check_comeback_token:
   36|     10|{
   37|     10|	u8 mac[SHA256_MAC_LEN];
   38|     10|	const u8 *addrs[2];
   39|     10|	size_t len[2];
   40|     10|	u16 token_idx;
   41|     10|	u8 idx;
   42|       |
   43|     10|	if (token_len != SHA256_MAC_LEN ||
  ------------------
  |  |   12|     20|#define SHA256_MAC_LEN 32
  ------------------
  |  Branch (43:6): [True: 9, False: 1]
  ------------------
   44|     10|	    comeback_token_hash(comeback_key, addr, &idx) < 0)
  ------------------
  |  Branch (44:6): [True: 1, False: 0]
  ------------------
   45|     10|		return -1;
   46|      0|	token_idx = comeback_pending_idx[idx];
   47|      0|	if (token_idx == 0 || token_idx != WPA_GET_BE16(token)) {
  ------------------
  |  Branch (47:6): [True: 0, False: 0]
  |  Branch (47:24): [True: 0, False: 0]
  ------------------
   48|      0|		wpa_printf(MSG_DEBUG,
   49|      0|			   "Comeback: Invalid anti-clogging token from "
   50|      0|			   MACSTR " - token_idx 0x%04x, expected 0x%04x",
   51|      0|			   MAC2STR(addr), WPA_GET_BE16(token), token_idx);
  ------------------
  |  |  418|      0|#define MAC2STR(a) (a)[0], (a)[1], (a)[2], (a)[3], (a)[4], (a)[5]
  ------------------
   52|      0|		return -1;
   53|      0|	}
   54|       |
   55|      0|	addrs[0] = addr;
   56|      0|	len[0] = ETH_ALEN;
  ------------------
  |  |  315|      0|#define ETH_ALEN 6
  ------------------
   57|      0|	addrs[1] = token;
   58|      0|	len[1] = 2;
   59|      0|	if (hmac_sha256_vector(comeback_key, COMEBACK_KEY_SIZE,
  ------------------
  |  |  356|      0|#define COMEBACK_KEY_SIZE 8
  ------------------
  |  Branch (59:6): [True: 0, False: 0]
  ------------------
   60|      0|			       2, addrs, len, mac) < 0 ||
   61|      0|	    os_memcmp_const(token + 2, &mac[2], SHA256_MAC_LEN - 2) != 0)
  ------------------
  |  |   12|      0|#define SHA256_MAC_LEN 32
  ------------------
  |  Branch (61:6): [True: 0, False: 0]
  ------------------
   62|      0|		return -1;
   63|       |
   64|      0|	comeback_pending_idx[idx] = 0; /* invalidate used token */
   65|       |
   66|      0|	return 0;
   67|      0|}
comeback_token.c:comeback_token_hash:
   22|      1|{
   23|      1|	u8 hash[SHA256_MAC_LEN];
   24|       |
   25|      1|	if (hmac_sha256(comeback_key, COMEBACK_KEY_SIZE,
  ------------------
  |  |  356|      1|#define COMEBACK_KEY_SIZE 8
  ------------------
  |  Branch (25:6): [True: 1, False: 0]
  ------------------
   26|      1|			addr, ETH_ALEN, hash) < 0)
  ------------------
  |  |  315|      1|#define ETH_ALEN 6
  ------------------
   27|      1|		return -1;
   28|      0|	*idx = hash[0];
   29|      0|	return 0;
   30|      1|}

wpa_common.c:wpa_key_mgmt_sha384:
  152|  3.33k|{
  153|  3.33k|	return !!(akm & (WPA_KEY_MGMT_IEEE8021X_SUITE_B_192 |
  ------------------
  |  |   44|  3.33k|#define WPA_KEY_MGMT_IEEE8021X_SUITE_B_192 BIT(17)
  |  |  ------------------
  |  |  |  |  429|  3.33k|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  154|  3.33k|			 WPA_KEY_MGMT_FT_IEEE8021X_SHA384 |
  ------------------
  |  |   51|  3.33k|#define WPA_KEY_MGMT_FT_IEEE8021X_SHA384 BIT(24)
  |  |  ------------------
  |  |  |  |  429|  3.33k|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  155|  3.33k|			 WPA_KEY_MGMT_FILS_SHA384 |
  ------------------
  |  |   46|  3.33k|#define WPA_KEY_MGMT_FILS_SHA384 BIT(19)
  |  |  ------------------
  |  |  |  |  429|  3.33k|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  156|  3.33k|			 WPA_KEY_MGMT_FT_FILS_SHA384));
  ------------------
  |  |   48|  3.33k|#define WPA_KEY_MGMT_FT_FILS_SHA384 BIT(21)
  |  |  ------------------
  |  |  |  |  429|  3.33k|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  157|  3.33k|}
pasn_responder.c:wpa_key_mgmt_ft:
  100|      1|{
  101|      1|	return !!(akm & WPA_KEY_MGMT_FT);
  ------------------
  |  |   57|      1|#define WPA_KEY_MGMT_FT (WPA_KEY_MGMT_FT_PSK | \
  |  |  ------------------
  |  |  |  |   33|      1|#define WPA_KEY_MGMT_FT_PSK BIT(6)
  |  |  |  |  ------------------
  |  |  |  |  |  |  429|      1|#define BIT(x) (1U << (x))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   58|      1|			 WPA_KEY_MGMT_FT_IEEE8021X | \
  |  |  ------------------
  |  |  |  |   32|      1|#define WPA_KEY_MGMT_FT_IEEE8021X BIT(5)
  |  |  |  |  ------------------
  |  |  |  |  |  |  429|      1|#define BIT(x) (1U << (x))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   59|      1|			 WPA_KEY_MGMT_FT_IEEE8021X_SHA384 | \
  |  |  ------------------
  |  |  |  |   51|      1|#define WPA_KEY_MGMT_FT_IEEE8021X_SHA384 BIT(24)
  |  |  |  |  ------------------
  |  |  |  |  |  |  429|      1|#define BIT(x) (1U << (x))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   60|      1|			 WPA_KEY_MGMT_FT_SAE | \
  |  |  ------------------
  |  |  |  |   38|      1|#define WPA_KEY_MGMT_FT_SAE BIT(11)
  |  |  |  |  ------------------
  |  |  |  |  |  |  429|      1|#define BIT(x) (1U << (x))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   61|      1|			 WPA_KEY_MGMT_FT_SAE_EXT_KEY | \
  |  |  ------------------
  |  |  |  |   54|      1|#define WPA_KEY_MGMT_FT_SAE_EXT_KEY BIT(27)
  |  |  |  |  ------------------
  |  |  |  |  |  |  429|      1|#define BIT(x) (1U << (x))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   62|      1|			 WPA_KEY_MGMT_FT_FILS_SHA256 | \
  |  |  ------------------
  |  |  |  |   47|      1|#define WPA_KEY_MGMT_FT_FILS_SHA256 BIT(20)
  |  |  |  |  ------------------
  |  |  |  |  |  |  429|      1|#define BIT(x) (1U << (x))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   63|      1|			 WPA_KEY_MGMT_FT_FILS_SHA384)
  |  |  ------------------
  |  |  |  |   48|      1|#define WPA_KEY_MGMT_FT_FILS_SHA384 BIT(21)
  |  |  |  |  ------------------
  |  |  |  |  |  |  429|      1|#define BIT(x) (1U << (x))
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  102|      1|}

ieee802_11_parse_elems:
  680|  5.42k|{
  681|  5.42k|	os_memset(elems, 0, sizeof(*elems));
  ------------------
  |  |  509|  5.42k|#define os_memset(s, c, n) memset(s, c, n)
  ------------------
  682|       |
  683|  5.42k|	return __ieee802_11_parse_elems(start, len, elems, show_errors);
  684|  5.42k|}
ieee802_11_defrag_data:
 3167|    115|{
 3168|    115|	struct wpabuf *buf;
 3169|    115|	const u8 *pos, *end = data + len;
 3170|    115|	size_t min_defrag_len = ext_elem ? 255 : 256;
  ------------------
  |  Branch (3170:26): [True: 115, False: 0]
  ------------------
 3171|       |
 3172|    115|	if (!data || !len)
  ------------------
  |  Branch (3172:6): [True: 3, False: 112]
  |  Branch (3172:15): [True: 1, False: 111]
  ------------------
 3173|      4|		return NULL;
 3174|       |
 3175|    111|	if (len < min_defrag_len)
  ------------------
  |  Branch (3175:6): [True: 14, False: 97]
  ------------------
 3176|     14|		return wpabuf_alloc_copy(data, len);
 3177|       |
 3178|     97|	buf = wpabuf_alloc_copy(data, min_defrag_len - 1);
 3179|     97|	if (!buf)
  ------------------
  |  Branch (3179:6): [True: 0, False: 97]
  ------------------
 3180|      0|		return NULL;
 3181|       |
 3182|     97|	pos = &data[min_defrag_len - 1];
 3183|     97|	len -= min_defrag_len - 1;
 3184|  3.28k|	while (len > 2 && pos[0] == WLAN_EID_FRAGMENT && pos[1]) {
  ------------------
  |  |  460|  6.50k|#define WLAN_EID_FRAGMENT 242
  ------------------
  |  Branch (3184:9): [True: 3.22k, False: 60]
  |  Branch (3184:20): [True: 3.22k, False: 0]
  |  Branch (3184:51): [True: 3.18k, False: 37]
  ------------------
 3185|  3.18k|		int ret;
 3186|  3.18k|		size_t elen = 2 + pos[1];
 3187|       |
 3188|  3.18k|		if (elen > (size_t) (end - pos) || elen > len)
  ------------------
  |  Branch (3188:7): [True: 0, False: 3.18k]
  |  Branch (3188:38): [True: 0, False: 3.18k]
  ------------------
 3189|      0|			break;
 3190|  3.18k|		ret = wpabuf_resize(&buf, pos[1]);
 3191|  3.18k|		if (ret < 0) {
  ------------------
  |  Branch (3191:7): [True: 0, False: 3.18k]
  ------------------
 3192|      0|			wpabuf_free(buf);
 3193|      0|			return NULL;
 3194|      0|		}
 3195|       |
 3196|       |		/* Copy only the fragment data (without the EID and length) */
 3197|  3.18k|		wpabuf_put_data(buf, &pos[2], pos[1]);
 3198|  3.18k|		pos += elen;
 3199|  3.18k|		len -= elen;
 3200|  3.18k|	}
 3201|       |
 3202|     97|	return buf;
 3203|     97|}
ieee802_11_defrag:
 3208|    115|{
 3209|    115|	const u8 *data;
 3210|    115|	size_t len;
 3211|       |
 3212|       |	/*
 3213|       |	 * TODO: Defragmentation mechanism can be supported for all IEs. For now
 3214|       |	 * handle only those that are used (or use ieee802_11_defrag_data()).
 3215|       |	 */
 3216|    115|	switch (eid) {
 3217|    115|	case WLAN_EID_EXTENSION:
  ------------------
  |  |  462|    115|#define WLAN_EID_EXTENSION 255
  ------------------
  |  Branch (3217:2): [True: 115, False: 0]
  ------------------
 3218|    115|		switch (eid_ext) {
 3219|      0|		case WLAN_EID_EXT_FILS_HLP_CONTAINER:
  ------------------
  |  |  469|      0|#define WLAN_EID_EXT_FILS_HLP_CONTAINER 5
  ------------------
  |  Branch (3219:3): [True: 0, False: 115]
  ------------------
 3220|      0|			data = elems->fils_hlp;
 3221|      0|			len = elems->fils_hlp_len;
 3222|      0|			break;
 3223|    115|		case WLAN_EID_EXT_WRAPPED_DATA:
  ------------------
  |  |  472|    115|#define WLAN_EID_EXT_WRAPPED_DATA 8
  ------------------
  |  Branch (3223:3): [True: 115, False: 0]
  ------------------
 3224|    115|			data = elems->wrapped_data;
 3225|    115|			len = elems->wrapped_data_len;
 3226|    115|			break;
 3227|      0|		default:
  ------------------
  |  Branch (3227:3): [True: 0, False: 115]
  ------------------
 3228|      0|			wpa_printf(MSG_DEBUG,
 3229|      0|				   "Defragmentation not supported. eid_ext=%u",
 3230|      0|				   eid_ext);
 3231|      0|			return NULL;
 3232|    115|		}
 3233|    115|		break;
 3234|    115|	default:
  ------------------
  |  Branch (3234:2): [True: 0, False: 115]
  ------------------
 3235|      0|		wpa_printf(MSG_DEBUG,
 3236|      0|			   "Defragmentation not supported. eid=%u", eid);
 3237|      0|		return NULL;
 3238|    115|	}
 3239|       |
 3240|    115|	return ieee802_11_defrag_data(data, len, true);
 3241|    115|}
ieee802_11_common.c:__ieee802_11_parse_elems:
  414|  5.42k|{
  415|  5.42k|	const struct element *elem;
  416|  5.42k|	int unknown = 0;
  417|       |
  418|  5.42k|	if (!start)
  ------------------
  |  Branch (418:6): [True: 0, False: 5.42k]
  ------------------
  419|      0|		return ParseOK;
  420|       |
  421|  10.4M|	for_each_element(elem, start, len) {
  ------------------
  |  |  296|  5.42k|	for (_elem = (const struct element *) (_data);			\
  |  |  297|  10.4M|	     (const u8 *) (_data) + (_datalen) - (const u8 *) _elem >=	\
  |  |  ------------------
  |  |  |  Branch (297:7): [True: 10.4M, False: 4.84k]
  |  |  ------------------
  |  |  298|  10.4M|		(int) sizeof(*_elem) &&					\
  |  |  299|  10.4M|	     (const u8 *) (_data) + (_datalen) - (const u8 *) _elem >=	\
  |  |  ------------------
  |  |  |  Branch (299:7): [True: 10.4M, False: 126]
  |  |  ------------------
  |  |  300|  10.4M|		(int) sizeof(*_elem) + _elem->datalen;			\
  |  |  301|  10.4M|	     _elem = (const struct element *) (_elem->data + _elem->datalen))
  ------------------
  422|  10.4M|		u8 id = elem->id, elen = elem->datalen;
  423|  10.4M|		const u8 *pos = elem->data;
  424|       |
  425|  10.4M|		if (id == WLAN_EID_FRAGMENT && elems->num_frag_elems > 0) {
  ------------------
  |  |  460|  20.9M|#define WLAN_EID_FRAGMENT 242
  ------------------
  |  Branch (425:7): [True: 4.93M, False: 5.53M]
  |  Branch (425:34): [True: 4.08M, False: 844k]
  ------------------
  426|  4.08M|			elems->num_frag_elems--;
  427|  4.08M|			continue;
  428|  4.08M|		}
  429|  6.37M|		elems->num_frag_elems = 0;
  430|       |
  431|  6.37M|		switch (id) {
  432|  4.16M|		case WLAN_EID_SSID:
  ------------------
  |  |  281|  4.16M|#define WLAN_EID_SSID 0
  ------------------
  |  Branch (432:3): [True: 4.16M, False: 2.20M]
  ------------------
  433|  4.16M|			if (elen > SSID_MAX_LEN) {
  ------------------
  |  |  469|  4.16M|#define SSID_MAX_LEN 32
  ------------------
  |  Branch (433:8): [True: 11.8k, False: 4.15M]
  ------------------
  434|  11.8k|				wpa_printf(MSG_DEBUG,
  435|  11.8k|					   "Ignored too long SSID element (elen=%u)",
  436|  11.8k|					   elen);
  437|  11.8k|				break;
  438|  11.8k|			}
  439|  4.15M|			if (elems->ssid) {
  ------------------
  |  Branch (439:8): [True: 4.15M, False: 162]
  ------------------
  440|  4.15M|				wpa_printf(MSG_MSGDUMP,
  441|  4.15M|					   "Ignored duplicated SSID element");
  442|  4.15M|				break;
  443|  4.15M|			}
  444|    162|			elems->ssid = pos;
  445|    162|			elems->ssid_len = elen;
  446|    162|			break;
  447|  70.5k|		case WLAN_EID_SUPP_RATES:
  ------------------
  |  |  282|  70.5k|#define WLAN_EID_SUPP_RATES 1
  ------------------
  |  Branch (447:3): [True: 70.5k, False: 6.30M]
  ------------------
  448|  70.5k|			elems->supp_rates = pos;
  449|  70.5k|			elems->supp_rates_len = elen;
  450|  70.5k|			break;
  451|  14.7k|		case WLAN_EID_DS_PARAMS:
  ------------------
  |  |  283|  14.7k|#define WLAN_EID_DS_PARAMS 3
  ------------------
  |  Branch (451:3): [True: 14.7k, False: 6.36M]
  ------------------
  452|  14.7k|			if (elen < 1)
  ------------------
  |  Branch (452:8): [True: 4.81k, False: 9.97k]
  ------------------
  453|  4.81k|				break;
  454|  9.97k|			elems->ds_params = pos;
  455|  9.97k|			break;
  456|  3.78k|		case WLAN_EID_CF_PARAMS:
  ------------------
  |  |  284|  3.78k|#define WLAN_EID_CF_PARAMS 4
  ------------------
  |  Branch (456:3): [True: 3.78k, False: 6.37M]
  ------------------
  457|  12.3k|		case WLAN_EID_TIM:
  ------------------
  |  |  285|  12.3k|#define WLAN_EID_TIM 5
  ------------------
  |  Branch (457:3): [True: 8.52k, False: 6.37M]
  ------------------
  458|  12.3k|			break;
  459|  1.26k|		case WLAN_EID_CHALLENGE:
  ------------------
  |  |  294|  1.26k|#define WLAN_EID_CHALLENGE 16
  ------------------
  |  Branch (459:3): [True: 1.26k, False: 6.37M]
  ------------------
  460|  1.26k|			elems->challenge = pos;
  461|  1.26k|			elems->challenge_len = elen;
  462|  1.26k|			break;
  463|    930|		case WLAN_EID_ERP_INFO:
  ------------------
  |  |  305|    930|#define WLAN_EID_ERP_INFO 42
  ------------------
  |  Branch (463:3): [True: 930, False: 6.37M]
  ------------------
  464|    930|			if (elen < 1)
  ------------------
  |  Branch (464:8): [True: 212, False: 718]
  ------------------
  465|    212|				break;
  466|    718|			elems->erp_info = pos;
  467|    718|			break;
  468|  1.12k|		case WLAN_EID_EXT_SUPP_RATES:
  ------------------
  |  |  311|  1.12k|#define WLAN_EID_EXT_SUPP_RATES 50
  ------------------
  |  Branch (468:3): [True: 1.12k, False: 6.37M]
  ------------------
  469|  1.12k|			elems->ext_supp_rates = pos;
  470|  1.12k|			elems->ext_supp_rates_len = elen;
  471|  1.12k|			break;
  472|  19.0k|		case WLAN_EID_VENDOR_SPECIFIC:
  ------------------
  |  |  454|  19.0k|#define WLAN_EID_VENDOR_SPECIFIC 221
  ------------------
  |  Branch (472:3): [True: 19.0k, False: 6.36M]
  ------------------
  473|  19.0k|			if (ieee802_11_parse_vendor_specific(pos, elen,
  ------------------
  |  Branch (473:8): [True: 3.85k, False: 15.2k]
  ------------------
  474|  19.0k|							     elems,
  475|  19.0k|							     show_errors))
  476|  3.85k|				unknown++;
  477|  19.0k|			break;
  478|  7.07k|		case WLAN_EID_RSN:
  ------------------
  |  |  310|  7.07k|#define WLAN_EID_RSN 48
  ------------------
  |  Branch (478:3): [True: 7.07k, False: 6.37M]
  ------------------
  479|  7.07k|			elems->rsn_ie = pos;
  480|  7.07k|			elems->rsn_ie_len = elen;
  481|  7.07k|			break;
  482|    264|		case WLAN_EID_RSNX:
  ------------------
  |  |  461|    264|#define WLAN_EID_RSNX 244
  ------------------
  |  Branch (482:3): [True: 264, False: 6.37M]
  ------------------
  483|    264|			elems->rsnxe = pos;
  484|    264|			elems->rsnxe_len = elen;
  485|    264|			break;
  486|    570|		case WLAN_EID_PWR_CAPABILITY:
  ------------------
  |  |  296|    570|#define WLAN_EID_PWR_CAPABILITY 33
  ------------------
  |  Branch (486:3): [True: 570, False: 6.37M]
  ------------------
  487|    570|			if (elen < 2)
  ------------------
  |  Branch (487:8): [True: 276, False: 294]
  ------------------
  488|    276|				break;
  489|    294|			elems->power_capab = pos;
  490|    294|			elems->power_capab_len = elen;
  491|    294|			break;
  492|  1.36k|		case WLAN_EID_SUPPORTED_CHANNELS:
  ------------------
  |  |  299|  1.36k|#define WLAN_EID_SUPPORTED_CHANNELS 36
  ------------------
  |  Branch (492:3): [True: 1.36k, False: 6.37M]
  ------------------
  493|  1.36k|			elems->supp_channels = pos;
  494|  1.36k|			elems->supp_channels_len = elen;
  495|  1.36k|			break;
  496|  3.46k|		case WLAN_EID_MOBILITY_DOMAIN:
  ------------------
  |  |  315|  3.46k|#define WLAN_EID_MOBILITY_DOMAIN 54
  ------------------
  |  Branch (496:3): [True: 3.46k, False: 6.37M]
  ------------------
  497|  3.46k|			if (elen < sizeof(struct rsn_mdie))
  ------------------
  |  Branch (497:8): [True: 2.36k, False: 1.09k]
  ------------------
  498|  2.36k|				break;
  499|  1.09k|			elems->mdie = pos;
  500|  1.09k|			elems->mdie_len = elen;
  501|  1.09k|			break;
  502|  1.44k|		case WLAN_EID_FAST_BSS_TRANSITION:
  ------------------
  |  |  316|  1.44k|#define WLAN_EID_FAST_BSS_TRANSITION 55
  ------------------
  |  Branch (502:3): [True: 1.44k, False: 6.37M]
  ------------------
  503|  1.44k|			if (elen < sizeof(struct rsn_ftie))
  ------------------
  |  Branch (503:8): [True: 1.24k, False: 196]
  ------------------
  504|  1.24k|				break;
  505|    196|			elems->ftie = pos;
  506|    196|			elems->ftie_len = elen;
  507|    196|			break;
  508|    954|		case WLAN_EID_TIMEOUT_INTERVAL:
  ------------------
  |  |  317|    954|#define WLAN_EID_TIMEOUT_INTERVAL 56
  ------------------
  |  Branch (508:3): [True: 954, False: 6.37M]
  ------------------
  509|    954|			if (elen != 5)
  ------------------
  |  Branch (509:8): [True: 764, False: 190]
  ------------------
  510|    764|				break;
  511|    190|			elems->timeout_int = pos;
  512|    190|			break;
  513|  3.08k|		case WLAN_EID_HT_CAP:
  ------------------
  |  |  308|  3.08k|#define WLAN_EID_HT_CAP 45
  ------------------
  |  Branch (513:3): [True: 3.08k, False: 6.37M]
  ------------------
  514|  3.08k|			if (elen < sizeof(struct ieee80211_ht_capabilities))
  ------------------
  |  Branch (514:8): [True: 2.80k, False: 288]
  ------------------
  515|  2.80k|				break;
  516|    288|			elems->ht_capabilities = pos;
  517|    288|			break;
  518|  2.18k|		case WLAN_EID_HT_OPERATION:
  ------------------
  |  |  322|  2.18k|#define WLAN_EID_HT_OPERATION 61
  ------------------
  |  Branch (518:3): [True: 2.18k, False: 6.37M]
  ------------------
  519|  2.18k|			if (elen < sizeof(struct ieee80211_ht_operation))
  ------------------
  |  Branch (519:8): [True: 1.32k, False: 864]
  ------------------
  520|  1.32k|				break;
  521|    864|			elems->ht_operation = pos;
  522|    864|			break;
  523|    242|		case WLAN_EID_MESH_CONFIG:
  ------------------
  |  |  372|    242|#define WLAN_EID_MESH_CONFIG 113
  ------------------
  |  Branch (523:3): [True: 242, False: 6.37M]
  ------------------
  524|    242|			elems->mesh_config = pos;
  525|    242|			elems->mesh_config_len = elen;
  526|    242|			break;
  527|  2.35k|		case WLAN_EID_MESH_ID:
  ------------------
  |  |  373|  2.35k|#define WLAN_EID_MESH_ID 114
  ------------------
  |  Branch (527:3): [True: 2.35k, False: 6.37M]
  ------------------
  528|  2.35k|			elems->mesh_id = pos;
  529|  2.35k|			elems->mesh_id_len = elen;
  530|  2.35k|			break;
  531|  2.05k|		case WLAN_EID_PEER_MGMT:
  ------------------
  |  |  376|  2.05k|#define WLAN_EID_PEER_MGMT 117
  ------------------
  |  Branch (531:3): [True: 2.05k, False: 6.37M]
  ------------------
  532|  2.05k|			elems->peer_mgmt = pos;
  533|  2.05k|			elems->peer_mgmt_len = elen;
  534|  2.05k|			break;
  535|  1.18k|		case WLAN_EID_VHT_CAP:
  ------------------
  |  |  436|  1.18k|#define WLAN_EID_VHT_CAP 191
  ------------------
  |  Branch (535:3): [True: 1.18k, False: 6.37M]
  ------------------
  536|  1.18k|			if (elen < sizeof(struct ieee80211_vht_capabilities))
  ------------------
  |  Branch (536:8): [True: 572, False: 612]
  ------------------
  537|    572|				break;
  538|    612|			elems->vht_capabilities = pos;
  539|    612|			break;
  540|    700|		case WLAN_EID_VHT_OPERATION:
  ------------------
  |  |  437|    700|#define WLAN_EID_VHT_OPERATION 192
  ------------------
  |  Branch (540:3): [True: 700, False: 6.37M]
  ------------------
  541|    700|			if (elen < sizeof(struct ieee80211_vht_operation))
  ------------------
  |  Branch (541:8): [True: 286, False: 414]
  ------------------
  542|    286|				break;
  543|    414|			elems->vht_operation = pos;
  544|    414|			break;
  545|    448|		case WLAN_EID_VHT_OPERATING_MODE_NOTIFICATION:
  ------------------
  |  |  444|    448|#define WLAN_EID_VHT_OPERATING_MODE_NOTIFICATION 199
  ------------------
  |  Branch (545:3): [True: 448, False: 6.37M]
  ------------------
  546|    448|			if (elen != 1)
  ------------------
  |  Branch (546:8): [True: 258, False: 190]
  ------------------
  547|    258|				break;
  548|    190|			elems->vht_opmode_notif = pos;
  549|    190|			break;
  550|  10.4k|		case WLAN_EID_LINK_ID:
  ------------------
  |  |  361|  10.4k|#define WLAN_EID_LINK_ID 101
  ------------------
  |  Branch (550:3): [True: 10.4k, False: 6.36M]
  ------------------
  551|  10.4k|			if (elen < 18)
  ------------------
  |  Branch (551:8): [True: 6.33k, False: 4.13k]
  ------------------
  552|  6.33k|				break;
  553|  4.13k|			elems->link_id = pos;
  554|  4.13k|			break;
  555|    874|		case WLAN_EID_INTERWORKING:
  ------------------
  |  |  366|    874|#define WLAN_EID_INTERWORKING 107
  ------------------
  |  Branch (555:3): [True: 874, False: 6.37M]
  ------------------
  556|    874|			elems->interworking = pos;
  557|    874|			elems->interworking_len = elen;
  558|    874|			break;
  559|  3.65k|		case WLAN_EID_QOS_MAP_SET:
  ------------------
  |  |  369|  3.65k|#define WLAN_EID_QOS_MAP_SET 110
  ------------------
  |  Branch (559:3): [True: 3.65k, False: 6.37M]
  ------------------
  560|  3.65k|			if (elen < 16)
  ------------------
  |  Branch (560:8): [True: 2.52k, False: 1.12k]
  ------------------
  561|  2.52k|				break;
  562|  1.12k|			elems->qos_map_set = pos;
  563|  1.12k|			elems->qos_map_set_len = elen;
  564|  1.12k|			break;
  565|    872|		case WLAN_EID_EXT_CAPAB:
  ------------------
  |  |  386|    872|#define WLAN_EID_EXT_CAPAB 127
  ------------------
  |  Branch (565:3): [True: 872, False: 6.37M]
  ------------------
  566|    872|			elems->ext_capab = pos;
  567|    872|			elems->ext_capab_len = elen;
  568|    872|			break;
  569|  2.19k|		case WLAN_EID_BSS_MAX_IDLE_PERIOD:
  ------------------
  |  |  350|  2.19k|#define WLAN_EID_BSS_MAX_IDLE_PERIOD 90
  ------------------
  |  Branch (569:3): [True: 2.19k, False: 6.37M]
  ------------------
  570|  2.19k|			if (elen < 3)
  ------------------
  |  Branch (570:8): [True: 892, False: 1.30k]
  ------------------
  571|    892|				break;
  572|  1.30k|			elems->bss_max_idle_period = pos;
  573|  1.30k|			break;
  574|  1.44k|		case WLAN_EID_SSID_LIST:
  ------------------
  |  |  344|  1.44k|#define WLAN_EID_SSID_LIST 84
  ------------------
  |  Branch (574:3): [True: 1.44k, False: 6.37M]
  ------------------
  575|  1.44k|			elems->ssid_list = pos;
  576|  1.44k|			elems->ssid_list_len = elen;
  577|  1.44k|			break;
  578|  1.22k|		case WLAN_EID_AMPE:
  ------------------
  |  |  392|  1.22k|#define WLAN_EID_AMPE 139
  ------------------
  |  Branch (578:3): [True: 1.22k, False: 6.37M]
  ------------------
  579|  1.22k|			elems->ampe = pos;
  580|  1.22k|			elems->ampe_len = elen;
  581|  1.22k|			break;
  582|    454|		case WLAN_EID_MIC:
  ------------------
  |  |  393|    454|#define WLAN_EID_MIC 140
  ------------------
  |  Branch (582:3): [True: 454, False: 6.37M]
  ------------------
  583|    454|			elems->mic = pos;
  584|    454|			elems->mic_len = elen;
  585|       |			/* after mic everything is encrypted, so stop. */
  586|    454|			goto done;
  587|  1.14k|		case WLAN_EID_MULTI_BAND:
  ------------------
  |  |  408|  1.14k|#define WLAN_EID_MULTI_BAND 158
  ------------------
  |  Branch (587:3): [True: 1.14k, False: 6.37M]
  ------------------
  588|  1.14k|			if (elems->mb_ies.nof_ies >= MAX_NOF_MB_IES_SUPPORTED) {
  ------------------
  |  |   23|  1.14k|#define MAX_NOF_MB_IES_SUPPORTED 5
  ------------------
  |  Branch (588:8): [True: 898, False: 246]
  ------------------
  589|    898|				wpa_printf(MSG_MSGDUMP,
  590|    898|					   "IEEE 802.11 element parse ignored MB IE (id=%d elen=%d)",
  591|    898|					   id, elen);
  592|    898|				break;
  593|    898|			}
  594|       |
  595|    246|			elems->mb_ies.ies[elems->mb_ies.nof_ies].ie = pos;
  596|    246|			elems->mb_ies.ies[elems->mb_ies.nof_ies].ie_len = elen;
  597|    246|			elems->mb_ies.nof_ies++;
  598|    246|			break;
  599|  1.46k|		case WLAN_EID_SUPPORTED_OPERATING_CLASSES:
  ------------------
  |  |  320|  1.46k|#define WLAN_EID_SUPPORTED_OPERATING_CLASSES 59
  ------------------
  |  Branch (599:3): [True: 1.46k, False: 6.37M]
  ------------------
  600|  1.46k|			elems->supp_op_classes = pos;
  601|  1.46k|			elems->supp_op_classes_len = elen;
  602|  1.46k|			break;
  603|  2.06k|		case WLAN_EID_RRM_ENABLED_CAPABILITIES:
  ------------------
  |  |  331|  2.06k|#define WLAN_EID_RRM_ENABLED_CAPABILITIES 70
  ------------------
  |  Branch (603:3): [True: 2.06k, False: 6.37M]
  ------------------
  604|  2.06k|			elems->rrm_enabled = pos;
  605|  2.06k|			elems->rrm_enabled_len = elen;
  606|  2.06k|			break;
  607|    230|		case WLAN_EID_CAG_NUMBER:
  ------------------
  |  |  456|    230|#define WLAN_EID_CAG_NUMBER 237
  ------------------
  |  Branch (607:3): [True: 230, False: 6.37M]
  ------------------
  608|    230|			elems->cag_number = pos;
  609|    230|			elems->cag_number_len = elen;
  610|    230|			break;
  611|  2.95k|		case WLAN_EID_AP_CSN:
  ------------------
  |  |  457|  2.95k|#define WLAN_EID_AP_CSN 239
  ------------------
  |  Branch (611:3): [True: 2.95k, False: 6.37M]
  ------------------
  612|  2.95k|			if (elen < 1)
  ------------------
  |  Branch (612:8): [True: 2.22k, False: 732]
  ------------------
  613|  2.22k|				break;
  614|    732|			elems->ap_csn = pos;
  615|    732|			break;
  616|  2.48k|		case WLAN_EID_FILS_INDICATION:
  ------------------
  |  |  458|  2.48k|#define WLAN_EID_FILS_INDICATION 240
  ------------------
  |  Branch (616:3): [True: 2.48k, False: 6.37M]
  ------------------
  617|  2.48k|			if (elen < 2)
  ------------------
  |  Branch (617:8): [True: 1.84k, False: 642]
  ------------------
  618|  1.84k|				break;
  619|    642|			elems->fils_indic = pos;
  620|    642|			elems->fils_indic_len = elen;
  621|    642|			break;
  622|    488|		case WLAN_EID_DILS:
  ------------------
  |  |  459|    488|#define WLAN_EID_DILS 241
  ------------------
  |  Branch (622:3): [True: 488, False: 6.37M]
  ------------------
  623|    488|			if (elen < 2)
  ------------------
  |  Branch (623:8): [True: 194, False: 294]
  ------------------
  624|    194|				break;
  625|    294|			elems->dils = pos;
  626|    294|			elems->dils_len = elen;
  627|    294|			break;
  628|  3.09k|		case WLAN_EID_S1G_CAPABILITIES:
  ------------------
  |  |  453|  3.09k|#define WLAN_EID_S1G_CAPABILITIES 217
  ------------------
  |  Branch (628:3): [True: 3.09k, False: 6.37M]
  ------------------
  629|  3.09k|			if (elen < 15)
  ------------------
  |  Branch (629:8): [True: 758, False: 2.34k]
  ------------------
  630|    758|				break;
  631|  2.34k|			elems->s1g_capab = pos;
  632|  2.34k|			break;
  633|   844k|		case WLAN_EID_FRAGMENT:
  ------------------
  |  |  460|   844k|#define WLAN_EID_FRAGMENT 242
  ------------------
  |  Branch (633:3): [True: 844k, False: 5.53M]
  ------------------
  634|   844k|			wpa_printf(MSG_MSGDUMP,
  635|   844k|				   "Fragment without a valid last element - skip");
  636|       |
  637|   844k|			break;
  638|  30.4k|		case WLAN_EID_EXTENSION:
  ------------------
  |  |  462|  30.4k|#define WLAN_EID_EXTENSION 255
  ------------------
  |  Branch (638:3): [True: 30.4k, False: 6.34M]
  ------------------
  639|  30.4k|			if (ieee802_11_parse_extension(pos, elen, elems, start,
  ------------------
  |  Branch (639:8): [True: 8.50k, False: 21.9k]
  ------------------
  640|  30.4k|						       len, show_errors))
  641|  8.50k|				unknown++;
  642|  30.4k|			break;
  643|  1.15M|		default:
  ------------------
  |  Branch (643:3): [True: 1.15M, False: 5.22M]
  ------------------
  644|  1.15M|			unknown++;
  645|  1.15M|			if (!show_errors)
  ------------------
  |  Branch (645:8): [True: 1.15M, False: 0]
  ------------------
  646|  1.15M|				break;
  647|      0|			wpa_printf(MSG_MSGDUMP, "IEEE 802.11 element parse "
  648|      0|				   "ignored unknown element (id=%d elen=%d)",
  649|      0|				   id, elen);
  650|      0|			break;
  651|  6.37M|		}
  652|  6.37M|	}
  653|       |
  654|  4.97k|	if (!for_each_element_completed(elem, start, len)) {
  ------------------
  |  Branch (654:6): [True: 158, False: 4.81k]
  ------------------
  655|    158|		if (show_errors) {
  ------------------
  |  Branch (655:7): [True: 0, False: 158]
  ------------------
  656|      0|			wpa_printf(MSG_DEBUG,
  657|      0|				   "IEEE 802.11 element parse failed @%d",
  658|      0|				   (int) (start + len - (const u8 *) elem));
  659|      0|			wpa_hexdump(MSG_MSGDUMP, "IEs", start, len);
  660|      0|		}
  661|    158|		return ParseFailed;
  662|    158|	}
  663|       |
  664|  5.27k|done:
  665|  5.27k|	return unknown ? ParseUnknown : ParseOK;
  ------------------
  |  Branch (665:9): [True: 638, False: 4.63k]
  ------------------
  666|  4.97k|}
ieee802_11_common.c:ieee802_11_parse_vendor_specific:
   23|  19.0k|{
   24|  19.0k|	unsigned int oui;
   25|       |
   26|       |	/* first 3 bytes in vendor specific information element are the IEEE
   27|       |	 * OUI of the vendor. The following byte is used a vendor specific
   28|       |	 * sub-type. */
   29|  19.0k|	if (elen < 4) {
  ------------------
  |  Branch (29:6): [True: 398, False: 18.6k]
  ------------------
   30|    398|		if (show_errors) {
  ------------------
  |  Branch (30:7): [True: 0, False: 398]
  ------------------
   31|      0|			wpa_printf(MSG_MSGDUMP, "short vendor specific "
   32|      0|				   "information element ignored (len=%lu)",
   33|      0|				   (unsigned long) elen);
   34|      0|		}
   35|    398|		return -1;
   36|    398|	}
   37|       |
   38|  18.6k|	oui = WPA_GET_BE24(pos);
   39|  18.6k|	switch (oui) {
   40|  2.21k|	case OUI_MICROSOFT:
  ------------------
  |  | 1367|  2.21k|#define OUI_MICROSOFT 0x0050f2 /* Microsoft (also used in Wi-Fi specs)
  ------------------
  |  Branch (40:2): [True: 2.21k, False: 16.4k]
  ------------------
   41|       |		/* Microsoft/Wi-Fi information elements are further typed and
   42|       |		 * subtyped */
   43|  2.21k|		switch (pos[3]) {
   44|    654|		case 1:
  ------------------
  |  Branch (44:3): [True: 654, False: 1.56k]
  ------------------
   45|       |			/* Microsoft OUI (00:50:F2) with OUI Type 1:
   46|       |			 * real WPA information element */
   47|    654|			elems->wpa_ie = pos;
   48|    654|			elems->wpa_ie_len = elen;
   49|    654|			break;
   50|  1.00k|		case WMM_OUI_TYPE:
  ------------------
  |  | 1398|  1.00k|#define WMM_OUI_TYPE 2
  ------------------
  |  Branch (50:3): [True: 1.00k, False: 1.21k]
  ------------------
   51|       |			/* WMM information element */
   52|  1.00k|			if (elen < 5) {
  ------------------
  |  Branch (52:8): [True: 190, False: 812]
  ------------------
   53|    190|				wpa_printf(MSG_MSGDUMP, "short WMM "
   54|    190|					   "information element ignored "
   55|    190|					   "(len=%lu)",
   56|    190|					   (unsigned long) elen);
   57|    190|				return -1;
   58|    190|			}
   59|    812|			switch (pos[4]) {
   60|    220|			case WMM_OUI_SUBTYPE_INFORMATION_ELEMENT:
  ------------------
  |  | 1399|    220|#define WMM_OUI_SUBTYPE_INFORMATION_ELEMENT 0
  ------------------
  |  Branch (60:4): [True: 220, False: 592]
  ------------------
   61|    418|			case WMM_OUI_SUBTYPE_PARAMETER_ELEMENT:
  ------------------
  |  | 1400|    418|#define WMM_OUI_SUBTYPE_PARAMETER_ELEMENT 1
  ------------------
  |  Branch (61:4): [True: 198, False: 614]
  ------------------
   62|       |				/*
   63|       |				 * Share same pointer since only one of these
   64|       |				 * is used and they start with same data.
   65|       |				 * Length field can be used to distinguish the
   66|       |				 * IEs.
   67|       |				 */
   68|    418|				elems->wmm = pos;
   69|    418|				elems->wmm_len = elen;
   70|    418|				break;
   71|    190|			case WMM_OUI_SUBTYPE_TSPEC_ELEMENT:
  ------------------
  |  | 1401|    190|#define WMM_OUI_SUBTYPE_TSPEC_ELEMENT 2
  ------------------
  |  Branch (71:4): [True: 190, False: 622]
  ------------------
   72|    190|				elems->wmm_tspec = pos;
   73|    190|				elems->wmm_tspec_len = elen;
   74|    190|				break;
   75|    204|			default:
  ------------------
  |  Branch (75:4): [True: 204, False: 608]
  ------------------
   76|    204|				wpa_printf(MSG_EXCESSIVE, "unknown WMM "
   77|    204|					   "information element ignored "
   78|    204|					   "(subtype=%d len=%lu)",
   79|    204|					   pos[4], (unsigned long) elen);
   80|    204|				return -1;
   81|    812|			}
   82|    608|			break;
   83|    608|		case 4:
  ------------------
  |  Branch (83:3): [True: 316, False: 1.90k]
  ------------------
   84|       |			/* Wi-Fi Protected Setup (WPS) IE */
   85|    316|			elems->wps_ie = pos;
   86|    316|			elems->wps_ie_len = elen;
   87|    316|			break;
   88|    246|		default:
  ------------------
  |  Branch (88:3): [True: 246, False: 1.97k]
  ------------------
   89|    246|			wpa_printf(MSG_EXCESSIVE, "Unknown Microsoft "
   90|    246|				   "information element ignored "
   91|    246|				   "(type=%d len=%lu)",
   92|    246|				   pos[3], (unsigned long) elen);
   93|    246|			return -1;
   94|  2.21k|		}
   95|  1.57k|		break;
   96|       |
   97|  12.7k|	case OUI_WFA:
  ------------------
  |  | 1372|  12.7k|#define OUI_WFA 0x506f9a
  ------------------
  |  Branch (97:2): [True: 12.7k, False: 5.88k]
  ------------------
   98|  12.7k|		switch (pos[3]) {
   99|  9.75k|		case P2P_OUI_TYPE:
  ------------------
  |  | 1645|  9.75k|#define P2P_OUI_TYPE 9
  ------------------
  |  Branch (99:3): [True: 9.75k, False: 3.03k]
  ------------------
  100|       |			/* Wi-Fi Alliance - P2P IE */
  101|  9.75k|			elems->p2p = pos;
  102|  9.75k|			elems->p2p_len = elen;
  103|  9.75k|			break;
  104|    212|		case WFD_OUI_TYPE:
  ------------------
  |  | 1375|    212|#define WFD_OUI_TYPE 10
  ------------------
  |  Branch (104:3): [True: 212, False: 12.5k]
  ------------------
  105|       |			/* Wi-Fi Alliance - WFD IE */
  106|    212|			elems->wfd = pos;
  107|    212|			elems->wfd_len = elen;
  108|    212|			break;
  109|    390|		case HS20_INDICATION_OUI_TYPE:
  ------------------
  |  | 1513|    390|#define HS20_INDICATION_OUI_TYPE 16
  ------------------
  |  Branch (109:3): [True: 390, False: 12.3k]
  ------------------
  110|       |			/* Hotspot 2.0 */
  111|    390|			elems->hs20 = pos;
  112|    390|			elems->hs20_len = elen;
  113|    390|			break;
  114|    192|		case HS20_OSEN_OUI_TYPE:
  ------------------
  |  | 1515|    192|#define HS20_OSEN_OUI_TYPE 18
  ------------------
  |  Branch (114:3): [True: 192, False: 12.5k]
  ------------------
  115|       |			/* Hotspot 2.0 OSEN */
  116|    192|			elems->osen = pos;
  117|    192|			elems->osen_len = elen;
  118|    192|			break;
  119|    190|		case MBO_OUI_TYPE:
  ------------------
  |  | 1379|    190|#define MBO_OUI_TYPE 22
  ------------------
  |  Branch (119:3): [True: 190, False: 12.5k]
  ------------------
  120|       |			/* MBO-OCE */
  121|    190|			elems->mbo = pos;
  122|    190|			elems->mbo_len = elen;
  123|    190|			break;
  124|    190|		case HS20_ROAMING_CONS_SEL_OUI_TYPE:
  ------------------
  |  | 1516|    190|#define HS20_ROAMING_CONS_SEL_OUI_TYPE 29
  ------------------
  |  Branch (124:3): [True: 190, False: 12.5k]
  ------------------
  125|       |			/* Hotspot 2.0 Roaming Consortium Selection */
  126|    190|			elems->roaming_cons_sel = pos;
  127|    190|			elems->roaming_cons_sel_len = elen;
  128|    190|			break;
  129|    286|		case MULTI_AP_OUI_TYPE:
  ------------------
  |  | 1382|    286|#define MULTI_AP_OUI_TYPE 0x1B
  ------------------
  |  Branch (129:3): [True: 286, False: 12.5k]
  ------------------
  130|    286|			elems->multi_ap = pos;
  131|    286|			elems->multi_ap_len = elen;
  132|    286|			break;
  133|    190|		case OWE_OUI_TYPE:
  ------------------
  |  | 1381|    190|#define OWE_OUI_TYPE 28
  ------------------
  |  Branch (133:3): [True: 190, False: 12.5k]
  ------------------
  134|       |			/* OWE Transition Mode element */
  135|    190|			break;
  136|    896|		case DPP_CC_OUI_TYPE:
  ------------------
  |  | 1384|    896|#define DPP_CC_OUI_TYPE 0x1e
  ------------------
  |  Branch (136:3): [True: 896, False: 11.8k]
  ------------------
  137|       |			/* DPP Configurator Connectivity element */
  138|    896|			break;
  139|    194|		case SAE_PK_OUI_TYPE:
  ------------------
  |  | 1386|    194|#define SAE_PK_OUI_TYPE 0x1f
  ------------------
  |  Branch (139:3): [True: 194, False: 12.5k]
  ------------------
  140|    194|			elems->sae_pk = pos + 4;
  141|    194|			elems->sae_pk_len = elen - 4;
  142|    194|			break;
  143|    296|		default:
  ------------------
  |  Branch (143:3): [True: 296, False: 12.4k]
  ------------------
  144|    296|			wpa_printf(MSG_MSGDUMP, "Unknown WFA "
  145|    296|				   "information element ignored "
  146|    296|				   "(type=%d len=%lu)",
  147|    296|				   pos[3], (unsigned long) elen);
  148|    296|			return -1;
  149|  12.7k|		}
  150|  12.4k|		break;
  151|       |
  152|  12.4k|	case OUI_BROADCOM:
  ------------------
  |  | 1818|  1.73k|#define OUI_BROADCOM 0x00904c /* Broadcom (Epigram) */
  ------------------
  |  Branch (152:2): [True: 1.73k, False: 16.9k]
  ------------------
  153|  1.73k|		switch (pos[3]) {
  154|    504|		case VENDOR_HT_CAPAB_OUI_TYPE:
  ------------------
  |  | 1823|    504|#define VENDOR_HT_CAPAB_OUI_TYPE 0x33 /* 00-90-4c:0x33 */
  ------------------
  |  Branch (154:3): [True: 504, False: 1.22k]
  ------------------
  155|    504|			elems->vendor_ht_cap = pos;
  156|    504|			elems->vendor_ht_cap_len = elen;
  157|    504|			break;
  158|    908|		case VENDOR_VHT_TYPE:
  ------------------
  |  | 1819|    908|#define VENDOR_VHT_TYPE		0x04
  ------------------
  |  Branch (158:3): [True: 908, False: 822]
  ------------------
  159|    908|			if (elen > 4 &&
  ------------------
  |  Branch (159:8): [True: 638, False: 270]
  ------------------
  160|    908|			    (pos[4] == VENDOR_VHT_SUBTYPE ||
  ------------------
  |  | 1820|  1.27k|#define VENDOR_VHT_SUBTYPE	0x08
  ------------------
  |  Branch (160:9): [True: 210, False: 428]
  ------------------
  161|    638|			     pos[4] == VENDOR_VHT_SUBTYPE2)) {
  ------------------
  |  | 1821|    428|#define VENDOR_VHT_SUBTYPE2	0x00
  ------------------
  |  Branch (161:9): [True: 192, False: 236]
  ------------------
  162|    402|				elems->vendor_vht = pos;
  163|    402|				elems->vendor_vht_len = elen;
  164|    402|			} else
  165|    506|				return -1;
  166|    402|			break;
  167|    402|		default:
  ------------------
  |  Branch (167:3): [True: 318, False: 1.41k]
  ------------------
  168|    318|			wpa_printf(MSG_EXCESSIVE, "Unknown Broadcom "
  169|    318|				   "information element ignored "
  170|    318|				   "(type=%d len=%lu)",
  171|    318|				   pos[3], (unsigned long) elen);
  172|    318|			return -1;
  173|  1.73k|		}
  174|    906|		break;
  175|       |
  176|    906|	case OUI_QCA:
  ------------------
  |  |   21|    524|#define OUI_QCA 0x001374
  ------------------
  |  Branch (176:2): [True: 524, False: 18.1k]
  ------------------
  177|    524|		switch (pos[3]) {
  178|    238|		case QCA_VENDOR_ELEM_P2P_PREF_CHAN_LIST:
  ------------------
  |  Branch (178:3): [True: 238, False: 286]
  ------------------
  179|    238|			elems->pref_freq_list = pos;
  180|    238|			elems->pref_freq_list_len = elen;
  181|    238|			break;
  182|    286|		default:
  ------------------
  |  Branch (182:3): [True: 286, False: 238]
  ------------------
  183|    286|			wpa_printf(MSG_EXCESSIVE,
  184|    286|				   "Unknown QCA information element ignored (type=%d len=%lu)",
  185|    286|				   pos[3], (unsigned long) elen);
  186|    286|			return -1;
  187|    524|		}
  188|    238|		break;
  189|       |
  190|  1.41k|	default:
  ------------------
  |  Branch (190:2): [True: 1.41k, False: 17.2k]
  ------------------
  191|  1.41k|		wpa_printf(MSG_EXCESSIVE, "unknown vendor specific "
  192|  1.41k|			   "information element ignored (vendor OUI "
  193|  1.41k|			   "%02x:%02x:%02x len=%lu)",
  194|  1.41k|			   pos[0], pos[1], pos[2], (unsigned long) elen);
  195|  1.41k|		return -1;
  196|  18.6k|	}
  197|       |
  198|  15.2k|	return 0;
  199|  18.6k|}
ieee802_11_common.c:ieee802_11_parse_extension:
  269|  30.4k|{
  270|  30.4k|	u8 ext_id;
  271|  30.4k|	size_t *total_len = NULL;
  272|       |
  273|  30.4k|	if (elen < 1) {
  ------------------
  |  Branch (273:6): [True: 2.22k, False: 28.1k]
  ------------------
  274|  2.22k|		if (show_errors) {
  ------------------
  |  Branch (274:7): [True: 0, False: 2.22k]
  ------------------
  275|      0|			wpa_printf(MSG_MSGDUMP,
  276|      0|				   "short information element (Ext)");
  277|      0|		}
  278|  2.22k|		return -1;
  279|  2.22k|	}
  280|       |
  281|  28.1k|	ext_id = *pos++;
  282|  28.1k|	elen--;
  283|       |
  284|  28.1k|	switch (ext_id) {
  285|    530|	case WLAN_EID_EXT_ASSOC_DELAY_INFO:
  ------------------
  |  |  465|    530|#define WLAN_EID_EXT_ASSOC_DELAY_INFO 1
  ------------------
  |  Branch (285:2): [True: 530, False: 27.6k]
  ------------------
  286|    530|		if (elen != 1)
  ------------------
  |  Branch (286:7): [True: 324, False: 206]
  ------------------
  287|    324|			break;
  288|    206|		elems->assoc_delay_info = pos;
  289|    206|		break;
  290|    744|	case WLAN_EID_EXT_FILS_REQ_PARAMS:
  ------------------
  |  |  466|    744|#define WLAN_EID_EXT_FILS_REQ_PARAMS 2
  ------------------
  |  Branch (290:2): [True: 744, False: 27.4k]
  ------------------
  291|    744|		if (elen < 3)
  ------------------
  |  Branch (291:7): [True: 522, False: 222]
  ------------------
  292|    522|			break;
  293|    222|		elems->fils_req_params = pos;
  294|    222|		elems->fils_req_params_len = elen;
  295|    222|		break;
  296|    228|	case WLAN_EID_EXT_FILS_KEY_CONFIRM:
  ------------------
  |  |  467|    228|#define WLAN_EID_EXT_FILS_KEY_CONFIRM 3
  ------------------
  |  Branch (296:2): [True: 228, False: 27.9k]
  ------------------
  297|    228|		elems->fils_key_confirm = pos;
  298|    228|		elems->fils_key_confirm_len = elen;
  299|    228|		break;
  300|    840|	case WLAN_EID_EXT_FILS_SESSION:
  ------------------
  |  |  468|    840|#define WLAN_EID_EXT_FILS_SESSION 4
  ------------------
  |  Branch (300:2): [True: 840, False: 27.3k]
  ------------------
  301|    840|		if (elen != FILS_SESSION_LEN)
  ------------------
  |  |  909|    840|#define FILS_SESSION_LEN 8
  ------------------
  |  Branch (301:7): [True: 542, False: 298]
  ------------------
  302|    542|			break;
  303|    298|		elems->fils_session = pos;
  304|    298|		break;
  305|    882|	case WLAN_EID_EXT_FILS_HLP_CONTAINER:
  ------------------
  |  |  469|    882|#define WLAN_EID_EXT_FILS_HLP_CONTAINER 5
  ------------------
  |  Branch (305:2): [True: 882, False: 27.3k]
  ------------------
  306|    882|		if (elen < 2 * ETH_ALEN)
  ------------------
  |  |  315|    882|#define ETH_ALEN 6
  ------------------
  |  Branch (306:7): [True: 254, False: 628]
  ------------------
  307|    254|			break;
  308|    628|		elems->fils_hlp = pos;
  309|    628|		elems->fils_hlp_len = elen;
  310|    628|		total_len = &elems->fils_hlp_len;
  311|    628|		break;
  312|    666|	case WLAN_EID_EXT_FILS_IP_ADDR_ASSIGN:
  ------------------
  |  |  470|    666|#define WLAN_EID_EXT_FILS_IP_ADDR_ASSIGN 6
  ------------------
  |  Branch (312:2): [True: 666, False: 27.5k]
  ------------------
  313|    666|		if (elen < 1)
  ------------------
  |  Branch (313:7): [True: 388, False: 278]
  ------------------
  314|    388|			break;
  315|    278|		elems->fils_ip_addr_assign = pos;
  316|    278|		elems->fils_ip_addr_assign_len = elen;
  317|    278|		break;
  318|  1.29k|	case WLAN_EID_EXT_KEY_DELIVERY:
  ------------------
  |  |  471|  1.29k|#define WLAN_EID_EXT_KEY_DELIVERY 7
  ------------------
  |  Branch (318:2): [True: 1.29k, False: 26.8k]
  ------------------
  319|  1.29k|		if (elen < WPA_KEY_RSC_LEN)
  ------------------
  |  |   19|  1.29k|#define WPA_KEY_RSC_LEN 8
  ------------------
  |  Branch (319:7): [True: 1.08k, False: 208]
  ------------------
  320|  1.08k|			break;
  321|    208|		elems->key_delivery = pos;
  322|    208|		elems->key_delivery_len = elen;
  323|    208|		break;
  324|    704|	case WLAN_EID_EXT_WRAPPED_DATA:
  ------------------
  |  |  472|    704|#define WLAN_EID_EXT_WRAPPED_DATA 8
  ------------------
  |  Branch (324:2): [True: 704, False: 27.4k]
  ------------------
  325|    704|		elems->wrapped_data = pos;
  326|    704|		elems->wrapped_data_len = elen;
  327|    704|		total_len = &elems->wrapped_data_len;
  328|    704|		break;
  329|  1.90k|	case WLAN_EID_EXT_FILS_PUBLIC_KEY:
  ------------------
  |  |  476|  1.90k|#define WLAN_EID_EXT_FILS_PUBLIC_KEY 12
  ------------------
  |  Branch (329:2): [True: 1.90k, False: 26.2k]
  ------------------
  330|  1.90k|		if (elen < 1)
  ------------------
  |  Branch (330:7): [True: 1.70k, False: 208]
  ------------------
  331|  1.70k|			break;
  332|    208|		elems->fils_pk = pos;
  333|    208|		elems->fils_pk_len = elen;
  334|    208|		break;
  335|  1.65k|	case WLAN_EID_EXT_FILS_NONCE:
  ------------------
  |  |  477|  1.65k|#define WLAN_EID_EXT_FILS_NONCE 13
  ------------------
  |  Branch (335:2): [True: 1.65k, False: 26.5k]
  ------------------
  336|  1.65k|		if (elen != FILS_NONCE_LEN)
  ------------------
  |  |  908|  1.65k|#define FILS_NONCE_LEN 16
  ------------------
  |  Branch (336:7): [True: 1.45k, False: 192]
  ------------------
  337|  1.45k|			break;
  338|    192|		elems->fils_nonce = pos;
  339|    192|		break;
  340|    942|	case WLAN_EID_EXT_OWE_DH_PARAM:
  ------------------
  |  |  479|    942|#define WLAN_EID_EXT_OWE_DH_PARAM 32
  ------------------
  |  Branch (340:2): [True: 942, False: 27.2k]
  ------------------
  341|    942|		if (elen < 2)
  ------------------
  |  Branch (341:7): [True: 716, False: 226]
  ------------------
  342|    716|			break;
  343|    226|		elems->owe_dh = pos;
  344|    226|		elems->owe_dh_len = elen;
  345|    226|		break;
  346|    206|	case WLAN_EID_EXT_PASSWORD_IDENTIFIER:
  ------------------
  |  |  480|    206|#define WLAN_EID_EXT_PASSWORD_IDENTIFIER 33
  ------------------
  |  Branch (346:2): [True: 206, False: 27.9k]
  ------------------
  347|    206|		elems->password_id = pos;
  348|    206|		elems->password_id_len = elen;
  349|    206|		break;
  350|    324|	case WLAN_EID_EXT_HE_CAPABILITIES:
  ------------------
  |  |  481|    324|#define WLAN_EID_EXT_HE_CAPABILITIES 35
  ------------------
  |  Branch (350:2): [True: 324, False: 27.8k]
  ------------------
  351|    324|		elems->he_capabilities = pos;
  352|    324|		elems->he_capabilities_len = elen;
  353|    324|		break;
  354|    288|	case WLAN_EID_EXT_HE_OPERATION:
  ------------------
  |  |  482|    288|#define WLAN_EID_EXT_HE_OPERATION 36
  ------------------
  |  Branch (354:2): [True: 288, False: 27.8k]
  ------------------
  355|    288|		elems->he_operation = pos;
  356|    288|		elems->he_operation_len = elen;
  357|    288|		break;
  358|    886|	case WLAN_EID_EXT_OCV_OCI:
  ------------------
  |  |  486|    886|#define WLAN_EID_EXT_OCV_OCI 54
  ------------------
  |  Branch (358:2): [True: 886, False: 27.3k]
  ------------------
  359|    886|		elems->oci = pos;
  360|    886|		elems->oci_len = elen;
  361|    886|		break;
  362|    220|	case WLAN_EID_EXT_SHORT_SSID_LIST:
  ------------------
  |  |  490|    220|#define WLAN_EID_EXT_SHORT_SSID_LIST 58
  ------------------
  |  Branch (362:2): [True: 220, False: 27.9k]
  ------------------
  363|    220|		elems->short_ssid_list = pos;
  364|    220|		elems->short_ssid_list_len = elen;
  365|    220|		break;
  366|  1.34k|	case WLAN_EID_EXT_HE_6GHZ_BAND_CAP:
  ------------------
  |  |  491|  1.34k|#define WLAN_EID_EXT_HE_6GHZ_BAND_CAP 59
  ------------------
  |  Branch (366:2): [True: 1.34k, False: 26.8k]
  ------------------
  367|  1.34k|		if (elen < sizeof(struct ieee80211_he_6ghz_band_cap))
  ------------------
  |  Branch (367:7): [True: 668, False: 676]
  ------------------
  368|    668|			break;
  369|    676|		elems->he_6ghz_band_cap = pos;
  370|    676|		break;
  371|  1.11k|	case WLAN_EID_EXT_PASN_PARAMS:
  ------------------
  |  |  498|  1.11k|#define WLAN_EID_EXT_PASN_PARAMS 100
  ------------------
  |  Branch (371:2): [True: 1.11k, False: 27.0k]
  ------------------
  372|  1.11k|		elems->pasn_params = pos;
  373|  1.11k|		elems->pasn_params_len = elen;
  374|  1.11k|		break;
  375|    956|	case WLAN_EID_EXT_EHT_CAPABILITIES:
  ------------------
  |  |  501|    956|#define WLAN_EID_EXT_EHT_CAPABILITIES 108
  ------------------
  |  Branch (375:2): [True: 956, False: 27.2k]
  ------------------
  376|    956|		elems->eht_capabilities = pos;
  377|    956|		elems->eht_capabilities_len = elen;
  378|    956|		break;
  379|  1.64k|	case WLAN_EID_EXT_EHT_OPERATION:
  ------------------
  |  |  499|  1.64k|#define WLAN_EID_EXT_EHT_OPERATION 106
  ------------------
  |  Branch (379:2): [True: 1.64k, False: 26.5k]
  ------------------
  380|  1.64k|		elems->eht_operation = pos;
  381|  1.64k|		elems->eht_operation_len = elen;
  382|  1.64k|		break;
  383|  4.58k|	case WLAN_EID_EXT_MULTI_LINK:
  ------------------
  |  |  500|  4.58k|#define WLAN_EID_EXT_MULTI_LINK 107
  ------------------
  |  Branch (383:2): [True: 4.58k, False: 23.6k]
  ------------------
  384|  4.58k|		if (elen < 2)
  ------------------
  |  Branch (384:7): [True: 1.39k, False: 3.18k]
  ------------------
  385|  1.39k|			break;
  386|  3.18k|		if (ieee802_11_parse_mle(pos, elen, &total_len, elems,
  ------------------
  |  Branch (386:7): [True: 246, False: 2.94k]
  ------------------
  387|  3.18k|					 show_errors))
  388|    246|			return -1;
  389|  2.94k|		break;
  390|  2.94k|	case WLAN_EID_EXT_KNOWN_BSSID:
  ------------------
  |  |  489|    198|#define WLAN_EID_EXT_KNOWN_BSSID 57
  ------------------
  |  Branch (390:2): [True: 198, False: 27.9k]
  ------------------
  391|    198|		elems->mbssid_known_bss = pos;
  392|    198|		elems->mbssid_known_bss_len = elen;
  393|    198|		break;
  394|  6.03k|	default:
  ------------------
  |  Branch (394:2): [True: 6.03k, False: 22.1k]
  ------------------
  395|  6.03k|		if (show_errors) {
  ------------------
  |  Branch (395:7): [True: 0, False: 6.03k]
  ------------------
  396|      0|			wpa_printf(MSG_MSGDUMP,
  397|      0|				   "IEEE 802.11 element parsing ignored unknown element extension (ext_id=%u elen=%u)",
  398|      0|				   ext_id, (unsigned int) elen);
  399|      0|		}
  400|  6.03k|		return -1;
  401|  28.1k|	}
  402|       |
  403|  21.9k|	if (elen == 254 && total_len)
  ------------------
  |  Branch (403:6): [True: 1.19k, False: 20.7k]
  |  Branch (403:21): [True: 644, False: 546]
  ------------------
  404|    644|		*total_len += ieee802_11_fragments_length(
  405|    644|			elems, pos + elen, (start + len) - (pos + elen));
  406|       |
  407|  21.9k|	return 0;
  408|  28.1k|}
ieee802_11_common.c:ieee802_11_parse_mle:
  205|  3.18k|{
  206|  3.18k|	u8 mle_type = pos[0] & MULTI_LINK_CONTROL_TYPE_MASK;
  ------------------
  |  | 2577|  3.18k|#define MULTI_LINK_CONTROL_TYPE_MASK			0x07
  ------------------
  207|       |
  208|  3.18k|	switch (mle_type) {
  209|    200|	case MULTI_LINK_CONTROL_TYPE_BASIC:
  ------------------
  |  | 2581|    200|#define MULTI_LINK_CONTROL_TYPE_BASIC			0
  ------------------
  |  Branch (209:2): [True: 200, False: 2.98k]
  ------------------
  210|    200|		elems->basic_mle = pos;
  211|    200|		elems->basic_mle_len = elen;
  212|    200|		*total_len = &elems->basic_mle_len;
  213|    200|		break;
  214|  1.57k|	case MULTI_LINK_CONTROL_TYPE_PROBE_REQ:
  ------------------
  |  | 2582|  1.57k|#define MULTI_LINK_CONTROL_TYPE_PROBE_REQ		1
  ------------------
  |  Branch (214:2): [True: 1.57k, False: 1.61k]
  ------------------
  215|  1.57k|		elems->probe_req_mle = pos;
  216|  1.57k|		elems->probe_req_mle_len = elen;
  217|  1.57k|		*total_len = &elems->probe_req_mle_len;
  218|  1.57k|		break;
  219|    214|	case MULTI_LINK_CONTROL_TYPE_RECONF:
  ------------------
  |  | 2583|    214|#define MULTI_LINK_CONTROL_TYPE_RECONF			2
  ------------------
  |  Branch (219:2): [True: 214, False: 2.97k]
  ------------------
  220|    214|		elems->reconf_mle = pos;
  221|    214|		elems->reconf_mle_len = elen;
  222|    214|		*total_len = &elems->reconf_mle_len;
  223|    214|		break;
  224|    496|	case MULTI_LINK_CONTROL_TYPE_TDLS:
  ------------------
  |  | 2584|    496|#define MULTI_LINK_CONTROL_TYPE_TDLS			3
  ------------------
  |  Branch (224:2): [True: 496, False: 2.69k]
  ------------------
  225|    496|		elems->tdls_mle = pos;
  226|    496|		elems->tdls_mle_len = elen;
  227|    496|		*total_len = &elems->tdls_mle_len;
  228|    496|		break;
  229|    456|	case MULTI_LINK_CONTROL_TYPE_PRIOR_ACCESS:
  ------------------
  |  | 2585|    456|#define MULTI_LINK_CONTROL_TYPE_PRIOR_ACCESS		4
  ------------------
  |  Branch (229:2): [True: 456, False: 2.73k]
  ------------------
  230|    456|		elems->prior_access_mle = pos;
  231|    456|		elems->prior_access_mle_len = elen;
  232|    456|		*total_len = &elems->prior_access_mle_len;
  233|    456|		break;
  234|    246|	default:
  ------------------
  |  Branch (234:2): [True: 246, False: 2.94k]
  ------------------
  235|    246|		if (show_errors) {
  ------------------
  |  Branch (235:7): [True: 0, False: 246]
  ------------------
  236|      0|			wpa_printf(MSG_MSGDUMP,
  237|      0|				   "Unknown Multi-Link element type %u",
  238|      0|				   mle_type);
  239|      0|		}
  240|    246|		return -1;
  241|  3.18k|	}
  242|       |
  243|  2.94k|	return 0;
  244|  3.18k|}
ieee802_11_common.c:ieee802_11_fragments_length:
  249|    644|{
  250|    644|	const struct element *elem;
  251|    644|	size_t frags_len = 0;
  252|       |
  253|  4.09M|	for_each_element(elem, start, len) {
  ------------------
  |  |  296|    644|	for (_elem = (const struct element *) (_data);			\
  |  |  297|  4.09M|	     (const u8 *) (_data) + (_datalen) - (const u8 *) _elem >=	\
  |  |  ------------------
  |  |  |  Branch (297:7): [True: 4.09M, False: 48]
  |  |  ------------------
  |  |  298|  4.09M|		(int) sizeof(*_elem) &&					\
  |  |  299|  4.09M|	     (const u8 *) (_data) + (_datalen) - (const u8 *) _elem >=	\
  |  |  ------------------
  |  |  |  Branch (299:7): [True: 4.09M, False: 30]
  |  |  ------------------
  |  |  300|  4.09M|		(int) sizeof(*_elem) + _elem->datalen;			\
  |  |  301|  4.08M|	     _elem = (const struct element *) (_elem->data + _elem->datalen))
  ------------------
  254|  4.09M|		if (elem->id != WLAN_EID_FRAGMENT)
  ------------------
  |  |  460|  4.09M|#define WLAN_EID_FRAGMENT 242
  ------------------
  |  Branch (254:7): [True: 566, False: 4.08M]
  ------------------
  255|    566|			break;
  256|       |
  257|  4.08M|		frags_len += elem->datalen + 2;
  258|  4.08M|		elems->num_frag_elems++;
  259|  4.08M|	}
  260|       |
  261|    644|	return frags_len;
  262|    644|}

ieee802_11_common.c:for_each_element_completed:
  337|  4.97k|{
  338|  4.97k|	return (const u8 *) element == (const u8 *) data + datalen;
  339|  4.97k|}

pasn_use_sha384:
 1308|  3.33k|{
 1309|  3.33k|	return (akmp == WPA_KEY_MGMT_PASN && (cipher == WPA_CIPHER_CCMP_256 ||
  ------------------
  |  |   52|  3.33k|#define WPA_KEY_MGMT_PASN BIT(25)
  |  |  ------------------
  |  |  |  |  429|  6.67k|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
              	return (akmp == WPA_KEY_MGMT_PASN && (cipher == WPA_CIPHER_CCMP_256 ||
  ------------------
  |  |   21|    725|#define WPA_CIPHER_CCMP_256 BIT(9)
  |  |  ------------------
  |  |  |  |  429|  1.45k|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (1309:10): [True: 725, False: 2.61k]
  |  Branch (1309:40): [True: 0, False: 725]
  ------------------
 1310|    725|					      cipher == WPA_CIPHER_GCMP_256)) ||
  ------------------
  |  |   20|    725|#define WPA_CIPHER_GCMP_256 BIT(8)
  |  |  ------------------
  |  |  |  |  429|    725|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (1310:12): [True: 0, False: 725]
  ------------------
 1311|  3.33k|		wpa_key_mgmt_sha384(akmp);
  ------------------
  |  Branch (1311:3): [True: 0, False: 3.33k]
  ------------------
 1312|  3.33k|}
pasn_pmk_to_ptk:
 1335|    108|{
 1336|    108|	u8 tmp[WPA_KCK_MAX_LEN + WPA_TK_MAX_LEN + WPA_KDK_MAX_LEN];
 1337|    108|	u8 *data;
 1338|    108|	size_t data_len, ptk_len;
 1339|    108|	int ret = -1;
 1340|    108|	const char *label = "PASN PTK Derivation";
 1341|       |
 1342|    108|	if (!pmk || !pmk_len) {
  ------------------
  |  Branch (1342:6): [True: 0, False: 108]
  |  Branch (1342:14): [True: 0, False: 108]
  ------------------
 1343|      0|		wpa_printf(MSG_ERROR, "PASN: No PMK set for PTK derivation");
 1344|      0|		return -1;
 1345|      0|	}
 1346|       |
 1347|    108|	if (!dhss || !dhss_len) {
  ------------------
  |  Branch (1347:6): [True: 0, False: 108]
  |  Branch (1347:15): [True: 0, False: 108]
  ------------------
 1348|      0|		wpa_printf(MSG_ERROR, "PASN: No DHss set for PTK derivation");
 1349|      0|		return -1;
 1350|      0|	}
 1351|       |
 1352|       |	/*
 1353|       |	 * PASN-PTK = KDF(PMK, “PASN PTK Derivation”, SPA || BSSID || DHss)
 1354|       |	 *
 1355|       |	 * KCK = L(PASN-PTK, 0, 256)
 1356|       |	 * TK = L(PASN-PTK, 256, TK_bits)
 1357|       |	 * KDK = L(PASN-PTK, 256 + TK_bits, kdk_len * 8)
 1358|       |	 */
 1359|    108|	data_len = 2 * ETH_ALEN + dhss_len;
  ------------------
  |  |  315|    108|#define ETH_ALEN 6
  ------------------
 1360|    108|	data = os_zalloc(data_len);
 1361|    108|	if (!data)
  ------------------
  |  Branch (1361:6): [True: 0, False: 108]
  ------------------
 1362|      0|		return -1;
 1363|       |
 1364|    108|	os_memcpy(data, spa, ETH_ALEN);
  ------------------
  |  |  503|    108|#define os_memcpy(d, s, n) memcpy((d), (s), (n))
  ------------------
 1365|    108|	os_memcpy(data + ETH_ALEN, bssid, ETH_ALEN);
  ------------------
  |  |  503|    108|#define os_memcpy(d, s, n) memcpy((d), (s), (n))
  ------------------
 1366|    108|	os_memcpy(data + 2 * ETH_ALEN, dhss, dhss_len);
  ------------------
  |  |  503|    108|#define os_memcpy(d, s, n) memcpy((d), (s), (n))
  ------------------
 1367|       |
 1368|    108|	ptk->kck_len = WPA_PASN_KCK_LEN;
  ------------------
  |  |  245|    108|#define WPA_PASN_KCK_LEN 32
  ------------------
 1369|    108|	ptk->tk_len = wpa_cipher_key_len(cipher);
 1370|    108|	ptk->kdk_len = kdk_len;
 1371|    108|	ptk->kek_len = 0;
 1372|    108|	ptk->kek2_len = 0;
 1373|    108|	ptk->kck2_len = 0;
 1374|       |
 1375|    108|	if (ptk->tk_len == 0) {
  ------------------
  |  Branch (1375:6): [True: 0, False: 108]
  ------------------
 1376|      0|		wpa_printf(MSG_ERROR,
 1377|      0|			   "PASN: Unsupported cipher (0x%x) used in PTK derivation",
 1378|      0|			   cipher);
 1379|      0|		goto err;
 1380|      0|	}
 1381|       |
 1382|    108|	ptk_len = ptk->kck_len + ptk->tk_len + ptk->kdk_len;
 1383|    108|	if (ptk_len > sizeof(tmp))
  ------------------
  |  Branch (1383:6): [True: 0, False: 108]
  ------------------
 1384|      0|		goto err;
 1385|       |
 1386|    108|	if (pasn_use_sha384(akmp, cipher)) {
  ------------------
  |  Branch (1386:6): [True: 0, False: 108]
  ------------------
 1387|      0|		wpa_printf(MSG_DEBUG, "PASN: PTK derivation using SHA384");
 1388|       |
 1389|      0|		if (sha384_prf(pmk, pmk_len, label, data, data_len, tmp,
  ------------------
  |  Branch (1389:7): [True: 0, False: 0]
  ------------------
 1390|      0|			       ptk_len) < 0)
 1391|      0|			goto err;
 1392|    108|	} else {
 1393|    108|		wpa_printf(MSG_DEBUG, "PASN: PTK derivation using SHA256");
 1394|       |
 1395|    108|		if (sha256_prf(pmk, pmk_len, label, data, data_len, tmp,
  ------------------
  |  Branch (1395:7): [True: 0, False: 108]
  ------------------
 1396|    108|			       ptk_len) < 0)
 1397|      0|			goto err;
 1398|    108|	}
 1399|       |
 1400|    108|	wpa_printf(MSG_DEBUG,
 1401|    108|		   "PASN: PTK derivation: SPA=" MACSTR " BSSID=" MACSTR,
  ------------------
  |  |  419|    108|#define MACSTR "%02x:%02x:%02x:%02x:%02x:%02x"
  ------------------
 1402|    108|		   MAC2STR(spa), MAC2STR(bssid));
  ------------------
  |  |  418|    108|#define MAC2STR(a) (a)[0], (a)[1], (a)[2], (a)[3], (a)[4], (a)[5]
  ------------------
              		   MAC2STR(spa), MAC2STR(bssid));
  ------------------
  |  |  418|    108|#define MAC2STR(a) (a)[0], (a)[1], (a)[2], (a)[3], (a)[4], (a)[5]
  ------------------
 1403|       |
 1404|    108|	wpa_hexdump_key(MSG_DEBUG, "PASN: DHss", dhss, dhss_len);
 1405|    108|	wpa_hexdump_key(MSG_DEBUG, "PASN: PMK", pmk, pmk_len);
 1406|    108|	wpa_hexdump_key(MSG_DEBUG, "PASN: PASN-PTK", tmp, ptk_len);
 1407|       |
 1408|    108|	os_memcpy(ptk->kck, tmp, WPA_PASN_KCK_LEN);
  ------------------
  |  |  503|    108|#define os_memcpy(d, s, n) memcpy((d), (s), (n))
  ------------------
 1409|    108|	wpa_hexdump_key(MSG_DEBUG, "PASN: KCK:", ptk->kck, WPA_PASN_KCK_LEN);
  ------------------
  |  |  245|    108|#define WPA_PASN_KCK_LEN 32
  ------------------
 1410|       |
 1411|    108|	os_memcpy(ptk->tk, tmp + WPA_PASN_KCK_LEN, ptk->tk_len);
  ------------------
  |  |  503|    108|#define os_memcpy(d, s, n) memcpy((d), (s), (n))
  ------------------
 1412|    108|	wpa_hexdump_key(MSG_DEBUG, "PASN: TK:", ptk->tk, ptk->tk_len);
 1413|       |
 1414|    108|	if (kdk_len) {
  ------------------
  |  Branch (1414:6): [True: 0, False: 108]
  ------------------
 1415|      0|		os_memcpy(ptk->kdk, tmp + WPA_PASN_KCK_LEN + ptk->tk_len,
  ------------------
  |  |  503|      0|#define os_memcpy(d, s, n) memcpy((d), (s), (n))
  ------------------
 1416|      0|			  ptk->kdk_len);
 1417|      0|		wpa_hexdump_key(MSG_DEBUG, "PASN: KDK:",
 1418|      0|				ptk->kdk, ptk->kdk_len);
 1419|      0|	}
 1420|       |
 1421|    108|	forced_memzero(tmp, sizeof(tmp));
 1422|    108|	ret = 0;
 1423|    108|err:
 1424|    108|	bin_clear_free(data, data_len);
 1425|    108|	return ret;
 1426|    108|}
pasn_mic_len:
 1433|  2.74k|{
 1434|  2.74k|	if (pasn_use_sha384(akmp, cipher))
  ------------------
  |  Branch (1434:6): [True: 0, False: 2.74k]
  ------------------
 1435|      0|		return 24;
 1436|       |
 1437|  2.74k|	return 16;
 1438|  2.74k|}
pasn_mic:
 1521|    268|{
 1522|    268|	u8 *buf;
 1523|    268|	u8 hash[SHA384_MAC_LEN];
 1524|    268|	size_t buf_len = 2 * ETH_ALEN + data_len + frame_len;
  ------------------
  |  |  315|    268|#define ETH_ALEN 6
  ------------------
 1525|    268|	int ret = -1;
 1526|       |
 1527|    268|	if (!kck) {
  ------------------
  |  Branch (1527:6): [True: 0, False: 268]
  ------------------
 1528|      0|		wpa_printf(MSG_ERROR, "PASN: No KCK for MIC calculation");
 1529|      0|		return -1;
 1530|      0|	}
 1531|       |
 1532|    268|	if (!data || !data_len) {
  ------------------
  |  Branch (1532:6): [True: 0, False: 268]
  |  Branch (1532:15): [True: 0, False: 268]
  ------------------
 1533|      0|		wpa_printf(MSG_ERROR, "PASN: invalid data for MIC calculation");
 1534|      0|		return -1;
 1535|      0|	}
 1536|       |
 1537|    268|	if (!frame || !frame_len) {
  ------------------
  |  Branch (1537:6): [True: 0, False: 268]
  |  Branch (1537:16): [True: 0, False: 268]
  ------------------
 1538|      0|		wpa_printf(MSG_ERROR, "PASN: invalid data for MIC calculation");
 1539|      0|		return -1;
 1540|      0|	}
 1541|       |
 1542|    268|	buf = os_zalloc(buf_len);
 1543|    268|	if (!buf)
  ------------------
  |  Branch (1543:6): [True: 0, False: 268]
  ------------------
 1544|      0|		return -1;
 1545|       |
 1546|    268|	os_memcpy(buf, addr1, ETH_ALEN);
  ------------------
  |  |  503|    268|#define os_memcpy(d, s, n) memcpy((d), (s), (n))
  ------------------
 1547|    268|	os_memcpy(buf + ETH_ALEN, addr2, ETH_ALEN);
  ------------------
  |  |  503|    268|#define os_memcpy(d, s, n) memcpy((d), (s), (n))
  ------------------
 1548|       |
 1549|    268|	wpa_hexdump_key(MSG_DEBUG, "PASN: MIC: data", data, data_len);
 1550|    268|	os_memcpy(buf + 2 * ETH_ALEN, data, data_len);
  ------------------
  |  |  503|    268|#define os_memcpy(d, s, n) memcpy((d), (s), (n))
  ------------------
 1551|       |
 1552|    268|	wpa_hexdump_key(MSG_DEBUG, "PASN: MIC: frame", frame, frame_len);
 1553|    268|	os_memcpy(buf + 2 * ETH_ALEN + data_len, frame, frame_len);
  ------------------
  |  |  503|    268|#define os_memcpy(d, s, n) memcpy((d), (s), (n))
  ------------------
 1554|       |
 1555|    268|	wpa_hexdump_key(MSG_DEBUG, "PASN: MIC: KCK", kck, WPA_PASN_KCK_LEN);
  ------------------
  |  |  245|    268|#define WPA_PASN_KCK_LEN 32
  ------------------
 1556|    268|	wpa_hexdump_key(MSG_DEBUG, "PASN: MIC: buf", buf, buf_len);
 1557|       |
 1558|    268|	if (pasn_use_sha384(akmp, cipher)) {
  ------------------
  |  Branch (1558:6): [True: 0, False: 268]
  ------------------
 1559|      0|		wpa_printf(MSG_DEBUG, "PASN: MIC using HMAC-SHA384");
 1560|       |
 1561|      0|		if (hmac_sha384(kck, WPA_PASN_KCK_LEN, buf, buf_len, hash))
  ------------------
  |  |  245|      0|#define WPA_PASN_KCK_LEN 32
  ------------------
  |  Branch (1561:7): [True: 0, False: 0]
  ------------------
 1562|      0|			goto err;
 1563|       |
 1564|      0|		os_memcpy(mic, hash, 24);
  ------------------
  |  |  503|      0|#define os_memcpy(d, s, n) memcpy((d), (s), (n))
  ------------------
 1565|      0|		wpa_hexdump_key(MSG_DEBUG, "PASN: MIC: mic: ", mic, 24);
 1566|    268|	} else {
 1567|    268|		wpa_printf(MSG_DEBUG, "PASN: MIC using HMAC-SHA256");
 1568|       |
 1569|    268|		if (hmac_sha256(kck, WPA_PASN_KCK_LEN, buf, buf_len, hash))
  ------------------
  |  |  245|    268|#define WPA_PASN_KCK_LEN 32
  ------------------
  |  Branch (1569:7): [True: 0, False: 268]
  ------------------
 1570|      0|			goto err;
 1571|       |
 1572|    268|		os_memcpy(mic, hash, 16);
  ------------------
  |  |  503|    268|#define os_memcpy(d, s, n) memcpy((d), (s), (n))
  ------------------
 1573|    268|		wpa_hexdump_key(MSG_DEBUG, "PASN: MIC: mic: ", mic, 16);
 1574|    268|	}
 1575|       |
 1576|    268|	ret = 0;
 1577|    268|err:
 1578|    268|	bin_clear_free(buf, buf_len);
 1579|    268|	return ret;
 1580|    268|}
pasn_auth_frame_hash:
 1595|    216|{
 1596|    216|	if (pasn_use_sha384(akmp, cipher)) {
  ------------------
  |  Branch (1596:6): [True: 0, False: 216]
  ------------------
 1597|      0|		wpa_printf(MSG_DEBUG, "PASN: Frame hash using SHA-384");
 1598|      0|		return sha384_vector(1, &data, &len, hash);
 1599|    216|	} else {
 1600|    216|		wpa_printf(MSG_DEBUG, "PASN: Frame hash using SHA-256");
 1601|    216|		return sha256_vector(1, &data, &len, hash);
 1602|    216|	}
 1603|    216|}
wpa_cipher_valid_group:
 1697|  1.07k|{
 1698|  1.07k|	return wpa_cipher_valid_pairwise(cipher) ||
  ------------------
  |  Branch (1698:9): [True: 250, False: 828]
  ------------------
 1699|  1.07k|		cipher == WPA_CIPHER_GTK_NOT_USED;
  ------------------
  |  |   25|    828|#define WPA_CIPHER_GTK_NOT_USED BIT(14)
  |  |  ------------------
  |  |  |  |  429|    828|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (1699:3): [True: 734, False: 94]
  ------------------
 1700|  1.07k|}
wpa_cipher_valid_mgmt_group:
 1704|    294|{
 1705|    294|	return cipher == WPA_CIPHER_GTK_NOT_USED ||
  ------------------
  |  |   25|    294|#define WPA_CIPHER_GTK_NOT_USED BIT(14)
  |  |  ------------------
  |  |  |  |  429|    588|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (1705:9): [True: 187, False: 107]
  ------------------
 1706|    294|		cipher == WPA_CIPHER_AES_128_CMAC ||
  ------------------
  |  |   17|    107|#define WPA_CIPHER_AES_128_CMAC BIT(5)
  |  |  ------------------
  |  |  |  |  429|    401|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (1706:3): [True: 3, False: 104]
  ------------------
 1707|    294|		cipher == WPA_CIPHER_BIP_GMAC_128 ||
  ------------------
  |  |   22|    104|#define WPA_CIPHER_BIP_GMAC_128 BIT(11)
  |  |  ------------------
  |  |  |  |  429|    398|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (1707:3): [True: 1, False: 103]
  ------------------
 1708|    294|		cipher == WPA_CIPHER_BIP_GMAC_256 ||
  ------------------
  |  |   23|    103|#define WPA_CIPHER_BIP_GMAC_256 BIT(12)
  |  |  ------------------
  |  |  |  |  429|    397|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (1708:3): [True: 1, False: 102]
  ------------------
 1709|    294|		cipher == WPA_CIPHER_BIP_CMAC_256;
  ------------------
  |  |   24|    102|#define WPA_CIPHER_BIP_CMAC_256 BIT(13)
  |  |  ------------------
  |  |  |  |  429|    102|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (1709:3): [True: 1, False: 101]
  ------------------
 1710|    294|}
wpa_parse_wpa_ie_rsn:
 1722|  1.18k|{
 1723|  1.18k|	const u8 *pos;
 1724|  1.18k|	int left;
 1725|  1.18k|	int i, count;
 1726|       |
 1727|  1.18k|	os_memset(data, 0, sizeof(*data));
  ------------------
  |  |  509|  1.18k|#define os_memset(s, c, n) memset(s, c, n)
  ------------------
 1728|  1.18k|	data->proto = WPA_PROTO_RSN;
  ------------------
  |  |  194|  1.18k|#define WPA_PROTO_RSN BIT(1)
  |  |  ------------------
  |  |  |  |  429|  1.18k|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 1729|  1.18k|	data->pairwise_cipher = WPA_CIPHER_CCMP;
  ------------------
  |  |   16|  1.18k|#define WPA_CIPHER_CCMP BIT(4)
  |  |  ------------------
  |  |  |  |  429|  1.18k|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 1730|  1.18k|	data->group_cipher = WPA_CIPHER_CCMP;
  ------------------
  |  |   16|  1.18k|#define WPA_CIPHER_CCMP BIT(4)
  |  |  ------------------
  |  |  |  |  429|  1.18k|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 1731|  1.18k|	data->key_mgmt = WPA_KEY_MGMT_IEEE8021X;
  ------------------
  |  |   27|  1.18k|#define WPA_KEY_MGMT_IEEE8021X BIT(0)
  |  |  ------------------
  |  |  |  |  429|  1.18k|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 1732|  1.18k|	data->capabilities = 0;
 1733|  1.18k|	data->pmkid = NULL;
 1734|  1.18k|	data->num_pmkid = 0;
 1735|  1.18k|	data->mgmt_group_cipher = WPA_CIPHER_AES_128_CMAC;
  ------------------
  |  |   17|  1.18k|#define WPA_CIPHER_AES_128_CMAC BIT(5)
  |  |  ------------------
  |  |  |  |  429|  1.18k|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 1736|       |
 1737|  1.18k|	if (rsn_ie_len == 0) {
  ------------------
  |  Branch (1737:6): [True: 0, False: 1.18k]
  ------------------
 1738|       |		/* No RSN IE - fail silently */
 1739|      0|		return -1;
 1740|      0|	}
 1741|       |
 1742|  1.18k|	if (rsn_ie_len < sizeof(struct rsn_ie_hdr)) {
  ------------------
  |  Branch (1742:6): [True: 16, False: 1.16k]
  ------------------
 1743|     16|		wpa_printf(MSG_DEBUG, "%s: ie len too short %lu",
 1744|     16|			   __func__, (unsigned long) rsn_ie_len);
 1745|     16|		return -1;
 1746|     16|	}
 1747|       |
 1748|  1.16k|	if (rsn_ie_len >= 6 && rsn_ie[1] >= 4 &&
  ------------------
  |  Branch (1748:6): [True: 1.14k, False: 18]
  |  Branch (1748:25): [True: 1.14k, False: 0]
  ------------------
 1749|  1.16k|	    rsn_ie[1] == rsn_ie_len - 2 &&
  ------------------
  |  Branch (1749:6): [True: 1.14k, False: 0]
  ------------------
 1750|  1.16k|	    WPA_GET_BE32(&rsn_ie[2]) == OSEN_IE_VENDOR_TYPE) {
  ------------------
  |  | 1377|  1.14k|#define OSEN_IE_VENDOR_TYPE 0x506f9a12
  ------------------
  |  Branch (1750:6): [True: 2, False: 1.14k]
  ------------------
 1751|      2|		pos = rsn_ie + 6;
 1752|      2|		left = rsn_ie_len - 6;
 1753|       |
 1754|      2|		data->group_cipher = WPA_CIPHER_GTK_NOT_USED;
  ------------------
  |  |   25|      2|#define WPA_CIPHER_GTK_NOT_USED BIT(14)
  |  |  ------------------
  |  |  |  |  429|      2|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 1755|      2|		data->has_group = 1;
 1756|      2|		data->key_mgmt = WPA_KEY_MGMT_OSEN;
  ------------------
  |  |   42|      2|#define WPA_KEY_MGMT_OSEN BIT(15)
  |  |  ------------------
  |  |  |  |  429|      2|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 1757|      2|		data->proto = WPA_PROTO_OSEN;
  ------------------
  |  |  196|      2|#define WPA_PROTO_OSEN BIT(3)
  |  |  ------------------
  |  |  |  |  429|      2|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 1758|  1.16k|	} else {
 1759|  1.16k|		const struct rsn_ie_hdr *hdr;
 1760|       |
 1761|  1.16k|		hdr = (const struct rsn_ie_hdr *) rsn_ie;
 1762|       |
 1763|  1.16k|		if (hdr->elem_id != WLAN_EID_RSN ||
  ------------------
  |  |  310|  2.32k|#define WLAN_EID_RSN 48
  ------------------
  |  Branch (1763:7): [True: 0, False: 1.16k]
  ------------------
 1764|  1.16k|		    hdr->len != rsn_ie_len - 2 ||
  ------------------
  |  Branch (1764:7): [True: 0, False: 1.16k]
  ------------------
 1765|  1.16k|		    WPA_GET_LE16(hdr->version) != RSN_VERSION) {
  ------------------
  |  |   52|  1.16k|#define RSN_VERSION 1
  ------------------
  |  Branch (1765:7): [True: 75, False: 1.08k]
  ------------------
 1766|     75|			wpa_printf(MSG_DEBUG, "%s: malformed ie or unknown version",
 1767|     75|				   __func__);
 1768|     75|			return -2;
 1769|     75|		}
 1770|       |
 1771|  1.08k|		pos = (const u8 *) (hdr + 1);
 1772|  1.08k|		left = rsn_ie_len - sizeof(*hdr);
 1773|  1.08k|	}
 1774|       |
 1775|  1.09k|	if (left >= RSN_SELECTOR_LEN) {
  ------------------
  |  |   51|  1.09k|#define RSN_SELECTOR_LEN 4
  ------------------
  |  Branch (1775:6): [True: 1.07k, False: 12]
  ------------------
 1776|  1.07k|		data->group_cipher = rsn_selector_to_bitfield(pos);
 1777|  1.07k|		data->has_group = 1;
 1778|  1.07k|		if (!wpa_cipher_valid_group(data->group_cipher)) {
  ------------------
  |  Branch (1778:7): [True: 94, False: 984]
  ------------------
 1779|     94|			wpa_printf(MSG_DEBUG,
 1780|     94|				   "%s: invalid group cipher 0x%x (%08x)",
 1781|     94|				   __func__, data->group_cipher,
 1782|     94|				   WPA_GET_BE32(pos));
 1783|       |#ifdef CONFIG_NO_TKIP
 1784|       |			if (RSN_SELECTOR_GET(pos) == RSN_CIPHER_SUITE_TKIP) {
 1785|       |				wpa_printf(MSG_DEBUG,
 1786|       |					   "%s: TKIP as group cipher not supported in CONFIG_NO_TKIP=y build",
 1787|       |					   __func__);
 1788|       |			}
 1789|       |#endif /* CONFIG_NO_TKIP */
 1790|     94|			return -1;
 1791|     94|		}
 1792|    984|		pos += RSN_SELECTOR_LEN;
  ------------------
  |  |   51|    984|#define RSN_SELECTOR_LEN 4
  ------------------
 1793|    984|		left -= RSN_SELECTOR_LEN;
  ------------------
  |  |   51|    984|#define RSN_SELECTOR_LEN 4
  ------------------
 1794|    984|	} else if (left > 0) {
  ------------------
  |  Branch (1794:13): [True: 10, False: 2]
  ------------------
 1795|     10|		wpa_printf(MSG_DEBUG, "%s: ie length mismatch, %u too much",
 1796|     10|			   __func__, left);
 1797|     10|		return -3;
 1798|     10|	}
 1799|       |
 1800|    986|	if (left >= 2) {
  ------------------
  |  Branch (1800:6): [True: 977, False: 9]
  ------------------
 1801|    977|		data->pairwise_cipher = 0;
 1802|    977|		count = WPA_GET_LE16(pos);
 1803|    977|		pos += 2;
 1804|    977|		left -= 2;
 1805|    977|		if (count == 0 || count > left / RSN_SELECTOR_LEN) {
  ------------------
  |  |   51|    975|#define RSN_SELECTOR_LEN 4
  ------------------
  |  Branch (1805:7): [True: 2, False: 975]
  |  Branch (1805:21): [True: 18, False: 957]
  ------------------
 1806|     20|			wpa_printf(MSG_DEBUG, "%s: ie count botch (pairwise), "
 1807|     20|				   "count %u left %u", __func__, count, left);
 1808|     20|			return -4;
 1809|     20|		}
 1810|    957|		if (count)
  ------------------
  |  Branch (1810:7): [True: 957, False: 0]
  ------------------
 1811|    957|			data->has_pairwise = 1;
 1812|  2.84k|		for (i = 0; i < count; i++) {
  ------------------
  |  Branch (1812:15): [True: 1.88k, False: 957]
  ------------------
 1813|  1.88k|			data->pairwise_cipher |= rsn_selector_to_bitfield(pos);
 1814|  1.88k|			pos += RSN_SELECTOR_LEN;
  ------------------
  |  |   51|  1.88k|#define RSN_SELECTOR_LEN 4
  ------------------
 1815|  1.88k|			left -= RSN_SELECTOR_LEN;
  ------------------
  |  |   51|  1.88k|#define RSN_SELECTOR_LEN 4
  ------------------
 1816|  1.88k|		}
 1817|    957|		if (data->pairwise_cipher & WPA_CIPHER_AES_128_CMAC) {
  ------------------
  |  |   17|    957|#define WPA_CIPHER_AES_128_CMAC BIT(5)
  |  |  ------------------
  |  |  |  |  429|    957|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (1817:7): [True: 11, False: 946]
  ------------------
 1818|     11|			wpa_printf(MSG_DEBUG, "%s: AES-128-CMAC used as "
 1819|     11|				   "pairwise cipher", __func__);
 1820|     11|			return -1;
 1821|     11|		}
 1822|    957|	} else if (left == 1) {
  ------------------
  |  Branch (1822:13): [True: 1, False: 8]
  ------------------
 1823|      1|		wpa_printf(MSG_DEBUG, "%s: ie too short (for key mgmt)",
 1824|      1|			   __func__);
 1825|      1|		return -5;
 1826|      1|	}
 1827|       |
 1828|    954|	if (left >= 2) {
  ------------------
  |  Branch (1828:6): [True: 803, False: 151]
  ------------------
 1829|    803|		data->key_mgmt = 0;
 1830|    803|		count = WPA_GET_LE16(pos);
 1831|    803|		pos += 2;
 1832|    803|		left -= 2;
 1833|    803|		if (count == 0 || count > left / RSN_SELECTOR_LEN) {
  ------------------
  |  |   51|    801|#define RSN_SELECTOR_LEN 4
  ------------------
  |  Branch (1833:7): [True: 2, False: 801]
  |  Branch (1833:21): [True: 27, False: 774]
  ------------------
 1834|     29|			wpa_printf(MSG_DEBUG, "%s: ie count botch (key mgmt), "
 1835|     29|				   "count %u left %u", __func__, count, left);
 1836|     29|			return -6;
 1837|     29|		}
 1838|  3.74k|		for (i = 0; i < count; i++) {
  ------------------
  |  Branch (1838:15): [True: 2.97k, False: 774]
  ------------------
 1839|  2.97k|			data->key_mgmt |= rsn_key_mgmt_to_bitfield(pos);
 1840|  2.97k|			pos += RSN_SELECTOR_LEN;
  ------------------
  |  |   51|  2.97k|#define RSN_SELECTOR_LEN 4
  ------------------
 1841|  2.97k|			left -= RSN_SELECTOR_LEN;
  ------------------
  |  |   51|  2.97k|#define RSN_SELECTOR_LEN 4
  ------------------
 1842|  2.97k|		}
 1843|    774|	} else if (left == 1) {
  ------------------
  |  Branch (1843:13): [True: 3, False: 148]
  ------------------
 1844|      3|		wpa_printf(MSG_DEBUG, "%s: ie too short (for capabilities)",
 1845|      3|			   __func__);
 1846|      3|		return -7;
 1847|      3|	}
 1848|       |
 1849|    922|	if (left >= 2) {
  ------------------
  |  Branch (1849:6): [True: 536, False: 386]
  ------------------
 1850|    536|		data->capabilities = WPA_GET_LE16(pos);
 1851|    536|		pos += 2;
 1852|    536|		left -= 2;
 1853|    536|	}
 1854|       |
 1855|    922|	if (left >= 2) {
  ------------------
  |  Branch (1855:6): [True: 326, False: 596]
  ------------------
 1856|    326|		u16 num_pmkid = WPA_GET_LE16(pos);
 1857|    326|		pos += 2;
 1858|    326|		left -= 2;
 1859|    326|		if (num_pmkid > (unsigned int) left / PMKID_LEN) {
  ------------------
  |  |   13|    326|#define PMKID_LEN 16
  ------------------
  |  Branch (1859:7): [True: 22, False: 304]
  ------------------
 1860|     22|			wpa_printf(MSG_DEBUG, "%s: PMKID underflow "
 1861|     22|				   "(num_pmkid=%u left=%d)",
 1862|     22|				   __func__, num_pmkid, left);
 1863|     22|			data->num_pmkid = 0;
 1864|     22|			return -9;
 1865|    304|		} else {
 1866|    304|			data->num_pmkid = num_pmkid;
 1867|    304|			data->pmkid = pos;
 1868|    304|			pos += data->num_pmkid * PMKID_LEN;
  ------------------
  |  |   13|    304|#define PMKID_LEN 16
  ------------------
 1869|    304|			left -= data->num_pmkid * PMKID_LEN;
  ------------------
  |  |   13|    304|#define PMKID_LEN 16
  ------------------
 1870|    304|		}
 1871|    326|	}
 1872|       |
 1873|    900|	if (left >= 4) {
  ------------------
  |  Branch (1873:6): [True: 294, False: 606]
  ------------------
 1874|    294|		data->mgmt_group_cipher = rsn_selector_to_bitfield(pos);
 1875|    294|		if (!wpa_cipher_valid_mgmt_group(data->mgmt_group_cipher)) {
  ------------------
  |  Branch (1875:7): [True: 101, False: 193]
  ------------------
 1876|    101|			wpa_printf(MSG_DEBUG,
 1877|    101|				   "%s: Unsupported management group cipher 0x%x (%08x)",
 1878|    101|				   __func__, data->mgmt_group_cipher,
 1879|    101|				   WPA_GET_BE32(pos));
 1880|    101|			return -10;
 1881|    101|		}
 1882|    193|		pos += RSN_SELECTOR_LEN;
  ------------------
  |  |   51|    193|#define RSN_SELECTOR_LEN 4
  ------------------
 1883|    193|		left -= RSN_SELECTOR_LEN;
  ------------------
  |  |   51|    193|#define RSN_SELECTOR_LEN 4
  ------------------
 1884|    193|	}
 1885|       |
 1886|    799|	if (left > 0) {
  ------------------
  |  Branch (1886:6): [True: 17, False: 782]
  ------------------
 1887|     17|		wpa_hexdump(MSG_DEBUG,
 1888|     17|			    "wpa_parse_wpa_ie_rsn: ignore trailing bytes",
 1889|     17|			    pos, left);
 1890|     17|	}
 1891|       |
 1892|    799|	return 0;
 1893|    900|}
wpa_cipher_key_len:
 2859|    108|{
 2860|    108|	switch (cipher) {
 2861|      0|	case WPA_CIPHER_CCMP_256:
  ------------------
  |  |   21|      0|#define WPA_CIPHER_CCMP_256 BIT(9)
  |  |  ------------------
  |  |  |  |  429|      0|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (2861:2): [True: 0, False: 108]
  ------------------
 2862|      0|	case WPA_CIPHER_GCMP_256:
  ------------------
  |  |   20|      0|#define WPA_CIPHER_GCMP_256 BIT(8)
  |  |  ------------------
  |  |  |  |  429|      0|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (2862:2): [True: 0, False: 108]
  ------------------
 2863|      0|	case WPA_CIPHER_BIP_GMAC_256:
  ------------------
  |  |   23|      0|#define WPA_CIPHER_BIP_GMAC_256 BIT(12)
  |  |  ------------------
  |  |  |  |  429|      0|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (2863:2): [True: 0, False: 108]
  ------------------
 2864|      0|	case WPA_CIPHER_BIP_CMAC_256:
  ------------------
  |  |   24|      0|#define WPA_CIPHER_BIP_CMAC_256 BIT(13)
  |  |  ------------------
  |  |  |  |  429|      0|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (2864:2): [True: 0, False: 108]
  ------------------
 2865|      0|		return 32;
 2866|    108|	case WPA_CIPHER_CCMP:
  ------------------
  |  |   16|    108|#define WPA_CIPHER_CCMP BIT(4)
  |  |  ------------------
  |  |  |  |  429|    108|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (2866:2): [True: 108, False: 0]
  ------------------
 2867|    108|	case WPA_CIPHER_GCMP:
  ------------------
  |  |   18|    108|#define WPA_CIPHER_GCMP BIT(6)
  |  |  ------------------
  |  |  |  |  429|    108|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (2867:2): [True: 0, False: 108]
  ------------------
 2868|    108|	case WPA_CIPHER_AES_128_CMAC:
  ------------------
  |  |   17|    108|#define WPA_CIPHER_AES_128_CMAC BIT(5)
  |  |  ------------------
  |  |  |  |  429|    108|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (2868:2): [True: 0, False: 108]
  ------------------
 2869|    108|	case WPA_CIPHER_BIP_GMAC_128:
  ------------------
  |  |   22|    108|#define WPA_CIPHER_BIP_GMAC_128 BIT(11)
  |  |  ------------------
  |  |  |  |  429|    108|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (2869:2): [True: 0, False: 108]
  ------------------
 2870|    108|		return 16;
 2871|      0|	case WPA_CIPHER_TKIP:
  ------------------
  |  |   15|      0|#define WPA_CIPHER_TKIP BIT(3)
  |  |  ------------------
  |  |  |  |  429|      0|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (2871:2): [True: 0, False: 108]
  ------------------
 2872|      0|		return 32;
 2873|      0|	default:
  ------------------
  |  Branch (2873:2): [True: 0, False: 108]
  ------------------
 2874|      0|		return 0;
 2875|    108|	}
 2876|    108|}
wpa_cipher_valid_pairwise:
 2922|  1.07k|{
 2923|       |#ifdef CONFIG_NO_TKIP
 2924|       |	return cipher == WPA_CIPHER_CCMP_256 ||
 2925|       |		cipher == WPA_CIPHER_GCMP_256 ||
 2926|       |		cipher == WPA_CIPHER_CCMP ||
 2927|       |		cipher == WPA_CIPHER_GCMP;
 2928|       |#else /* CONFIG_NO_TKIP */
 2929|  1.07k|	return cipher == WPA_CIPHER_CCMP_256 ||
  ------------------
  |  |   21|  1.07k|#define WPA_CIPHER_CCMP_256 BIT(9)
  |  |  ------------------
  |  |  |  |  429|  2.15k|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (2929:9): [True: 58, False: 1.02k]
  ------------------
 2930|  1.07k|		cipher == WPA_CIPHER_GCMP_256 ||
  ------------------
  |  |   20|  1.02k|#define WPA_CIPHER_GCMP_256 BIT(8)
  |  |  ------------------
  |  |  |  |  429|  2.09k|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (2930:3): [True: 41, False: 979]
  ------------------
 2931|  1.07k|		cipher == WPA_CIPHER_CCMP ||
  ------------------
  |  |   16|    979|#define WPA_CIPHER_CCMP BIT(4)
  |  |  ------------------
  |  |  |  |  429|  2.05k|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (2931:3): [True: 72, False: 907]
  ------------------
 2932|  1.07k|		cipher == WPA_CIPHER_GCMP ||
  ------------------
  |  |   18|    907|#define WPA_CIPHER_GCMP BIT(6)
  |  |  ------------------
  |  |  |  |  429|  1.98k|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (2932:3): [True: 42, False: 865]
  ------------------
 2933|  1.07k|		cipher == WPA_CIPHER_TKIP;
  ------------------
  |  |   15|    865|#define WPA_CIPHER_TKIP BIT(3)
  |  |  ------------------
  |  |  |  |  429|    865|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (2933:3): [True: 37, False: 828]
  ------------------
 2934|  1.07k|#endif /* CONFIG_NO_TKIP */
 2935|  1.07k|}
wpa_cipher_to_suite:
 2939|    216|{
 2940|    216|	if (cipher & WPA_CIPHER_CCMP_256)
  ------------------
  |  |   21|    216|#define WPA_CIPHER_CCMP_256 BIT(9)
  |  |  ------------------
  |  |  |  |  429|    216|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (2940:6): [True: 0, False: 216]
  ------------------
 2941|      0|		return RSN_CIPHER_SUITE_CCMP_256;
  ------------------
  |  |  109|      0|#define RSN_CIPHER_SUITE_CCMP_256 RSN_SELECTOR(0x00, 0x0f, 0xac, 10)
  |  |  ------------------
  |  |  |  |   55|      0|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|      0|	 (u32) (d))
  |  |  ------------------
  ------------------
 2942|    216|	if (cipher & WPA_CIPHER_GCMP_256)
  ------------------
  |  |   20|    216|#define WPA_CIPHER_GCMP_256 BIT(8)
  |  |  ------------------
  |  |  |  |  429|    216|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (2942:6): [True: 0, False: 216]
  ------------------
 2943|      0|		return RSN_CIPHER_SUITE_GCMP_256;
  ------------------
  |  |  108|      0|#define RSN_CIPHER_SUITE_GCMP_256 RSN_SELECTOR(0x00, 0x0f, 0xac, 9)
  |  |  ------------------
  |  |  |  |   55|      0|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|      0|	 (u32) (d))
  |  |  ------------------
  ------------------
 2944|    216|	if (cipher & WPA_CIPHER_CCMP)
  ------------------
  |  |   16|    216|#define WPA_CIPHER_CCMP BIT(4)
  |  |  ------------------
  |  |  |  |  429|    216|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (2944:6): [True: 216, False: 0]
  ------------------
 2945|    216|		return (proto == WPA_PROTO_RSN ?
  ------------------
  |  |  194|    216|#define WPA_PROTO_RSN BIT(1)
  |  |  ------------------
  |  |  |  |  429|    216|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (2945:11): [True: 216, False: 0]
  ------------------
 2946|    216|			RSN_CIPHER_SUITE_CCMP : WPA_CIPHER_SUITE_CCMP);
  ------------------
  |  |  103|    216|#define RSN_CIPHER_SUITE_CCMP RSN_SELECTOR(0x00, 0x0f, 0xac, 4)
  |  |  ------------------
  |  |  |  |   55|    216|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|    216|	 (u32) (d))
  |  |  ------------------
  ------------------
              			RSN_CIPHER_SUITE_CCMP : WPA_CIPHER_SUITE_CCMP);
  ------------------
  |  |   64|      0|#define WPA_CIPHER_SUITE_CCMP RSN_SELECTOR(0x00, 0x50, 0xf2, 4)
  |  |  ------------------
  |  |  |  |   55|      0|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|      0|	 (u32) (d))
  |  |  ------------------
  ------------------
 2947|      0|	if (cipher & WPA_CIPHER_GCMP)
  ------------------
  |  |   18|      0|#define WPA_CIPHER_GCMP BIT(6)
  |  |  ------------------
  |  |  |  |  429|      0|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (2947:6): [True: 0, False: 0]
  ------------------
 2948|      0|		return RSN_CIPHER_SUITE_GCMP;
  ------------------
  |  |  107|      0|#define RSN_CIPHER_SUITE_GCMP RSN_SELECTOR(0x00, 0x0f, 0xac, 8)
  |  |  ------------------
  |  |  |  |   55|      0|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|      0|	 (u32) (d))
  |  |  ------------------
  ------------------
 2949|      0|	if (cipher & WPA_CIPHER_TKIP)
  ------------------
  |  |   15|      0|#define WPA_CIPHER_TKIP BIT(3)
  |  |  ------------------
  |  |  |  |  429|      0|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (2949:6): [True: 0, False: 0]
  ------------------
 2950|      0|		return (proto == WPA_PROTO_RSN ?
  ------------------
  |  |  194|      0|#define WPA_PROTO_RSN BIT(1)
  |  |  ------------------
  |  |  |  |  429|      0|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (2950:11): [True: 0, False: 0]
  ------------------
 2951|      0|			RSN_CIPHER_SUITE_TKIP : WPA_CIPHER_SUITE_TKIP);
  ------------------
  |  |   99|      0|#define RSN_CIPHER_SUITE_TKIP RSN_SELECTOR(0x00, 0x0f, 0xac, 2)
  |  |  ------------------
  |  |  |  |   55|      0|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|      0|	 (u32) (d))
  |  |  ------------------
  ------------------
              			RSN_CIPHER_SUITE_TKIP : WPA_CIPHER_SUITE_TKIP);
  ------------------
  |  |   63|      0|#define WPA_CIPHER_SUITE_TKIP RSN_SELECTOR(0x00, 0x50, 0xf2, 2)
  |  |  ------------------
  |  |  |  |   55|      0|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|      0|	 (u32) (d))
  |  |  ------------------
  ------------------
 2952|      0|	if (cipher & WPA_CIPHER_NONE)
  ------------------
  |  |   12|      0|#define WPA_CIPHER_NONE BIT(0)
  |  |  ------------------
  |  |  |  |  429|      0|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (2952:6): [True: 0, False: 0]
  ------------------
 2953|      0|		return (proto == WPA_PROTO_RSN ?
  ------------------
  |  |  194|      0|#define WPA_PROTO_RSN BIT(1)
  |  |  ------------------
  |  |  |  |  429|      0|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (2953:11): [True: 0, False: 0]
  ------------------
 2954|      0|			RSN_CIPHER_SUITE_NONE : WPA_CIPHER_SUITE_NONE);
  ------------------
  |  |   97|      0|#define RSN_CIPHER_SUITE_NONE RSN_SELECTOR(0x00, 0x0f, 0xac, 0)
  |  |  ------------------
  |  |  |  |   55|      0|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|      0|	 (u32) (d))
  |  |  ------------------
  ------------------
              			RSN_CIPHER_SUITE_NONE : WPA_CIPHER_SUITE_NONE);
  ------------------
  |  |   62|      0|#define WPA_CIPHER_SUITE_NONE RSN_SELECTOR(0x00, 0x50, 0xf2, 0)
  |  |  ------------------
  |  |  |  |   55|      0|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|      0|	 (u32) (d))
  |  |  ------------------
  ------------------
 2955|      0|	if (cipher & WPA_CIPHER_GTK_NOT_USED)
  ------------------
  |  |   25|      0|#define WPA_CIPHER_GTK_NOT_USED BIT(14)
  |  |  ------------------
  |  |  |  |  429|      0|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (2955:6): [True: 0, False: 0]
  ------------------
 2956|      0|		return RSN_CIPHER_SUITE_NO_GROUP_ADDRESSED;
  ------------------
  |  |  106|      0|#define RSN_CIPHER_SUITE_NO_GROUP_ADDRESSED RSN_SELECTOR(0x00, 0x0f, 0xac, 7)
  |  |  ------------------
  |  |  |  |   55|      0|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|      0|	 (u32) (d))
  |  |  ------------------
  ------------------
 2957|      0|	if (cipher & WPA_CIPHER_AES_128_CMAC)
  ------------------
  |  |   17|      0|#define WPA_CIPHER_AES_128_CMAC BIT(5)
  |  |  ------------------
  |  |  |  |  429|      0|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (2957:6): [True: 0, False: 0]
  ------------------
 2958|      0|		return RSN_CIPHER_SUITE_AES_128_CMAC;
  ------------------
  |  |  105|      0|#define RSN_CIPHER_SUITE_AES_128_CMAC RSN_SELECTOR(0x00, 0x0f, 0xac, 6)
  |  |  ------------------
  |  |  |  |   55|      0|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|      0|	 (u32) (d))
  |  |  ------------------
  ------------------
 2959|      0|	if (cipher & WPA_CIPHER_BIP_GMAC_128)
  ------------------
  |  |   22|      0|#define WPA_CIPHER_BIP_GMAC_128 BIT(11)
  |  |  ------------------
  |  |  |  |  429|      0|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (2959:6): [True: 0, False: 0]
  ------------------
 2960|      0|		return RSN_CIPHER_SUITE_BIP_GMAC_128;
  ------------------
  |  |  110|      0|#define RSN_CIPHER_SUITE_BIP_GMAC_128 RSN_SELECTOR(0x00, 0x0f, 0xac, 11)
  |  |  ------------------
  |  |  |  |   55|      0|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|      0|	 (u32) (d))
  |  |  ------------------
  ------------------
 2961|      0|	if (cipher & WPA_CIPHER_BIP_GMAC_256)
  ------------------
  |  |   23|      0|#define WPA_CIPHER_BIP_GMAC_256 BIT(12)
  |  |  ------------------
  |  |  |  |  429|      0|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (2961:6): [True: 0, False: 0]
  ------------------
 2962|      0|		return RSN_CIPHER_SUITE_BIP_GMAC_256;
  ------------------
  |  |  111|      0|#define RSN_CIPHER_SUITE_BIP_GMAC_256 RSN_SELECTOR(0x00, 0x0f, 0xac, 12)
  |  |  ------------------
  |  |  |  |   55|      0|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|      0|	 (u32) (d))
  |  |  ------------------
  ------------------
 2963|      0|	if (cipher & WPA_CIPHER_BIP_CMAC_256)
  ------------------
  |  |   24|      0|#define WPA_CIPHER_BIP_CMAC_256 BIT(13)
  |  |  ------------------
  |  |  |  |  429|      0|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (2963:6): [True: 0, False: 0]
  ------------------
 2964|      0|		return RSN_CIPHER_SUITE_BIP_CMAC_256;
  ------------------
  |  |  112|      0|#define RSN_CIPHER_SUITE_BIP_CMAC_256 RSN_SELECTOR(0x00, 0x0f, 0xac, 13)
  |  |  ------------------
  |  |  |  |   55|      0|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|      0|	 (u32) (d))
  |  |  ------------------
  ------------------
 2965|      0|	return 0;
 2966|      0|}
wpa_pasn_build_auth_header:
 3644|  2.71k|{
 3645|  2.71k|	struct ieee80211_mgmt *auth;
 3646|       |
 3647|  2.71k|	wpa_printf(MSG_DEBUG, "PASN: Add authentication header. trans_seq=%u",
 3648|  2.71k|		   trans_seq);
 3649|       |
 3650|  2.71k|	auth = wpabuf_put(buf, offsetof(struct ieee80211_mgmt,
 3651|  2.71k|					u.auth.variable));
 3652|       |
 3653|  2.71k|	auth->frame_control = host_to_le16((WLAN_FC_TYPE_MGMT << 2) |
  ------------------
  |  |  176|  2.71k|#define host_to_le16(n) ((__force le16) (u16) (n))
  ------------------
 3654|  2.71k|					   (WLAN_FC_STYPE_AUTH << 4));
 3655|       |
 3656|  2.71k|	os_memcpy(auth->da, dst, ETH_ALEN);
  ------------------
  |  |  503|  2.71k|#define os_memcpy(d, s, n) memcpy((d), (s), (n))
  ------------------
 3657|  2.71k|	os_memcpy(auth->sa, src, ETH_ALEN);
  ------------------
  |  |  503|  2.71k|#define os_memcpy(d, s, n) memcpy((d), (s), (n))
  ------------------
 3658|  2.71k|	os_memcpy(auth->bssid, bssid, ETH_ALEN);
  ------------------
  |  |  503|  2.71k|#define os_memcpy(d, s, n) memcpy((d), (s), (n))
  ------------------
 3659|  2.71k|	auth->seq_ctrl = 0;
 3660|       |
 3661|  2.71k|	auth->u.auth.auth_alg = host_to_le16(WLAN_AUTH_PASN);
  ------------------
  |  |  176|  2.71k|#define host_to_le16(n) ((__force le16) (u16) (n))
  ------------------
 3662|  2.71k|	auth->u.auth.auth_transaction = host_to_le16(trans_seq);
  ------------------
  |  |  176|  2.71k|#define host_to_le16(n) ((__force le16) (u16) (n))
  ------------------
 3663|  2.71k|	auth->u.auth.status_code = host_to_le16(status);
  ------------------
  |  |  176|  2.71k|#define host_to_le16(n) ((__force le16) (u16) (n))
  ------------------
 3664|  2.71k|}
wpa_pasn_add_rsne:
 3675|    216|{
 3676|    216|	struct rsn_ie_hdr *hdr;
 3677|    216|	u32 suite;
 3678|    216|	u16 capab;
 3679|    216|	u8 *pos;
 3680|    216|	u8 rsne_len;
 3681|       |
 3682|    216|	wpa_printf(MSG_DEBUG, "PASN: Add RSNE");
 3683|       |
 3684|    216|	rsne_len = sizeof(*hdr) + RSN_SELECTOR_LEN +
  ------------------
  |  |   51|    216|#define RSN_SELECTOR_LEN 4
  ------------------
 3685|    216|		2 + RSN_SELECTOR_LEN + 2 + RSN_SELECTOR_LEN +
  ------------------
  |  |   51|    216|#define RSN_SELECTOR_LEN 4
  ------------------
              		2 + RSN_SELECTOR_LEN + 2 + RSN_SELECTOR_LEN +
  ------------------
  |  |   51|    216|#define RSN_SELECTOR_LEN 4
  ------------------
 3686|    216|		2 + RSN_SELECTOR_LEN + 2 + (pmkid ? PMKID_LEN : 0);
  ------------------
  |  |   51|    216|#define RSN_SELECTOR_LEN 4
  ------------------
              		2 + RSN_SELECTOR_LEN + 2 + (pmkid ? PMKID_LEN : 0);
  ------------------
  |  |   13|      0|#define PMKID_LEN 16
  ------------------
  |  Branch (3686:31): [True: 0, False: 216]
  ------------------
 3687|       |
 3688|    216|	if (wpabuf_tailroom(buf) < rsne_len)
  ------------------
  |  Branch (3688:6): [True: 0, False: 216]
  ------------------
 3689|      0|		return -1;
 3690|    216|	hdr = wpabuf_put(buf, rsne_len);
 3691|    216|	hdr->elem_id = WLAN_EID_RSN;
  ------------------
  |  |  310|    216|#define WLAN_EID_RSN 48
  ------------------
 3692|    216|	hdr->len = rsne_len - 2;
 3693|    216|	WPA_PUT_LE16(hdr->version, RSN_VERSION);
  ------------------
  |  |   52|    216|#define RSN_VERSION 1
  ------------------
 3694|    216|	pos = (u8 *) (hdr + 1);
 3695|       |
 3696|       |	/* Group addressed data is not allowed */
 3697|    216|	RSN_SELECTOR_PUT(pos, RSN_CIPHER_SUITE_NO_GROUP_ADDRESSED);
  ------------------
  |  |  147|    216|#define RSN_SELECTOR_PUT(a, val) WPA_PUT_BE32((u8 *) (a), (val))
  ------------------
 3698|    216|	pos += RSN_SELECTOR_LEN;
  ------------------
  |  |   51|    216|#define RSN_SELECTOR_LEN 4
  ------------------
 3699|       |
 3700|       |	/* Add the pairwise cipher */
 3701|    216|	WPA_PUT_LE16(pos, 1);
 3702|    216|	pos += 2;
 3703|    216|	suite = wpa_cipher_to_suite(WPA_PROTO_RSN, cipher);
  ------------------
  |  |  194|    216|#define WPA_PROTO_RSN BIT(1)
  |  |  ------------------
  |  |  |  |  429|    216|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 3704|    216|	RSN_SELECTOR_PUT(pos, suite);
  ------------------
  |  |  147|    216|#define RSN_SELECTOR_PUT(a, val) WPA_PUT_BE32((u8 *) (a), (val))
  ------------------
 3705|    216|	pos += RSN_SELECTOR_LEN;
  ------------------
  |  |   51|    216|#define RSN_SELECTOR_LEN 4
  ------------------
 3706|       |
 3707|       |	/* Add the AKM suite */
 3708|    216|	WPA_PUT_LE16(pos, 1);
 3709|    216|	pos += 2;
 3710|       |
 3711|    216|	switch (akmp) {
 3712|    216|	case WPA_KEY_MGMT_PASN:
  ------------------
  |  |   52|    216|#define WPA_KEY_MGMT_PASN BIT(25)
  |  |  ------------------
  |  |  |  |  429|    216|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (3712:2): [True: 216, False: 0]
  ------------------
 3713|    216|		RSN_SELECTOR_PUT(pos, RSN_AUTH_KEY_MGMT_PASN);
  ------------------
  |  |  147|    216|#define RSN_SELECTOR_PUT(a, val) WPA_PUT_BE32((u8 *) (a), (val))
  ------------------
 3714|    216|		break;
 3715|      0|#ifdef CONFIG_SAE
 3716|      0|	case WPA_KEY_MGMT_SAE:
  ------------------
  |  |   37|      0|#define WPA_KEY_MGMT_SAE BIT(10)
  |  |  ------------------
  |  |  |  |  429|      0|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (3716:2): [True: 0, False: 216]
  ------------------
 3717|      0|		RSN_SELECTOR_PUT(pos, RSN_AUTH_KEY_MGMT_SAE);
  ------------------
  |  |  147|      0|#define RSN_SELECTOR_PUT(a, val) WPA_PUT_BE32((u8 *) (a), (val))
  ------------------
 3718|      0|		break;
 3719|      0|	case WPA_KEY_MGMT_SAE_EXT_KEY:
  ------------------
  |  |   53|      0|#define WPA_KEY_MGMT_SAE_EXT_KEY BIT(26)
  |  |  ------------------
  |  |  |  |  429|      0|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (3719:2): [True: 0, False: 216]
  ------------------
 3720|      0|		RSN_SELECTOR_PUT(pos, RSN_AUTH_KEY_MGMT_SAE_EXT_KEY);
  ------------------
  |  |  147|      0|#define RSN_SELECTOR_PUT(a, val) WPA_PUT_BE32((u8 *) (a), (val))
  ------------------
 3721|      0|		break;
 3722|      0|#endif /* CONFIG_SAE */
 3723|      0|#ifdef CONFIG_FILS
 3724|      0|	case WPA_KEY_MGMT_FILS_SHA256:
  ------------------
  |  |   45|      0|#define WPA_KEY_MGMT_FILS_SHA256 BIT(18)
  |  |  ------------------
  |  |  |  |  429|      0|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (3724:2): [True: 0, False: 216]
  ------------------
 3725|      0|		RSN_SELECTOR_PUT(pos, RSN_AUTH_KEY_MGMT_FILS_SHA256);
  ------------------
  |  |  147|      0|#define RSN_SELECTOR_PUT(a, val) WPA_PUT_BE32((u8 *) (a), (val))
  ------------------
 3726|      0|		break;
 3727|      0|	case WPA_KEY_MGMT_FILS_SHA384:
  ------------------
  |  |   46|      0|#define WPA_KEY_MGMT_FILS_SHA384 BIT(19)
  |  |  ------------------
  |  |  |  |  429|      0|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (3727:2): [True: 0, False: 216]
  ------------------
 3728|      0|		RSN_SELECTOR_PUT(pos, RSN_AUTH_KEY_MGMT_FILS_SHA384);
  ------------------
  |  |  147|      0|#define RSN_SELECTOR_PUT(a, val) WPA_PUT_BE32((u8 *) (a), (val))
  ------------------
 3729|      0|		break;
 3730|      0|#endif /* CONFIG_FILS */
 3731|      0|#ifdef CONFIG_IEEE80211R
 3732|      0|	case WPA_KEY_MGMT_FT_PSK:
  ------------------
  |  |   33|      0|#define WPA_KEY_MGMT_FT_PSK BIT(6)
  |  |  ------------------
  |  |  |  |  429|      0|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (3732:2): [True: 0, False: 216]
  ------------------
 3733|      0|		RSN_SELECTOR_PUT(pos, RSN_AUTH_KEY_MGMT_FT_PSK);
  ------------------
  |  |  147|      0|#define RSN_SELECTOR_PUT(a, val) WPA_PUT_BE32((u8 *) (a), (val))
  ------------------
 3734|      0|		break;
 3735|      0|	case WPA_KEY_MGMT_FT_IEEE8021X:
  ------------------
  |  |   32|      0|#define WPA_KEY_MGMT_FT_IEEE8021X BIT(5)
  |  |  ------------------
  |  |  |  |  429|      0|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (3735:2): [True: 0, False: 216]
  ------------------
 3736|      0|		RSN_SELECTOR_PUT(pos, RSN_AUTH_KEY_MGMT_FT_802_1X);
  ------------------
  |  |  147|      0|#define RSN_SELECTOR_PUT(a, val) WPA_PUT_BE32((u8 *) (a), (val))
  ------------------
 3737|      0|		break;
 3738|      0|	case WPA_KEY_MGMT_FT_IEEE8021X_SHA384:
  ------------------
  |  |   51|      0|#define WPA_KEY_MGMT_FT_IEEE8021X_SHA384 BIT(24)
  |  |  ------------------
  |  |  |  |  429|      0|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (3738:2): [True: 0, False: 216]
  ------------------
 3739|      0|		RSN_SELECTOR_PUT(pos, RSN_AUTH_KEY_MGMT_FT_802_1X_SHA384);
  ------------------
  |  |  147|      0|#define RSN_SELECTOR_PUT(a, val) WPA_PUT_BE32((u8 *) (a), (val))
  ------------------
 3740|      0|		break;
 3741|      0|#endif /* CONFIG_IEEE80211R */
 3742|      0|	default:
  ------------------
  |  Branch (3742:2): [True: 0, False: 216]
  ------------------
 3743|      0|		wpa_printf(MSG_ERROR, "PASN: Invalid AKMP=0x%x", akmp);
 3744|      0|		return -1;
 3745|    216|	}
 3746|    216|	pos += RSN_SELECTOR_LEN;
  ------------------
  |  |   51|    216|#define RSN_SELECTOR_LEN 4
  ------------------
 3747|       |
 3748|       |	/* RSN Capabilities: PASN mandates both MFP capable and required */
 3749|    216|	capab = WPA_CAPABILITY_MFPC | WPA_CAPABILITY_MFPR;
  ------------------
  |  |  172|    216|#define WPA_CAPABILITY_MFPC BIT(7)
  |  |  ------------------
  |  |  |  |  429|    216|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
              	capab = WPA_CAPABILITY_MFPC | WPA_CAPABILITY_MFPR;
  ------------------
  |  |  171|    216|#define WPA_CAPABILITY_MFPR BIT(6)
  |  |  ------------------
  |  |  |  |  429|    216|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 3750|    216|	WPA_PUT_LE16(pos, capab);
 3751|    216|	pos += 2;
 3752|       |
 3753|    216|	if (pmkid) {
  ------------------
  |  Branch (3753:6): [True: 0, False: 216]
  ------------------
 3754|      0|		wpa_printf(MSG_DEBUG, "PASN: Adding PMKID");
 3755|       |
 3756|      0|		WPA_PUT_LE16(pos, 1);
 3757|      0|		pos += 2;
 3758|      0|		os_memcpy(pos, pmkid, PMKID_LEN);
  ------------------
  |  |  503|      0|#define os_memcpy(d, s, n) memcpy((d), (s), (n))
  ------------------
 3759|      0|		pos += PMKID_LEN;
  ------------------
  |  |   13|      0|#define PMKID_LEN 16
  ------------------
 3760|    216|	} else {
 3761|    216|		WPA_PUT_LE16(pos, 0);
 3762|    216|		pos += 2;
 3763|    216|	}
 3764|       |
 3765|       |	/* Group addressed management is not allowed */
 3766|    216|	RSN_SELECTOR_PUT(pos, RSN_CIPHER_SUITE_NO_GROUP_ADDRESSED);
  ------------------
  |  |  147|    216|#define RSN_SELECTOR_PUT(a, val) WPA_PUT_BE32((u8 *) (a), (val))
  ------------------
 3767|       |
 3768|    216|	return 0;
 3769|    216|}
wpa_pasn_add_parameter_ie:
 3789|    108|{
 3790|    108|	struct pasn_parameter_ie *params;
 3791|       |
 3792|    108|	wpa_printf(MSG_DEBUG, "PASN: Add PASN Parameters element");
 3793|       |
 3794|    108|	params = wpabuf_put(buf, sizeof(*params));
 3795|       |
 3796|    108|	params->id = WLAN_EID_EXTENSION;
  ------------------
  |  |  462|    108|#define WLAN_EID_EXTENSION 255
  ------------------
 3797|    108|	params->len = sizeof(*params) - 2;
 3798|    108|	params->id_ext = WLAN_EID_EXT_PASN_PARAMS;
  ------------------
  |  |  498|    108|#define WLAN_EID_EXT_PASN_PARAMS 100
  ------------------
 3799|    108|	params->control = 0;
 3800|    108|	params->wrapped_data_format = wrapped_data_format;
 3801|       |
 3802|    108|	if (comeback) {
  ------------------
  |  Branch (3802:6): [True: 0, False: 108]
  ------------------
 3803|      0|		wpa_printf(MSG_DEBUG, "PASN: Adding comeback data");
 3804|       |
 3805|       |		/*
 3806|       |		 * 2 octets for the 'after' field + 1 octet for the length +
 3807|       |		 * actual cookie data
 3808|       |		 */
 3809|      0|		if (after >= 0)
  ------------------
  |  Branch (3809:7): [True: 0, False: 0]
  ------------------
 3810|      0|			params->len += 2;
 3811|      0|		params->len += 1 + wpabuf_len(comeback);
 3812|      0|		params->control |= WPA_PASN_CTRL_COMEBACK_INFO_PRESENT;
  ------------------
  |  |  595|      0|#define WPA_PASN_CTRL_COMEBACK_INFO_PRESENT BIT(0)
  |  |  ------------------
  |  |  |  |  429|      0|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 3813|       |
 3814|      0|		if (after >= 0)
  ------------------
  |  Branch (3814:7): [True: 0, False: 0]
  ------------------
 3815|      0|			wpabuf_put_le16(buf, after);
 3816|      0|		wpabuf_put_u8(buf, wpabuf_len(comeback));
 3817|      0|		wpabuf_put_buf(buf, comeback);
 3818|      0|	}
 3819|       |
 3820|    108|	if (pubkey) {
  ------------------
  |  Branch (3820:6): [True: 108, False: 0]
  ------------------
 3821|    108|		wpa_printf(MSG_DEBUG,
 3822|    108|			   "PASN: Adding public key and group ID %u",
 3823|    108|			   pasn_group);
 3824|       |
 3825|       |		/*
 3826|       |		 * 2 octets for the finite cyclic group + 2 octets public key
 3827|       |		 * length + 1 octet for the compressed/uncompressed indication +
 3828|       |		 * the actual key.
 3829|       |		 */
 3830|    108|		params->len += 2 + 1 + 1 + wpabuf_len(pubkey);
 3831|    108|		params->control |= WPA_PASN_CTRL_GROUP_AND_KEY_PRESENT;
  ------------------
  |  |  596|    108|#define WPA_PASN_CTRL_GROUP_AND_KEY_PRESENT BIT(1)
  |  |  ------------------
  |  |  |  |  429|    108|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 3832|       |
 3833|    108|		wpabuf_put_le16(buf, pasn_group);
 3834|       |
 3835|       |		/*
 3836|       |		 * The first octet indicates whether the public key is
 3837|       |		 * compressed, as defined in RFC 5480 section 2.2.
 3838|       |		 */
 3839|    108|		wpabuf_put_u8(buf, wpabuf_len(pubkey) + 1);
 3840|    108|		wpabuf_put_u8(buf, compressed ? WPA_PASN_PUBKEY_COMPRESSED_0 :
  ------------------
  |  |  622|    108|#define WPA_PASN_PUBKEY_COMPRESSED_0 0x02
  ------------------
  |  Branch (3840:22): [True: 108, False: 0]
  ------------------
 3841|    108|			      WPA_PASN_PUBKEY_UNCOMPRESSED);
  ------------------
  |  |  624|    108|#define WPA_PASN_PUBKEY_UNCOMPRESSED 0x04
  ------------------
 3842|       |
 3843|    108|		wpabuf_put_buf(buf, pubkey);
 3844|    108|	}
 3845|    108|}
wpa_pasn_add_wrapped_data:
 3856|    108|{
 3857|    108|	const u8 *data;
 3858|    108|	size_t data_len;
 3859|    108|	u8 len;
 3860|       |
 3861|    108|	if (!wrapped_data_buf)
  ------------------
  |  Branch (3861:6): [True: 108, False: 0]
  ------------------
 3862|    108|		return 0;
 3863|       |
 3864|      0|	wpa_printf(MSG_DEBUG, "PASN: Add wrapped data");
 3865|       |
 3866|      0|	data = wpabuf_head_u8(wrapped_data_buf);
 3867|      0|	data_len = wpabuf_len(wrapped_data_buf);
 3868|       |
 3869|       |	/* nothing to add */
 3870|      0|	if (!data_len)
  ------------------
  |  Branch (3870:6): [True: 0, False: 0]
  ------------------
 3871|      0|		return 0;
 3872|       |
 3873|      0|	if (data_len <= 254)
  ------------------
  |  Branch (3873:6): [True: 0, False: 0]
  ------------------
 3874|      0|		len = 1 + data_len;
 3875|      0|	else
 3876|      0|		len = 255;
 3877|       |
 3878|      0|	if (wpabuf_tailroom(buf) < 3 + data_len)
  ------------------
  |  Branch (3878:6): [True: 0, False: 0]
  ------------------
 3879|      0|		return -1;
 3880|       |
 3881|      0|	wpabuf_put_u8(buf, WLAN_EID_EXTENSION);
  ------------------
  |  |  462|      0|#define WLAN_EID_EXTENSION 255
  ------------------
 3882|      0|	wpabuf_put_u8(buf, len);
 3883|      0|	wpabuf_put_u8(buf, WLAN_EID_EXT_WRAPPED_DATA);
  ------------------
  |  |  472|      0|#define WLAN_EID_EXT_WRAPPED_DATA 8
  ------------------
 3884|      0|	wpabuf_put_data(buf, data, len - 1);
 3885|       |
 3886|      0|	data += len - 1;
 3887|      0|	data_len -= len - 1;
 3888|       |
 3889|      0|	while (data_len) {
  ------------------
  |  Branch (3889:9): [True: 0, False: 0]
  ------------------
 3890|      0|		if (wpabuf_tailroom(buf) < 1 + data_len)
  ------------------
  |  Branch (3890:7): [True: 0, False: 0]
  ------------------
 3891|      0|			return -1;
 3892|      0|		wpabuf_put_u8(buf, WLAN_EID_FRAGMENT);
  ------------------
  |  |  460|      0|#define WLAN_EID_FRAGMENT 242
  ------------------
 3893|      0|		len = data_len > 255 ? 255 : data_len;
  ------------------
  |  Branch (3893:9): [True: 0, False: 0]
  ------------------
 3894|      0|		wpabuf_put_u8(buf, len);
 3895|      0|		wpabuf_put_data(buf, data, len);
 3896|      0|		data += len;
 3897|      0|		data_len -= len;
 3898|      0|	}
 3899|       |
 3900|      0|	return 0;
 3901|      0|}
wpa_pasn_validate_rsne:
 3910|    799|{
 3911|    799|	u16 capab = WPA_CAPABILITY_MFPC | WPA_CAPABILITY_MFPR;
  ------------------
  |  |  172|    799|#define WPA_CAPABILITY_MFPC BIT(7)
  |  |  ------------------
  |  |  |  |  429|    799|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
              	u16 capab = WPA_CAPABILITY_MFPC | WPA_CAPABILITY_MFPR;
  ------------------
  |  |  171|    799|#define WPA_CAPABILITY_MFPR BIT(6)
  |  |  ------------------
  |  |  |  |  429|    799|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 3912|       |
 3913|    799|	if (data->proto != WPA_PROTO_RSN)
  ------------------
  |  |  194|    799|#define WPA_PROTO_RSN BIT(1)
  |  |  ------------------
  |  |  |  |  429|    799|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (3913:6): [True: 1, False: 798]
  ------------------
 3914|      1|		return -1;
 3915|       |
 3916|    798|	if ((data->capabilities & capab) != capab) {
  ------------------
  |  Branch (3916:6): [True: 409, False: 389]
  ------------------
 3917|    409|		wpa_printf(MSG_DEBUG, "PASN: Invalid RSNE capabilities");
 3918|    409|		return -1;
 3919|    409|	}
 3920|       |
 3921|    389|	if (!data->has_group || data->group_cipher != WPA_CIPHER_GTK_NOT_USED) {
  ------------------
  |  |   25|    389|#define WPA_CIPHER_GTK_NOT_USED BIT(14)
  |  |  ------------------
  |  |  |  |  429|    389|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (3921:6): [True: 0, False: 389]
  |  Branch (3921:26): [True: 5, False: 384]
  ------------------
 3922|      5|		wpa_printf(MSG_DEBUG, "PASN: Invalid group data cipher");
 3923|      5|		return -1;
 3924|      5|	}
 3925|       |
 3926|    384|	if (!data->has_pairwise || !data->pairwise_cipher ||
  ------------------
  |  Branch (3926:6): [True: 0, False: 384]
  |  Branch (3926:29): [True: 6, False: 378]
  ------------------
 3927|    384|	    (data->pairwise_cipher & (data->pairwise_cipher - 1))) {
  ------------------
  |  Branch (3927:6): [True: 9, False: 369]
  ------------------
 3928|     15|		wpa_printf(MSG_DEBUG, "PASN: No valid pairwise suite");
 3929|     15|		return -1;
 3930|     15|	}
 3931|       |
 3932|    369|	switch (data->key_mgmt) {
 3933|      0|#ifdef CONFIG_SAE
 3934|      1|	case WPA_KEY_MGMT_SAE:
  ------------------
  |  |   37|      1|#define WPA_KEY_MGMT_SAE BIT(10)
  |  |  ------------------
  |  |  |  |  429|      1|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (3934:2): [True: 1, False: 368]
  ------------------
 3935|      2|	case WPA_KEY_MGMT_SAE_EXT_KEY:
  ------------------
  |  |   53|      2|#define WPA_KEY_MGMT_SAE_EXT_KEY BIT(26)
  |  |  ------------------
  |  |  |  |  429|      2|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (3935:2): [True: 1, False: 368]
  ------------------
 3936|       |	/* fall through */
 3937|      2|#endif /* CONFIG_SAE */
 3938|      2|#ifdef CONFIG_FILS
 3939|      3|	case WPA_KEY_MGMT_FILS_SHA256:
  ------------------
  |  |   45|      3|#define WPA_KEY_MGMT_FILS_SHA256 BIT(18)
  |  |  ------------------
  |  |  |  |  429|      3|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (3939:2): [True: 1, False: 368]
  ------------------
 3940|      4|	case WPA_KEY_MGMT_FILS_SHA384:
  ------------------
  |  |   46|      4|#define WPA_KEY_MGMT_FILS_SHA384 BIT(19)
  |  |  ------------------
  |  |  |  |  429|      4|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (3940:2): [True: 1, False: 368]
  ------------------
 3941|       |	/* fall through */
 3942|      4|#endif /* CONFIG_FILS */
 3943|      4|#ifdef CONFIG_IEEE80211R
 3944|      6|	case WPA_KEY_MGMT_FT_PSK:
  ------------------
  |  |   33|      6|#define WPA_KEY_MGMT_FT_PSK BIT(6)
  |  |  ------------------
  |  |  |  |  429|      6|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (3944:2): [True: 2, False: 367]
  ------------------
 3945|      9|	case WPA_KEY_MGMT_FT_IEEE8021X:
  ------------------
  |  |   32|      9|#define WPA_KEY_MGMT_FT_IEEE8021X BIT(5)
  |  |  ------------------
  |  |  |  |  429|      9|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (3945:2): [True: 3, False: 366]
  ------------------
 3946|     10|	case WPA_KEY_MGMT_FT_IEEE8021X_SHA384:
  ------------------
  |  |   51|     10|#define WPA_KEY_MGMT_FT_IEEE8021X_SHA384 BIT(24)
  |  |  ------------------
  |  |  |  |  429|     10|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (3946:2): [True: 1, False: 368]
  ------------------
 3947|       |	/* fall through */
 3948|     10|#endif /* CONFIG_IEEE80211R */
 3949|    197|	case WPA_KEY_MGMT_PASN:
  ------------------
  |  |   52|    197|#define WPA_KEY_MGMT_PASN BIT(25)
  |  |  ------------------
  |  |  |  |  429|    197|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (3949:2): [True: 187, False: 182]
  ------------------
 3950|    197|		break;
 3951|    172|	default:
  ------------------
  |  Branch (3951:2): [True: 172, False: 197]
  ------------------
 3952|    172|		wpa_printf(MSG_ERROR, "PASN: invalid key_mgmt: 0x%0x",
 3953|    172|			   data->key_mgmt);
 3954|    172|		return -1;
 3955|    369|	}
 3956|       |
 3957|    197|	if (data->mgmt_group_cipher != WPA_CIPHER_GTK_NOT_USED) {
  ------------------
  |  |   25|    197|#define WPA_CIPHER_GTK_NOT_USED BIT(14)
  |  |  ------------------
  |  |  |  |  429|    197|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (3957:6): [True: 10, False: 187]
  ------------------
 3958|     10|		wpa_printf(MSG_DEBUG, "PASN: Invalid group mgmt cipher");
 3959|     10|		return -1;
 3960|     10|	}
 3961|       |
 3962|    187|	if (data->num_pmkid > 1) {
  ------------------
  |  Branch (3962:6): [True: 2, False: 185]
  ------------------
 3963|      2|		wpa_printf(MSG_DEBUG, "PASN: Invalid number of PMKIDs");
 3964|      2|		return -1;
 3965|      2|	}
 3966|       |
 3967|    185|	return 0;
 3968|    187|}
wpa_pasn_parse_parameter_ie:
 3984|    394|{
 3985|    394|	struct pasn_parameter_ie *params = (struct pasn_parameter_ie *) data;
 3986|    394|	const u8 *pos = (const u8 *) (params + 1);
 3987|       |
 3988|    394|	if (!pasn_params) {
  ------------------
  |  Branch (3988:6): [True: 0, False: 394]
  ------------------
 3989|      0|		wpa_printf(MSG_DEBUG, "PASN: Invalid params");
 3990|      0|		return -1;
 3991|      0|	}
 3992|       |
 3993|    394|	if (!params || ((size_t) (params->len + 2) < sizeof(*params)) ||
  ------------------
  |  Branch (3993:6): [True: 0, False: 394]
  |  Branch (3993:17): [True: 4, False: 390]
  ------------------
 3994|    394|	    len < sizeof(*params) || params->len + 2 != len) {
  ------------------
  |  Branch (3994:6): [True: 3, False: 387]
  |  Branch (3994:31): [True: 0, False: 387]
  ------------------
 3995|      7|		wpa_printf(MSG_DEBUG,
 3996|      7|			   "PASN: Invalid parameters IE. len=(%u, %u)",
 3997|      7|			   params ? params->len : 0, len);
  ------------------
  |  Branch (3997:7): [True: 7, False: 0]
  ------------------
 3998|      7|		return -1;
 3999|      7|	}
 4000|       |
 4001|    387|	os_memset(pasn_params, 0, sizeof(*pasn_params));
  ------------------
  |  |  509|    387|#define os_memset(s, c, n) memset(s, c, n)
  ------------------
 4002|       |
 4003|    387|	switch (params->wrapped_data_format) {
 4004|     90|	case WPA_PASN_WRAPPED_DATA_NO:
  ------------------
  |  |  598|     90|#define WPA_PASN_WRAPPED_DATA_NO      0
  ------------------
  |  Branch (4004:2): [True: 90, False: 297]
  ------------------
 4005|     99|	case WPA_PASN_WRAPPED_DATA_SAE:
  ------------------
  |  |  601|     99|#define WPA_PASN_WRAPPED_DATA_SAE     3
  ------------------
  |  Branch (4005:2): [True: 9, False: 378]
  ------------------
 4006|    115|	case WPA_PASN_WRAPPED_DATA_FILS_SK:
  ------------------
  |  |  600|    115|#define WPA_PASN_WRAPPED_DATA_FILS_SK 2
  ------------------
  |  Branch (4006:2): [True: 16, False: 371]
  ------------------
 4007|    382|	case WPA_PASN_WRAPPED_DATA_FT:
  ------------------
  |  |  599|    382|#define WPA_PASN_WRAPPED_DATA_FT      1
  ------------------
  |  Branch (4007:2): [True: 267, False: 120]
  ------------------
 4008|    382|		break;
 4009|      5|	default:
  ------------------
  |  Branch (4009:2): [True: 5, False: 382]
  ------------------
 4010|      5|		wpa_printf(MSG_DEBUG, "PASN: Invalid wrapped data format");
 4011|      5|		return -1;
 4012|    387|	}
 4013|       |
 4014|    382|	pasn_params->wrapped_data_format = params->wrapped_data_format;
 4015|       |
 4016|    382|	len -= sizeof(*params);
 4017|       |
 4018|    382|	if (params->control & WPA_PASN_CTRL_COMEBACK_INFO_PRESENT) {
  ------------------
  |  |  595|    382|#define WPA_PASN_CTRL_COMEBACK_INFO_PRESENT BIT(0)
  |  |  ------------------
  |  |  |  |  429|    382|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (4018:6): [True: 42, False: 340]
  ------------------
 4019|     42|		if (from_ap) {
  ------------------
  |  Branch (4019:7): [True: 0, False: 42]
  ------------------
 4020|      0|			if (len < 2) {
  ------------------
  |  Branch (4020:8): [True: 0, False: 0]
  ------------------
 4021|      0|				wpa_printf(MSG_DEBUG,
 4022|      0|					   "PASN: Invalid Parameters IE: Truncated Comeback After");
 4023|      0|				return -1;
 4024|      0|			}
 4025|      0|			pasn_params->after = WPA_GET_LE16(pos);
 4026|      0|			pos += 2;
 4027|      0|			len -= 2;
 4028|      0|		}
 4029|       |
 4030|     42|		if (len < 1 || len < 1 + *pos) {
  ------------------
  |  Branch (4030:7): [True: 3, False: 39]
  |  Branch (4030:18): [True: 17, False: 22]
  ------------------
 4031|     20|			wpa_printf(MSG_DEBUG,
 4032|     20|				   "PASN: Invalid Parameters IE: comeback len");
 4033|     20|			return -1;
 4034|     20|		}
 4035|       |
 4036|     22|		pasn_params->comeback_len = *pos++;
 4037|     22|		len--;
 4038|     22|		pasn_params->comeback = pos;
 4039|     22|		len -=  pasn_params->comeback_len;
 4040|     22|		pos += pasn_params->comeback_len;
 4041|     22|	}
 4042|       |
 4043|    362|	if (params->control & WPA_PASN_CTRL_GROUP_AND_KEY_PRESENT) {
  ------------------
  |  |  596|    362|#define WPA_PASN_CTRL_GROUP_AND_KEY_PRESENT BIT(1)
  |  |  ------------------
  |  |  |  |  429|    362|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (4043:6): [True: 194, False: 168]
  ------------------
 4044|    194|		if (len < 3 || len < 3 + pos[2]) {
  ------------------
  |  Branch (4044:7): [True: 6, False: 188]
  |  Branch (4044:18): [True: 18, False: 170]
  ------------------
 4045|     24|			wpa_printf(MSG_DEBUG,
 4046|     24|				   "PASN: Invalid Parameters IE: group and key");
 4047|     24|			return -1;
 4048|     24|		}
 4049|       |
 4050|    170|		pasn_params->group = WPA_GET_LE16(pos);
 4051|    170|		pos += 2;
 4052|    170|		len -= 2;
 4053|    170|		pasn_params->pubkey_len = *pos++;
 4054|    170|		len--;
 4055|    170|		pasn_params->pubkey = pos;
 4056|    170|		len -= pasn_params->pubkey_len;
 4057|    170|		pos += pasn_params->pubkey_len;
 4058|    170|	}
 4059|       |
 4060|    338|	if (len) {
  ------------------
  |  Branch (4060:6): [True: 10, False: 328]
  ------------------
 4061|     10|		wpa_printf(MSG_DEBUG,
 4062|     10|			   "PASN: Invalid Parameters IE. Bytes left=%u", len);
 4063|     10|		return -1;
 4064|     10|	}
 4065|       |
 4066|    328|	return 0;
 4067|    338|}
wpa_pasn_add_extra_ies:
 4101|    108|{
 4102|    108|	if (!len || !extra_ies || !buf)
  ------------------
  |  Branch (4102:6): [True: 108, False: 0]
  |  Branch (4102:14): [True: 0, False: 0]
  |  Branch (4102:28): [True: 0, False: 0]
  ------------------
 4103|    108|		return 0;
 4104|       |
 4105|      0|	if (wpabuf_tailroom(buf) < sizeof(len))
  ------------------
  |  Branch (4105:6): [True: 0, False: 0]
  ------------------
 4106|      0|		return -1;
 4107|       |
 4108|      0|	wpabuf_put_data(buf, extra_ies, len);
 4109|      0|	return 0;
 4110|      0|}
wpa_common.c:rsn_selector_to_bitfield:
 1609|  3.25k|{
 1610|  3.25k|	if (RSN_SELECTOR_GET(s) == RSN_CIPHER_SUITE_NONE)
  ------------------
  |  |  148|  3.25k|#define RSN_SELECTOR_GET(a) WPA_GET_BE32((const u8 *) (a))
  ------------------
              	if (RSN_SELECTOR_GET(s) == RSN_CIPHER_SUITE_NONE)
  ------------------
  |  |   97|  3.25k|#define RSN_CIPHER_SUITE_NONE RSN_SELECTOR(0x00, 0x0f, 0xac, 0)
  |  |  ------------------
  |  |  |  |   55|  3.25k|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|  3.25k|	 (u32) (d))
  |  |  ------------------
  ------------------
  |  Branch (1610:6): [True: 51, False: 3.20k]
  ------------------
 1611|     51|		return WPA_CIPHER_NONE;
  ------------------
  |  |   12|     51|#define WPA_CIPHER_NONE BIT(0)
  |  |  ------------------
  |  |  |  |  429|     51|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 1612|  3.20k|	if (RSN_SELECTOR_GET(s) == RSN_CIPHER_SUITE_TKIP)
  ------------------
  |  |  148|  3.20k|#define RSN_SELECTOR_GET(a) WPA_GET_BE32((const u8 *) (a))
  ------------------
              	if (RSN_SELECTOR_GET(s) == RSN_CIPHER_SUITE_TKIP)
  ------------------
  |  |   99|  3.20k|#define RSN_CIPHER_SUITE_TKIP RSN_SELECTOR(0x00, 0x0f, 0xac, 2)
  |  |  ------------------
  |  |  |  |   55|  3.20k|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|  3.20k|	 (u32) (d))
  |  |  ------------------
  ------------------
  |  Branch (1612:6): [True: 115, False: 3.09k]
  ------------------
 1613|    115|		return WPA_CIPHER_TKIP;
  ------------------
  |  |   15|    115|#define WPA_CIPHER_TKIP BIT(3)
  |  |  ------------------
  |  |  |  |  429|    115|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 1614|  3.09k|	if (RSN_SELECTOR_GET(s) == RSN_CIPHER_SUITE_CCMP)
  ------------------
  |  |  148|  3.09k|#define RSN_SELECTOR_GET(a) WPA_GET_BE32((const u8 *) (a))
  ------------------
              	if (RSN_SELECTOR_GET(s) == RSN_CIPHER_SUITE_CCMP)
  ------------------
  |  |  103|  3.09k|#define RSN_CIPHER_SUITE_CCMP RSN_SELECTOR(0x00, 0x0f, 0xac, 4)
  |  |  ------------------
  |  |  |  |   55|  3.09k|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|  3.09k|	 (u32) (d))
  |  |  ------------------
  ------------------
  |  Branch (1614:6): [True: 421, False: 2.67k]
  ------------------
 1615|    421|		return WPA_CIPHER_CCMP;
  ------------------
  |  |   16|    421|#define WPA_CIPHER_CCMP BIT(4)
  |  |  ------------------
  |  |  |  |  429|    421|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 1616|  2.67k|	if (RSN_SELECTOR_GET(s) == RSN_CIPHER_SUITE_AES_128_CMAC)
  ------------------
  |  |  148|  2.67k|#define RSN_SELECTOR_GET(a) WPA_GET_BE32((const u8 *) (a))
  ------------------
              	if (RSN_SELECTOR_GET(s) == RSN_CIPHER_SUITE_AES_128_CMAC)
  ------------------
  |  |  105|  2.67k|#define RSN_CIPHER_SUITE_AES_128_CMAC RSN_SELECTOR(0x00, 0x0f, 0xac, 6)
  |  |  ------------------
  |  |  |  |   55|  2.67k|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|  2.67k|	 (u32) (d))
  |  |  ------------------
  ------------------
  |  Branch (1616:6): [True: 77, False: 2.59k]
  ------------------
 1617|     77|		return WPA_CIPHER_AES_128_CMAC;
  ------------------
  |  |   17|     77|#define WPA_CIPHER_AES_128_CMAC BIT(5)
  |  |  ------------------
  |  |  |  |  429|     77|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 1618|  2.59k|	if (RSN_SELECTOR_GET(s) == RSN_CIPHER_SUITE_GCMP)
  ------------------
  |  |  148|  2.59k|#define RSN_SELECTOR_GET(a) WPA_GET_BE32((const u8 *) (a))
  ------------------
              	if (RSN_SELECTOR_GET(s) == RSN_CIPHER_SUITE_GCMP)
  ------------------
  |  |  107|  2.59k|#define RSN_CIPHER_SUITE_GCMP RSN_SELECTOR(0x00, 0x0f, 0xac, 8)
  |  |  ------------------
  |  |  |  |   55|  2.59k|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|  2.59k|	 (u32) (d))
  |  |  ------------------
  ------------------
  |  Branch (1618:6): [True: 188, False: 2.40k]
  ------------------
 1619|    188|		return WPA_CIPHER_GCMP;
  ------------------
  |  |   18|    188|#define WPA_CIPHER_GCMP BIT(6)
  |  |  ------------------
  |  |  |  |  429|    188|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 1620|  2.40k|	if (RSN_SELECTOR_GET(s) == RSN_CIPHER_SUITE_CCMP_256)
  ------------------
  |  |  148|  2.40k|#define RSN_SELECTOR_GET(a) WPA_GET_BE32((const u8 *) (a))
  ------------------
              	if (RSN_SELECTOR_GET(s) == RSN_CIPHER_SUITE_CCMP_256)
  ------------------
  |  |  109|  2.40k|#define RSN_CIPHER_SUITE_CCMP_256 RSN_SELECTOR(0x00, 0x0f, 0xac, 10)
  |  |  ------------------
  |  |  |  |   55|  2.40k|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|  2.40k|	 (u32) (d))
  |  |  ------------------
  ------------------
  |  Branch (1620:6): [True: 156, False: 2.25k]
  ------------------
 1621|    156|		return WPA_CIPHER_CCMP_256;
  ------------------
  |  |   21|    156|#define WPA_CIPHER_CCMP_256 BIT(9)
  |  |  ------------------
  |  |  |  |  429|    156|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 1622|  2.25k|	if (RSN_SELECTOR_GET(s) == RSN_CIPHER_SUITE_GCMP_256)
  ------------------
  |  |  148|  2.25k|#define RSN_SELECTOR_GET(a) WPA_GET_BE32((const u8 *) (a))
  ------------------
              	if (RSN_SELECTOR_GET(s) == RSN_CIPHER_SUITE_GCMP_256)
  ------------------
  |  |  108|  2.25k|#define RSN_CIPHER_SUITE_GCMP_256 RSN_SELECTOR(0x00, 0x0f, 0xac, 9)
  |  |  ------------------
  |  |  |  |   55|  2.25k|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|  2.25k|	 (u32) (d))
  |  |  ------------------
  ------------------
  |  Branch (1622:6): [True: 131, False: 2.12k]
  ------------------
 1623|    131|		return WPA_CIPHER_GCMP_256;
  ------------------
  |  |   20|    131|#define WPA_CIPHER_GCMP_256 BIT(8)
  |  |  ------------------
  |  |  |  |  429|    131|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 1624|  2.12k|	if (RSN_SELECTOR_GET(s) == RSN_CIPHER_SUITE_BIP_GMAC_128)
  ------------------
  |  |  148|  2.12k|#define RSN_SELECTOR_GET(a) WPA_GET_BE32((const u8 *) (a))
  ------------------
              	if (RSN_SELECTOR_GET(s) == RSN_CIPHER_SUITE_BIP_GMAC_128)
  ------------------
  |  |  110|  2.12k|#define RSN_CIPHER_SUITE_BIP_GMAC_128 RSN_SELECTOR(0x00, 0x0f, 0xac, 11)
  |  |  ------------------
  |  |  |  |   55|  2.12k|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|  2.12k|	 (u32) (d))
  |  |  ------------------
  ------------------
  |  Branch (1624:6): [True: 118, False: 2.00k]
  ------------------
 1625|    118|		return WPA_CIPHER_BIP_GMAC_128;
  ------------------
  |  |   22|    118|#define WPA_CIPHER_BIP_GMAC_128 BIT(11)
  |  |  ------------------
  |  |  |  |  429|    118|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 1626|  2.00k|	if (RSN_SELECTOR_GET(s) == RSN_CIPHER_SUITE_BIP_GMAC_256)
  ------------------
  |  |  148|  2.00k|#define RSN_SELECTOR_GET(a) WPA_GET_BE32((const u8 *) (a))
  ------------------
              	if (RSN_SELECTOR_GET(s) == RSN_CIPHER_SUITE_BIP_GMAC_256)
  ------------------
  |  |  111|  2.00k|#define RSN_CIPHER_SUITE_BIP_GMAC_256 RSN_SELECTOR(0x00, 0x0f, 0xac, 12)
  |  |  ------------------
  |  |  |  |   55|  2.00k|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|  2.00k|	 (u32) (d))
  |  |  ------------------
  ------------------
  |  Branch (1626:6): [True: 107, False: 1.89k]
  ------------------
 1627|    107|		return WPA_CIPHER_BIP_GMAC_256;
  ------------------
  |  |   23|    107|#define WPA_CIPHER_BIP_GMAC_256 BIT(12)
  |  |  ------------------
  |  |  |  |  429|    107|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 1628|  1.89k|	if (RSN_SELECTOR_GET(s) == RSN_CIPHER_SUITE_BIP_CMAC_256)
  ------------------
  |  |  148|  1.89k|#define RSN_SELECTOR_GET(a) WPA_GET_BE32((const u8 *) (a))
  ------------------
              	if (RSN_SELECTOR_GET(s) == RSN_CIPHER_SUITE_BIP_CMAC_256)
  ------------------
  |  |  112|  1.89k|#define RSN_CIPHER_SUITE_BIP_CMAC_256 RSN_SELECTOR(0x00, 0x0f, 0xac, 13)
  |  |  ------------------
  |  |  |  |   55|  1.89k|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|  1.89k|	 (u32) (d))
  |  |  ------------------
  ------------------
  |  Branch (1628:6): [True: 90, False: 1.80k]
  ------------------
 1629|     90|		return WPA_CIPHER_BIP_CMAC_256;
  ------------------
  |  |   24|     90|#define WPA_CIPHER_BIP_CMAC_256 BIT(13)
  |  |  ------------------
  |  |  |  |  429|     90|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 1630|  1.80k|	if (RSN_SELECTOR_GET(s) == RSN_CIPHER_SUITE_NO_GROUP_ADDRESSED)
  ------------------
  |  |  148|  1.80k|#define RSN_SELECTOR_GET(a) WPA_GET_BE32((const u8 *) (a))
  ------------------
              	if (RSN_SELECTOR_GET(s) == RSN_CIPHER_SUITE_NO_GROUP_ADDRESSED)
  ------------------
  |  |  106|  1.80k|#define RSN_CIPHER_SUITE_NO_GROUP_ADDRESSED RSN_SELECTOR(0x00, 0x0f, 0xac, 7)
  |  |  ------------------
  |  |  |  |   55|  1.80k|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|  1.80k|	 (u32) (d))
  |  |  ------------------
  ------------------
  |  Branch (1630:6): [True: 1.02k, False: 783]
  ------------------
 1631|  1.02k|		return WPA_CIPHER_GTK_NOT_USED;
  ------------------
  |  |   25|  1.02k|#define WPA_CIPHER_GTK_NOT_USED BIT(14)
  |  |  ------------------
  |  |  |  |  429|  1.02k|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 1632|    783|	return 0;
 1633|  1.80k|}
wpa_common.c:rsn_key_mgmt_to_bitfield:
 1637|  2.97k|{
 1638|  2.97k|	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_UNSPEC_802_1X)
  ------------------
  |  |  148|  2.97k|#define RSN_SELECTOR_GET(a) WPA_GET_BE32((const u8 *) (a))
  ------------------
              	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_UNSPEC_802_1X)
  ------------------
  |  |   67|  2.97k|#define RSN_AUTH_KEY_MGMT_UNSPEC_802_1X RSN_SELECTOR(0x00, 0x0f, 0xac, 1)
  |  |  ------------------
  |  |  |  |   55|  2.97k|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|  2.97k|	 (u32) (d))
  |  |  ------------------
  ------------------
  |  Branch (1638:6): [True: 143, False: 2.82k]
  ------------------
 1639|    143|		return WPA_KEY_MGMT_IEEE8021X;
  ------------------
  |  |   27|    143|#define WPA_KEY_MGMT_IEEE8021X BIT(0)
  |  |  ------------------
  |  |  |  |  429|    143|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 1640|  2.82k|	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_PSK_OVER_802_1X)
  ------------------
  |  |  148|  2.82k|#define RSN_SELECTOR_GET(a) WPA_GET_BE32((const u8 *) (a))
  ------------------
              	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_PSK_OVER_802_1X)
  ------------------
  |  |   68|  2.82k|#define RSN_AUTH_KEY_MGMT_PSK_OVER_802_1X RSN_SELECTOR(0x00, 0x0f, 0xac, 2)
  |  |  ------------------
  |  |  |  |   55|  2.82k|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|  2.82k|	 (u32) (d))
  |  |  ------------------
  ------------------
  |  Branch (1640:6): [True: 141, False: 2.68k]
  ------------------
 1641|    141|		return WPA_KEY_MGMT_PSK;
  ------------------
  |  |   28|    141|#define WPA_KEY_MGMT_PSK BIT(1)
  |  |  ------------------
  |  |  |  |  429|    141|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 1642|  2.68k|#ifdef CONFIG_IEEE80211R
 1643|  2.68k|	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_FT_802_1X)
  ------------------
  |  |  148|  2.68k|#define RSN_SELECTOR_GET(a) WPA_GET_BE32((const u8 *) (a))
  ------------------
              	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_FT_802_1X)
  ------------------
  |  |   69|  2.68k|#define RSN_AUTH_KEY_MGMT_FT_802_1X RSN_SELECTOR(0x00, 0x0f, 0xac, 3)
  |  |  ------------------
  |  |  |  |   55|  2.68k|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|  2.68k|	 (u32) (d))
  |  |  ------------------
  ------------------
  |  Branch (1643:6): [True: 95, False: 2.59k]
  ------------------
 1644|     95|		return WPA_KEY_MGMT_FT_IEEE8021X;
  ------------------
  |  |   32|     95|#define WPA_KEY_MGMT_FT_IEEE8021X BIT(5)
  |  |  ------------------
  |  |  |  |  429|     95|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 1645|  2.59k|	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_FT_PSK)
  ------------------
  |  |  148|  2.59k|#define RSN_SELECTOR_GET(a) WPA_GET_BE32((const u8 *) (a))
  ------------------
              	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_FT_PSK)
  ------------------
  |  |   70|  2.59k|#define RSN_AUTH_KEY_MGMT_FT_PSK RSN_SELECTOR(0x00, 0x0f, 0xac, 4)
  |  |  ------------------
  |  |  |  |   55|  2.59k|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|  2.59k|	 (u32) (d))
  |  |  ------------------
  ------------------
  |  Branch (1645:6): [True: 138, False: 2.45k]
  ------------------
 1646|    138|		return WPA_KEY_MGMT_FT_PSK;
  ------------------
  |  |   33|    138|#define WPA_KEY_MGMT_FT_PSK BIT(6)
  |  |  ------------------
  |  |  |  |  429|    138|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 1647|  2.45k|#ifdef CONFIG_SHA384
 1648|  2.45k|	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_FT_802_1X_SHA384)
  ------------------
  |  |  148|  2.45k|#define RSN_SELECTOR_GET(a) WPA_GET_BE32((const u8 *) (a))
  ------------------
              	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_FT_802_1X_SHA384)
  ------------------
  |  |   78|  2.45k|#define RSN_AUTH_KEY_MGMT_FT_802_1X_SHA384 RSN_SELECTOR(0x00, 0x0f, 0xac, 13)
  |  |  ------------------
  |  |  |  |   55|  2.45k|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|  2.45k|	 (u32) (d))
  |  |  ------------------
  ------------------
  |  Branch (1648:6): [True: 110, False: 2.34k]
  ------------------
 1649|    110|		return WPA_KEY_MGMT_FT_IEEE8021X_SHA384;
  ------------------
  |  |   51|    110|#define WPA_KEY_MGMT_FT_IEEE8021X_SHA384 BIT(24)
  |  |  ------------------
  |  |  |  |  429|    110|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 1650|  2.34k|#endif /* CONFIG_SHA384 */
 1651|  2.34k|#endif /* CONFIG_IEEE80211R */
 1652|  2.34k|	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_802_1X_SHA256)
  ------------------
  |  |  148|  2.34k|#define RSN_SELECTOR_GET(a) WPA_GET_BE32((const u8 *) (a))
  ------------------
              	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_802_1X_SHA256)
  ------------------
  |  |   71|  2.34k|#define RSN_AUTH_KEY_MGMT_802_1X_SHA256 RSN_SELECTOR(0x00, 0x0f, 0xac, 5)
  |  |  ------------------
  |  |  |  |   55|  2.34k|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|  2.34k|	 (u32) (d))
  |  |  ------------------
  ------------------
  |  Branch (1652:6): [True: 119, False: 2.22k]
  ------------------
 1653|    119|		return WPA_KEY_MGMT_IEEE8021X_SHA256;
  ------------------
  |  |   34|    119|#define WPA_KEY_MGMT_IEEE8021X_SHA256 BIT(7)
  |  |  ------------------
  |  |  |  |  429|    119|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 1654|  2.22k|	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_PSK_SHA256)
  ------------------
  |  |  148|  2.22k|#define RSN_SELECTOR_GET(a) WPA_GET_BE32((const u8 *) (a))
  ------------------
              	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_PSK_SHA256)
  ------------------
  |  |   72|  2.22k|#define RSN_AUTH_KEY_MGMT_PSK_SHA256 RSN_SELECTOR(0x00, 0x0f, 0xac, 6)
  |  |  ------------------
  |  |  |  |   55|  2.22k|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|  2.22k|	 (u32) (d))
  |  |  ------------------
  ------------------
  |  Branch (1654:6): [True: 127, False: 2.09k]
  ------------------
 1655|    127|		return WPA_KEY_MGMT_PSK_SHA256;
  ------------------
  |  |   35|    127|#define WPA_KEY_MGMT_PSK_SHA256 BIT(8)
  |  |  ------------------
  |  |  |  |  429|    127|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 1656|  2.09k|#ifdef CONFIG_SAE
 1657|  2.09k|	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_SAE)
  ------------------
  |  |  148|  2.09k|#define RSN_SELECTOR_GET(a) WPA_GET_BE32((const u8 *) (a))
  ------------------
              	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_SAE)
  ------------------
  |  |   74|  2.09k|#define RSN_AUTH_KEY_MGMT_SAE RSN_SELECTOR(0x00, 0x0f, 0xac, 8)
  |  |  ------------------
  |  |  |  |   55|  2.09k|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|  2.09k|	 (u32) (d))
  |  |  ------------------
  ------------------
  |  Branch (1657:6): [True: 132, False: 1.96k]
  ------------------
 1658|    132|		return WPA_KEY_MGMT_SAE;
  ------------------
  |  |   37|    132|#define WPA_KEY_MGMT_SAE BIT(10)
  |  |  ------------------
  |  |  |  |  429|    132|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 1659|  1.96k|	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_SAE_EXT_KEY)
  ------------------
  |  |  148|  1.96k|#define RSN_SELECTOR_GET(a) WPA_GET_BE32((const u8 *) (a))
  ------------------
              	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_SAE_EXT_KEY)
  ------------------
  |  |   90|  1.96k|#define RSN_AUTH_KEY_MGMT_SAE_EXT_KEY RSN_SELECTOR(0x00, 0x0f, 0xac, 24)
  |  |  ------------------
  |  |  |  |   55|  1.96k|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|  1.96k|	 (u32) (d))
  |  |  ------------------
  ------------------
  |  Branch (1659:6): [True: 89, False: 1.87k]
  ------------------
 1660|     89|		return WPA_KEY_MGMT_SAE_EXT_KEY;
  ------------------
  |  |   53|     89|#define WPA_KEY_MGMT_SAE_EXT_KEY BIT(26)
  |  |  ------------------
  |  |  |  |  429|     89|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 1661|  1.87k|	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_FT_SAE)
  ------------------
  |  |  148|  1.87k|#define RSN_SELECTOR_GET(a) WPA_GET_BE32((const u8 *) (a))
  ------------------
              	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_FT_SAE)
  ------------------
  |  |   75|  1.87k|#define RSN_AUTH_KEY_MGMT_FT_SAE RSN_SELECTOR(0x00, 0x0f, 0xac, 9)
  |  |  ------------------
  |  |  |  |   55|  1.87k|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|  1.87k|	 (u32) (d))
  |  |  ------------------
  ------------------
  |  Branch (1661:6): [True: 137, False: 1.73k]
  ------------------
 1662|    137|		return WPA_KEY_MGMT_FT_SAE;
  ------------------
  |  |   38|    137|#define WPA_KEY_MGMT_FT_SAE BIT(11)
  |  |  ------------------
  |  |  |  |  429|    137|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 1663|  1.73k|	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_FT_SAE_EXT_KEY)
  ------------------
  |  |  148|  1.73k|#define RSN_SELECTOR_GET(a) WPA_GET_BE32((const u8 *) (a))
  ------------------
              	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_FT_SAE_EXT_KEY)
  ------------------
  |  |   91|  1.73k|#define RSN_AUTH_KEY_MGMT_FT_SAE_EXT_KEY RSN_SELECTOR(0x00, 0x0f, 0xac, 25)
  |  |  ------------------
  |  |  |  |   55|  1.73k|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|  1.73k|	 (u32) (d))
  |  |  ------------------
  ------------------
  |  Branch (1663:6): [True: 60, False: 1.67k]
  ------------------
 1664|     60|		return WPA_KEY_MGMT_FT_SAE_EXT_KEY;
  ------------------
  |  |   54|     60|#define WPA_KEY_MGMT_FT_SAE_EXT_KEY BIT(27)
  |  |  ------------------
  |  |  |  |  429|     60|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 1665|  1.67k|#endif /* CONFIG_SAE */
 1666|  1.67k|	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_802_1X_SUITE_B)
  ------------------
  |  |  148|  1.67k|#define RSN_SELECTOR_GET(a) WPA_GET_BE32((const u8 *) (a))
  ------------------
              	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_802_1X_SUITE_B)
  ------------------
  |  |   76|  1.67k|#define RSN_AUTH_KEY_MGMT_802_1X_SUITE_B RSN_SELECTOR(0x00, 0x0f, 0xac, 11)
  |  |  ------------------
  |  |  |  |   55|  1.67k|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|  1.67k|	 (u32) (d))
  |  |  ------------------
  ------------------
  |  Branch (1666:6): [True: 129, False: 1.55k]
  ------------------
 1667|    129|		return WPA_KEY_MGMT_IEEE8021X_SUITE_B;
  ------------------
  |  |   43|    129|#define WPA_KEY_MGMT_IEEE8021X_SUITE_B BIT(16)
  |  |  ------------------
  |  |  |  |  429|    129|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 1668|  1.55k|	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_802_1X_SUITE_B_192)
  ------------------
  |  |  148|  1.55k|#define RSN_SELECTOR_GET(a) WPA_GET_BE32((const u8 *) (a))
  ------------------
              	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_802_1X_SUITE_B_192)
  ------------------
  |  |   77|  1.55k|#define RSN_AUTH_KEY_MGMT_802_1X_SUITE_B_192 RSN_SELECTOR(0x00, 0x0f, 0xac, 12)
  |  |  ------------------
  |  |  |  |   55|  1.55k|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|  1.55k|	 (u32) (d))
  |  |  ------------------
  ------------------
  |  Branch (1668:6): [True: 116, False: 1.43k]
  ------------------
 1669|    116|		return WPA_KEY_MGMT_IEEE8021X_SUITE_B_192;
  ------------------
  |  |   44|    116|#define WPA_KEY_MGMT_IEEE8021X_SUITE_B_192 BIT(17)
  |  |  ------------------
  |  |  |  |  429|    116|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 1670|  1.43k|	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_FILS_SHA256)
  ------------------
  |  |  148|  1.43k|#define RSN_SELECTOR_GET(a) WPA_GET_BE32((const u8 *) (a))
  ------------------
              	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_FILS_SHA256)
  ------------------
  |  |   79|  1.43k|#define RSN_AUTH_KEY_MGMT_FILS_SHA256 RSN_SELECTOR(0x00, 0x0f, 0xac, 14)
  |  |  ------------------
  |  |  |  |   55|  1.43k|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|  1.43k|	 (u32) (d))
  |  |  ------------------
  ------------------
  |  Branch (1670:6): [True: 132, False: 1.30k]
  ------------------
 1671|    132|		return WPA_KEY_MGMT_FILS_SHA256;
  ------------------
  |  |   45|    132|#define WPA_KEY_MGMT_FILS_SHA256 BIT(18)
  |  |  ------------------
  |  |  |  |  429|    132|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 1672|  1.30k|	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_FILS_SHA384)
  ------------------
  |  |  148|  1.30k|#define RSN_SELECTOR_GET(a) WPA_GET_BE32((const u8 *) (a))
  ------------------
              	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_FILS_SHA384)
  ------------------
  |  |   80|  1.30k|#define RSN_AUTH_KEY_MGMT_FILS_SHA384 RSN_SELECTOR(0x00, 0x0f, 0xac, 15)
  |  |  ------------------
  |  |  |  |   55|  1.30k|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|  1.30k|	 (u32) (d))
  |  |  ------------------
  ------------------
  |  Branch (1672:6): [True: 104, False: 1.19k]
  ------------------
 1673|    104|		return WPA_KEY_MGMT_FILS_SHA384;
  ------------------
  |  |   46|    104|#define WPA_KEY_MGMT_FILS_SHA384 BIT(19)
  |  |  ------------------
  |  |  |  |  429|    104|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 1674|  1.19k|	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_FT_FILS_SHA256)
  ------------------
  |  |  148|  1.19k|#define RSN_SELECTOR_GET(a) WPA_GET_BE32((const u8 *) (a))
  ------------------
              	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_FT_FILS_SHA256)
  ------------------
  |  |   81|  1.19k|#define RSN_AUTH_KEY_MGMT_FT_FILS_SHA256 RSN_SELECTOR(0x00, 0x0f, 0xac, 16)
  |  |  ------------------
  |  |  |  |   55|  1.19k|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|  1.19k|	 (u32) (d))
  |  |  ------------------
  ------------------
  |  Branch (1674:6): [True: 108, False: 1.09k]
  ------------------
 1675|    108|		return WPA_KEY_MGMT_FT_FILS_SHA256;
  ------------------
  |  |   47|    108|#define WPA_KEY_MGMT_FT_FILS_SHA256 BIT(20)
  |  |  ------------------
  |  |  |  |  429|    108|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 1676|  1.09k|	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_FT_FILS_SHA384)
  ------------------
  |  |  148|  1.09k|#define RSN_SELECTOR_GET(a) WPA_GET_BE32((const u8 *) (a))
  ------------------
              	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_FT_FILS_SHA384)
  ------------------
  |  |   82|  1.09k|#define RSN_AUTH_KEY_MGMT_FT_FILS_SHA384 RSN_SELECTOR(0x00, 0x0f, 0xac, 17)
  |  |  ------------------
  |  |  |  |   55|  1.09k|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|  1.09k|	 (u32) (d))
  |  |  ------------------
  ------------------
  |  Branch (1676:6): [True: 76, False: 1.01k]
  ------------------
 1677|     76|		return WPA_KEY_MGMT_FT_FILS_SHA384;
  ------------------
  |  |   48|     76|#define WPA_KEY_MGMT_FT_FILS_SHA384 BIT(21)
  |  |  ------------------
  |  |  |  |  429|     76|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 1678|       |#ifdef CONFIG_OWE
 1679|       |	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_OWE)
 1680|       |		return WPA_KEY_MGMT_OWE;
 1681|       |#endif /* CONFIG_OWE */
 1682|       |#ifdef CONFIG_DPP
 1683|       |	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_DPP)
 1684|       |		return WPA_KEY_MGMT_DPP;
 1685|       |#endif /* CONFIG_DPP */
 1686|  1.01k|	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_OSEN)
  ------------------
  |  |  148|  1.01k|#define RSN_SELECTOR_GET(a) WPA_GET_BE32((const u8 *) (a))
  ------------------
              	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_OSEN)
  ------------------
  |  |   94|  1.01k|#define RSN_AUTH_KEY_MGMT_OSEN RSN_SELECTOR(0x50, 0x6f, 0x9a, 0x01)
  |  |  ------------------
  |  |  |  |   55|  1.01k|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|  1.01k|	 (u32) (d))
  |  |  ------------------
  ------------------
  |  Branch (1686:6): [True: 127, False: 887]
  ------------------
 1687|    127|		return WPA_KEY_MGMT_OSEN;
  ------------------
  |  |   42|    127|#define WPA_KEY_MGMT_OSEN BIT(15)
  |  |  ------------------
  |  |  |  |  429|    127|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 1688|    887|#ifdef CONFIG_PASN
 1689|    887|	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_PASN)
  ------------------
  |  |  148|    887|#define RSN_SELECTOR_GET(a) WPA_GET_BE32((const u8 *) (a))
  ------------------
              	if (RSN_SELECTOR_GET(s) == RSN_AUTH_KEY_MGMT_PASN)
  ------------------
  |  |   86|    887|#define RSN_AUTH_KEY_MGMT_PASN RSN_SELECTOR(0x00, 0x0f, 0xac, 21)
  |  |  ------------------
  |  |  |  |   55|    887|	((((u32) (a)) << 24) | (((u32) (b)) << 16) | (((u32) (c)) << 8) | \
  |  |  |  |   56|    887|	 (u32) (d))
  |  |  ------------------
  ------------------
  |  Branch (1689:6): [True: 289, False: 598]
  ------------------
 1690|    289|		return WPA_KEY_MGMT_PASN;
  ------------------
  |  |   52|    289|#define WPA_KEY_MGMT_PASN BIT(25)
  |  |  ------------------
  |  |  |  |  429|    289|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
 1691|    598|#endif /* CONFIG_PASN */
 1692|    598|	return 0;
 1693|    887|}

sha256_vector:
  417|    216|{
  418|    216|	return openssl_digest_vector(EVP_sha256(), num_elem, addr, len, mac);
  419|    216|}
hmac_sha256_vector:
 1706|    485|{
 1707|    485|	return openssl_hmac_vector(EVP_sha256(), key, key_len, num_elem, addr,
 1708|    485|				   len, mac, 32);
 1709|    485|}
hmac_sha256:
 1714|    269|{
 1715|    269|	return hmac_sha256_vector(key, key_len, 1, &data, &data_len, mac);
 1716|    269|}
crypto_bignum_to_bin:
 1928|    108|{
 1929|    108|	int num_bytes, offset;
 1930|       |
 1931|    108|	if (TEST_FAIL())
  ------------------
  |  |  677|    108|#define TEST_FAIL() 0
  |  |  ------------------
  |  |  |  Branch (677:21): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1932|      0|		return -1;
 1933|       |
 1934|    108|	if (padlen > buflen)
  ------------------
  |  Branch (1934:6): [True: 0, False: 108]
  ------------------
 1935|      0|		return -1;
 1936|       |
 1937|    108|	if (padlen) {
  ------------------
  |  Branch (1937:6): [True: 108, False: 0]
  ------------------
 1938|       |#ifdef OPENSSL_IS_BORINGSSL
 1939|       |		if (BN_bn2bin_padded(buf, padlen, (const BIGNUM *) a) == 0)
 1940|       |			return -1;
 1941|       |		return padlen;
 1942|       |#else /* OPENSSL_IS_BORINGSSL */
 1943|    108|#if OPENSSL_VERSION_NUMBER >= 0x10100000L && !defined(LIBRESSL_VERSION_NUMBER)
 1944|    108|		return BN_bn2binpad((const BIGNUM *) a, buf, padlen);
 1945|    108|#endif
 1946|    108|#endif
 1947|    108|	}
 1948|       |
 1949|      0|	num_bytes = BN_num_bytes((const BIGNUM *) a);
 1950|      0|	if ((size_t) num_bytes > buflen)
  ------------------
  |  Branch (1950:6): [True: 0, False: 0]
  ------------------
 1951|      0|		return -1;
 1952|      0|	if (padlen > (size_t) num_bytes)
  ------------------
  |  Branch (1952:6): [True: 0, False: 0]
  ------------------
 1953|      0|		offset = padlen - num_bytes;
 1954|      0|	else
 1955|      0|		offset = 0;
 1956|       |
 1957|      0|	os_memset(buf, 0, offset);
  ------------------
  |  |  509|      0|#define os_memset(s, c, n) memset(s, c, n)
  ------------------
 1958|      0|	BN_bn2bin((const BIGNUM *) a, buf + offset);
 1959|       |
 1960|      0|	return num_bytes + offset;
 1961|      0|}
crypto_ec_init:
 2311|    129|{
 2312|    129|	struct crypto_ec *e;
 2313|    129|	int nid;
 2314|       |
 2315|    129|	nid = crypto_ec_group_2_nid(group);
 2316|    129|	if (nid < 0)
  ------------------
  |  Branch (2316:6): [True: 0, False: 129]
  ------------------
 2317|      0|		return NULL;
 2318|       |
 2319|    129|	e = os_zalloc(sizeof(*e));
 2320|    129|	if (e == NULL)
  ------------------
  |  Branch (2320:6): [True: 0, False: 129]
  ------------------
 2321|      0|		return NULL;
 2322|       |
 2323|    129|	e->nid = nid;
 2324|    129|	e->iana_group = group;
 2325|    129|	e->bnctx = BN_CTX_new();
 2326|    129|	e->group = EC_GROUP_new_by_curve_name(nid);
 2327|    129|	e->prime = BN_new();
 2328|    129|	e->order = BN_new();
 2329|    129|	e->a = BN_new();
 2330|    129|	e->b = BN_new();
 2331|    129|	if (e->group == NULL || e->bnctx == NULL || e->prime == NULL ||
  ------------------
  |  Branch (2331:6): [True: 0, False: 129]
  |  Branch (2331:26): [True: 0, False: 129]
  |  Branch (2331:46): [True: 0, False: 129]
  ------------------
 2332|    129|	    e->order == NULL || e->a == NULL || e->b == NULL ||
  ------------------
  |  Branch (2332:6): [True: 0, False: 129]
  |  Branch (2332:26): [True: 0, False: 129]
  |  Branch (2332:42): [True: 0, False: 129]
  ------------------
 2333|    129|	    !EC_GROUP_get_curve(e->group, e->prime, e->a, e->b, e->bnctx) ||
  ------------------
  |  Branch (2333:6): [True: 0, False: 129]
  ------------------
 2334|    129|	    !EC_GROUP_get_order(e->group, e->order, e->bnctx)) {
  ------------------
  |  Branch (2334:6): [True: 0, False: 129]
  ------------------
 2335|      0|		crypto_ec_deinit(e);
 2336|      0|		e = NULL;
 2337|      0|	}
 2338|       |
 2339|    129|	return e;
 2340|    129|}
crypto_ec_deinit:
 2344|    129|{
 2345|    129|	if (e == NULL)
  ------------------
  |  Branch (2345:6): [True: 0, False: 129]
  ------------------
 2346|      0|		return;
 2347|    129|	BN_clear_free(e->b);
 2348|    129|	BN_clear_free(e->a);
 2349|    129|	BN_clear_free(e->order);
 2350|    129|	BN_clear_free(e->prime);
 2351|    129|	EC_GROUP_free(e->group);
 2352|    129|	BN_CTX_free(e->bnctx);
 2353|    129|	os_free(e);
  ------------------
  |  |  491|    129|#define os_free(p) free((p))
  ------------------
 2354|    129|}
crypto_ec_prime_len:
 2368|    108|{
 2369|    108|	return BN_num_bytes(e->prime);
 2370|    108|}
crypto_ecdh_init:
 2616|    129|{
 2617|       |#if OPENSSL_VERSION_NUMBER >= 0x30000000L
 2618|       |	struct crypto_ecdh *ecdh;
 2619|       |	const char *name;
 2620|       |
 2621|       |	ecdh = os_zalloc(sizeof(*ecdh));
 2622|       |	if (!ecdh)
 2623|       |		goto fail;
 2624|       |
 2625|       |	ecdh->ec = crypto_ec_init(group);
 2626|       |	if (!ecdh->ec)
 2627|       |		goto fail;
 2628|       |
 2629|       |	name = OSSL_EC_curve_nid2name(ecdh->ec->nid);
 2630|       |	if (!name)
 2631|       |		goto fail;
 2632|       |
 2633|       |	ecdh->pkey = EVP_EC_gen(name);
 2634|       |	if (!ecdh->pkey)
 2635|       |		goto fail;
 2636|       |
 2637|       |done:
 2638|       |	return ecdh;
 2639|       |fail:
 2640|       |	crypto_ecdh_deinit(ecdh);
 2641|       |	ecdh = NULL;
 2642|       |	goto done;
 2643|       |#else /* OpenSSL version >= 3.0 */
 2644|    129|	struct crypto_ecdh *ecdh;
 2645|    129|	EVP_PKEY *params = NULL;
 2646|    129|	EC_KEY *ec_params = NULL;
 2647|    129|	EVP_PKEY_CTX *kctx = NULL;
 2648|       |
 2649|    129|	ecdh = os_zalloc(sizeof(*ecdh));
 2650|    129|	if (!ecdh)
  ------------------
  |  Branch (2650:6): [True: 0, False: 129]
  ------------------
 2651|      0|		goto fail;
 2652|       |
 2653|    129|	ecdh->ec = crypto_ec_init(group);
 2654|    129|	if (!ecdh->ec)
  ------------------
  |  Branch (2654:6): [True: 0, False: 129]
  ------------------
 2655|      0|		goto fail;
 2656|       |
 2657|    129|	ec_params = EC_KEY_new_by_curve_name(ecdh->ec->nid);
 2658|    129|	if (!ec_params) {
  ------------------
  |  Branch (2658:6): [True: 0, False: 129]
  ------------------
 2659|      0|		wpa_printf(MSG_ERROR,
 2660|      0|			   "OpenSSL: Failed to generate EC_KEY parameters");
 2661|      0|		goto fail;
 2662|      0|	}
 2663|    129|	EC_KEY_set_asn1_flag(ec_params, OPENSSL_EC_NAMED_CURVE);
 2664|    129|	params = EVP_PKEY_new();
 2665|    129|	if (!params || EVP_PKEY_set1_EC_KEY(params, ec_params) != 1) {
  ------------------
  |  Branch (2665:6): [True: 0, False: 129]
  |  Branch (2665:17): [True: 0, False: 129]
  ------------------
 2666|      0|		wpa_printf(MSG_ERROR,
 2667|      0|			   "OpenSSL: Failed to generate EVP_PKEY parameters");
 2668|      0|		goto fail;
 2669|      0|	}
 2670|       |
 2671|    129|	kctx = EVP_PKEY_CTX_new(params, NULL);
 2672|    129|	if (!kctx)
  ------------------
  |  Branch (2672:6): [True: 0, False: 129]
  ------------------
 2673|      0|		goto fail;
 2674|       |
 2675|    129|	if (EVP_PKEY_keygen_init(kctx) != 1) {
  ------------------
  |  Branch (2675:6): [True: 0, False: 129]
  ------------------
 2676|      0|		wpa_printf(MSG_ERROR,
 2677|      0|			   "OpenSSL: EVP_PKEY_keygen_init failed: %s",
 2678|      0|			   ERR_error_string(ERR_get_error(), NULL));
 2679|      0|		goto fail;
 2680|      0|	}
 2681|       |
 2682|    129|	if (EVP_PKEY_keygen(kctx, &ecdh->pkey) != 1) {
  ------------------
  |  Branch (2682:6): [True: 0, False: 129]
  ------------------
 2683|      0|		wpa_printf(MSG_ERROR, "OpenSSL: EVP_PKEY_keygen failed: %s",
 2684|      0|			   ERR_error_string(ERR_get_error(), NULL));
 2685|      0|		goto fail;
 2686|      0|	}
 2687|       |
 2688|    129|done:
 2689|    129|	EC_KEY_free(ec_params);
 2690|    129|	EVP_PKEY_free(params);
 2691|    129|	EVP_PKEY_CTX_free(kctx);
 2692|       |
 2693|    129|	return ecdh;
 2694|      0|fail:
 2695|      0|	crypto_ecdh_deinit(ecdh);
 2696|      0|	ecdh = NULL;
 2697|      0|	goto done;
 2698|    129|#endif /* OpenSSL version >= 3.0 */
 2699|    129|}
crypto_ecdh_get_pubkey:
 2750|    108|{
 2751|       |#if OPENSSL_VERSION_NUMBER >= 0x30000000L
 2752|       |	struct wpabuf *buf = NULL;
 2753|       |	unsigned char *pub;
 2754|       |	size_t len, exp_len;
 2755|       |
 2756|       |	len = EVP_PKEY_get1_encoded_public_key(ecdh->pkey, &pub);
 2757|       |	if (len == 0)
 2758|       |		return NULL;
 2759|       |
 2760|       |	/* Encoded using SECG SEC 1, Sec. 2.3.4 format */
 2761|       |	exp_len = 1 + 2 * crypto_ec_prime_len(ecdh->ec);
 2762|       |	if (len != exp_len) {
 2763|       |		wpa_printf(MSG_ERROR,
 2764|       |			   "OpenSSL:%s: Unexpected encoded public key length %zu (expected %zu)",
 2765|       |			   __func__, len, exp_len);
 2766|       |		goto fail;
 2767|       |	}
 2768|       |	buf = wpabuf_alloc_copy(pub + 1, inc_y ? len - 1 : len / 2);
 2769|       |fail:
 2770|       |	OPENSSL_free(pub);
 2771|       |	return buf;
 2772|       |#else /* OpenSSL version >= 3.0 */
 2773|    108|	struct wpabuf *buf = NULL;
 2774|    108|	EC_KEY *eckey;
 2775|    108|	const EC_POINT *pubkey;
 2776|    108|	BIGNUM *x, *y = NULL;
 2777|    108|	int len = BN_num_bytes(ecdh->ec->prime);
 2778|    108|	int res;
 2779|       |
 2780|    108|	eckey = EVP_PKEY_get1_EC_KEY(ecdh->pkey);
 2781|    108|	if (!eckey)
  ------------------
  |  Branch (2781:6): [True: 0, False: 108]
  ------------------
 2782|      0|		return NULL;
 2783|       |
 2784|    108|	pubkey = EC_KEY_get0_public_key(eckey);
 2785|    108|	if (!pubkey)
  ------------------
  |  Branch (2785:6): [True: 0, False: 108]
  ------------------
 2786|      0|		return NULL;
 2787|       |
 2788|    108|	x = BN_new();
 2789|    108|	if (inc_y) {
  ------------------
  |  Branch (2789:6): [True: 0, False: 108]
  ------------------
 2790|      0|		y = BN_new();
 2791|      0|		if (!y)
  ------------------
  |  Branch (2791:7): [True: 0, False: 0]
  ------------------
 2792|      0|			goto fail;
 2793|      0|	}
 2794|    108|	buf = wpabuf_alloc(inc_y ? 2 * len : len);
  ------------------
  |  Branch (2794:21): [True: 0, False: 108]
  ------------------
 2795|    108|	if (!x || !buf)
  ------------------
  |  Branch (2795:6): [True: 0, False: 108]
  |  Branch (2795:12): [True: 0, False: 108]
  ------------------
 2796|      0|		goto fail;
 2797|       |
 2798|    108|	if (EC_POINT_get_affine_coordinates(ecdh->ec->group, pubkey,
  ------------------
  |  Branch (2798:6): [True: 0, False: 108]
  ------------------
 2799|    108|					    x, y, ecdh->ec->bnctx) != 1) {
 2800|      0|		wpa_printf(MSG_ERROR,
 2801|      0|			   "OpenSSL: EC_POINT_get_affine_coordinates failed: %s",
 2802|      0|			   ERR_error_string(ERR_get_error(), NULL));
 2803|      0|		goto fail;
 2804|      0|	}
 2805|       |
 2806|    108|	res = crypto_bignum_to_bin((struct crypto_bignum *) x,
 2807|    108|				   wpabuf_put(buf, len), len, len);
 2808|    108|	if (res < 0)
  ------------------
  |  Branch (2808:6): [True: 0, False: 108]
  ------------------
 2809|      0|		goto fail;
 2810|       |
 2811|    108|	if (inc_y) {
  ------------------
  |  Branch (2811:6): [True: 0, False: 108]
  ------------------
 2812|      0|		res = crypto_bignum_to_bin((struct crypto_bignum *) y,
 2813|      0|					   wpabuf_put(buf, len), len, len);
 2814|      0|		if (res < 0)
  ------------------
  |  Branch (2814:7): [True: 0, False: 0]
  ------------------
 2815|      0|			goto fail;
 2816|      0|	}
 2817|       |
 2818|    108|done:
 2819|    108|	BN_clear_free(x);
 2820|    108|	BN_clear_free(y);
 2821|    108|	EC_KEY_free(eckey);
 2822|       |
 2823|    108|	return buf;
 2824|      0|fail:
 2825|      0|	wpabuf_free(buf);
 2826|      0|	buf = NULL;
 2827|      0|	goto done;
 2828|    108|#endif /* OpenSSL version >= 3.0 */
 2829|    108|}
crypto_ecdh_set_peerkey:
 2834|    112|{
 2835|       |#if OPENSSL_VERSION_NUMBER >= 0x30000000L
 2836|       |	EVP_PKEY *peerkey = EVP_PKEY_new();
 2837|       |	EVP_PKEY_CTX *ctx;
 2838|       |	size_t res_len;
 2839|       |	struct wpabuf *res = NULL;
 2840|       |	u8 *peer;
 2841|       |
 2842|       |	/* Encode using SECG SEC 1, Sec. 2.3.4 format */
 2843|       |	peer = os_malloc(1 + len);
 2844|       |	if (!peer)
 2845|       |		return NULL;
 2846|       |	peer[0] = inc_y ? 0x04 : 0x02;
 2847|       |	os_memcpy(peer + 1, key, len);
 2848|       |
 2849|       |	if (!peerkey ||
 2850|       |	    EVP_PKEY_copy_parameters(peerkey, ecdh->pkey) != 1 ||
 2851|       |	    EVP_PKEY_set1_encoded_public_key(peerkey, peer, 1 + len) != 1) {
 2852|       |		wpa_printf(MSG_INFO, "OpenSSL: EVP_PKEY_set1_encoded_public_key failed: %s",
 2853|       |			   ERR_error_string(ERR_get_error(), NULL));
 2854|       |		EVP_PKEY_free(peerkey);
 2855|       |		os_free(peer);
 2856|       |		return NULL;
 2857|       |	}
 2858|       |	os_free(peer);
 2859|       |
 2860|       |	ctx = EVP_PKEY_CTX_new(ecdh->pkey, NULL);
 2861|       |	if (!ctx ||
 2862|       |	    EVP_PKEY_derive_init(ctx) != 1 ||
 2863|       |	    EVP_PKEY_derive_set_peer(ctx, peerkey) != 1 ||
 2864|       |	    EVP_PKEY_derive(ctx, NULL, &res_len) != 1 ||
 2865|       |	    !(res = wpabuf_alloc(res_len)) ||
 2866|       |	    EVP_PKEY_derive(ctx, wpabuf_mhead(res), &res_len) != 1) {
 2867|       |		wpa_printf(MSG_INFO, "OpenSSL: EVP_PKEY_derive failed: %s",
 2868|       |			   ERR_error_string(ERR_get_error(), NULL));
 2869|       |		wpabuf_free(res);
 2870|       |		res = NULL;
 2871|       |	} else {
 2872|       |		wpabuf_put(res, res_len);
 2873|       |	}
 2874|       |
 2875|       |	EVP_PKEY_free(peerkey);
 2876|       |	EVP_PKEY_CTX_free(ctx);
 2877|       |	return res;
 2878|       |#else /* OpenSSL version >= 3.0 */
 2879|    112|	BIGNUM *x, *y = NULL;
 2880|    112|	EVP_PKEY_CTX *ctx = NULL;
 2881|    112|	EVP_PKEY *peerkey = NULL;
 2882|    112|	struct wpabuf *secret = NULL;
 2883|    112|	size_t secret_len;
 2884|    112|	EC_POINT *pub;
 2885|    112|	EC_KEY *eckey = NULL;
 2886|       |
 2887|    112|	x = BN_bin2bn(key, inc_y ? len / 2 : len, NULL);
  ------------------
  |  Branch (2887:21): [True: 1, False: 111]
  ------------------
 2888|    112|	pub = EC_POINT_new(ecdh->ec->group);
 2889|    112|	if (!x || !pub)
  ------------------
  |  Branch (2889:6): [True: 0, False: 112]
  |  Branch (2889:12): [True: 0, False: 112]
  ------------------
 2890|      0|		goto fail;
 2891|       |
 2892|    112|	if (inc_y) {
  ------------------
  |  Branch (2892:6): [True: 1, False: 111]
  ------------------
 2893|      1|		y = BN_bin2bn(key + len / 2, len / 2, NULL);
 2894|      1|		if (!y)
  ------------------
  |  Branch (2894:7): [True: 0, False: 1]
  ------------------
 2895|      0|			goto fail;
 2896|      1|		if (!EC_POINT_set_affine_coordinates(ecdh->ec->group, pub,
  ------------------
  |  Branch (2896:7): [True: 1, False: 0]
  ------------------
 2897|      1|						     x, y, ecdh->ec->bnctx)) {
 2898|      1|			wpa_printf(MSG_ERROR,
 2899|      1|				   "OpenSSL: EC_POINT_set_affine_coordinates failed: %s",
 2900|      1|				   ERR_error_string(ERR_get_error(), NULL));
 2901|      1|			goto fail;
 2902|      1|		}
 2903|    111|	} else if (!EC_POINT_set_compressed_coordinates(ecdh->ec->group,
  ------------------
  |  Branch (2903:13): [True: 1, False: 110]
  ------------------
 2904|    111|							pub, x, 0,
 2905|    111|							ecdh->ec->bnctx)) {
 2906|      1|		wpa_printf(MSG_ERROR,
 2907|      1|			   "OpenSSL: EC_POINT_set_compressed_coordinates failed: %s",
 2908|      1|			   ERR_error_string(ERR_get_error(), NULL));
 2909|      1|		goto fail;
 2910|      1|	}
 2911|       |
 2912|    110|	if (!EC_POINT_is_on_curve(ecdh->ec->group, pub, ecdh->ec->bnctx)) {
  ------------------
  |  Branch (2912:6): [True: 0, False: 110]
  ------------------
 2913|      0|		wpa_printf(MSG_ERROR,
 2914|      0|			   "OpenSSL: ECDH peer public key is not on curve");
 2915|      0|		goto fail;
 2916|      0|	}
 2917|       |
 2918|    110|	eckey = EC_KEY_new_by_curve_name(ecdh->ec->nid);
 2919|    110|	if (!eckey || EC_KEY_set_public_key(eckey, pub) != 1) {
  ------------------
  |  Branch (2919:6): [True: 0, False: 110]
  |  Branch (2919:16): [True: 0, False: 110]
  ------------------
 2920|      0|		wpa_printf(MSG_ERROR,
 2921|      0|			   "OpenSSL: EC_KEY_set_public_key failed: %s",
 2922|      0|			   ERR_error_string(ERR_get_error(), NULL));
 2923|      0|		goto fail;
 2924|      0|	}
 2925|       |
 2926|    110|	peerkey = EVP_PKEY_new();
 2927|    110|	if (!peerkey || EVP_PKEY_set1_EC_KEY(peerkey, eckey) != 1)
  ------------------
  |  Branch (2927:6): [True: 0, False: 110]
  |  Branch (2927:18): [True: 0, False: 110]
  ------------------
 2928|      0|		goto fail;
 2929|       |
 2930|    110|	ctx = EVP_PKEY_CTX_new(ecdh->pkey, NULL);
 2931|    110|	if (!ctx || EVP_PKEY_derive_init(ctx) != 1 ||
  ------------------
  |  Branch (2931:6): [True: 0, False: 110]
  |  Branch (2931:14): [True: 0, False: 110]
  ------------------
 2932|    110|	    EVP_PKEY_derive_set_peer(ctx, peerkey) != 1 ||
  ------------------
  |  Branch (2932:6): [True: 0, False: 110]
  ------------------
 2933|    110|	    EVP_PKEY_derive(ctx, NULL, &secret_len) != 1) {
  ------------------
  |  Branch (2933:6): [True: 0, False: 110]
  ------------------
 2934|      0|		wpa_printf(MSG_ERROR,
 2935|      0|			   "OpenSSL: EVP_PKEY_derive(1) failed: %s",
 2936|      0|			   ERR_error_string(ERR_get_error(), NULL));
 2937|      0|		goto fail;
 2938|      0|	}
 2939|       |
 2940|    110|	secret = wpabuf_alloc(secret_len);
 2941|    110|	if (!secret)
  ------------------
  |  Branch (2941:6): [True: 0, False: 110]
  ------------------
 2942|      0|		goto fail;
 2943|    110|	if (EVP_PKEY_derive(ctx, wpabuf_put(secret, 0), &secret_len) != 1) {
  ------------------
  |  Branch (2943:6): [True: 0, False: 110]
  ------------------
 2944|      0|		wpa_printf(MSG_ERROR,
 2945|      0|			   "OpenSSL: EVP_PKEY_derive(2) failed: %s",
 2946|      0|			   ERR_error_string(ERR_get_error(), NULL));
 2947|      0|		goto fail;
 2948|      0|	}
 2949|    110|	if (secret->size != secret_len)
  ------------------
  |  Branch (2949:6): [True: 0, False: 110]
  ------------------
 2950|      0|		wpa_printf(MSG_DEBUG,
 2951|      0|			   "OpenSSL: EVP_PKEY_derive(2) changed secret_len %d -> %d",
 2952|      0|			   (int) secret->size, (int) secret_len);
 2953|    110|	wpabuf_put(secret, secret_len);
 2954|       |
 2955|    112|done:
 2956|    112|	BN_free(x);
 2957|    112|	BN_free(y);
 2958|    112|	EC_KEY_free(eckey);
 2959|    112|	EC_POINT_free(pub);
 2960|    112|	EVP_PKEY_CTX_free(ctx);
 2961|    112|	EVP_PKEY_free(peerkey);
 2962|    112|	return secret;
 2963|      2|fail:
 2964|      2|	wpabuf_free(secret);
 2965|      2|	secret = NULL;
 2966|      2|	goto done;
 2967|    110|#endif /* OpenSSL version >= 3.0 */
 2968|    110|}
crypto_ecdh_deinit:
 2972|    129|{
 2973|    129|	if (ecdh) {
  ------------------
  |  Branch (2973:6): [True: 129, False: 0]
  ------------------
 2974|    129|		crypto_ec_deinit(ecdh->ec);
 2975|    129|		EVP_PKEY_free(ecdh->pkey);
 2976|    129|		os_free(ecdh);
  ------------------
  |  |  491|    129|#define os_free(p) free((p))
  ------------------
 2977|    129|	}
 2978|    129|}
crypto_ecdh_prime_len:
 2982|    108|{
 2983|    108|	return crypto_ec_prime_len(ecdh->ec);
 2984|    108|}
crypto_openssl.c:openssl_digest_vector:
  277|    216|{
  278|    216|	EVP_MD_CTX *ctx;
  279|    216|	size_t i;
  280|    216|	unsigned int mac_len;
  281|       |
  282|    216|	if (TEST_FAIL())
  ------------------
  |  |  677|    216|#define TEST_FAIL() 0
  |  |  ------------------
  |  |  |  Branch (677:21): [Folded - Ignored]
  |  |  ------------------
  ------------------
  283|      0|		return -1;
  284|       |
  285|    216|	ctx = EVP_MD_CTX_new();
  286|    216|	if (!ctx)
  ------------------
  |  Branch (286:6): [True: 0, False: 216]
  ------------------
  287|      0|		return -1;
  288|    216|	if (!EVP_DigestInit_ex(ctx, type, NULL)) {
  ------------------
  |  Branch (288:6): [True: 0, False: 216]
  ------------------
  289|      0|		wpa_printf(MSG_ERROR, "OpenSSL: EVP_DigestInit_ex failed: %s",
  290|      0|			   ERR_error_string(ERR_get_error(), NULL));
  291|      0|		EVP_MD_CTX_free(ctx);
  292|      0|		return -1;
  293|      0|	}
  294|    432|	for (i = 0; i < num_elem; i++) {
  ------------------
  |  Branch (294:14): [True: 216, False: 216]
  ------------------
  295|    216|		if (!EVP_DigestUpdate(ctx, addr[i], len[i])) {
  ------------------
  |  Branch (295:7): [True: 0, False: 216]
  ------------------
  296|      0|			wpa_printf(MSG_ERROR, "OpenSSL: EVP_DigestUpdate "
  297|      0|				   "failed: %s",
  298|      0|				   ERR_error_string(ERR_get_error(), NULL));
  299|      0|			EVP_MD_CTX_free(ctx);
  300|      0|			return -1;
  301|      0|		}
  302|    216|	}
  303|    216|	if (!EVP_DigestFinal(ctx, mac, &mac_len)) {
  ------------------
  |  Branch (303:6): [True: 0, False: 216]
  ------------------
  304|      0|		wpa_printf(MSG_ERROR, "OpenSSL: EVP_DigestFinal failed: %s",
  305|      0|			   ERR_error_string(ERR_get_error(), NULL));
  306|      0|		EVP_MD_CTX_free(ctx);
  307|      0|		return -1;
  308|      0|	}
  309|    216|	EVP_MD_CTX_free(ctx);
  310|       |
  311|    216|	return 0;
  312|    216|}
crypto_openssl.c:openssl_hmac_vector:
 1642|    485|{
 1643|    485|	HMAC_CTX *ctx;
 1644|    485|	size_t i;
 1645|    485|	int res;
 1646|       |
 1647|    485|	if (TEST_FAIL())
  ------------------
  |  |  677|    485|#define TEST_FAIL() 0
  |  |  ------------------
  |  |  |  Branch (677:21): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1648|      0|		return -1;
 1649|       |
 1650|    485|	ctx = HMAC_CTX_new();
 1651|    485|	if (!ctx)
  ------------------
  |  Branch (1651:6): [True: 0, False: 485]
  ------------------
 1652|      0|		return -1;
 1653|    485|	res = HMAC_Init_ex(ctx, key, key_len, type, NULL);
 1654|    485|	if (res != 1)
  ------------------
  |  Branch (1654:6): [True: 1, False: 484]
  ------------------
 1655|      1|		goto done;
 1656|       |
 1657|  1.61k|	for (i = 0; i < num_elem; i++)
  ------------------
  |  Branch (1657:14): [True: 1.13k, False: 484]
  ------------------
 1658|  1.13k|		HMAC_Update(ctx, addr[i], len[i]);
 1659|       |
 1660|    484|	res = HMAC_Final(ctx, mac, &mdlen);
 1661|    485|done:
 1662|    485|	HMAC_CTX_free(ctx);
 1663|       |
 1664|    485|	return res == 1 ? 0 : -1;
  ------------------
  |  Branch (1664:9): [True: 484, False: 1]
  ------------------
 1665|    484|}
crypto_openssl.c:crypto_ec_group_2_nid:
 2237|    129|{
 2238|       |	/* Map from IANA registry for IKE D-H groups to OpenSSL NID */
 2239|    129|	switch (group) {
 2240|    129|	case 19:
  ------------------
  |  Branch (2240:2): [True: 129, False: 0]
  ------------------
 2241|    129|		return NID_X9_62_prime256v1;
 2242|      0|	case 20:
  ------------------
  |  Branch (2242:2): [True: 0, False: 129]
  ------------------
 2243|      0|		return NID_secp384r1;
 2244|      0|	case 21:
  ------------------
  |  Branch (2244:2): [True: 0, False: 129]
  ------------------
 2245|      0|		return NID_secp521r1;
 2246|      0|	case 25:
  ------------------
  |  Branch (2246:2): [True: 0, False: 129]
  ------------------
 2247|      0|		return NID_X9_62_prime192v1;
 2248|      0|	case 26:
  ------------------
  |  Branch (2248:2): [True: 0, False: 129]
  ------------------
 2249|      0|		return NID_secp224r1;
 2250|      0|#ifdef NID_brainpoolP224r1
 2251|      0|	case 27:
  ------------------
  |  Branch (2251:2): [True: 0, False: 129]
  ------------------
 2252|      0|		return NID_brainpoolP224r1;
 2253|      0|#endif /* NID_brainpoolP224r1 */
 2254|      0|#ifdef NID_brainpoolP256r1
 2255|      0|	case 28:
  ------------------
  |  Branch (2255:2): [True: 0, False: 129]
  ------------------
 2256|      0|		return NID_brainpoolP256r1;
 2257|      0|#endif /* NID_brainpoolP256r1 */
 2258|      0|#ifdef NID_brainpoolP384r1
 2259|      0|	case 29:
  ------------------
  |  Branch (2259:2): [True: 0, False: 129]
  ------------------
 2260|      0|		return NID_brainpoolP384r1;
 2261|      0|#endif /* NID_brainpoolP384r1 */
 2262|      0|#ifdef NID_brainpoolP512r1
 2263|      0|	case 30:
  ------------------
  |  Branch (2263:2): [True: 0, False: 129]
  ------------------
 2264|      0|		return NID_brainpoolP512r1;
 2265|      0|#endif /* NID_brainpoolP512r1 */
 2266|      0|	default:
  ------------------
  |  Branch (2266:2): [True: 0, False: 129]
  ------------------
 2267|      0|		return -1;
 2268|    129|	}
 2269|    129|}

sha256_prf:
   32|    108|{
   33|    108|	return sha256_prf_bits(key, key_len, label, data, data_len, buf,
   34|    108|			       buf_len * 8);
   35|    108|}
sha256_prf_bits:
   57|    108|{
   58|    108|	u16 counter = 1;
   59|    108|	size_t pos, plen;
   60|    108|	u8 hash[SHA256_MAC_LEN];
   61|    108|	const u8 *addr[4];
   62|    108|	size_t len[4];
   63|    108|	u8 counter_le[2], length_le[2];
   64|    108|	size_t buf_len = (buf_len_bits + 7) / 8;
   65|       |
   66|    108|	addr[0] = counter_le;
   67|    108|	len[0] = 2;
   68|    108|	addr[1] = (u8 *) label;
   69|    108|	len[1] = os_strlen(label);
  ------------------
  |  |  516|    108|#define os_strlen(s) strlen(s)
  ------------------
   70|    108|	addr[2] = data;
   71|    108|	len[2] = data_len;
   72|    108|	addr[3] = length_le;
   73|    108|	len[3] = sizeof(length_le);
   74|       |
   75|    108|	WPA_PUT_LE16(length_le, buf_len_bits);
   76|    108|	pos = 0;
   77|    216|	while (pos < buf_len) {
  ------------------
  |  Branch (77:9): [True: 216, False: 0]
  ------------------
   78|    216|		plen = buf_len - pos;
   79|    216|		WPA_PUT_LE16(counter_le, counter);
   80|    216|		if (plen >= SHA256_MAC_LEN) {
  ------------------
  |  |   12|    216|#define SHA256_MAC_LEN 32
  ------------------
  |  Branch (80:7): [True: 108, False: 108]
  ------------------
   81|    108|			if (hmac_sha256_vector(key, key_len, 4, addr, len,
  ------------------
  |  Branch (81:8): [True: 0, False: 108]
  ------------------
   82|    108|					       &buf[pos]) < 0)
   83|      0|				return -1;
   84|    108|			pos += SHA256_MAC_LEN;
  ------------------
  |  |   12|    108|#define SHA256_MAC_LEN 32
  ------------------
   85|    108|		} else {
   86|    108|			if (hmac_sha256_vector(key, key_len, 4, addr, len,
  ------------------
  |  Branch (86:8): [True: 0, False: 108]
  ------------------
   87|    108|					       hash) < 0)
   88|      0|				return -1;
   89|    108|			os_memcpy(&buf[pos], hash, plen);
  ------------------
  |  |  503|    108|#define os_memcpy(d, s, n) memcpy((d), (s), (n))
  ------------------
   90|    108|			pos += plen;
   91|    108|			break;
   92|    108|		}
   93|    108|		counter++;
   94|    108|	}
   95|       |
   96|       |	/*
   97|       |	 * Mask out unused bits in the last octet if it does not use all the
   98|       |	 * bits.
   99|       |	 */
  100|    108|	if (buf_len_bits % 8) {
  ------------------
  |  Branch (100:6): [True: 0, False: 108]
  ------------------
  101|      0|		u8 mask = 0xff << (8 - buf_len_bits % 8);
  102|      0|		buf[pos - 1] &= mask;
  103|      0|	}
  104|       |
  105|    108|	forced_memzero(hash, sizeof(hash));
  106|       |
  107|    108|	return 0;
  108|    108|}

handle_auth_pasn_resp:
  417|  2.71k|{
  418|  2.71k|	struct wpabuf *buf, *pubkey = NULL, *wrapped_data_buf = NULL;
  419|  2.71k|	struct wpabuf *rsn_buf = NULL;
  420|  2.71k|	u8 mic[WPA_PASN_MAX_MIC_LEN];
  421|  2.71k|	u8 mic_len;
  422|  2.71k|	u8 *ptr;
  423|  2.71k|	const u8 *frame, *data, *rsn_ie, *rsnxe_ie;
  424|  2.71k|	u8 *data_buf = NULL;
  425|  2.71k|	size_t frame_len, data_len;
  426|  2.71k|	int ret;
  427|  2.71k|	const u8 *pmkid = NULL;
  428|       |
  429|  2.71k|	wpa_printf(MSG_DEBUG, "PASN: Building frame 2: status=%u", status);
  430|       |
  431|  2.71k|	buf = wpabuf_alloc(1500);
  432|  2.71k|	if (!buf)
  ------------------
  |  Branch (432:6): [True: 0, False: 2.71k]
  ------------------
  433|      0|		goto fail;
  434|       |
  435|  2.71k|	wpa_pasn_build_auth_header(buf, pasn->bssid, own_addr, peer_addr, 2,
  436|  2.71k|				   status);
  437|       |
  438|  2.71k|	if (status != WLAN_STATUS_SUCCESS)
  ------------------
  |  |  111|  2.71k|#define WLAN_STATUS_SUCCESS 0
  ------------------
  |  Branch (438:6): [True: 2.60k, False: 108]
  ------------------
  439|  2.60k|		goto done;
  440|       |
  441|    108|	if (pmksa && pasn->custom_pmkid_valid)
  ------------------
  |  Branch (441:6): [True: 0, False: 108]
  |  Branch (441:15): [True: 0, False: 0]
  ------------------
  442|      0|		pmkid = pasn->custom_pmkid;
  443|    108|	else if (pmksa) {
  ------------------
  |  Branch (443:11): [True: 0, False: 108]
  ------------------
  444|      0|		pmkid = pmksa->pmkid;
  445|      0|#ifdef CONFIG_SAE
  446|    108|	} else if (pasn->akmp == WPA_KEY_MGMT_SAE) {
  ------------------
  |  |   37|    108|#define WPA_KEY_MGMT_SAE BIT(10)
  |  |  ------------------
  |  |  |  |  429|    108|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (446:13): [True: 0, False: 108]
  ------------------
  447|      0|		wpa_printf(MSG_DEBUG, "PASN: Use SAE PMKID");
  448|      0|		pmkid = pasn->sae.pmkid;
  449|      0|#endif /* CONFIG_SAE */
  450|      0|#ifdef CONFIG_FILS
  451|    108|	} else if (pasn->akmp == WPA_KEY_MGMT_FILS_SHA256 ||
  ------------------
  |  |   45|    108|#define WPA_KEY_MGMT_FILS_SHA256 BIT(18)
  |  |  ------------------
  |  |  |  |  429|    216|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (451:13): [True: 0, False: 108]
  ------------------
  452|    108|		   pasn->akmp == WPA_KEY_MGMT_FILS_SHA384) {
  ------------------
  |  |   46|    108|#define WPA_KEY_MGMT_FILS_SHA384 BIT(19)
  |  |  ------------------
  |  |  |  |  429|    108|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (452:6): [True: 0, False: 108]
  ------------------
  453|      0|		wpa_printf(MSG_DEBUG, "PASN: Use FILS ERP PMKID");
  454|      0|		pmkid = pasn->fils.erp_pmkid;
  455|      0|#endif /* CONFIG_FILS */
  456|      0|	}
  457|       |
  458|    108|	if (wpa_pasn_add_rsne(buf, pmkid,
  ------------------
  |  Branch (458:6): [True: 0, False: 108]
  ------------------
  459|    108|			      pasn->akmp, pasn->cipher) < 0)
  460|      0|		goto fail;
  461|       |
  462|       |	/* No need to derive PMK if PMKSA is given */
  463|    108|	if (!pmksa)
  ------------------
  |  Branch (463:6): [True: 108, False: 0]
  ------------------
  464|    108|		wrapped_data_buf = pasn_get_wrapped_data(pasn);
  465|      0|	else
  466|      0|		pasn->wrapped_data_format = WPA_PASN_WRAPPED_DATA_NO;
  ------------------
  |  |  598|      0|#define WPA_PASN_WRAPPED_DATA_NO      0
  ------------------
  467|       |
  468|       |	/* Get public key */
  469|    108|	pubkey = crypto_ecdh_get_pubkey(pasn->ecdh, 0);
  470|    108|	pubkey = wpabuf_zeropad(pubkey,
  471|    108|				crypto_ecdh_prime_len(pasn->ecdh));
  472|    108|	if (!pubkey) {
  ------------------
  |  Branch (472:6): [True: 0, False: 108]
  ------------------
  473|      0|		wpa_printf(MSG_DEBUG, "PASN: Failed to get pubkey");
  474|      0|		goto fail;
  475|      0|	}
  476|       |
  477|    108|	wpa_pasn_add_parameter_ie(buf, pasn->group,
  478|    108|				  pasn->wrapped_data_format,
  479|    108|				  pubkey, true, NULL, 0);
  480|       |
  481|    108|	if (wpa_pasn_add_wrapped_data(buf, wrapped_data_buf) < 0)
  ------------------
  |  Branch (481:6): [True: 0, False: 108]
  ------------------
  482|      0|		goto fail;
  483|       |
  484|    108|	wpabuf_free(wrapped_data_buf);
  485|    108|	wrapped_data_buf = NULL;
  486|    108|	wpabuf_free(pubkey);
  487|    108|	pubkey = NULL;
  488|       |
  489|       |	/* Add RSNXE if needed */
  490|    108|	rsnxe_ie = pasn->rsnxe_ie;
  491|    108|	if (rsnxe_ie)
  ------------------
  |  Branch (491:6): [True: 0, False: 108]
  ------------------
  492|      0|		wpabuf_put_data(buf, rsnxe_ie, 2 + rsnxe_ie[1]);
  493|       |
  494|    108|	wpa_pasn_add_extra_ies(buf, pasn->extra_ies, pasn->extra_ies_len);
  495|       |
  496|       |	/* Add the mic */
  497|    108|	mic_len = pasn_mic_len(pasn->akmp, pasn->cipher);
  498|    108|	wpabuf_put_u8(buf, WLAN_EID_MIC);
  ------------------
  |  |  393|    108|#define WLAN_EID_MIC 140
  ------------------
  499|    108|	wpabuf_put_u8(buf, mic_len);
  500|    108|	ptr = wpabuf_put(buf, mic_len);
  501|       |
  502|    108|	os_memset(ptr, 0, mic_len);
  ------------------
  |  |  509|    108|#define os_memset(s, c, n) memset(s, c, n)
  ------------------
  503|       |
  504|    108|	frame = wpabuf_head_u8(buf) + IEEE80211_HDRLEN;
  ------------------
  |  |  932|    108|#define IEEE80211_HDRLEN (sizeof(struct ieee80211_hdr))
  ------------------
  505|    108|	frame_len = wpabuf_len(buf) - IEEE80211_HDRLEN;
  ------------------
  |  |  932|    108|#define IEEE80211_HDRLEN (sizeof(struct ieee80211_hdr))
  ------------------
  506|       |
  507|    108|	if (pasn->rsn_ie && pasn->rsn_ie_len) {
  ------------------
  |  Branch (507:6): [True: 0, False: 108]
  |  Branch (507:22): [True: 0, False: 0]
  ------------------
  508|      0|		rsn_ie = pasn->rsn_ie;
  509|    108|	} else {
  510|       |		/*
  511|       |		 * Note: when pasn->rsn_ie is NULL, it is likely that Beacon
  512|       |		 * frame RSNE is not initialized. This is possible in case of
  513|       |		 * PASN authentication used for Wi-Fi Aware for which Beacon
  514|       |		 * frame RSNE and RSNXE are same as RSNE and RSNXE in the
  515|       |		 * Authentication frame.
  516|       |		 */
  517|    108|		rsn_buf = wpabuf_alloc(500);
  518|    108|		if (!rsn_buf)
  ------------------
  |  Branch (518:7): [True: 0, False: 108]
  ------------------
  519|      0|			goto fail;
  520|       |
  521|    108|		if (wpa_pasn_add_rsne(rsn_buf, pmkid,
  ------------------
  |  Branch (521:7): [True: 0, False: 108]
  ------------------
  522|    108|				      pasn->akmp, pasn->cipher) < 0)
  523|      0|			goto fail;
  524|       |
  525|    108|		rsn_ie = wpabuf_head_u8(rsn_buf);
  526|    108|	}
  527|       |
  528|       |	/*
  529|       |	 * Note: wpa_auth_get_wpa_ie() might return not only the RSNE but also
  530|       |	 * MDE, etc. Thus, do not use the returned length but instead use the
  531|       |	 * length specified in the IE header.
  532|       |	 */
  533|    108|	data_len = rsn_ie[1] + 2;
  534|    108|	if (rsnxe_ie) {
  ------------------
  |  Branch (534:6): [True: 0, False: 108]
  ------------------
  535|      0|		data_buf = os_zalloc(rsn_ie[1] + 2 + rsnxe_ie[1] + 2);
  536|      0|		if (!data_buf)
  ------------------
  |  Branch (536:7): [True: 0, False: 0]
  ------------------
  537|      0|			goto fail;
  538|       |
  539|      0|		os_memcpy(data_buf, rsn_ie, rsn_ie[1] + 2);
  ------------------
  |  |  503|      0|#define os_memcpy(d, s, n) memcpy((d), (s), (n))
  ------------------
  540|      0|		os_memcpy(data_buf + rsn_ie[1] + 2, rsnxe_ie, rsnxe_ie[1] + 2);
  ------------------
  |  |  503|      0|#define os_memcpy(d, s, n) memcpy((d), (s), (n))
  ------------------
  541|      0|		data_len += rsnxe_ie[1] + 2;
  542|      0|		data = data_buf;
  543|    108|	} else {
  544|    108|		data = rsn_ie;
  545|    108|	}
  546|       |
  547|    108|	ret = pasn_mic(pasn->ptk.kck, pasn->akmp, pasn->cipher,
  548|    108|		       own_addr, peer_addr, data, data_len,
  549|    108|		       frame, frame_len, mic);
  550|    108|	os_free(data_buf);
  ------------------
  |  |  491|    108|#define os_free(p) free((p))
  ------------------
  551|    108|	if (ret) {
  ------------------
  |  Branch (551:6): [True: 0, False: 108]
  ------------------
  552|      0|		wpa_printf(MSG_DEBUG, "PASN: Frame 3: Failed MIC calculation");
  553|      0|		goto fail;
  554|      0|	}
  555|       |
  556|       |#ifdef CONFIG_TESTING_OPTIONS
  557|       |	if (pasn->corrupt_mic) {
  558|       |		wpa_printf(MSG_DEBUG, "PASN: frame 2: Corrupt MIC");
  559|       |		mic[0] = ~mic[0];
  560|       |	}
  561|       |#endif /* CONFIG_TESTING_OPTIONS */
  562|       |
  563|    108|	os_memcpy(ptr, mic, mic_len);
  ------------------
  |  |  503|    108|#define os_memcpy(d, s, n) memcpy((d), (s), (n))
  ------------------
  564|       |
  565|  2.71k|done:
  566|  2.71k|	wpa_printf(MSG_DEBUG,
  567|  2.71k|		   "PASN: Building frame 2: success; resp STA=" MACSTR,
  ------------------
  |  |  419|  2.71k|#define MACSTR "%02x:%02x:%02x:%02x:%02x:%02x"
  ------------------
  568|  2.71k|		   MAC2STR(peer_addr));
  ------------------
  |  |  418|  2.71k|#define MAC2STR(a) (a)[0], (a)[1], (a)[2], (a)[3], (a)[4], (a)[5]
  ------------------
  569|       |
  570|  2.71k|	ret = pasn->send_mgmt(pasn->cb_ctx, wpabuf_head_u8(buf),
  571|  2.71k|			      wpabuf_len(buf), 0, 0, 0);
  572|  2.71k|	if (ret)
  ------------------
  |  Branch (572:6): [True: 0, False: 2.71k]
  ------------------
  573|      0|		wpa_printf(MSG_INFO, "send_auth_reply: Send failed");
  574|       |
  575|  2.71k|	wpabuf_free(rsn_buf);
  576|  2.71k|	wpabuf_free(buf);
  577|  2.71k|	return ret;
  578|      0|fail:
  579|      0|	wpabuf_free(wrapped_data_buf);
  580|      0|	wpabuf_free(pubkey);
  581|      0|	wpabuf_free(rsn_buf);
  582|      0|	wpabuf_free(buf);
  583|      0|	return -1;
  584|    108|}
handle_auth_pasn_1:
  590|  2.71k|{
  591|  2.71k|	struct ieee802_11_elems elems;
  592|  2.71k|	struct wpa_ie_data rsn_data;
  593|  2.71k|	struct wpa_pasn_params_data pasn_params;
  594|  2.71k|	struct rsn_pmksa_cache_entry *pmksa = NULL;
  595|  2.71k|	const u8 *cached_pmk = NULL;
  596|  2.71k|	size_t cached_pmk_len = 0;
  597|  2.71k|	struct wpabuf *wrapped_data = NULL, *secret = NULL;
  598|  2.71k|	const int *groups = pasn->pasn_groups;
  599|  2.71k|	static const int default_groups[] = { 19, 0 };
  600|  2.71k|	u16 status = WLAN_STATUS_SUCCESS;
  ------------------
  |  |  111|  2.71k|#define WLAN_STATUS_SUCCESS 0
  ------------------
  601|  2.71k|	int ret, inc_y;
  602|  2.71k|	bool derive_keys;
  603|  2.71k|	u32 i;
  604|       |
  605|  2.71k|	if (!groups)
  ------------------
  |  Branch (605:6): [True: 2.71k, False: 0]
  ------------------
  606|  2.71k|		groups = default_groups;
  607|       |
  608|  2.71k|	if (ieee802_11_parse_elems(mgmt->u.auth.variable,
  ------------------
  |  Branch (608:6): [True: 79, False: 2.63k]
  ------------------
  609|  2.71k|				   len - offsetof(struct ieee80211_mgmt,
  610|  2.71k|						  u.auth.variable),
  611|  2.71k|				   &elems, 0) == ParseFailed) {
  612|     79|		wpa_printf(MSG_DEBUG,
  613|     79|			   "PASN: Failed parsing Authentication frame");
  614|     79|		status = WLAN_STATUS_UNSPECIFIED_FAILURE;
  ------------------
  |  |  112|     79|#define WLAN_STATUS_UNSPECIFIED_FAILURE 1
  ------------------
  615|     79|		goto send_resp;
  616|     79|	}
  617|       |
  618|  2.63k|	if (!elems.rsn_ie) {
  ------------------
  |  Branch (618:6): [True: 1.45k, False: 1.18k]
  ------------------
  619|  1.45k|		wpa_printf(MSG_DEBUG, "PASN: No RSNE");
  620|  1.45k|		status = WLAN_STATUS_INVALID_RSNIE;
  ------------------
  |  |  172|  1.45k|#define WLAN_STATUS_INVALID_RSNIE 72
  ------------------
  621|  1.45k|		goto send_resp;
  622|  1.45k|	}
  623|       |
  624|  1.18k|	ret = wpa_parse_wpa_ie_rsn(elems.rsn_ie - 2, elems.rsn_ie_len + 2,
  625|  1.18k|				   &rsn_data);
  626|  1.18k|	if (ret) {
  ------------------
  |  Branch (626:6): [True: 382, False: 799]
  ------------------
  627|    382|		wpa_printf(MSG_DEBUG, "PASN: Failed parsing RSNE");
  628|    382|		status = WLAN_STATUS_INVALID_RSNIE;
  ------------------
  |  |  172|    382|#define WLAN_STATUS_INVALID_RSNIE 72
  ------------------
  629|    382|		goto send_resp;
  630|    382|	}
  631|       |
  632|    799|	ret = wpa_pasn_validate_rsne(&rsn_data);
  633|    799|	if (ret) {
  ------------------
  |  Branch (633:6): [True: 614, False: 185]
  ------------------
  634|    614|		wpa_printf(MSG_DEBUG, "PASN: Failed validating RSNE");
  635|    614|		status = WLAN_STATUS_INVALID_RSNIE;
  ------------------
  |  |  172|    614|#define WLAN_STATUS_INVALID_RSNIE 72
  ------------------
  636|    614|		goto send_resp;
  637|    614|	}
  638|       |
  639|    185|	if (!(rsn_data.key_mgmt & pasn->wpa_key_mgmt) ||
  ------------------
  |  Branch (639:6): [True: 1, False: 184]
  ------------------
  640|    185|	    !(rsn_data.pairwise_cipher & pasn->rsn_pairwise)) {
  ------------------
  |  Branch (640:6): [True: 2, False: 182]
  ------------------
  641|      3|		wpa_printf(MSG_DEBUG, "PASN: Mismatch in AKMP/cipher");
  642|      3|		status = WLAN_STATUS_INVALID_RSNIE;
  ------------------
  |  |  172|      3|#define WLAN_STATUS_INVALID_RSNIE 72
  ------------------
  643|      3|		goto send_resp;
  644|      3|	}
  645|       |
  646|    182|	pasn->akmp = rsn_data.key_mgmt;
  647|    182|	pasn->cipher = rsn_data.pairwise_cipher;
  648|       |
  649|    182|	if (pasn->derive_kdk &&
  ------------------
  |  Branch (649:6): [True: 0, False: 182]
  ------------------
  650|    182|	    ieee802_11_rsnx_capab_len(elems.rsnxe, elems.rsnxe_len,
  ------------------
  |  Branch (650:6): [True: 0, False: 0]
  ------------------
  651|      0|				      WLAN_RSNX_CAPAB_SECURE_LTF))
  ------------------
  |  |  593|      0|#define WLAN_RSNX_CAPAB_SECURE_LTF 8
  ------------------
  652|      0|		pasn->secure_ltf = true;
  653|       |
  654|    182|	if (pasn->derive_kdk)
  ------------------
  |  Branch (654:6): [True: 0, False: 182]
  ------------------
  655|      0|		pasn->kdk_len = WPA_KDK_MAX_LEN;
  ------------------
  |  |  242|      0|#define WPA_KDK_MAX_LEN 32
  ------------------
  656|    182|	else
  657|    182|		pasn->kdk_len = 0;
  658|       |
  659|    182|	wpa_printf(MSG_DEBUG, "PASN: kdk_len=%zu", pasn->kdk_len);
  660|       |
  661|    182|	if (!elems.pasn_params || !elems.pasn_params_len) {
  ------------------
  |  Branch (661:6): [True: 2, False: 180]
  |  Branch (661:28): [True: 1, False: 179]
  ------------------
  662|      3|		wpa_printf(MSG_DEBUG,
  663|      3|			   "PASN: No PASN Parameters element found");
  664|      3|		status = WLAN_STATUS_INVALID_PARAMETERS;
  ------------------
  |  |  142|      3|#define WLAN_STATUS_INVALID_PARAMETERS 38
  ------------------
  665|      3|		goto send_resp;
  666|      3|	}
  667|       |
  668|    179|	ret = wpa_pasn_parse_parameter_ie(elems.pasn_params - 3,
  669|    179|					  elems.pasn_params_len + 3,
  670|    179|					  false, &pasn_params);
  671|    179|	if (ret) {
  ------------------
  |  Branch (671:6): [True: 13, False: 166]
  ------------------
  672|     13|		wpa_printf(MSG_DEBUG,
  673|     13|			   "PASN: Failed validation of PASN Parameters IE");
  674|     13|		status = WLAN_STATUS_INVALID_PARAMETERS;
  ------------------
  |  |  142|     13|#define WLAN_STATUS_INVALID_PARAMETERS 38
  ------------------
  675|     13|		goto send_resp;
  676|     13|	}
  677|       |
  678|    192|	for (i = 0; groups[i] > 0 && groups[i] != pasn_params.group; i++)
  ------------------
  |  Branch (678:14): [True: 166, False: 26]
  |  Branch (678:31): [True: 26, False: 140]
  ------------------
  679|     26|		;
  680|       |
  681|    166|	if (!pasn_params.group || groups[i] != pasn_params.group) {
  ------------------
  |  Branch (681:6): [True: 5, False: 161]
  |  Branch (681:28): [True: 21, False: 140]
  ------------------
  682|     26|		wpa_printf(MSG_DEBUG, "PASN: Requested group=%hu not allowed",
  683|     26|			   pasn_params.group);
  684|     26|		status = WLAN_STATUS_FINITE_CYCLIC_GROUP_NOT_SUPPORTED;
  ------------------
  |  |  177|     26|#define WLAN_STATUS_FINITE_CYCLIC_GROUP_NOT_SUPPORTED 77
  ------------------
  685|     26|		goto send_resp;
  686|     26|	}
  687|       |
  688|    140|	if (!pasn_params.pubkey || !pasn_params.pubkey_len) {
  ------------------
  |  Branch (688:6): [True: 0, False: 140]
  |  Branch (688:29): [True: 1, False: 139]
  ------------------
  689|      1|		wpa_printf(MSG_DEBUG, "PASN: Invalid public key");
  690|      1|		status = WLAN_STATUS_INVALID_PARAMETERS;
  ------------------
  |  |  142|      1|#define WLAN_STATUS_INVALID_PARAMETERS 38
  ------------------
  691|      1|		goto send_resp;
  692|      1|	}
  693|       |
  694|    139|	if (pasn_params.comeback) {
  ------------------
  |  Branch (694:6): [True: 10, False: 129]
  ------------------
  695|     10|		wpa_printf(MSG_DEBUG, "PASN: Checking peer comeback token");
  696|       |
  697|     10|		ret = check_comeback_token(pasn->comeback_key,
  698|     10|					   pasn->comeback_pending_idx,
  699|     10|					   peer_addr,
  700|     10|					   pasn_params.comeback,
  701|     10|					   pasn_params.comeback_len);
  702|       |
  703|     10|		if (ret) {
  ------------------
  |  Branch (703:7): [True: 10, False: 0]
  ------------------
  704|     10|			wpa_printf(MSG_DEBUG, "PASN: Invalid comeback token");
  705|     10|			status = WLAN_STATUS_INVALID_PARAMETERS;
  ------------------
  |  |  142|     10|#define WLAN_STATUS_INVALID_PARAMETERS 38
  ------------------
  706|     10|			goto send_resp;
  707|     10|		}
  708|    129|	} else if (pasn->use_anti_clogging) {
  ------------------
  |  Branch (708:13): [True: 0, False: 129]
  ------------------
  709|      0|		wpa_printf(MSG_DEBUG, "PASN: Respond with comeback");
  710|      0|		handle_auth_pasn_comeback(pasn, own_addr, peer_addr,
  711|      0|					  pasn_params.group);
  712|      0|		return -1;
  713|      0|	}
  714|       |
  715|    129|	pasn->ecdh = crypto_ecdh_init(pasn_params.group);
  716|    129|	if (!pasn->ecdh) {
  ------------------
  |  Branch (716:6): [True: 0, False: 129]
  ------------------
  717|      0|		wpa_printf(MSG_DEBUG, "PASN: Failed to init ECDH");
  718|      0|		status = WLAN_STATUS_UNSPECIFIED_FAILURE;
  ------------------
  |  |  112|      0|#define WLAN_STATUS_UNSPECIFIED_FAILURE 1
  ------------------
  719|      0|		goto send_resp;
  720|      0|	}
  721|       |
  722|    129|	pasn->group = pasn_params.group;
  723|       |
  724|    129|	if (pasn_params.pubkey[0] == WPA_PASN_PUBKEY_UNCOMPRESSED) {
  ------------------
  |  |  624|    129|#define WPA_PASN_PUBKEY_UNCOMPRESSED 0x04
  ------------------
  |  Branch (724:6): [True: 1, False: 128]
  ------------------
  725|      1|		inc_y = 1;
  726|    128|	} else if (pasn_params.pubkey[0] == WPA_PASN_PUBKEY_COMPRESSED_0 ||
  ------------------
  |  |  622|    256|#define WPA_PASN_PUBKEY_COMPRESSED_0 0x02
  ------------------
  |  Branch (726:13): [True: 101, False: 27]
  ------------------
  727|    128|		   pasn_params.pubkey[0] == WPA_PASN_PUBKEY_COMPRESSED_1) {
  ------------------
  |  |  623|     27|#define WPA_PASN_PUBKEY_COMPRESSED_1 0x03
  ------------------
  |  Branch (727:6): [True: 10, False: 17]
  ------------------
  728|    111|		inc_y = 0;
  729|    111|	} else {
  730|     17|		wpa_printf(MSG_DEBUG,
  731|     17|			   "PASN: Invalid first octet in pubkey=0x%x",
  732|     17|			   pasn_params.pubkey[0]);
  733|     17|		status = WLAN_STATUS_INVALID_PUBLIC_KEY;
  ------------------
  |  |  212|     17|#define WLAN_STATUS_INVALID_PUBLIC_KEY 136
  ------------------
  734|     17|		goto send_resp;
  735|     17|	}
  736|       |
  737|    112|	secret = crypto_ecdh_set_peerkey(pasn->ecdh, inc_y,
  738|    112|					 pasn_params.pubkey + 1,
  739|    112|					 pasn_params.pubkey_len - 1);
  740|    112|	if (!secret) {
  ------------------
  |  Branch (740:6): [True: 2, False: 110]
  ------------------
  741|      2|		wpa_printf(MSG_DEBUG, "PASN: Failed to derive shared secret");
  742|      2|		status = WLAN_STATUS_UNSPECIFIED_FAILURE;
  ------------------
  |  |  112|      2|#define WLAN_STATUS_UNSPECIFIED_FAILURE 1
  ------------------
  743|      2|		goto send_resp;
  744|      2|	}
  745|       |
  746|    110|	derive_keys = true;
  747|    110|	if (pasn_params.wrapped_data_format != WPA_PASN_WRAPPED_DATA_NO) {
  ------------------
  |  |  598|    110|#define WPA_PASN_WRAPPED_DATA_NO      0
  ------------------
  |  Branch (747:6): [True: 106, False: 4]
  ------------------
  748|    106|		wrapped_data = ieee802_11_defrag(&elems,
  749|    106|						 WLAN_EID_EXTENSION,
  ------------------
  |  |  462|    106|#define WLAN_EID_EXTENSION 255
  ------------------
  750|    106|						 WLAN_EID_EXT_WRAPPED_DATA);
  ------------------
  |  |  472|    106|#define WLAN_EID_EXT_WRAPPED_DATA 8
  ------------------
  751|    106|		if (!wrapped_data) {
  ------------------
  |  Branch (751:7): [True: 2, False: 104]
  ------------------
  752|      2|			wpa_printf(MSG_DEBUG, "PASN: Missing wrapped data");
  753|      2|			status = WLAN_STATUS_UNSPECIFIED_FAILURE;
  ------------------
  |  |  112|      2|#define WLAN_STATUS_UNSPECIFIED_FAILURE 1
  ------------------
  754|      2|			goto send_resp;
  755|      2|		}
  756|       |
  757|    104|#ifdef CONFIG_SAE
  758|    104|		if (pasn->akmp == WPA_KEY_MGMT_SAE) {
  ------------------
  |  |   37|    104|#define WPA_KEY_MGMT_SAE BIT(10)
  |  |  ------------------
  |  |  |  |  429|    104|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (758:7): [True: 0, False: 104]
  ------------------
  759|      0|			ret = pasn_wd_handle_sae_commit(pasn, own_addr,
  760|      0|							peer_addr,
  761|      0|							wrapped_data);
  762|      0|			if (ret) {
  ------------------
  |  Branch (762:8): [True: 0, False: 0]
  ------------------
  763|      0|				wpa_printf(MSG_DEBUG,
  764|      0|					   "PASN: Failed processing SAE commit");
  765|      0|				status = WLAN_STATUS_UNSPECIFIED_FAILURE;
  ------------------
  |  |  112|      0|#define WLAN_STATUS_UNSPECIFIED_FAILURE 1
  ------------------
  766|      0|				goto send_resp;
  767|      0|			}
  768|      0|		}
  769|    104|#endif /* CONFIG_SAE */
  770|    104|#ifdef CONFIG_FILS
  771|    104|		if (pasn->akmp == WPA_KEY_MGMT_FILS_SHA256 ||
  ------------------
  |  |   45|    104|#define WPA_KEY_MGMT_FILS_SHA256 BIT(18)
  |  |  ------------------
  |  |  |  |  429|    208|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (771:7): [True: 0, False: 104]
  ------------------
  772|    104|		    pasn->akmp == WPA_KEY_MGMT_FILS_SHA384) {
  ------------------
  |  |   46|    104|#define WPA_KEY_MGMT_FILS_SHA384 BIT(19)
  |  |  ------------------
  |  |  |  |  429|    104|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (772:7): [True: 0, False: 104]
  ------------------
  773|      0|			if (!pasn->fils_wd_valid) {
  ------------------
  |  Branch (773:8): [True: 0, False: 0]
  ------------------
  774|      0|				wpa_printf(MSG_DEBUG,
  775|      0|					   "PASN: Invalid FILS wrapped data");
  776|      0|				status = WLAN_STATUS_UNSPECIFIED_FAILURE;
  ------------------
  |  |  112|      0|#define WLAN_STATUS_UNSPECIFIED_FAILURE 1
  ------------------
  777|      0|				goto send_resp;
  778|      0|			}
  779|       |
  780|      0|			wpa_printf(MSG_DEBUG,
  781|      0|				   "PASN: FILS: Pending AS response");
  782|       |
  783|       |			/*
  784|       |			 * With PASN/FILS, keys can be derived only after a
  785|       |			 * response from the AS is processed.
  786|       |			 */
  787|      0|			derive_keys = false;
  788|      0|		}
  789|    104|#endif /* CONFIG_FILS */
  790|    104|	}
  791|       |
  792|    108|	pasn->wrapped_data_format = pasn_params.wrapped_data_format;
  793|       |
  794|    108|	ret = pasn_auth_frame_hash(pasn->akmp, pasn->cipher,
  795|    108|				   ((const u8 *) mgmt) + IEEE80211_HDRLEN,
  ------------------
  |  |  932|    108|#define IEEE80211_HDRLEN (sizeof(struct ieee80211_hdr))
  ------------------
  796|    108|				   len - IEEE80211_HDRLEN, pasn->hash);
  ------------------
  |  |  932|    108|#define IEEE80211_HDRLEN (sizeof(struct ieee80211_hdr))
  ------------------
  797|    108|	if (ret) {
  ------------------
  |  Branch (797:6): [True: 0, False: 108]
  ------------------
  798|      0|		wpa_printf(MSG_DEBUG, "PASN: Failed to compute hash");
  799|      0|		status = WLAN_STATUS_UNSPECIFIED_FAILURE;
  ------------------
  |  |  112|      0|#define WLAN_STATUS_UNSPECIFIED_FAILURE 1
  ------------------
  800|      0|		goto send_resp;
  801|      0|	}
  802|       |
  803|    108|	if (!derive_keys) {
  ------------------
  |  Branch (803:6): [True: 0, False: 108]
  ------------------
  804|      0|		wpa_printf(MSG_DEBUG, "PASN: Storing secret");
  805|      0|		pasn->secret = secret;
  806|      0|		wpabuf_free(wrapped_data);
  807|      0|		return 0;
  808|      0|	}
  809|       |
  810|    108|	if (rsn_data.num_pmkid) {
  ------------------
  |  Branch (810:6): [True: 1, False: 107]
  ------------------
  811|      1|		if (wpa_key_mgmt_ft(pasn->akmp)) {
  ------------------
  |  Branch (811:7): [True: 0, False: 1]
  ------------------
  812|       |#ifdef CONFIG_IEEE80211R_AP
  813|       |			wpa_printf(MSG_DEBUG, "PASN: FT: Fetch PMK-R1");
  814|       |
  815|       |			if (!pasn->pmk_r1_len) {
  816|       |				wpa_printf(MSG_DEBUG,
  817|       |					   "PASN: FT: Failed getting PMK-R1");
  818|       |				status = WLAN_STATUS_UNSPECIFIED_FAILURE;
  819|       |				goto send_resp;
  820|       |			}
  821|       |			cached_pmk = pasn->pmk_r1;
  822|       |			cached_pmk_len = pasn->pmk_r1_len;
  823|       |#else /* CONFIG_IEEE80211R_AP */
  824|      0|			wpa_printf(MSG_DEBUG, "PASN: FT: Not supported");
  825|      0|			status = WLAN_STATUS_UNSPECIFIED_FAILURE;
  ------------------
  |  |  112|      0|#define WLAN_STATUS_UNSPECIFIED_FAILURE 1
  ------------------
  826|      0|			goto send_resp;
  827|      0|#endif /* CONFIG_IEEE80211R_AP */
  828|      1|		} else {
  829|      1|			wpa_printf(MSG_DEBUG, "PASN: Try to find PMKSA entry");
  830|       |
  831|      1|			if (pasn->pmksa) {
  ------------------
  |  Branch (831:8): [True: 0, False: 1]
  ------------------
  832|      0|				const u8 *pmkid = NULL;
  833|       |
  834|      0|				if (pasn->custom_pmkid_valid) {
  ------------------
  |  Branch (834:9): [True: 0, False: 0]
  ------------------
  835|      0|					ret = pasn->validate_custom_pmkid(
  836|      0|						pasn->cb_ctx, peer_addr,
  837|      0|						rsn_data.pmkid);
  838|      0|					if (ret) {
  ------------------
  |  Branch (838:10): [True: 0, False: 0]
  ------------------
  839|      0|						wpa_printf(MSG_DEBUG,
  840|      0|							   "PASN: Failed custom PMKID validation");
  841|      0|						status = WLAN_STATUS_UNSPECIFIED_FAILURE;
  ------------------
  |  |  112|      0|#define WLAN_STATUS_UNSPECIFIED_FAILURE 1
  ------------------
  842|      0|						goto send_resp;
  843|      0|					}
  844|      0|				} else {
  845|      0|					pmkid = rsn_data.pmkid;
  846|      0|				}
  847|       |
  848|      0|				pmksa = pmksa_cache_auth_get(pasn->pmksa,
  849|      0|							     peer_addr,
  850|      0|							     pmkid);
  851|      0|				if (pmksa) {
  ------------------
  |  Branch (851:9): [True: 0, False: 0]
  ------------------
  852|      0|					cached_pmk = pmksa->pmk;
  853|      0|					cached_pmk_len = pmksa->pmk_len;
  854|      0|				}
  855|      0|			}
  856|      1|		}
  857|    107|	} else {
  858|    107|		wpa_printf(MSG_DEBUG, "PASN: No PMKID specified");
  859|    107|	}
  860|       |
  861|    108|	ret = pasn_derive_keys(pasn, own_addr, peer_addr,
  862|    108|			       cached_pmk, cached_pmk_len,
  863|    108|			       &pasn_params, wrapped_data, secret);
  864|    108|	if (ret) {
  ------------------
  |  Branch (864:6): [True: 0, False: 108]
  ------------------
  865|      0|		wpa_printf(MSG_DEBUG, "PASN: Failed to derive keys");
  866|      0|		status = WLAN_STATUS_PASN_BASE_AKMP_FAILED;
  ------------------
  |  |  213|      0|#define WLAN_STATUS_PASN_BASE_AKMP_FAILED 137
  ------------------
  867|      0|		goto send_resp;
  868|      0|	}
  869|       |
  870|    108|	ret = pasn_auth_frame_hash(pasn->akmp, pasn->cipher,
  871|    108|				   ((const u8 *) mgmt) + IEEE80211_HDRLEN,
  ------------------
  |  |  932|    108|#define IEEE80211_HDRLEN (sizeof(struct ieee80211_hdr))
  ------------------
  872|    108|				   len - IEEE80211_HDRLEN, pasn->hash);
  ------------------
  |  |  932|    108|#define IEEE80211_HDRLEN (sizeof(struct ieee80211_hdr))
  ------------------
  873|    108|	if (ret) {
  ------------------
  |  Branch (873:6): [True: 0, False: 108]
  ------------------
  874|      0|		wpa_printf(MSG_DEBUG, "PASN: Failed to compute hash");
  875|      0|		status = WLAN_STATUS_UNSPECIFIED_FAILURE;
  ------------------
  |  |  112|      0|#define WLAN_STATUS_UNSPECIFIED_FAILURE 1
  ------------------
  876|      0|	}
  877|       |
  878|  2.71k|send_resp:
  879|  2.71k|	ret = handle_auth_pasn_resp(pasn, own_addr, peer_addr, pmksa, status);
  880|  2.71k|	if (ret) {
  ------------------
  |  Branch (880:6): [True: 0, False: 2.71k]
  ------------------
  881|      0|		wpa_printf(MSG_DEBUG, "PASN: Failed to send response");
  882|      0|		status = WLAN_STATUS_UNSPECIFIED_FAILURE;
  ------------------
  |  |  112|      0|#define WLAN_STATUS_UNSPECIFIED_FAILURE 1
  ------------------
  883|  2.71k|	} else {
  884|  2.71k|		wpa_printf(MSG_DEBUG,
  885|  2.71k|			   "PASN: Success handling transaction == 1");
  886|  2.71k|	}
  887|       |
  888|  2.71k|	wpabuf_free(secret);
  889|  2.71k|	wpabuf_free(wrapped_data);
  890|       |
  891|  2.71k|	if (status != WLAN_STATUS_SUCCESS)
  ------------------
  |  |  111|  2.71k|#define WLAN_STATUS_SUCCESS 0
  ------------------
  |  Branch (891:6): [True: 2.60k, False: 108]
  ------------------
  892|  2.60k|		return -1;
  893|       |
  894|    108|	return 0;
  895|  2.71k|}
handle_auth_pasn_3:
  901|  2.71k|{
  902|  2.71k|	struct ieee802_11_elems elems;
  903|  2.71k|	struct wpa_pasn_params_data pasn_params;
  904|  2.71k|	struct wpabuf *wrapped_data = NULL;
  905|  2.71k|	u8 mic[WPA_PASN_MAX_MIC_LEN], out_mic[WPA_PASN_MAX_MIC_LEN];
  906|  2.71k|	u8 mic_len;
  907|  2.71k|	int ret;
  908|  2.71k|	u8 *copy = NULL;
  909|  2.71k|	size_t copy_len, mic_offset;
  910|       |
  911|  2.71k|	if (ieee802_11_parse_elems(mgmt->u.auth.variable,
  ------------------
  |  Branch (911:6): [True: 79, False: 2.63k]
  ------------------
  912|  2.71k|				   len - offsetof(struct ieee80211_mgmt,
  913|  2.71k|						  u.auth.variable),
  914|  2.71k|				   &elems, 0) == ParseFailed) {
  915|     79|		wpa_printf(MSG_DEBUG,
  916|     79|			   "PASN: Failed parsing Authentication frame");
  917|     79|		goto fail;
  918|     79|	}
  919|       |
  920|       |	/* Check that the MIC IE exists. Save it and zero out the memory. */
  921|  2.63k|	mic_len = pasn_mic_len(pasn->akmp, pasn->cipher);
  922|  2.63k|	if (!elems.mic || elems.mic_len != mic_len) {
  ------------------
  |  Branch (922:6): [True: 2.40k, False: 227]
  |  Branch (922:20): [True: 10, False: 217]
  ------------------
  923|  2.41k|		wpa_printf(MSG_DEBUG,
  924|  2.41k|			   "PASN: Invalid MIC. Expecting len=%u", mic_len);
  925|  2.41k|		goto fail;
  926|  2.41k|	}
  927|    217|	os_memcpy(mic, elems.mic, mic_len);
  ------------------
  |  |  503|    217|#define os_memcpy(d, s, n) memcpy((d), (s), (n))
  ------------------
  928|       |
  929|    217|	if (!elems.pasn_params || !elems.pasn_params_len) {
  ------------------
  |  Branch (929:6): [True: 1, False: 216]
  |  Branch (929:28): [True: 1, False: 215]
  ------------------
  930|      2|		wpa_printf(MSG_DEBUG,
  931|      2|			   "PASN: No PASN Parameters element found");
  932|      2|		goto fail;
  933|      2|	}
  934|       |
  935|    215|	ret = wpa_pasn_parse_parameter_ie(elems.pasn_params - 3,
  936|    215|					  elems.pasn_params_len + 3,
  937|    215|					  false, &pasn_params);
  938|    215|	if (ret) {
  ------------------
  |  Branch (938:6): [True: 53, False: 162]
  ------------------
  939|     53|		wpa_printf(MSG_DEBUG,
  940|     53|			   "PASN: Failed validation of PASN Parameters IE");
  941|     53|		goto fail;
  942|     53|	}
  943|       |
  944|    162|	if (pasn_params.pubkey || pasn_params.pubkey_len) {
  ------------------
  |  Branch (944:6): [True: 2, False: 160]
  |  Branch (944:28): [True: 0, False: 160]
  ------------------
  945|      2|		wpa_printf(MSG_DEBUG,
  946|      2|			   "PASN: Public key should not be included");
  947|      2|		goto fail;
  948|      2|	}
  949|       |
  950|       |	/* Verify the MIC */
  951|    160|	copy_len = len - offsetof(struct ieee80211_mgmt, u.auth);
  952|    160|	mic_offset = elems.mic - (const u8 *) &mgmt->u.auth;
  953|    160|	copy_len = len - offsetof(struct ieee80211_mgmt, u.auth);
  954|    160|	if (mic_offset + mic_len > copy_len)
  ------------------
  |  Branch (954:6): [True: 0, False: 160]
  ------------------
  955|      0|		goto fail;
  956|    160|	copy = os_memdup(&mgmt->u.auth, copy_len);
  957|    160|	if (!copy)
  ------------------
  |  Branch (957:6): [True: 0, False: 160]
  ------------------
  958|      0|		goto fail;
  959|    160|	os_memset(copy + mic_offset, 0, mic_len);
  ------------------
  |  |  509|    160|#define os_memset(s, c, n) memset(s, c, n)
  ------------------
  960|    160|	ret = pasn_mic(pasn->ptk.kck, pasn->akmp, pasn->cipher,
  961|    160|		       peer_addr, own_addr,
  962|    160|		       pasn->hash, mic_len * 2,
  963|    160|		       copy, copy_len, out_mic);
  964|    160|	os_free(copy);
  ------------------
  |  |  491|    160|#define os_free(p) free((p))
  ------------------
  965|    160|	copy = NULL;
  966|       |
  967|    160|	wpa_hexdump_key(MSG_DEBUG, "PASN: Frame MIC", mic, mic_len);
  968|    160|	if (ret || os_memcmp(mic, out_mic, mic_len) != 0) {
  ------------------
  |  |  512|    160|#define os_memcmp(s1, s2, n) memcmp((s1), (s2), (n))
  ------------------
  |  Branch (968:6): [True: 0, False: 160]
  |  Branch (968:13): [True: 150, False: 10]
  ------------------
  969|    150|		wpa_printf(MSG_DEBUG, "PASN: Failed MIC verification");
  970|    150|		goto fail;
  971|    150|	}
  972|       |
  973|     10|	if (pasn_params.wrapped_data_format != WPA_PASN_WRAPPED_DATA_NO) {
  ------------------
  |  |  598|     10|#define WPA_PASN_WRAPPED_DATA_NO      0
  ------------------
  |  Branch (973:6): [True: 9, False: 1]
  ------------------
  974|      9|		wrapped_data = ieee802_11_defrag(&elems,
  975|      9|						 WLAN_EID_EXTENSION,
  ------------------
  |  |  462|      9|#define WLAN_EID_EXTENSION 255
  ------------------
  976|      9|						 WLAN_EID_EXT_WRAPPED_DATA);
  ------------------
  |  |  472|      9|#define WLAN_EID_EXT_WRAPPED_DATA 8
  ------------------
  977|       |
  978|      9|		if (!wrapped_data) {
  ------------------
  |  Branch (978:7): [True: 2, False: 7]
  ------------------
  979|      2|			wpa_printf(MSG_DEBUG, "PASN: Missing wrapped data");
  980|      2|			goto fail;
  981|      2|		}
  982|       |
  983|      7|#ifdef CONFIG_SAE
  984|      7|		if (pasn->akmp == WPA_KEY_MGMT_SAE) {
  ------------------
  |  |   37|      7|#define WPA_KEY_MGMT_SAE BIT(10)
  |  |  ------------------
  |  |  |  |  429|      7|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (984:7): [True: 0, False: 7]
  ------------------
  985|      0|			ret = pasn_wd_handle_sae_confirm(pasn, peer_addr,
  986|      0|							 wrapped_data);
  987|      0|			if (ret) {
  ------------------
  |  Branch (987:8): [True: 0, False: 0]
  ------------------
  988|      0|				wpa_printf(MSG_DEBUG,
  989|      0|					   "PASN: Failed processing SAE confirm");
  990|      0|				wpabuf_free(wrapped_data);
  991|      0|				goto fail;
  992|      0|			}
  993|      0|		}
  994|      7|#endif /* CONFIG_SAE */
  995|      7|#ifdef CONFIG_FILS
  996|      7|		if (pasn->akmp == WPA_KEY_MGMT_FILS_SHA256 ||
  ------------------
  |  |   45|      7|#define WPA_KEY_MGMT_FILS_SHA256 BIT(18)
  |  |  ------------------
  |  |  |  |  429|     14|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (996:7): [True: 0, False: 7]
  ------------------
  997|      7|		    pasn->akmp == WPA_KEY_MGMT_FILS_SHA384) {
  ------------------
  |  |   46|      7|#define WPA_KEY_MGMT_FILS_SHA384 BIT(19)
  |  |  ------------------
  |  |  |  |  429|      7|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (997:7): [True: 0, False: 7]
  ------------------
  998|      0|			if (wrapped_data) {
  ------------------
  |  Branch (998:8): [True: 0, False: 0]
  ------------------
  999|      0|				wpa_printf(MSG_DEBUG,
 1000|      0|					   "PASN: FILS: Ignore wrapped data");
 1001|      0|			}
 1002|      0|		}
 1003|      7|#endif /* CONFIG_FILS */
 1004|      7|		wpabuf_free(wrapped_data);
 1005|      7|	}
 1006|       |
 1007|      8|	wpa_printf(MSG_INFO,
 1008|      8|		   "PASN: Success handling transaction == 3. Store PTK");
 1009|      8|	return 0;
 1010|       |
 1011|  2.70k|fail:
 1012|  2.70k|	os_free(copy);
  ------------------
  |  |  491|  2.70k|#define os_free(p) free((p))
  ------------------
 1013|  2.70k|	return -1;
 1014|     10|}
pasn_responder.c:pasn_get_wrapped_data:
  259|    108|{
  260|    108|	switch (pasn->akmp) {
  261|    108|	case WPA_KEY_MGMT_PASN:
  ------------------
  |  |   52|    108|#define WPA_KEY_MGMT_PASN BIT(25)
  |  |  ------------------
  |  |  |  |  429|    108|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (261:2): [True: 108, False: 0]
  ------------------
  262|       |		/* no wrapped data */
  263|    108|		return NULL;
  264|      0|	case WPA_KEY_MGMT_SAE:
  ------------------
  |  |   37|      0|#define WPA_KEY_MGMT_SAE BIT(10)
  |  |  ------------------
  |  |  |  |  429|      0|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (264:2): [True: 0, False: 108]
  ------------------
  265|      0|#ifdef CONFIG_SAE
  266|      0|		return pasn_get_sae_wd(pasn);
  267|       |#else /* CONFIG_SAE */
  268|       |		wpa_printf(MSG_ERROR,
  269|       |			   "PASN: SAE: Cannot derive wrapped data");
  270|       |		return NULL;
  271|       |#endif /* CONFIG_SAE */
  272|      0|	case WPA_KEY_MGMT_FILS_SHA256:
  ------------------
  |  |   45|      0|#define WPA_KEY_MGMT_FILS_SHA256 BIT(18)
  |  |  ------------------
  |  |  |  |  429|      0|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (272:2): [True: 0, False: 108]
  ------------------
  273|      0|	case WPA_KEY_MGMT_FILS_SHA384:
  ------------------
  |  |   46|      0|#define WPA_KEY_MGMT_FILS_SHA384 BIT(19)
  |  |  ------------------
  |  |  |  |  429|      0|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (273:2): [True: 0, False: 108]
  ------------------
  274|      0|#ifdef CONFIG_FILS
  275|      0|		return pasn_get_fils_wd(pasn);
  276|      0|#endif /* CONFIG_FILS */
  277|       |		/* fall through */
  278|      0|	case WPA_KEY_MGMT_FT_PSK:
  ------------------
  |  |   33|      0|#define WPA_KEY_MGMT_FT_PSK BIT(6)
  |  |  ------------------
  |  |  |  |  429|      0|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (278:2): [True: 0, False: 108]
  ------------------
  279|      0|	case WPA_KEY_MGMT_FT_IEEE8021X:
  ------------------
  |  |   32|      0|#define WPA_KEY_MGMT_FT_IEEE8021X BIT(5)
  |  |  ------------------
  |  |  |  |  429|      0|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (279:2): [True: 0, False: 108]
  ------------------
  280|      0|	case WPA_KEY_MGMT_FT_IEEE8021X_SHA384:
  ------------------
  |  |   51|      0|#define WPA_KEY_MGMT_FT_IEEE8021X_SHA384 BIT(24)
  |  |  ------------------
  |  |  |  |  429|      0|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (280:2): [True: 0, False: 108]
  ------------------
  281|      0|	default:
  ------------------
  |  Branch (281:2): [True: 0, False: 108]
  ------------------
  282|      0|		wpa_printf(MSG_ERROR,
  283|      0|			   "PASN: TODO: Wrapped data for akmp=0x%x",
  284|      0|			   pasn->akmp);
  285|      0|		return NULL;
  286|    108|	}
  287|    108|}
pasn_responder.c:pasn_derive_keys:
  297|    108|{
  298|    108|	static const u8 pasn_default_pmk[] = {'P', 'M', 'K', 'z'};
  299|    108|	u8 pmk[PMK_LEN_MAX];
  300|    108|	u8 pmk_len;
  301|    108|	int ret;
  302|       |
  303|    108|	os_memset(pmk, 0, sizeof(pmk));
  ------------------
  |  |  509|    108|#define os_memset(s, c, n) memset(s, c, n)
  ------------------
  304|    108|	pmk_len = 0;
  305|       |
  306|    108|	if (!cached_pmk || !cached_pmk_len)
  ------------------
  |  Branch (306:6): [True: 108, False: 0]
  |  Branch (306:21): [True: 0, False: 0]
  ------------------
  307|    108|		wpa_printf(MSG_DEBUG, "PASN: No valid PMKSA entry");
  308|       |
  309|    108|	if (pasn->akmp == WPA_KEY_MGMT_PASN) {
  ------------------
  |  |   52|    108|#define WPA_KEY_MGMT_PASN BIT(25)
  |  |  ------------------
  |  |  |  |  429|    108|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (309:6): [True: 108, False: 0]
  ------------------
  310|    108|		wpa_printf(MSG_DEBUG, "PASN: Using default PMK");
  311|       |
  312|    108|		pmk_len = WPA_PASN_PMK_LEN;
  ------------------
  |  |   22|    108|#define WPA_PASN_PMK_LEN 32
  ------------------
  313|    108|		os_memcpy(pmk, pasn_default_pmk, sizeof(pasn_default_pmk));
  ------------------
  |  |  503|    108|#define os_memcpy(d, s, n) memcpy((d), (s), (n))
  ------------------
  314|    108|	} else if (cached_pmk && cached_pmk_len) {
  ------------------
  |  Branch (314:13): [True: 0, False: 0]
  |  Branch (314:27): [True: 0, False: 0]
  ------------------
  315|      0|		wpa_printf(MSG_DEBUG, "PASN: Using PMKSA entry");
  316|       |
  317|      0|		pmk_len = cached_pmk_len;
  318|      0|		os_memcpy(pmk, cached_pmk, cached_pmk_len);
  ------------------
  |  |  503|      0|#define os_memcpy(d, s, n) memcpy((d), (s), (n))
  ------------------
  319|      0|	} else {
  320|      0|		switch (pasn->akmp) {
  321|      0|#ifdef CONFIG_SAE
  322|      0|		case WPA_KEY_MGMT_SAE:
  ------------------
  |  |   37|      0|#define WPA_KEY_MGMT_SAE BIT(10)
  |  |  ------------------
  |  |  |  |  429|      0|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (322:3): [True: 0, False: 0]
  ------------------
  323|      0|			if (pasn->sae.state == SAE_COMMITTED) {
  ------------------
  |  Branch (323:8): [True: 0, False: 0]
  ------------------
  324|      0|				pmk_len = PMK_LEN;
  ------------------
  |  |  152|      0|#define PMK_LEN 32
  ------------------
  325|      0|				os_memcpy(pmk, pasn->sae.pmk, PMK_LEN);
  ------------------
  |  |  503|      0|#define os_memcpy(d, s, n) memcpy((d), (s), (n))
  ------------------
  326|      0|				break;
  327|      0|			}
  328|      0|#endif /* CONFIG_SAE */
  329|       |			/* fall through */
  330|      0|		default:
  ------------------
  |  Branch (330:3): [True: 0, False: 0]
  ------------------
  331|       |			/* TODO: Derive PMK based on wrapped data */
  332|      0|			wpa_printf(MSG_DEBUG,
  333|      0|				   "PASN: Missing PMK derivation");
  334|      0|			return -1;
  335|      0|		}
  336|      0|	}
  337|       |
  338|    108|	ret = pasn_pmk_to_ptk(pmk, pmk_len, peer_addr, own_addr,
  339|    108|			      wpabuf_head(secret), wpabuf_len(secret),
  340|    108|			      &pasn->ptk, pasn->akmp,
  341|    108|			      pasn->cipher, pasn->kdk_len);
  342|    108|	if (ret) {
  ------------------
  |  Branch (342:6): [True: 0, False: 108]
  ------------------
  343|      0|		wpa_printf(MSG_DEBUG, "PASN: Failed to derive PTK");
  344|      0|		return -1;
  345|      0|	}
  346|       |
  347|    108|	if (pasn->secure_ltf) {
  ------------------
  |  Branch (347:6): [True: 0, False: 108]
  ------------------
  348|      0|		ret = wpa_ltf_keyseed(&pasn->ptk, pasn->akmp,
  349|      0|				      pasn->cipher);
  350|      0|		if (ret) {
  ------------------
  |  Branch (350:7): [True: 0, False: 0]
  ------------------
  351|      0|			wpa_printf(MSG_DEBUG,
  352|      0|				   "PASN: Failed to derive LTF keyseed");
  353|      0|			return -1;
  354|      0|		}
  355|      0|	}
  356|       |
  357|    108|	wpa_printf(MSG_DEBUG, "PASN: PTK successfully derived");
  358|    108|	return 0;
  359|    108|}

hex2num:
   17|  65.1k|{
   18|  65.1k|	if (c >= '0' && c <= '9')
  ------------------
  |  Branch (18:6): [True: 65.1k, False: 0]
  |  Branch (18:18): [True: 65.1k, False: 0]
  ------------------
   19|  65.1k|		return c - '0';
   20|      0|	if (c >= 'a' && c <= 'f')
  ------------------
  |  Branch (20:6): [True: 0, False: 0]
  |  Branch (20:18): [True: 0, False: 0]
  ------------------
   21|      0|		return c - 'a' + 10;
   22|      0|	if (c >= 'A' && c <= 'F')
  ------------------
  |  Branch (22:6): [True: 0, False: 0]
  |  Branch (22:18): [True: 0, False: 0]
  ------------------
   23|      0|		return c - 'A' + 10;
   24|      0|	return -1;
   25|      0|}
hex2byte:
   29|  32.5k|{
   30|  32.5k|	int a, b;
   31|  32.5k|	a = hex2num(*hex++);
   32|  32.5k|	if (a < 0)
  ------------------
  |  Branch (32:6): [True: 0, False: 32.5k]
  ------------------
   33|      0|		return -1;
   34|  32.5k|	b = hex2num(*hex++);
   35|  32.5k|	if (b < 0)
  ------------------
  |  Branch (35:6): [True: 0, False: 32.5k]
  ------------------
   36|      0|		return -1;
   37|  32.5k|	return (a << 4) | b;
   38|  32.5k|}
hwaddr_aton:
   67|  5.42k|{
   68|  5.42k|	return hwaddr_parse(txt, addr) ? 0 : -1;
  ------------------
  |  Branch (68:9): [True: 5.42k, False: 0]
  ------------------
   69|  5.42k|}
bin_clear_free:
 1004|    376|{
 1005|    376|	if (bin) {
  ------------------
  |  Branch (1005:6): [True: 376, False: 0]
  ------------------
 1006|    376|		forced_memzero(bin, len);
 1007|    376|		os_free(bin);
  ------------------
  |  |  491|    376|#define os_free(p) free((p))
  ------------------
 1008|    376|	}
 1009|    376|}
forced_memzero:
 1300|    592|{
 1301|    592|	memset_func(ptr, 0, len);
 1302|    592|	if (len)
  ------------------
  |  Branch (1302:6): [True: 592, False: 0]
  ------------------
 1303|    592|		forced_memzero_val = ((u8 *) ptr)[0];
 1304|    592|}
common.c:hwaddr_parse:
   42|  5.42k|{
   43|  5.42k|	size_t i;
   44|       |
   45|  37.9k|	for (i = 0; i < ETH_ALEN; i++) {
  ------------------
  |  |  315|  37.9k|#define ETH_ALEN 6
  ------------------
  |  Branch (45:14): [True: 32.5k, False: 5.42k]
  ------------------
   46|  32.5k|		int a;
   47|       |
   48|  32.5k|		a = hex2byte(txt);
   49|  32.5k|		if (a < 0)
  ------------------
  |  Branch (49:7): [True: 0, False: 32.5k]
  ------------------
   50|      0|			return NULL;
   51|  32.5k|		txt += 2;
   52|  32.5k|		addr[i] = a;
   53|  32.5k|		if (i < ETH_ALEN - 1 && *txt++ != ':')
  ------------------
  |  |  315|  32.5k|#define ETH_ALEN 6
  ------------------
  |  Branch (53:7): [True: 27.1k, False: 5.42k]
  |  Branch (53:27): [True: 0, False: 27.1k]
  ------------------
   54|      0|			return NULL;
   55|  32.5k|	}
   56|  5.42k|	return txt;
   57|  5.42k|}

wpa_common.c:WPA_GET_BE32:
  248|  64.5k|{
  249|  64.5k|	return ((u32) a[0] << 24) | (a[1] << 16) | (a[2] << 8) | a[3];
  250|  64.5k|}
wpa_common.c:WPA_GET_LE16:
  225|  3.97k|{
  226|  3.97k|	return (a[1] << 8) | a[0];
  227|  3.97k|}
wpa_common.c:WPA_PUT_LE16:
  230|  1.18k|{
  231|  1.18k|	a[1] = val >> 8;
  232|  1.18k|	a[0] = val & 0xff;
  233|  1.18k|}
wpa_common.c:WPA_PUT_BE32:
  253|    864|{
  254|    864|	a[0] = (val >> 24) & 0xff;
  255|    864|	a[1] = (val >> 16) & 0xff;
  256|    864|	a[2] = (val >> 8) & 0xff;
  257|    864|	a[3] = val & 0xff;
  258|    864|}
ieee802_11_common.c:WPA_GET_BE24:
  236|  18.6k|{
  237|  18.6k|	return (a[0] << 16) | (a[1] << 8) | a[2];
  238|  18.6k|}
sha256-prf.c:WPA_PUT_LE16:
  230|    324|{
  231|    324|	a[1] = val >> 8;
  232|    324|	a[0] = val & 0xff;
  233|    324|}

eloop_init:
  164|  2.71k|{
  165|  2.71k|	os_memset(&eloop, 0, sizeof(eloop));
  ------------------
  |  |  509|  2.71k|#define os_memset(s, c, n) memset(s, c, n)
  ------------------
  166|  2.71k|	dl_list_init(&eloop.timeout);
  167|       |#ifdef CONFIG_ELOOP_EPOLL
  168|       |	eloop.epollfd = epoll_create1(0);
  169|       |	if (eloop.epollfd < 0) {
  170|       |		wpa_printf(MSG_ERROR, "%s: epoll_create1 failed. %s",
  171|       |			   __func__, strerror(errno));
  172|       |		return -1;
  173|       |	}
  174|       |#endif /* CONFIG_ELOOP_EPOLL */
  175|       |#ifdef CONFIG_ELOOP_KQUEUE
  176|       |	eloop.kqueuefd = kqueue();
  177|       |	if (eloop.kqueuefd < 0) {
  178|       |		wpa_printf(MSG_ERROR, "%s: kqueue failed: %s",
  179|       |			   __func__, strerror(errno));
  180|       |		return -1;
  181|       |	}
  182|       |#endif /* CONFIG_ELOOP_KQUEUE */
  183|       |#if defined(CONFIG_ELOOP_EPOLL) || defined(CONFIG_ELOOP_KQUEUE)
  184|       |	eloop.readers.type = EVENT_TYPE_READ;
  185|       |	eloop.writers.type = EVENT_TYPE_WRITE;
  186|       |	eloop.exceptions.type = EVENT_TYPE_EXCEPTION;
  187|       |#endif /* CONFIG_ELOOP_EPOLL || CONFIG_ELOOP_KQUEUE */
  188|       |#ifdef WPA_TRACE
  189|       |	signal(SIGSEGV, eloop_sigsegv_handler);
  190|       |#endif /* WPA_TRACE */
  191|  2.71k|	return 0;
  192|  2.71k|}
eloop_destroy:
 1263|  2.71k|{
 1264|  2.71k|	struct eloop_timeout *timeout, *prev;
 1265|  2.71k|	struct os_reltime now;
 1266|       |
 1267|  2.71k|	os_get_reltime(&now);
 1268|  2.71k|	dl_list_for_each_safe(timeout, prev, &eloop.timeout,
  ------------------
  |  |   84|  2.71k|	for (item = dl_list_entry((list)->next, type, member), \
  |  |  ------------------
  |  |  |  |   68|  2.71k|	((type *) ((char *) item - offsetof(type, member)))
  |  |  ------------------
  |  |   85|  2.71k|		     n = dl_list_entry(item->member.next, type, member); \
  |  |  ------------------
  |  |  |  |   68|  2.71k|	((type *) ((char *) item - offsetof(type, member)))
  |  |  ------------------
  |  |   86|  2.71k|	     &item->member != (list); \
  |  |  ------------------
  |  |  |  Branch (86:7): [True: 0, False: 2.71k]
  |  |  ------------------
  |  |   87|  2.71k|	     item = n, n = dl_list_entry(n->member.next, type, member))
  |  |  ------------------
  |  |  |  |   68|      0|	((type *) ((char *) item - offsetof(type, member)))
  |  |  ------------------
  ------------------
 1269|  2.71k|			      struct eloop_timeout, list) {
 1270|      0|		int sec, usec;
 1271|      0|		sec = timeout->time.sec - now.sec;
 1272|      0|		usec = timeout->time.usec - now.usec;
 1273|      0|		if (timeout->time.usec < now.usec) {
  ------------------
  |  Branch (1273:7): [True: 0, False: 0]
  ------------------
 1274|      0|			sec--;
 1275|      0|			usec += 1000000;
 1276|      0|		}
 1277|      0|		wpa_printf(MSG_INFO, "ELOOP: remaining timeout: %d.%06d "
 1278|      0|			   "eloop_data=%p user_data=%p handler=%p",
 1279|      0|			   sec, usec, timeout->eloop_data, timeout->user_data,
 1280|      0|			   timeout->handler);
 1281|      0|		wpa_trace_dump_funcname("eloop unregistered timeout handler",
  ------------------
  |  |   65|      0|#define wpa_trace_dump_funcname(title, pc) do { } while (0)
  |  |  ------------------
  |  |  |  Branch (65:58): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1282|      0|					timeout->handler);
 1283|      0|		wpa_trace_dump("eloop timeout", timeout);
  ------------------
  |  |   49|      0|#define wpa_trace_dump(title, ptr) do { } while (0)
  |  |  ------------------
  |  |  |  Branch (49:50): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1284|      0|		eloop_remove_timeout(timeout);
 1285|      0|	}
 1286|  2.71k|	eloop_sock_table_destroy(&eloop.readers);
 1287|  2.71k|	eloop_sock_table_destroy(&eloop.writers);
 1288|  2.71k|	eloop_sock_table_destroy(&eloop.exceptions);
 1289|  2.71k|	os_free(eloop.signals);
  ------------------
  |  |  491|  2.71k|#define os_free(p) free((p))
  ------------------
 1290|       |
 1291|       |#ifdef CONFIG_ELOOP_POLL
 1292|       |	os_free(eloop.pollfds);
 1293|       |	os_free(eloop.pollfds_map);
 1294|       |#endif /* CONFIG_ELOOP_POLL */
 1295|       |#if defined(CONFIG_ELOOP_EPOLL) || defined(CONFIG_ELOOP_KQUEUE)
 1296|       |	os_free(eloop.fd_table);
 1297|       |#endif /* CONFIG_ELOOP_EPOLL || CONFIG_ELOOP_KQUEUE */
 1298|       |#ifdef CONFIG_ELOOP_EPOLL
 1299|       |	os_free(eloop.epoll_events);
 1300|       |	close(eloop.epollfd);
 1301|       |#endif /* CONFIG_ELOOP_EPOLL */
 1302|       |#ifdef CONFIG_ELOOP_KQUEUE
 1303|       |	os_free(eloop.kqueue_events);
 1304|       |	close(eloop.kqueuefd);
 1305|       |#endif /* CONFIG_ELOOP_KQUEUE */
 1306|  2.71k|}
eloop.c:eloop_sock_table_destroy:
  699|  8.14k|{
  700|  8.14k|	if (table) {
  ------------------
  |  Branch (700:6): [True: 8.14k, False: 0]
  ------------------
  701|  8.14k|		size_t i;
  702|       |
  703|  8.14k|		for (i = 0; i < table->count && table->table; i++) {
  ------------------
  |  Branch (703:15): [True: 0, False: 8.14k]
  |  Branch (703:35): [True: 0, False: 0]
  ------------------
  704|      0|			wpa_printf(MSG_INFO, "ELOOP: remaining socket: "
  705|      0|				   "sock=%d eloop_data=%p user_data=%p "
  706|      0|				   "handler=%p",
  707|      0|				   table->table[i].sock,
  708|      0|				   table->table[i].eloop_data,
  709|      0|				   table->table[i].user_data,
  710|      0|				   table->table[i].handler);
  711|      0|			wpa_trace_dump_funcname("eloop unregistered socket "
  ------------------
  |  |   65|      0|#define wpa_trace_dump_funcname(title, pc) do { } while (0)
  |  |  ------------------
  |  |  |  Branch (65:58): [Folded - Ignored]
  |  |  ------------------
  ------------------
  712|      0|						"handler",
  713|      0|						table->table[i].handler);
  714|      0|			wpa_trace_dump("eloop sock", &table->table[i]);
  ------------------
  |  |   49|      0|#define wpa_trace_dump(title, ptr) do { } while (0)
  |  |  ------------------
  |  |  |  Branch (49:50): [Folded - Ignored]
  |  |  ------------------
  ------------------
  715|      0|		}
  716|  8.14k|		os_free(table->table);
  ------------------
  |  |  491|  8.14k|#define os_free(p) free((p))
  ------------------
  717|  8.14k|	}
  718|  8.14k|}

eloop.c:dl_list_init:
   23|  2.71k|{
   24|  2.71k|	list->next = list;
   25|  2.71k|	list->prev = list;
   26|  2.71k|}

os_get_reltime:
   77|  2.71k|{
   78|  2.71k|#ifndef __MACH__
   79|  2.71k|#if defined(CLOCK_BOOTTIME)
   80|  2.71k|	static clockid_t clock_id = CLOCK_BOOTTIME;
   81|       |#elif defined(CLOCK_MONOTONIC)
   82|       |	static clockid_t clock_id = CLOCK_MONOTONIC;
   83|       |#else
   84|       |	static clockid_t clock_id = CLOCK_REALTIME;
   85|       |#endif
   86|  2.71k|	struct timespec ts;
   87|  2.71k|	int res;
   88|       |
   89|  2.71k|	if (TEST_FAIL())
  ------------------
  |  |  677|  2.71k|#define TEST_FAIL() 0
  |  |  ------------------
  |  |  |  Branch (677:21): [Folded - Ignored]
  |  |  ------------------
  ------------------
   90|      0|		return -1;
   91|       |
   92|  2.71k|	while (1) {
  ------------------
  |  Branch (92:9): [Folded - Ignored]
  ------------------
   93|  2.71k|		res = clock_gettime(clock_id, &ts);
   94|  2.71k|		if (res == 0) {
  ------------------
  |  Branch (94:7): [True: 2.71k, False: 0]
  ------------------
   95|  2.71k|			t->sec = ts.tv_sec;
   96|  2.71k|			t->usec = ts.tv_nsec / 1000;
   97|  2.71k|			return 0;
   98|  2.71k|		}
   99|      0|		switch (clock_id) {
  ------------------
  |  Branch (99:11): [True: 0, False: 0]
  ------------------
  100|      0|#ifdef CLOCK_BOOTTIME
  101|      0|		case CLOCK_BOOTTIME:
  ------------------
  |  Branch (101:3): [True: 0, False: 0]
  ------------------
  102|      0|			clock_id = CLOCK_MONOTONIC;
  103|      0|			break;
  104|      0|#endif
  105|      0|#ifdef CLOCK_MONOTONIC
  106|      0|		case CLOCK_MONOTONIC:
  ------------------
  |  Branch (106:3): [True: 0, False: 0]
  ------------------
  107|      0|			clock_id = CLOCK_REALTIME;
  108|      0|			break;
  109|      0|#endif
  110|      0|		case CLOCK_REALTIME:
  ------------------
  |  Branch (110:3): [True: 0, False: 0]
  ------------------
  111|      0|			return -1;
  112|      0|		}
  113|      0|	}
  114|       |#else /* __MACH__ */
  115|       |	uint64_t abstime, nano;
  116|       |	static mach_timebase_info_data_t info = { 0, 0 };
  117|       |
  118|       |	if (!info.denom) {
  119|       |		if (mach_timebase_info(&info) != KERN_SUCCESS)
  120|       |			return -1;
  121|       |	}
  122|       |
  123|       |	abstime = mach_absolute_time();
  124|       |	nano = (abstime * info.numer) / info.denom;
  125|       |
  126|       |	t->sec = nano / NSEC_PER_SEC;
  127|       |	t->usec = (nano - (((uint64_t) t->sec) * NSEC_PER_SEC)) / NSEC_PER_USEC;
  128|       |
  129|       |	return 0;
  130|       |#endif /* __MACH__ */
  131|  2.71k|}
os_get_random:
  258|  2.71k|{
  259|  2.71k|#ifdef TEST_FUZZ
  260|  2.71k|	size_t i;
  261|       |
  262|  13.5k|	for (i = 0; i < len; i++)
  ------------------
  |  Branch (262:14): [True: 10.8k, False: 2.71k]
  ------------------
  263|  10.8k|		buf[i] = i & 0xff;
  264|  2.71k|	return 0;
  265|       |#else /* TEST_FUZZ */
  266|       |	FILE *f;
  267|       |	size_t rc;
  268|       |
  269|       |	if (TEST_FAIL())
  270|       |		return -1;
  271|       |
  272|       |	f = fopen("/dev/urandom", "rb");
  273|       |	if (f == NULL) {
  274|       |		printf("Could not open /dev/urandom.\n");
  275|       |		return -1;
  276|       |	}
  277|       |
  278|       |	rc = fread(buf, 1, len, f);
  279|       |	fclose(f);
  280|       |
  281|       |	return rc != len ? -1 : 0;
  282|       |#endif /* TEST_FUZZ */
  283|  2.71k|}
os_program_init:
  339|  2.71k|{
  340|  2.71k|	unsigned int seed;
  341|       |
  342|       |#ifdef ANDROID
  343|       |	/*
  344|       |	 * We ignore errors here since errors are normal if we
  345|       |	 * are already running as non-root.
  346|       |	 */
  347|       |#ifdef ANDROID_SETGROUPS_OVERRIDE
  348|       |	gid_t groups[] = { ANDROID_SETGROUPS_OVERRIDE };
  349|       |#else /* ANDROID_SETGROUPS_OVERRIDE */
  350|       |	gid_t groups[] = { AID_INET, AID_WIFI, AID_KEYSTORE };
  351|       |#endif /* ANDROID_SETGROUPS_OVERRIDE */
  352|       |	struct __user_cap_header_struct header;
  353|       |	struct __user_cap_data_struct cap;
  354|       |
  355|       |	setgroups(ARRAY_SIZE(groups), groups);
  356|       |
  357|       |	prctl(PR_SET_KEEPCAPS, 1, 0, 0, 0);
  358|       |
  359|       |	setgid(AID_WIFI);
  360|       |	setuid(AID_WIFI);
  361|       |
  362|       |	header.version = _LINUX_CAPABILITY_VERSION;
  363|       |	header.pid = 0;
  364|       |	cap.effective = cap.permitted =
  365|       |		(1 << CAP_NET_ADMIN) | (1 << CAP_NET_RAW);
  366|       |	cap.inheritable = 0;
  367|       |	capset(&header, &cap);
  368|       |#endif /* ANDROID */
  369|       |
  370|  2.71k|	if (os_get_random((unsigned char *) &seed, sizeof(seed)) == 0)
  ------------------
  |  Branch (370:6): [True: 2.71k, False: 0]
  ------------------
  371|  2.71k|		srandom(seed);
  372|       |
  373|  2.71k|	return 0;
  374|  2.71k|}
os_program_deinit:
  378|  2.71k|{
  379|       |#ifdef WPA_TRACE
  380|       |	struct os_alloc_trace *a;
  381|       |	unsigned long total = 0;
  382|       |	dl_list_for_each(a, &alloc_list, struct os_alloc_trace, list) {
  383|       |		total += a->len;
  384|       |		if (a->magic != ALLOC_MAGIC) {
  385|       |			wpa_printf(MSG_INFO, "MEMLEAK[%p]: invalid magic 0x%x "
  386|       |				   "len %lu",
  387|       |				   a, a->magic, (unsigned long) a->len);
  388|       |			continue;
  389|       |		}
  390|       |		wpa_printf(MSG_INFO, "MEMLEAK[%p]: len %lu",
  391|       |			   a, (unsigned long) a->len);
  392|       |		wpa_trace_dump("memleak", a);
  393|       |	}
  394|       |	if (total)
  395|       |		wpa_printf(MSG_INFO, "MEMLEAK: total %lu bytes",
  396|       |			   (unsigned long) total);
  397|       |	wpa_trace_deinit();
  398|       |#endif /* WPA_TRACE */
  399|  2.71k|}
os_zalloc:
  485|  3.78k|{
  486|  3.78k|	return calloc(1, size);
  487|  3.78k|}
os_memdup:
  531|    160|{
  532|    160|	void *r = os_malloc(len);
  ------------------
  |  |  485|    160|#define os_malloc(s) malloc((s))
  ------------------
  533|       |
  534|    160|	if (r && src)
  ------------------
  |  Branch (534:6): [True: 160, False: 0]
  |  Branch (534:11): [True: 160, False: 0]
  ------------------
  535|    160|		os_memcpy(r, src, len);
  ------------------
  |  |  503|    160|#define os_memcpy(d, s, n) memcpy((d), (s), (n))
  ------------------
  536|    160|	return r;
  537|    160|}

wpa_printf:
  210|  5.04M|{
  211|  5.04M|	va_list ap;
  212|       |
  213|  5.04M|	if (level >= wpa_debug_level) {
  ------------------
  |  Branch (213:6): [True: 0, False: 5.04M]
  ------------------
  214|       |#ifdef CONFIG_ANDROID_LOG
  215|       |		va_start(ap, fmt);
  216|       |		__android_log_vprint(wpa_to_android_level(level),
  217|       |				     ANDROID_LOG_NAME, fmt, ap);
  218|       |		va_end(ap);
  219|       |#else /* CONFIG_ANDROID_LOG */
  220|       |#ifdef CONFIG_DEBUG_SYSLOG
  221|       |		if (wpa_debug_syslog) {
  222|       |			va_start(ap, fmt);
  223|       |			vsyslog(syslog_priority(level), fmt, ap);
  224|       |			va_end(ap);
  225|       |		}
  226|       |#endif /* CONFIG_DEBUG_SYSLOG */
  227|      0|		wpa_debug_print_timestamp();
  228|       |#ifdef CONFIG_DEBUG_FILE
  229|       |		if (out_file) {
  230|       |			va_start(ap, fmt);
  231|       |			vfprintf(out_file, fmt, ap);
  232|       |			fprintf(out_file, "\n");
  233|       |			va_end(ap);
  234|       |		}
  235|       |#endif /* CONFIG_DEBUG_FILE */
  236|      0|		if (!wpa_debug_syslog && !out_file) {
  ------------------
  |  Branch (236:7): [True: 0, False: 0]
  |  Branch (236:28): [True: 0, False: 0]
  ------------------
  237|      0|			va_start(ap, fmt);
  238|      0|			vprintf(fmt, ap);
  239|      0|			printf("\n");
  240|      0|			va_end(ap);
  241|      0|		}
  242|      0|#endif /* CONFIG_ANDROID_LOG */
  243|      0|	}
  244|       |
  245|       |#ifdef CONFIG_DEBUG_LINUX_TRACING
  246|       |	if (wpa_debug_tracing_file != NULL) {
  247|       |		va_start(ap, fmt);
  248|       |		fprintf(wpa_debug_tracing_file, WPAS_TRACE_PFX, level);
  249|       |		vfprintf(wpa_debug_tracing_file, fmt, ap);
  250|       |		fprintf(wpa_debug_tracing_file, "\n");
  251|       |		fflush(wpa_debug_tracing_file);
  252|       |		va_end(ap);
  253|       |	}
  254|       |#endif /* CONFIG_DEBUG_LINUX_TRACING */
  255|  5.04M|}
wpa_hexdump:
  386|     17|{
  387|     17|	_wpa_hexdump(level, title, buf, len, 1, 0);
  388|     17|}
wpa_hexdump_key:
  392|  2.04k|{
  393|  2.04k|	_wpa_hexdump(level, title, buf, len, wpa_debug_show_keys, 0);
  394|  2.04k|}
wpa_debug.c:_wpa_hexdump:
  260|  2.05k|{
  261|  2.05k|	size_t i;
  262|       |
  263|       |#ifdef CONFIG_DEBUG_LINUX_TRACING
  264|       |	if (wpa_debug_tracing_file != NULL) {
  265|       |		fprintf(wpa_debug_tracing_file,
  266|       |			WPAS_TRACE_PFX "%s - hexdump(len=%lu):",
  267|       |			level, title, (unsigned long) len);
  268|       |		if (buf == NULL) {
  269|       |			fprintf(wpa_debug_tracing_file, " [NULL]\n");
  270|       |		} else if (!show) {
  271|       |			fprintf(wpa_debug_tracing_file, " [REMOVED]\n");
  272|       |		} else {
  273|       |			for (i = 0; i < len; i++)
  274|       |				fprintf(wpa_debug_tracing_file,
  275|       |					" %02x", buf[i]);
  276|       |		}
  277|       |		fflush(wpa_debug_tracing_file);
  278|       |	}
  279|       |#endif /* CONFIG_DEBUG_LINUX_TRACING */
  280|       |
  281|  2.05k|	if (level < wpa_debug_level)
  ------------------
  |  Branch (281:6): [True: 2.05k, False: 0]
  ------------------
  282|  2.05k|		return;
  283|       |#ifdef CONFIG_ANDROID_LOG
  284|       |	{
  285|       |		const char *display;
  286|       |		char *strbuf = NULL;
  287|       |		size_t slen = len;
  288|       |		if (buf == NULL) {
  289|       |			display = " [NULL]";
  290|       |		} else if (len == 0) {
  291|       |			display = "";
  292|       |		} else if (show && len) {
  293|       |			/* Limit debug message length for Android log */
  294|       |			if (slen > 32)
  295|       |				slen = 32;
  296|       |			strbuf = os_malloc(1 + 3 * slen);
  297|       |			if (strbuf == NULL) {
  298|       |				wpa_printf(MSG_ERROR, "wpa_hexdump: Failed to "
  299|       |					   "allocate message buffer");
  300|       |				return;
  301|       |			}
  302|       |
  303|       |			for (i = 0; i < slen; i++)
  304|       |				os_snprintf(&strbuf[i * 3], 4, " %02x",
  305|       |					    buf[i]);
  306|       |
  307|       |			display = strbuf;
  308|       |		} else {
  309|       |			display = " [REMOVED]";
  310|       |		}
  311|       |
  312|       |		__android_log_print(wpa_to_android_level(level),
  313|       |				    ANDROID_LOG_NAME,
  314|       |				    "%s - hexdump(len=%lu):%s%s",
  315|       |				    title, (long unsigned int) len, display,
  316|       |				    len > slen ? " ..." : "");
  317|       |		bin_clear_free(strbuf, 1 + 3 * slen);
  318|       |		return;
  319|       |	}
  320|       |#else /* CONFIG_ANDROID_LOG */
  321|       |#ifdef CONFIG_DEBUG_SYSLOG
  322|       |	if (wpa_debug_syslog) {
  323|       |		const char *display;
  324|       |		char *strbuf = NULL;
  325|       |
  326|       |		if (buf == NULL) {
  327|       |			display = " [NULL]";
  328|       |		} else if (len == 0) {
  329|       |			display = "";
  330|       |		} else if (show && len) {
  331|       |			strbuf = os_malloc(1 + 3 * len);
  332|       |			if (strbuf == NULL) {
  333|       |				wpa_printf(MSG_ERROR, "wpa_hexdump: Failed to "
  334|       |					   "allocate message buffer");
  335|       |				return;
  336|       |			}
  337|       |
  338|       |			for (i = 0; i < len; i++)
  339|       |				os_snprintf(&strbuf[i * 3], 4, " %02x",
  340|       |					    buf[i]);
  341|       |
  342|       |			display = strbuf;
  343|       |		} else {
  344|       |			display = " [REMOVED]";
  345|       |		}
  346|       |
  347|       |		syslog(syslog_priority(level), "%s - hexdump(len=%lu):%s",
  348|       |		       title, (unsigned long) len, display);
  349|       |		bin_clear_free(strbuf, 1 + 3 * len);
  350|       |		if (only_syslog)
  351|       |			return;
  352|       |	}
  353|       |#endif /* CONFIG_DEBUG_SYSLOG */
  354|      0|	wpa_debug_print_timestamp();
  355|       |#ifdef CONFIG_DEBUG_FILE
  356|       |	if (out_file) {
  357|       |		fprintf(out_file, "%s - hexdump(len=%lu):",
  358|       |			title, (unsigned long) len);
  359|       |		if (buf == NULL) {
  360|       |			fprintf(out_file, " [NULL]");
  361|       |		} else if (show) {
  362|       |			for (i = 0; i < len; i++)
  363|       |				fprintf(out_file, " %02x", buf[i]);
  364|       |		} else {
  365|       |			fprintf(out_file, " [REMOVED]");
  366|       |		}
  367|       |		fprintf(out_file, "\n");
  368|       |	}
  369|       |#endif /* CONFIG_DEBUG_FILE */
  370|      0|	if (!wpa_debug_syslog && !out_file) {
  ------------------
  |  Branch (370:6): [True: 0, False: 0]
  |  Branch (370:27): [True: 0, False: 0]
  ------------------
  371|      0|		printf("%s - hexdump(len=%lu):", title, (unsigned long) len);
  372|      0|		if (buf == NULL) {
  ------------------
  |  Branch (372:7): [True: 0, False: 0]
  ------------------
  373|      0|			printf(" [NULL]");
  374|      0|		} else if (show) {
  ------------------
  |  Branch (374:14): [True: 0, False: 0]
  ------------------
  375|      0|			for (i = 0; i < len; i++)
  ------------------
  |  Branch (375:16): [True: 0, False: 0]
  ------------------
  376|      0|				printf(" %02x", buf[i]);
  377|      0|		} else {
  378|      0|			printf(" [REMOVED]");
  379|      0|		}
  380|      0|		printf("\n");
  381|      0|	}
  382|      0|#endif /* CONFIG_ANDROID_LOG */
  383|      0|}

wpabuf_resize:
   48|  3.18k|{
   49|  3.18k|	struct wpabuf *buf = *_buf;
   50|       |#ifdef WPA_TRACE
   51|       |	struct wpabuf_trace *trace;
   52|       |#endif /* WPA_TRACE */
   53|       |
   54|  3.18k|	if (buf == NULL) {
  ------------------
  |  Branch (54:6): [True: 0, False: 3.18k]
  ------------------
   55|      0|		*_buf = wpabuf_alloc(add_len);
   56|      0|		return *_buf == NULL ? -1 : 0;
  ------------------
  |  Branch (56:10): [True: 0, False: 0]
  ------------------
   57|      0|	}
   58|       |
   59|       |#ifdef WPA_TRACE
   60|       |	trace = wpabuf_get_trace(buf);
   61|       |	if (trace->magic != WPABUF_MAGIC) {
   62|       |		wpa_printf(MSG_ERROR, "wpabuf: invalid magic %x",
   63|       |			   trace->magic);
   64|       |		wpa_trace_show("wpabuf_resize invalid magic");
   65|       |		abort();
   66|       |	}
   67|       |#endif /* WPA_TRACE */
   68|       |
   69|  3.18k|	if (buf->used + add_len > buf->size) {
  ------------------
  |  Branch (69:6): [True: 3.18k, False: 0]
  ------------------
   70|  3.18k|		unsigned char *nbuf;
   71|  3.18k|		if (buf->flags & WPABUF_FLAG_EXT_DATA) {
  ------------------
  |  |   13|  3.18k|#define WPABUF_FLAG_EXT_DATA BIT(0)
  |  |  ------------------
  |  |  |  |  429|  3.18k|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (71:7): [True: 0, False: 3.18k]
  ------------------
   72|      0|			nbuf = os_realloc(buf->buf, buf->used + add_len);
  ------------------
  |  |  488|      0|#define os_realloc(p, s) realloc((p), (s))
  ------------------
   73|      0|			if (nbuf == NULL)
  ------------------
  |  Branch (73:8): [True: 0, False: 0]
  ------------------
   74|      0|				return -1;
   75|      0|			os_memset(nbuf + buf->used, 0, add_len);
  ------------------
  |  |  509|      0|#define os_memset(s, c, n) memset(s, c, n)
  ------------------
   76|      0|			buf->buf = nbuf;
   77|  3.18k|		} else {
   78|       |#ifdef WPA_TRACE
   79|       |			nbuf = os_realloc(trace, sizeof(struct wpabuf_trace) +
   80|       |					  sizeof(struct wpabuf) +
   81|       |					  buf->used + add_len);
   82|       |			if (nbuf == NULL)
   83|       |				return -1;
   84|       |			trace = (struct wpabuf_trace *) nbuf;
   85|       |			buf = (struct wpabuf *) (trace + 1);
   86|       |			os_memset(nbuf + sizeof(struct wpabuf_trace) +
   87|       |				  sizeof(struct wpabuf) + buf->used, 0,
   88|       |				  add_len);
   89|       |#else /* WPA_TRACE */
   90|  3.18k|			nbuf = os_realloc(buf, sizeof(struct wpabuf) +
  ------------------
  |  |  488|  3.18k|#define os_realloc(p, s) realloc((p), (s))
  ------------------
   91|  3.18k|					  buf->used + add_len);
   92|  3.18k|			if (nbuf == NULL)
  ------------------
  |  Branch (92:8): [True: 0, False: 3.18k]
  ------------------
   93|      0|				return -1;
   94|  3.18k|			buf = (struct wpabuf *) nbuf;
   95|  3.18k|			os_memset(nbuf + sizeof(struct wpabuf) + buf->used, 0,
  ------------------
  |  |  509|  3.18k|#define os_memset(s, c, n) memset(s, c, n)
  ------------------
   96|  3.18k|				  add_len);
   97|  3.18k|#endif /* WPA_TRACE */
   98|  3.18k|			buf->buf = (u8 *) (buf + 1);
   99|  3.18k|			*_buf = buf;
  100|  3.18k|		}
  101|  3.18k|		buf->size = buf->used + add_len;
  102|  3.18k|	}
  103|       |
  104|  3.18k|	return 0;
  105|  3.18k|}
wpabuf_alloc:
  114|  3.15k|{
  115|       |#ifdef WPA_TRACE
  116|       |	struct wpabuf_trace *trace = os_zalloc(sizeof(struct wpabuf_trace) +
  117|       |					       sizeof(struct wpabuf) + len);
  118|       |	struct wpabuf *buf;
  119|       |	if (trace == NULL)
  120|       |		return NULL;
  121|       |	trace->magic = WPABUF_MAGIC;
  122|       |	buf = (struct wpabuf *) (trace + 1);
  123|       |#else /* WPA_TRACE */
  124|  3.15k|	struct wpabuf *buf = os_zalloc(sizeof(struct wpabuf) + len);
  125|  3.15k|	if (buf == NULL)
  ------------------
  |  Branch (125:6): [True: 0, False: 3.15k]
  ------------------
  126|      0|		return NULL;
  127|  3.15k|#endif /* WPA_TRACE */
  128|       |
  129|  3.15k|	buf->size = len;
  130|  3.15k|	buf->buf = (u8 *) (buf + 1);
  131|  3.15k|	return buf;
  132|  3.15k|}
wpabuf_alloc_copy:
  161|    111|{
  162|    111|	struct wpabuf *buf = wpabuf_alloc(len);
  163|    111|	if (buf)
  ------------------
  |  Branch (163:6): [True: 111, False: 0]
  ------------------
  164|    111|		wpabuf_put_data(buf, data, len);
  165|    111|	return buf;
  166|    111|}
wpabuf_free:
  183|  11.0k|{
  184|       |#ifdef WPA_TRACE
  185|       |	struct wpabuf_trace *trace;
  186|       |	if (buf == NULL)
  187|       |		return;
  188|       |	trace = wpabuf_get_trace(buf);
  189|       |	if (trace->magic != WPABUF_MAGIC) {
  190|       |		wpa_printf(MSG_ERROR, "wpabuf_free: invalid magic %x",
  191|       |			   trace->magic);
  192|       |		wpa_trace_show("wpabuf_free magic mismatch");
  193|       |		abort();
  194|       |	}
  195|       |	if (buf->flags & WPABUF_FLAG_EXT_DATA)
  196|       |		os_free(buf->buf);
  197|       |	os_free(trace);
  198|       |#else /* WPA_TRACE */
  199|  11.0k|	if (buf == NULL)
  ------------------
  |  Branch (199:6): [True: 7.93k, False: 3.15k]
  ------------------
  200|  7.93k|		return;
  201|  3.15k|	if (buf->flags & WPABUF_FLAG_EXT_DATA)
  ------------------
  |  |   13|  3.15k|#define WPABUF_FLAG_EXT_DATA BIT(0)
  |  |  ------------------
  |  |  |  |  429|  3.15k|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
  |  Branch (201:6): [True: 0, False: 3.15k]
  ------------------
  202|      0|		os_free(buf->buf);
  ------------------
  |  |  491|      0|#define os_free(p) free((p))
  ------------------
  203|  3.15k|	os_free(buf);
  ------------------
  |  |  491|  3.15k|#define os_free(p) free((p))
  ------------------
  204|  3.15k|#endif /* WPA_TRACE */
  205|  3.15k|}
wpabuf_put:
  218|  7.41k|{
  219|  7.41k|	void *tmp = wpabuf_mhead_u8(buf) + wpabuf_len(buf);
  220|  7.41k|	buf->used += len;
  221|  7.41k|	if (buf->used > buf->size) {
  ------------------
  |  Branch (221:6): [True: 0, False: 7.41k]
  ------------------
  222|      0|		wpabuf_overflow(buf, len);
  223|      0|	}
  224|  7.41k|	return tmp;
  225|  7.41k|}
wpabuf_zeropad:
  276|    108|{
  277|    108|	struct wpabuf *ret;
  278|    108|	size_t blen;
  279|       |
  280|    108|	if (buf == NULL)
  ------------------
  |  Branch (280:6): [True: 0, False: 108]
  ------------------
  281|      0|		return NULL;
  282|       |
  283|    108|	blen = wpabuf_len(buf);
  284|    108|	if (blen >= len)
  ------------------
  |  Branch (284:6): [True: 108, False: 0]
  ------------------
  285|    108|		return buf;
  286|       |
  287|      0|	ret = wpabuf_alloc(len);
  288|      0|	if (ret) {
  ------------------
  |  Branch (288:6): [True: 0, False: 0]
  ------------------
  289|      0|		os_memset(wpabuf_put(ret, len - blen), 0, len - blen);
  ------------------
  |  |  509|      0|#define os_memset(s, c, n) memset(s, c, n)
  ------------------
  290|      0|		wpabuf_put_buf(ret, buf);
  291|      0|	}
  292|      0|	wpabuf_free(buf);
  293|       |
  294|      0|	return ret;
  295|    108|}

wpabuf.c:wpabuf_put_data:
  168|    111|{
  169|    111|	if (data)
  ------------------
  |  Branch (169:6): [True: 111, False: 0]
  ------------------
  170|    111|		os_memcpy(wpabuf_put(buf, len), data, len);
  ------------------
  |  |  503|    111|#define os_memcpy(d, s, n) memcpy((d), (s), (n))
  ------------------
  171|    111|}
wpabuf.c:wpabuf_len:
   59|  7.52k|{
   60|  7.52k|	return buf->used;
   61|  7.52k|}
wpabuf.c:wpabuf_mhead:
  109|  7.41k|{
  110|  7.41k|	return buf->buf;
  111|  7.41k|}
wpabuf.c:wpabuf_mhead_u8:
  114|  7.41k|{
  115|  7.41k|	return (u8 *) wpabuf_mhead(buf);
  116|  7.41k|}
wpa_common.c:wpabuf_tailroom:
   69|    216|{
   70|    216|	return buf->size - buf->used;
   71|    216|}
wpa_common.c:wpabuf_len:
   59|    324|{
   60|    324|	return buf->used;
   61|    324|}
wpa_common.c:wpabuf_put_le16:
  125|    108|{
  126|    108|	u8 *pos = (u8 *) wpabuf_put(buf, 2);
  127|    108|	WPA_PUT_LE16(pos, data);
  128|    108|}
wpa_common.c:wpabuf_put_u8:
  119|    216|{
  120|    216|	u8 *pos = (u8 *) wpabuf_put(buf, 1);
  121|    216|	*pos = data;
  122|    216|}
wpa_common.c:wpabuf_put_buf:
  175|    108|{
  176|    108|	wpabuf_put_data(dst, wpabuf_head(src), wpabuf_len(src));
  177|    108|}
wpa_common.c:wpabuf_head:
   94|    108|{
   95|    108|	return buf->buf;
   96|    108|}
wpa_common.c:wpabuf_put_data:
  168|    108|{
  169|    108|	if (data)
  ------------------
  |  Branch (169:6): [True: 108, False: 0]
  ------------------
  170|    108|		os_memcpy(wpabuf_put(buf, len), data, len);
  ------------------
  |  |  503|    108|#define os_memcpy(d, s, n) memcpy((d), (s), (n))
  ------------------
  171|    108|}
ieee802_11_common.c:wpabuf_put_data:
  168|  3.18k|{
  169|  3.18k|	if (data)
  ------------------
  |  Branch (169:6): [True: 3.18k, False: 0]
  ------------------
  170|  3.18k|		os_memcpy(wpabuf_put(buf, len), data, len);
  ------------------
  |  |  503|  3.18k|#define os_memcpy(d, s, n) memcpy((d), (s), (n))
  ------------------
  171|  3.18k|}
pasn_responder.c:wpabuf_head:
   94|  3.03k|{
   95|  3.03k|	return buf->buf;
   96|  3.03k|}
pasn_responder.c:wpabuf_put_u8:
  119|    216|{
  120|    216|	u8 *pos = (u8 *) wpabuf_put(buf, 1);
  121|    216|	*pos = data;
  122|    216|}
pasn_responder.c:wpabuf_head_u8:
   99|  2.93k|{
  100|  2.93k|	return (const u8 *) wpabuf_head(buf);
  101|  2.93k|}
pasn_responder.c:wpabuf_len:
   59|  2.93k|{
   60|  2.93k|	return buf->used;
   61|  2.93k|}

wpa_fuzzer_set_debug_level:
   15|  2.71k|{
   16|  2.71k|	static int first = 1;
   17|       |
   18|  2.71k|	if (first) {
  ------------------
  |  Branch (18:6): [True: 1, False: 2.71k]
  ------------------
   19|      1|		char *env;
   20|       |
   21|      1|		first = 0;
   22|      1|		env = getenv("WPADEBUG");
   23|      1|		if (env)
  ------------------
  |  Branch (23:7): [True: 0, False: 1]
  ------------------
   24|      0|			wpa_debug_level = atoi(env);
   25|      1|		else
   26|      1|			wpa_debug_level = MSG_ERROR + 1;
   27|       |
   28|      1|		wpa_debug_show_keys = 1;
   29|      1|	}
   30|  2.71k|}

LLVMFuzzerTestOneInput:
   52|  2.71k|{
   53|  2.71k|	struct pasn_data pasn;
   54|  2.71k|	u8 own_addr[ETH_ALEN], bssid[ETH_ALEN];
   55|       |
   56|  2.71k|	wpa_fuzzer_set_debug_level();
   57|       |
   58|  2.71k|	if (os_program_init())
  ------------------
  |  Branch (58:6): [True: 0, False: 2.71k]
  ------------------
   59|      0|		return 0;
   60|       |
   61|  2.71k|	if (eloop_init()) {
  ------------------
  |  Branch (61:6): [True: 0, False: 2.71k]
  ------------------
   62|      0|		wpa_printf(MSG_ERROR, "Failed to initialize event loop");
   63|      0|		return 0;
   64|      0|	}
   65|       |
   66|  2.71k|	os_memset(&pasn, 0, sizeof(pasn));
  ------------------
  |  |  509|  2.71k|#define os_memset(s, c, n) memset(s, c, n)
  ------------------
   67|  2.71k|	pasn.send_mgmt = pasn_send_mgmt;
   68|  2.71k|	hwaddr_aton("02:00:00:00:03:00", own_addr);
   69|  2.71k|	hwaddr_aton("02:00:00:00:00:00", bssid);
   70|  2.71k|	os_memcpy(pasn.own_addr, own_addr, ETH_ALEN);
  ------------------
  |  |  503|  2.71k|#define os_memcpy(d, s, n) memcpy((d), (s), (n))
  ------------------
   71|  2.71k|	os_memcpy(pasn.bssid, bssid, ETH_ALEN);
  ------------------
  |  |  503|  2.71k|#define os_memcpy(d, s, n) memcpy((d), (s), (n))
  ------------------
   72|  2.71k|	pasn.wpa_key_mgmt = WPA_KEY_MGMT_PASN;
  ------------------
  |  |   52|  2.71k|#define WPA_KEY_MGMT_PASN BIT(25)
  |  |  ------------------
  |  |  |  |  429|  2.71k|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
   73|  2.71k|	pasn.rsn_pairwise = WPA_CIPHER_CCMP;
  ------------------
  |  |   16|  2.71k|#define WPA_CIPHER_CCMP BIT(4)
  |  |  ------------------
  |  |  |  |  429|  2.71k|#define BIT(x) (1U << (x))
  |  |  ------------------
  ------------------
   74|       |
   75|  2.71k|	wpa_printf(MSG_DEBUG, "TESTING: Try to parse as PASN Auth 1");
   76|  2.71k|	if (handle_auth_pasn_1(&pasn, own_addr, bssid,
  ------------------
  |  Branch (76:6): [True: 2.60k, False: 108]
  ------------------
   77|  2.71k|			       (const struct ieee80211_mgmt *) data, size))
   78|  2.60k|		wpa_printf(MSG_ERROR, "handle_auth_pasn_1 failed");
   79|       |
   80|  2.71k|	wpa_printf(MSG_DEBUG, "TESTING: Try to parse as PASN Auth 3");
   81|  2.71k|	if (handle_auth_pasn_3(&pasn, own_addr, bssid,
  ------------------
  |  Branch (81:6): [True: 2.70k, False: 8]
  ------------------
   82|  2.71k|			       (const struct ieee80211_mgmt *) data, size))
   83|  2.70k|		wpa_printf(MSG_ERROR, "handle_auth_pasn_3 failed");
   84|       |
   85|  2.71k|	if (pasn.ecdh) {
  ------------------
  |  Branch (85:6): [True: 129, False: 2.58k]
  ------------------
   86|    129|		crypto_ecdh_deinit(pasn.ecdh);
   87|    129|		pasn.ecdh = NULL;
   88|    129|	}
   89|       |
   90|  2.71k|	eloop_destroy();
   91|  2.71k|	os_program_deinit();
   92|       |
   93|  2.71k|	return 0;
   94|  2.71k|}
pasn-resp.c:pasn_send_mgmt:
   46|  2.71k|{
   47|  2.71k|	return 0;
   48|  2.71k|}

