general_name_encodingENS_9ASN1_TypeENS_10ASN1_ClassENSt3__14spanIKhLm18446744073709551615EEEENK3$_0clERKNS_7X509_DNE:
 1036|      2|      std::ranges::any_of(decoded_name.directory_names(), [](const X509_DN& dn) { return dn.empty(); })) {
x509_ext.cpp:_ZZN5Botan14Cert_Extension16Authority_Key_ID12decode_innerERKNSt3__16vectorIhNS2_9allocatorIhEEEEENK3$_0clERNS_11BER_DecoderE:
  646|     16|                             [&](BER_Decoder& d) {
  647|     16|                                d.decode(m_key_id, ASN1_Type::OctetString, ASN1_Type(0), ASN1_Class::ContextSpecific);
  648|     16|                                key_id_present = true;
  649|     16|                             })
x509_ext.cpp:_ZZN5Botan14Cert_Extension16Authority_Key_ID12decode_innerERKNSt3__16vectorIhNS2_9allocatorIhEEEEENK3$_1clERNS_11BER_DecoderE:
  652|      9|                             [&](BER_Decoder& d) {
  653|      9|                                AlternativeName names;
  654|      9|                                d.decode_implicit(names,
  655|      9|                                                  ASN1_Type(1),
  656|      9|                                                  ASN1_Class::ContextSpecific | ASN1_Class::Constructed,
  657|      9|                                                  ASN1_Type::Sequence,
  658|      9|                                                  ASN1_Class::Constructed);
  659|      9|                                authority_cert_issuer = std::move(names);
  660|      9|                             })
x509_ext.cpp:_ZZN5Botan14Cert_Extension16Authority_Key_ID12decode_innerERKNSt3__16vectorIhNS2_9allocatorIhEEEEENK3$_2clERNS_11BER_DecoderE:
  661|     10|      .decode_optional_field(2, ASN1_Class::ContextSpecific, [&](BER_Decoder& d) {
  662|     10|         X509_Serial_Number serial;
  663|     10|         d.decode_implicit(
  664|     10|            serial, ASN1_Type(2), ASN1_Class::ContextSpecific, ASN1_Type::Integer, ASN1_Class::Universal);
  665|     10|         authority_cert_serial = std::move(serial);
  666|     10|      });
x509_ext.cpp:_ZN5Botan14Cert_Extension12_GLOBAL__N_128decode_reason_flags_implicitERNS_11BER_DecoderEj:
 1297|     42|ReasonFlags decode_reason_flags_implicit(BER_Decoder& decoder, uint32_t tag) {
 1298|     42|   uint64_t bits = 0;
 1299|     42|   decoder.decode_named_bitstring(bits, ReasonFlagsNamedBitWidth, ASN1_Type(tag), ASN1_Class::ContextSpecific);
 1300|     42|   return ReasonFlags(checked_cast_to<uint16_t>(bits));
 1301|     42|}
x509_ext.cpp:_ZZN5Botan14Cert_Extension30CRL_Issuing_Distribution_Point12decode_innerERKNSt3__16vectorIhNS2_9allocatorIhEEEEENK3$_1clERNS_11BER_DecoderE:
 1585|     39|                             [&](BER_Decoder& d) {
 1586|     39|                                DistributionPointName name;
 1587|     39|                                d.start_context_specific(0).decode(name).verify_end();
 1588|     39|                                m_dp_name = std::move(name);
 1589|     39|                             })
x509_ext.cpp:_ZZN5Botan14Cert_Extension30CRL_Issuing_Distribution_Point12decode_innerERKNSt3__16vectorIhNS2_9allocatorIhEEEEENK3$_2clERNS_11BER_DecoderE:
 1592|      8|                             [&](BER_Decoder& d) { m_only_contains_user_certs = decode_implicit_bool(d, 1); })
x509_ext.cpp:_ZZN5Botan14Cert_Extension30CRL_Issuing_Distribution_Point12decode_innerERKNSt3__16vectorIhNS2_9allocatorIhEEEEENK3$_0clERNS_11BER_DecoderEj:
 1574|     37|   auto decode_implicit_bool = [&](BER_Decoder& dec, uint32_t tag) -> bool {
 1575|     37|      bool value = false;
 1576|     37|      dec.decode(value, ASN1_Type(tag), ASN1_Class::ContextSpecific);
 1577|     37|      return value;
 1578|     37|   };
x509_ext.cpp:_ZZN5Botan14Cert_Extension30CRL_Issuing_Distribution_Point12decode_innerERKNSt3__16vectorIhNS2_9allocatorIhEEEEENK3$_3clERNS_11BER_DecoderE:
 1594|     14|         2, ASN1_Class::ContextSpecific, [&](BER_Decoder& d) { m_only_contains_ca_certs = decode_implicit_bool(d, 2); })
x509_ext.cpp:_ZZN5Botan14Cert_Extension30CRL_Issuing_Distribution_Point12decode_innerERKNSt3__16vectorIhNS2_9allocatorIhEEEEENK3$_4clERNS_11BER_DecoderE:
 1597|     42|                             [&](BER_Decoder& d) { m_only_some_reasons = decode_reason_flags_implicit(d, 3); })
x509_ext.cpp:_ZZN5Botan14Cert_Extension30CRL_Issuing_Distribution_Point12decode_innerERKNSt3__16vectorIhNS2_9allocatorIhEEEEENK3$_5clERNS_11BER_DecoderE:
 1599|      6|         4, ASN1_Class::ContextSpecific, [&](BER_Decoder& d) { m_indirect_crl = decode_implicit_bool(d, 4); })
x509_ext.cpp:_ZZN5Botan14Cert_Extension30CRL_Issuing_Distribution_Point12decode_innerERKNSt3__16vectorIhNS2_9allocatorIhEEEEENK3$_6clERNS_11BER_DecoderE:
 1600|      9|      .decode_optional_field(5, ASN1_Class::ContextSpecific, [&](BER_Decoder& d) {
 1601|      9|         m_only_contains_attribute_certs = decode_implicit_bool(d, 5);
 1602|      9|      });

_ZN5Botan11X509_Object9load_dataERNS_10DataSourceE:
   24|  3.84k|void X509_Object::load_data(DataSource& in) {
   25|  3.84k|   try {
   26|  3.84k|      if(ASN1::maybe_BER(in) && !PEM_Code::matches(in)) {
  ------------------
  |  Branch (26:10): [True: 3.50k, False: 345]
  |  Branch (26:33): [True: 3.49k, False: 6]
  ------------------
   27|  3.49k|         BER_Decoder dec(in, BER_Decoder::Limits::DER());
   28|  3.49k|         decode_from(dec);
   29|       |         // Call to verify_end omitted here since we have to sometimes decode
   30|       |         // multiple certificates encoded sequentially in a DataSource
   31|  3.49k|      } else {
   32|    351|         std::string got_label;
   33|    351|         DataSource_Memory ber(PEM_Code::decode(in, got_label));
   34|       |
   35|    351|         if(got_label != PEM_label()) {
  ------------------
  |  Branch (35:13): [True: 98, False: 253]
  ------------------
   36|     98|            bool is_alternate = false;
   37|     98|            for(const std::string_view alt_label : alternate_PEM_labels()) {
  ------------------
  |  Branch (37:50): [True: 98, False: 97]
  ------------------
   38|     98|               if(got_label == alt_label) {
  ------------------
  |  Branch (38:19): [True: 1, False: 97]
  ------------------
   39|      1|                  is_alternate = true;
   40|      1|                  break;
   41|      1|               }
   42|     98|            }
   43|       |
   44|     98|            if(!is_alternate) {
  ------------------
  |  Branch (44:16): [True: 97, False: 1]
  ------------------
   45|     97|               throw Decoding_Error("Unexpected PEM label for " + PEM_label() + " of " + got_label);
   46|     97|            }
   47|     98|         }
   48|       |
   49|    254|         BER_Decoder dec(ber, BER_Decoder::Limits::DER());
   50|    254|         decode_from(dec);
   51|       |         // Call to verify_end omitted here since we have to sometimes decode
   52|       |         // multiple certificates encoded sequentially in a DataSource
   53|    254|      }
   54|  3.84k|   } catch(Decoding_Error& e) {
   55|  3.72k|      throw Decoding_Error(PEM_label() + " decoding", e);
   56|  3.72k|   }
   57|  3.84k|}
_ZNK5Botan11X509_Object11signed_bodyEv:
   66|  2.67k|const std::vector<uint8_t>& X509_Object::signed_body() const {
   67|  2.67k|   if(!m_signed_data) {
  ------------------
  |  Branch (67:7): [True: 0, False: 2.67k]
  ------------------
   68|      0|      throw Invalid_State("X509_Object uninitialized");
   69|      0|   }
   70|  2.67k|   return m_signed_data->m_tbs_bits;
   71|  2.67k|}
_ZNK5Botan11X509_Object19signature_algorithmEv:
   73|  2.67k|const AlgorithmIdentifier& X509_Object::signature_algorithm() const {
   74|  2.67k|   if(!m_signed_data) {
  ------------------
  |  Branch (74:7): [True: 0, False: 2.67k]
  ------------------
   75|      0|      throw Invalid_State("X509_Object uninitialized");
   76|      0|   }
   77|  2.67k|   return m_signed_data->m_sig_algo;
   78|  2.67k|}
_ZN5Botan11X509_Object11decode_fromERNS_11BER_DecoderE:
   93|  3.50k|void X509_Object::decode_from(BER_Decoder& from) {
   94|  3.50k|   auto data = std::make_shared<Signed_Data>();
   95|       |
   96|  3.50k|   from.start_sequence()
   97|  3.50k|      .start_sequence()
   98|  3.50k|      .raw_bytes(data->m_tbs_bits)
   99|  3.50k|      .end_cons()
  100|  3.50k|      .decode(data->m_sig_algo)
  101|  3.50k|      .decode_octet_aligned_bitstring(data->m_sig)
  102|  3.50k|      .end_cons();
  103|       |
  104|  3.50k|   m_signed_data = std::move(data);
  105|  3.50k|   force_decode();
  106|  3.50k|}

_ZN5Botan18X509_Serial_NumberC2ERKNS_6BigIntE:
   20|  8.96k|X509_Serial_Number::X509_Serial_Number(const BigInt& value) : m_contents(ASN1::integer_contents(value)) {}
_ZNK5Botan18X509_Serial_Number11is_negativeEv:
   65|  59.9k|bool X509_Serial_Number::is_negative() const {
   66|  59.9k|   BOTAN_STATE_CHECK(!m_contents.empty());
  ------------------
  |  |   51|  59.9k|   do {                                                         \
  |  |   52|  59.9k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */             \
  |  |   53|  59.9k|      if(!(expr)) {                                             \
  |  |  ------------------
  |  |  |  Branch (53:10): [True: 0, False: 59.9k]
  |  |  ------------------
  |  |   54|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */    \
  |  |   55|      0|         Botan::throw_invalid_state(#expr, __func__, __FILE__); \
  |  |   56|      0|      }                                                         \
  |  |   57|  59.9k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (57:12): [Folded, False: 59.9k]
  |  |  ------------------
  ------------------
   67|  59.9k|   return (m_contents[0] & 0x80) == 0x80;
   68|  59.9k|}
_ZNK5Botan18X509_Serial_Number7is_zeroEv:
   70|  8.78k|bool X509_Serial_Number::is_zero() const {
   71|  8.78k|   return m_contents.size() == 1 && m_contents[0] == 0x00;
  ------------------
  |  Branch (71:11): [True: 1.45k, False: 7.32k]
  |  Branch (71:37): [True: 246, False: 1.21k]
  ------------------
   72|  8.78k|}
_ZNK5Botan18X509_Serial_Number9magnitudeEv:
   74|  8.78k|std::vector<uint8_t> X509_Serial_Number::magnitude() const {
   75|  8.78k|   BOTAN_STATE_CHECK(!m_contents.empty());
  ------------------
  |  |   51|  8.78k|   do {                                                         \
  |  |   52|  8.78k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */             \
  |  |   53|  8.78k|      if(!(expr)) {                                             \
  |  |  ------------------
  |  |  |  Branch (53:10): [True: 0, False: 8.78k]
  |  |  ------------------
  |  |   54|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */    \
  |  |   55|      0|         Botan::throw_invalid_state(#expr, __func__, __FILE__); \
  |  |   56|      0|      }                                                         \
  |  |   57|  8.78k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (57:12): [Folded, False: 8.78k]
  |  |  ------------------
  ------------------
   76|       |
   77|  8.78k|   if(is_zero()) {
  ------------------
  |  Branch (77:7): [True: 246, False: 8.53k]
  ------------------
   78|    246|      return {};
   79|  8.53k|   } else if(is_negative()) {
  ------------------
  |  Branch (79:14): [True: 723, False: 7.81k]
  ------------------
   80|    723|      return to_bigint().serialize();
   81|  7.81k|   } else if(m_contents[0] == 0x00) {
  ------------------
  |  Branch (81:14): [True: 197, False: 7.61k]
  ------------------
   82|       |      // Positive value whose leading magnitude bit is set; skip the sign octet
   83|    197|      return {m_contents.begin() + 1, m_contents.end()};
   84|  7.61k|   } else {
   85|  7.61k|      return m_contents;
   86|  7.61k|   }
   87|  8.78k|}
_ZNK5Botan18X509_Serial_Number9to_bigintEv:
   89|    723|BigInt X509_Serial_Number::to_bigint() const {
   90|    723|   BOTAN_STATE_CHECK(!m_contents.empty());
  ------------------
  |  |   51|    723|   do {                                                         \
  |  |   52|    723|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */             \
  |  |   53|    723|      if(!(expr)) {                                             \
  |  |  ------------------
  |  |  |  Branch (53:10): [True: 0, False: 723]
  |  |  ------------------
  |  |   54|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */    \
  |  |   55|      0|         Botan::throw_invalid_state(#expr, __func__, __FILE__); \
  |  |   56|      0|      }                                                         \
  |  |   57|    723|   } while(0)
  |  |  ------------------
  |  |  |  Branch (57:12): [Folded, False: 723]
  |  |  ------------------
  ------------------
   91|    723|   return ASN1::integer_from_contents(m_contents);
   92|    723|}
_ZN5Botan18X509_Serial_Number11decode_fromERNS_11BER_DecoderE:
  108|  8.97k|void X509_Serial_Number::decode_from(BER_Decoder& from) {
  109|       |   // Decode via BigInt so the decoder's limits apply, in particular the
  110|       |   // rejection of non-minimal INTEGER encodings in DER mode
  111|  8.97k|   BigInt value;
  112|  8.97k|   from.decode(value);
  113|  8.97k|   *this = X509_Serial_Number(value);
  114|  8.97k|}
_ZNK5Botan18X509_Serial_NumberssERKS0_:
  116|  25.6k|std::strong_ordering X509_Serial_Number::operator<=>(const X509_Serial_Number& other) const {
  117|  25.6k|   BOTAN_STATE_CHECK(!m_contents.empty());
  ------------------
  |  |   51|  25.6k|   do {                                                         \
  |  |   52|  25.6k|      /* NOLINTNEXTLINE(*-simplify-boolean-expr) */             \
  |  |   53|  25.6k|      if(!(expr)) {                                             \
  |  |  ------------------
  |  |  |  Branch (53:10): [True: 0, False: 25.6k]
  |  |  ------------------
  |  |   54|      0|         /* NOLINTNEXTLINE(bugprone-lambda-function-name) */    \
  |  |   55|      0|         Botan::throw_invalid_state(#expr, __func__, __FILE__); \
  |  |   56|      0|      }                                                         \
  |  |   57|  25.6k|   } while(0)
  |  |  ------------------
  |  |  |  Branch (57:12): [Folded, False: 25.6k]
  |  |  ------------------
  ------------------
  118|       |
  119|  25.6k|   const bool neg = is_negative();
  120|       |
  121|  25.6k|   if(neg != other.is_negative()) {
  ------------------
  |  Branch (121:7): [True: 1.21k, False: 24.4k]
  ------------------
  122|  1.21k|      return neg ? std::strong_ordering::less : std::strong_ordering::greater;
  ------------------
  |  Branch (122:14): [True: 903, False: 310]
  ------------------
  123|  1.21k|   }
  124|       |
  125|       |   // Same sign: for positive values the longer encoding is the larger value,
  126|       |   // for negative values the longer encoding is the smaller (more negative)
  127|  24.4k|   if(m_contents.size() != other.m_contents.size()) {
  ------------------
  |  Branch (127:7): [True: 1.13k, False: 23.3k]
  ------------------
  128|  1.13k|      const bool shorter = m_contents.size() < other.m_contents.size();
  129|  1.13k|      return (shorter != neg) ? std::strong_ordering::less : std::strong_ordering::greater;
  ------------------
  |  Branch (129:14): [True: 965, False: 170]
  ------------------
  130|  1.13k|   }
  131|       |
  132|       |   /*
  133|       |   * When comparing two values of the same sign in two's complement
  134|       |   * encoding, the lexicographic ordering is correct for both signs,
  135|       |   * for instance -2 (0xFE) is less than -1 (0xFF)
  136|       |   */
  137|  23.3k|   const int cmp = std::memcmp(m_contents.data(), other.m_contents.data(), m_contents.size());
  138|  23.3k|   if(cmp < 0) {
  ------------------
  |  Branch (138:7): [True: 13.6k, False: 9.66k]
  ------------------
  139|  13.6k|      return std::strong_ordering::less;
  140|  13.6k|   } else if(cmp > 0) {
  ------------------
  |  Branch (140:14): [True: 7.87k, False: 1.78k]
  ------------------
  141|  7.87k|      return std::strong_ordering::greater;
  142|  7.87k|   } else {
  143|  1.78k|      return std::strong_ordering::equal;
  144|  1.78k|   }
  145|  23.3k|}

