ssh_digest_alg_by_name:
   82|  2.16k|{
   83|  2.16k|	int alg;
   84|       |
   85|  8.89k|	for (alg = 0; digests[alg].id != -1; alg++) {
  ------------------
  |  Branch (85:16): [True: 8.89k, False: 0]
  ------------------
   86|  8.89k|		if (strcasecmp(name, digests[alg].name) == 0)
  ------------------
  |  Branch (86:7): [True: 2.16k, False: 6.73k]
  ------------------
   87|  2.16k|			return digests[alg].id;
   88|  8.89k|	}
   89|      0|	return -1;
   90|  2.16k|}
ssh_digest_bytes:
  102|  4.46k|{
  103|  4.46k|	const struct ssh_digest *digest = ssh_digest_by_alg(alg);
  104|       |
  105|  4.46k|	return digest == NULL ? 0 : digest->digest_len;
  ------------------
  |  Branch (105:9): [True: 0, False: 4.46k]
  ------------------
  106|  4.46k|}
ssh_digest_memory:
  187|  2.21k|{
  188|  2.21k|	const struct ssh_digest *digest = ssh_digest_by_alg(alg);
  189|  2.21k|	u_int mdlen;
  190|       |
  191|  2.21k|	if (digest == NULL)
  ------------------
  |  Branch (191:6): [True: 0, False: 2.21k]
  ------------------
  192|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  193|  2.21k|	if (dlen > UINT_MAX)
  ------------------
  |  Branch (193:6): [True: 0, False: 2.21k]
  ------------------
  194|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  195|  2.21k|	if (dlen < digest->digest_len)
  ------------------
  |  Branch (195:6): [True: 0, False: 2.21k]
  ------------------
  196|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  197|  2.21k|	mdlen = dlen;
  198|  2.21k|	if (!EVP_Digest(m, mlen, d, &mdlen, digest->mdfunc(), NULL))
  ------------------
  |  Branch (198:6): [True: 0, False: 2.21k]
  ------------------
  199|      0|		return SSH_ERR_LIBCRYPTO_ERROR;
  ------------------
  |  |   46|      0|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
  200|  2.21k|	return 0;
  201|  2.21k|}
ssh_digest_buffer:
  205|  2.16k|{
  206|  2.16k|	return ssh_digest_memory(alg, sshbuf_ptr(b), sshbuf_len(b), d, dlen);
  207|  2.16k|}
digest-openssl.c:ssh_digest_by_alg:
   70|  6.68k|{
   71|  6.68k|	if (alg < 0 || alg >= SSH_DIGEST_MAX)
  ------------------
  |  |   31|  6.68k|#define SSH_DIGEST_MAX		6
  ------------------
  |  Branch (71:6): [True: 0, False: 6.68k]
  |  Branch (71:17): [True: 0, False: 6.68k]
  ------------------
   72|      0|		return NULL;
   73|  6.68k|	if (digests[alg].id != alg) /* sanity */
  ------------------
  |  Branch (73:6): [True: 0, False: 6.68k]
  ------------------
   74|      0|		return NULL;
   75|  6.68k|	if (digests[alg].mdfunc == NULL)
  ------------------
  |  Branch (75:6): [True: 0, False: 6.68k]
  ------------------
   76|      0|		return NULL;
   77|  6.68k|	return &(digests[alg]);
   78|  6.68k|}

crypto_sign_ed25519_ref_fe25519_getparity:
  268|    102|{
  269|    102|  fe25519 t = *x;
  ------------------
  |  |   72|    102|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  270|    102|  fe25519_freeze(&t);
  ------------------
  |  |   73|    102|#define fe25519_freeze       crypto_sign_ed25519_ref_fe25519_freeze
  ------------------
  271|    102|  return t.v[0] & 1;
  272|    102|}
crypto_sign_ed25519_ref_unpackneg_vartime:
 1786|     59|{
 1787|     59|  unsigned char par;
 1788|     59|  fe25519 t, chk, num, den, den2, den4, den6;
  ------------------
  |  |   72|     59|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
 1789|     59|  fe25519_setone(&r->z);
  ------------------
  |  |   79|     59|#define fe25519_setone       crypto_sign_ed25519_ref_fe25519_setone
  ------------------
 1790|     59|  par = p[31] >> 7;
 1791|     59|  fe25519_unpack(&r->y, p);
  ------------------
  |  |   74|     59|#define fe25519_unpack       crypto_sign_ed25519_ref_fe25519_unpack
  ------------------
 1792|     59|  fe25519_square(&num, &r->y); /* x = y^2 */
  ------------------
  |  |   86|     59|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
 1793|     59|  fe25519_mul(&den, &num, &ge25519_ecd); /* den = dy^2 */
  ------------------
  |  |   85|     59|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1794|     59|  fe25519_sub(&num, &num, &r->z); /* x = y^2-1 */
  ------------------
  |  |   84|     59|#define fe25519_sub          crypto_sign_ed25519_ref_fe25519_sub
  ------------------
 1795|     59|  fe25519_add(&den, &r->z, &den); /* den = dy^2+1 */
  ------------------
  |  |   83|     59|#define fe25519_add          crypto_sign_ed25519_ref_fe25519_add
  ------------------
 1796|       |
 1797|       |  /* Computation of sqrt(num/den) */
 1798|       |  /* 1.: computation of num^((p-5)/8)*den^((7p-35)/8) = (num*den^7)^((p-5)/8) */
 1799|     59|  fe25519_square(&den2, &den);
  ------------------
  |  |   86|     59|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
 1800|     59|  fe25519_square(&den4, &den2);
  ------------------
  |  |   86|     59|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
 1801|     59|  fe25519_mul(&den6, &den4, &den2);
  ------------------
  |  |   85|     59|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1802|     59|  fe25519_mul(&t, &den6, &num);
  ------------------
  |  |   85|     59|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1803|     59|  fe25519_mul(&t, &t, &den);
  ------------------
  |  |   85|     59|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1804|       |
 1805|     59|  fe25519_pow2523(&t, &t);
  ------------------
  |  |   88|     59|#define fe25519_pow2523      crypto_sign_ed25519_ref_fe25519_pow2523
  ------------------
 1806|       |  /* 2. computation of r->x = t * num * den^3 */
 1807|     59|  fe25519_mul(&t, &t, &num);
  ------------------
  |  |   85|     59|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1808|     59|  fe25519_mul(&t, &t, &den);
  ------------------
  |  |   85|     59|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1809|     59|  fe25519_mul(&t, &t, &den);
  ------------------
  |  |   85|     59|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1810|     59|  fe25519_mul(&r->x, &t, &den);
  ------------------
  |  |   85|     59|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1811|       |
 1812|       |  /* 3. Check whether sqrt computation gave correct result, multiply by sqrt(-1) if not: */
 1813|     59|  fe25519_square(&chk, &r->x);
  ------------------
  |  |   86|     59|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
 1814|     59|  fe25519_mul(&chk, &chk, &den);
  ------------------
  |  |   85|     59|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1815|     59|  if (!fe25519_iseq_vartime(&chk, &num))
  ------------------
  |  |   77|     59|#define fe25519_iseq_vartime crypto_sign_ed25519_ref_fe25519_iseq_vartime
  ------------------
  |  Branch (1815:7): [True: 41, False: 18]
  ------------------
 1816|     41|    fe25519_mul(&r->x, &r->x, &ge25519_sqrtm1);
  ------------------
  |  |   85|     41|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1817|       |
 1818|       |  /* 4. Now we have one of the two square roots, except if input was not a square */
 1819|     59|  fe25519_square(&chk, &r->x);
  ------------------
  |  |   86|     59|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
 1820|     59|  fe25519_mul(&chk, &chk, &den);
  ------------------
  |  |   85|     59|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1821|     59|  if (!fe25519_iseq_vartime(&chk, &num))
  ------------------
  |  |   77|     59|#define fe25519_iseq_vartime crypto_sign_ed25519_ref_fe25519_iseq_vartime
  ------------------
  |  Branch (1821:7): [True: 8, False: 51]
  ------------------
 1822|      8|    return -1;
 1823|       |
 1824|       |  /* 5. Choose the desired square root according to parity: */
 1825|     51|  if(fe25519_getparity(&r->x) != (1-par))
  ------------------
  |  |   82|     51|#define fe25519_getparity    crypto_sign_ed25519_ref_fe25519_getparity
  ------------------
  |  Branch (1825:6): [True: 33, False: 18]
  ------------------
 1826|     33|    fe25519_neg(&r->x, &r->x);
  ------------------
  |  |   81|     33|#define fe25519_neg          crypto_sign_ed25519_ref_fe25519_neg
  ------------------
 1827|       |
 1828|     51|  fe25519_mul(&r->t, &r->x, &r->y);
  ------------------
  |  |   85|     51|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1829|     51|  return 0;
 1830|     59|}
crypto_sign_ed25519_open:
 1993|     77|{
 1994|     77|  unsigned char pkcopy[32];
 1995|     77|  unsigned char rcopy[32];
 1996|     77|  unsigned char hram[64];
 1997|     77|  unsigned char rcheck[32];
 1998|     77|  ge25519 get1, get2;
  ------------------
  |  |  724|     77|#define ge25519                           crypto_sign_ed25519_ref_ge25519
  ------------------
 1999|     77|  sc25519 schram, scs;
  ------------------
  |  |  461|     77|#define sc25519                  crypto_sign_ed25519_ref_sc25519
  ------------------
 2000|       |
 2001|     77|  if (smlen < 64) goto badsig;
  ------------------
  |  Branch (2001:7): [True: 0, False: 77]
  ------------------
 2002|     77|  if (sm[63] & 224) goto badsig;
  ------------------
  |  Branch (2002:7): [True: 18, False: 59]
  ------------------
 2003|     59|  if (ge25519_unpackneg_vartime(&get1,pk)) goto badsig;
  ------------------
  |  |  726|     59|#define ge25519_unpackneg_vartime         crypto_sign_ed25519_ref_unpackneg_vartime
  ------------------
  |  Branch (2003:7): [True: 8, False: 51]
  ------------------
 2004|       |
 2005|     51|  memmove(pkcopy,pk,32);
 2006|     51|  memmove(rcopy,sm,32);
 2007|       |
 2008|     51|  sc25519_from32bytes(&scs, sm+32);
  ------------------
  |  |  463|     51|#define sc25519_from32bytes      crypto_sign_ed25519_ref_sc25519_from32bytes
  ------------------
 2009|       |
 2010|     51|  memmove(m,sm,smlen);
 2011|     51|  memmove(m + 32,pkcopy,32);
 2012|     51|  crypto_hash_sha512(hram,m,smlen);
 2013|       |
 2014|     51|  sc25519_from64bytes(&schram, hram);
  ------------------
  |  |  464|     51|#define sc25519_from64bytes      crypto_sign_ed25519_ref_sc25519_from64bytes
  ------------------
 2015|       |
 2016|     51|  ge25519_double_scalarmult_vartime(&get2, &get1, &schram, &ge25519_base, &scs);
  ------------------
  |  |  729|     51|#define ge25519_double_scalarmult_vartime crypto_sign_ed25519_ref_double_scalarmult_vartime
  ------------------
                ge25519_double_scalarmult_vartime(&get2, &get1, &schram, &ge25519_base, &scs);
  ------------------
  |  |  725|     51|#define ge25519_base                      crypto_sign_ed25519_ref_ge25519_base
  ------------------
 2017|     51|  ge25519_pack(rcheck, &get2);
  ------------------
  |  |  727|     51|#define ge25519_pack                      crypto_sign_ed25519_ref_pack
  ------------------
 2018|       |
 2019|     51|  if (crypto_verify_32(rcopy,rcheck) == 0) {
  ------------------
  |  Branch (2019:7): [True: 8, False: 43]
  ------------------
 2020|      8|    memmove(m,m + 64,smlen - 64);
 2021|      8|    memset(m + smlen - 64,0,64);
 2022|      8|    *mlen = smlen - 64;
 2023|      8|    return 0;
 2024|      8|  }
 2025|       |
 2026|     69|badsig:
 2027|     69|  *mlen = (unsigned long long) -1;
 2028|     69|  memset(m,0,smlen);
 2029|     69|  return -1;
 2030|     51|}
ed25519.c:crypto_sign_ed25519_ref_fe25519_freeze:
  203|    389|{
  204|    389|  int i;
  205|    389|  crypto_uint32 m = fe25519_equal(r->v[31],127);
  206|  12.0k|  for(i=30;i>0;i--)
  ------------------
  |  Branch (206:12): [True: 11.6k, False: 389]
  ------------------
  207|  11.6k|    m &= fe25519_equal(r->v[i],255);
  208|    389|  m &= ge(r->v[0],237);
  209|       |
  210|    389|  m = -m;
  211|       |
  212|    389|  r->v[31] -= m&127;
  213|  12.0k|  for(i=30;i>0;i--)
  ------------------
  |  Branch (213:12): [True: 11.6k, False: 389]
  ------------------
  214|  11.6k|    r->v[i] -= m&255;
  215|    389|  r->v[0] -= m&237;
  216|    389|}
ed25519.c:fe25519_equal:
  135|  12.0k|{
  136|  12.0k|  crypto_uint32 x = a ^ b; /* 0: yes; 1..65535: no */
  137|  12.0k|  x -= 1; /* 4294967295: yes; 0..65534: no */
  138|  12.0k|  x >>= 31; /* 1: yes; 0: no */
  139|  12.0k|  return x;
  140|  12.0k|}
ed25519.c:ge:
  143|    389|{
  144|    389|  unsigned int x = a;
  145|    389|  x -= (unsigned int) b; /* 0..65535: yes; 4294901761..4294967295: no */
  146|    389|  x >>= 31; /* 0: yes; 1: no */
  147|    389|  x ^= 1; /* 1: yes; 0: no */
  148|    389|  return x;
  149|    389|}
ed25519.c:crypto_sign_ed25519_ref_fe25519_setone:
  275|    161|{
  276|    161|  int i;
  277|    161|  r->v[0] = 1;
  278|  5.15k|  for(i=1;i<32;i++) r->v[i]=0;
  ------------------
  |  Branch (278:11): [True: 4.99k, False: 161]
  ------------------
  279|    161|}
ed25519.c:crypto_sign_ed25519_ref_fe25519_unpack:
  219|     59|{
  220|     59|  int i;
  221|  1.94k|  for(i=0;i<32;i++) r->v[i] = x[i];
  ------------------
  |  Branch (221:11): [True: 1.88k, False: 59]
  ------------------
  222|     59|  r->v[31] &= 127;
  223|     59|}
ed25519.c:crypto_sign_ed25519_ref_fe25519_square:
  332|  80.0k|{
  333|  80.0k|  fe25519_mul(r, x, x);
  ------------------
  |  |   85|  80.0k|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  334|  80.0k|}
ed25519.c:crypto_sign_ed25519_ref_fe25519_mul:
  315|   174k|{
  316|   174k|  int i,j;
  317|   174k|  crypto_uint32 t[63];
  318|  11.1M|  for(i=0;i<63;i++)t[i] = 0;
  ------------------
  |  Branch (318:11): [True: 10.9M, False: 174k]
  ------------------
  319|       |
  320|  5.75M|  for(i=0;i<32;i++)
  ------------------
  |  Branch (320:11): [True: 5.57M, False: 174k]
  ------------------
  321|   184M|    for(j=0;j<32;j++)
  ------------------
  |  Branch (321:13): [True: 178M, False: 5.57M]
  ------------------
  322|   178M|      t[i+j] += x->v[i] * y->v[j];
  323|       |
  324|  5.57M|  for(i=32;i<63;i++)
  ------------------
  |  Branch (324:12): [True: 5.40M, False: 174k]
  ------------------
  325|  5.40M|    r->v[i-32] = t[i-32] + times38(t[i]);
  326|   174k|  r->v[31] = t[31]; /* result now in r[0]...r[31] */
  327|       |
  328|   174k|  reduce_mul(r);
  329|   174k|}
ed25519.c:times38:
  157|  5.40M|{
  158|  5.40M|  return (a << 5) + (a << 2) + (a << 1);
  159|  5.40M|}
ed25519.c:reduce_mul:
  182|   174k|{
  183|   174k|  crypto_uint32 t;
  184|   174k|  int i,rep;
  185|       |
  186|   522k|  for(rep=0;rep<2;rep++)
  ------------------
  |  Branch (186:13): [True: 348k, False: 174k]
  ------------------
  187|   348k|  {
  188|   348k|    t = r->v[31] >> 7;
  189|   348k|    r->v[31] &= 127;
  190|   348k|    t = times19(t);
  191|   348k|    r->v[0] += t;
  192|  11.1M|    for(i=0;i<31;i++)
  ------------------
  |  Branch (192:13): [True: 10.8M, False: 348k]
  ------------------
  193|  10.8M|    {
  194|  10.8M|      t = r->v[i] >> 8;
  195|  10.8M|      r->v[i+1] += t;
  196|  10.8M|      r->v[i] &= 255;
  197|  10.8M|    }
  198|   348k|  }
  199|   174k|}
ed25519.c:times19:
  152|   977k|{
  153|   977k|  return (a << 4) + (a << 1) + a;
  154|   977k|}
ed25519.c:crypto_sign_ed25519_ref_fe25519_sub:
  304|  88.6k|{
  305|  88.6k|  int i;
  306|  88.6k|  crypto_uint32 t[32];
  307|  88.6k|  t[0] = x->v[0] + 0x1da;
  308|  88.6k|  t[31] = x->v[31] + 0xfe;
  309|  2.74M|  for(i=1;i<31;i++) t[i] = x->v[i] + 0x1fe;
  ------------------
  |  Branch (309:11): [True: 2.65M, False: 88.6k]
  ------------------
  310|  2.92M|  for(i=0;i<32;i++) r->v[i] = t[i] - y->v[i];
  ------------------
  |  Branch (310:11): [True: 2.83M, False: 88.6k]
  ------------------
  311|  88.6k|  fe25519_reduce_add_sub(r);
  312|  88.6k|}
ed25519.c:fe25519_reduce_add_sub:
  162|   157k|{
  163|   157k|  crypto_uint32 t;
  164|   157k|  int i,rep;
  165|       |
  166|   785k|  for(rep=0;rep<4;rep++)
  ------------------
  |  Branch (166:13): [True: 628k, False: 157k]
  ------------------
  167|   628k|  {
  168|   628k|    t = r->v[31] >> 7;
  169|   628k|    r->v[31] &= 127;
  170|   628k|    t = times19(t);
  171|   628k|    r->v[0] += t;
  172|  20.1M|    for(i=0;i<31;i++)
  ------------------
  |  Branch (172:13): [True: 19.4M, False: 628k]
  ------------------
  173|  19.4M|    {
  174|  19.4M|      t = r->v[i] >> 8;
  175|  19.4M|      r->v[i+1] += t;
  176|  19.4M|      r->v[i] &= 255;
  177|  19.4M|    }
  178|   628k|  }
  179|   157k|}
ed25519.c:crypto_sign_ed25519_ref_fe25519_add:
  297|  68.4k|{
  298|  68.4k|  int i;
  299|  2.26M|  for(i=0;i<32;i++) r->v[i] = x->v[i] + y->v[i];
  ------------------
  |  Branch (299:11): [True: 2.19M, False: 68.4k]
  ------------------
  300|  68.4k|  fe25519_reduce_add_sub(r);
  301|  68.4k|}
ed25519.c:crypto_sign_ed25519_ref_fe25519_pow2523:
  404|     59|{
  405|     59|	fe25519 z2;
  ------------------
  |  |   72|     59|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  406|     59|	fe25519 z9;
  ------------------
  |  |   72|     59|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  407|     59|	fe25519 z11;
  ------------------
  |  |   72|     59|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  408|     59|	fe25519 z2_5_0;
  ------------------
  |  |   72|     59|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  409|     59|	fe25519 z2_10_0;
  ------------------
  |  |   72|     59|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  410|     59|	fe25519 z2_20_0;
  ------------------
  |  |   72|     59|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  411|     59|	fe25519 z2_50_0;
  ------------------
  |  |   72|     59|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  412|     59|	fe25519 z2_100_0;
  ------------------
  |  |   72|     59|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  413|     59|	fe25519 t;
  ------------------
  |  |   72|     59|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  414|     59|	int i;
  415|       |
  416|     59|	/* 2 */ fe25519_square(&z2,x);
  ------------------
  |  |   86|     59|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  417|       |	/* 4 */ fe25519_square(&t,&z2);
  ------------------
  |  |   86|     59|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  418|       |	/* 8 */ fe25519_square(&t,&t);
  ------------------
  |  |   86|     59|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  419|       |	/* 9 */ fe25519_mul(&z9,&t,x);
  ------------------
  |  |   85|     59|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  420|       |	/* 11 */ fe25519_mul(&z11,&z9,&z2);
  ------------------
  |  |   85|     59|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  421|       |	/* 22 */ fe25519_square(&t,&z11);
  ------------------
  |  |   86|     59|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  422|       |	/* 2^5 - 2^0 = 31 */ fe25519_mul(&z2_5_0,&t,&z9);
  ------------------
  |  |   85|     59|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  423|       |
  424|     59|	/* 2^6 - 2^1 */ fe25519_square(&t,&z2_5_0);
  ------------------
  |  |   86|     59|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  425|    295|	/* 2^10 - 2^5 */ for (i = 1;i < 5;i++) { fe25519_square(&t,&t); }
  ------------------
  |  |   86|    236|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  |  Branch (425:30): [True: 236, False: 59]
  ------------------
  426|       |	/* 2^10 - 2^0 */ fe25519_mul(&z2_10_0,&t,&z2_5_0);
  ------------------
  |  |   85|     59|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  427|       |
  428|     59|	/* 2^11 - 2^1 */ fe25519_square(&t,&z2_10_0);
  ------------------
  |  |   86|     59|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  429|    590|	/* 2^20 - 2^10 */ for (i = 1;i < 10;i++) { fe25519_square(&t,&t); }
  ------------------
  |  |   86|    531|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  |  Branch (429:31): [True: 531, False: 59]
  ------------------
  430|       |	/* 2^20 - 2^0 */ fe25519_mul(&z2_20_0,&t,&z2_10_0);
  ------------------
  |  |   85|     59|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  431|       |
  432|     59|	/* 2^21 - 2^1 */ fe25519_square(&t,&z2_20_0);
  ------------------
  |  |   86|     59|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  433|  1.18k|	/* 2^40 - 2^20 */ for (i = 1;i < 20;i++) { fe25519_square(&t,&t); }
  ------------------
  |  |   86|  1.12k|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  |  Branch (433:31): [True: 1.12k, False: 59]
  ------------------
  434|       |	/* 2^40 - 2^0 */ fe25519_mul(&t,&t,&z2_20_0);
  ------------------
  |  |   85|     59|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  435|       |
  436|     59|	/* 2^41 - 2^1 */ fe25519_square(&t,&t);
  ------------------
  |  |   86|     59|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  437|    590|	/* 2^50 - 2^10 */ for (i = 1;i < 10;i++) { fe25519_square(&t,&t); }
  ------------------
  |  |   86|    531|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  |  Branch (437:31): [True: 531, False: 59]
  ------------------
  438|       |	/* 2^50 - 2^0 */ fe25519_mul(&z2_50_0,&t,&z2_10_0);
  ------------------
  |  |   85|     59|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  439|       |
  440|     59|	/* 2^51 - 2^1 */ fe25519_square(&t,&z2_50_0);
  ------------------
  |  |   86|     59|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  441|  2.95k|	/* 2^100 - 2^50 */ for (i = 1;i < 50;i++) { fe25519_square(&t,&t); }
  ------------------
  |  |   86|  2.89k|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  |  Branch (441:32): [True: 2.89k, False: 59]
  ------------------
  442|       |	/* 2^100 - 2^0 */ fe25519_mul(&z2_100_0,&t,&z2_50_0);
  ------------------
  |  |   85|     59|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  443|       |
  444|     59|	/* 2^101 - 2^1 */ fe25519_square(&t,&z2_100_0);
  ------------------
  |  |   86|     59|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  445|  5.90k|	/* 2^200 - 2^100 */ for (i = 1;i < 100;i++) { fe25519_square(&t,&t); }
  ------------------
  |  |   86|  5.84k|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  |  Branch (445:33): [True: 5.84k, False: 59]
  ------------------
  446|       |	/* 2^200 - 2^0 */ fe25519_mul(&t,&t,&z2_100_0);
  ------------------
  |  |   85|     59|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  447|       |
  448|     59|	/* 2^201 - 2^1 */ fe25519_square(&t,&t);
  ------------------
  |  |   86|     59|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  449|  2.95k|	/* 2^250 - 2^50 */ for (i = 1;i < 50;i++) { fe25519_square(&t,&t); }
  ------------------
  |  |   86|  2.89k|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  |  Branch (449:32): [True: 2.89k, False: 59]
  ------------------
  450|       |	/* 2^250 - 2^0 */ fe25519_mul(&t,&t,&z2_50_0);
  ------------------
  |  |   85|     59|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  451|       |
  452|     59|	/* 2^251 - 2^1 */ fe25519_square(&t,&t);
  ------------------
  |  |   86|     59|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  453|       |	/* 2^252 - 2^2 */ fe25519_square(&t,&t);
  ------------------
  |  |   86|     59|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  454|       |	/* 2^252 - 3 */ fe25519_mul(r,&t,x);
  ------------------
  |  |   85|     59|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  455|     59|}
ed25519.c:crypto_sign_ed25519_ref_fe25519_iseq_vartime:
  248|    118|{
  249|    118|  int i;
  250|    118|  fe25519 t1 = *x;
  ------------------
  |  |   72|    118|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  251|    118|  fe25519 t2 = *y;
  ------------------
  |  |   72|    118|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  252|    118|  fe25519_freeze(&t1);
  ------------------
  |  |   73|    118|#define fe25519_freeze       crypto_sign_ed25519_ref_fe25519_freeze
  ------------------
  253|    118|  fe25519_freeze(&t2);
  ------------------
  |  |   73|    118|#define fe25519_freeze       crypto_sign_ed25519_ref_fe25519_freeze
  ------------------
  254|  2.33k|  for(i=0;i<32;i++)
  ------------------
  |  Branch (254:11): [True: 2.26k, False: 69]
  ------------------
  255|  2.26k|    if(t1.v[i] != t2.v[i]) return 0;
  ------------------
  |  Branch (255:8): [True: 49, False: 2.22k]
  ------------------
  256|     69|  return 1;
  257|    118|}
ed25519.c:crypto_sign_ed25519_ref_fe25519_neg:
  288|  13.0k|{
  289|  13.0k|  fe25519 t;
  ------------------
  |  |   72|  13.0k|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  290|  13.0k|  int i;
  291|   430k|  for(i=0;i<32;i++) t.v[i]=x->v[i];
  ------------------
  |  Branch (291:11): [True: 417k, False: 13.0k]
  ------------------
  292|  13.0k|  fe25519_setzero(r);
  ------------------
  |  |   80|  13.0k|#define fe25519_setzero      crypto_sign_ed25519_ref_fe25519_setzero
  ------------------
  293|  13.0k|  fe25519_sub(r, r, &t);
  ------------------
  |  |   84|  13.0k|#define fe25519_sub          crypto_sign_ed25519_ref_fe25519_sub
  ------------------
  294|  13.0k|}
ed25519.c:crypto_sign_ed25519_ref_fe25519_setzero:
  282|  13.1k|{
  283|  13.1k|  int i;
  284|   433k|  for(i=0;i<32;i++) r->v[i]=0;
  ------------------
  |  Branch (284:11): [True: 420k, False: 13.1k]
  ------------------
  285|  13.1k|}
ed25519.c:crypto_sign_ed25519_ref_sc25519_from32bytes:
  604|     51|{
  605|     51|  int i;
  606|     51|  crypto_uint32 t[64];
  607|  1.68k|  for(i=0;i<32;i++) t[i] = x[i];
  ------------------
  |  Branch (607:11): [True: 1.63k, False: 51]
  ------------------
  608|  1.68k|  for(i=32;i<64;++i) t[i] = 0;
  ------------------
  |  Branch (608:12): [True: 1.63k, False: 51]
  ------------------
  609|     51|  barrett_reduce(r, t);
  610|     51|}
ed25519.c:barrett_reduce:
  553|    102|{
  554|       |  /* See HAC, Alg. 14.42 */
  555|    102|  int i,j;
  556|    102|  crypto_uint32 q2[66];
  557|    102|  crypto_uint32 *q3 = q2 + 33;
  558|    102|  crypto_uint32 r1[33];
  559|    102|  crypto_uint32 r2[33];
  560|    102|  crypto_uint32 carry;
  561|    102|  crypto_uint32 pb = 0;
  562|    102|  crypto_uint32 b;
  563|       |
  564|  6.83k|  for (i = 0;i < 66;++i) q2[i] = 0;
  ------------------
  |  Branch (564:14): [True: 6.73k, False: 102]
  ------------------
  565|  3.46k|  for (i = 0;i < 33;++i) r2[i] = 0;
  ------------------
  |  Branch (565:14): [True: 3.36k, False: 102]
  ------------------
  566|       |
  567|  3.46k|  for(i=0;i<33;i++)
  ------------------
  |  Branch (567:11): [True: 3.36k, False: 102]
  ------------------
  568|   114k|    for(j=0;j<33;j++)
  ------------------
  |  Branch (568:13): [True: 111k, False: 3.36k]
  ------------------
  569|   111k|      if(i+j >= 31) q2[i+j] += sc25519_mu[i]*x[j+31];
  ------------------
  |  Branch (569:10): [True: 60.4k, False: 50.5k]
  ------------------
  570|    102|  carry = q2[31] >> 8;
  571|    102|  q2[32] += carry;
  572|    102|  carry = q2[32] >> 8;
  573|    102|  q2[33] += carry;
  574|       |
  575|  3.46k|  for(i=0;i<33;i++)r1[i] = x[i];
  ------------------
  |  Branch (575:11): [True: 3.36k, False: 102]
  ------------------
  576|  3.36k|  for(i=0;i<32;i++)
  ------------------
  |  Branch (576:11): [True: 3.26k, False: 102]
  ------------------
  577|   110k|    for(j=0;j<33;j++)
  ------------------
  |  Branch (577:13): [True: 107k, False: 3.26k]
  ------------------
  578|   107k|      if(i+j < 33) r2[i+j] += sc25519_m[i]*q3[j];
  ------------------
  |  Branch (578:10): [True: 57.1k, False: 50.5k]
  ------------------
  579|       |
  580|  3.36k|  for(i=0;i<32;i++)
  ------------------
  |  Branch (580:11): [True: 3.26k, False: 102]
  ------------------
  581|  3.26k|  {
  582|  3.26k|    carry = r2[i] >> 8;
  583|  3.26k|    r2[i+1] += carry;
  584|  3.26k|    r2[i] &= 0xff;
  585|  3.26k|  }
  586|       |
  587|  3.36k|  for(i=0;i<32;i++)
  ------------------
  |  Branch (587:11): [True: 3.26k, False: 102]
  ------------------
  588|  3.26k|  {
  589|  3.26k|    pb += r2[i];
  590|  3.26k|    b = lt(r1[i],pb);
  591|  3.26k|    r->v[i] = r1[i]-pb+(b<<8);
  592|  3.26k|    pb = b;
  593|  3.26k|  }
  594|       |
  595|       |  /* XXX: Can it really happen that r<0?, See HAC, Alg 14.42, Step 3
  596|       |   * If so: Handle  it here!
  597|       |   */
  598|       |
  599|    102|  sc25519_reduce_add_sub(r);
  600|    102|  sc25519_reduce_add_sub(r);
  601|    102|}
ed25519.c:lt:
  523|  9.79k|{
  524|  9.79k|  unsigned int x = a;
  525|  9.79k|  x -= (unsigned int) b; /* 0..65535: no; 4294901761..4294967295: yes */
  526|  9.79k|  x >>= 31; /* 0: no; 1: yes */
  527|  9.79k|  return x;
  528|  9.79k|}
ed25519.c:sc25519_reduce_add_sub:
  532|    204|{
  533|    204|  crypto_uint32 pb = 0;
  534|    204|  crypto_uint32 b;
  535|    204|  crypto_uint32 mask;
  536|    204|  int i;
  537|    204|  unsigned char t[32];
  538|       |
  539|  6.73k|  for(i=0;i<32;i++)
  ------------------
  |  Branch (539:11): [True: 6.52k, False: 204]
  ------------------
  540|  6.52k|  {
  541|  6.52k|    pb += sc25519_m[i];
  542|  6.52k|    b = lt(r->v[i],pb);
  543|  6.52k|    t[i] = r->v[i]-pb+(b<<8);
  544|  6.52k|    pb = b;
  545|  6.52k|  }
  546|    204|  mask = b - 1;
  547|  6.73k|  for(i=0;i<32;i++)
  ------------------
  |  Branch (547:11): [True: 6.52k, False: 204]
  ------------------
  548|  6.52k|    r->v[i] ^= mask & (r->v[i] ^ t[i]);
  549|    204|}
ed25519.c:crypto_sign_ed25519_ref_pack:
 1833|     51|{
 1834|     51|  fe25519 tx, ty, zi;
  ------------------
  |  |   72|     51|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
 1835|     51|  fe25519_invert(&zi, &p->z);
  ------------------
  |  |   87|     51|#define fe25519_invert       crypto_sign_ed25519_ref_fe25519_invert
  ------------------
 1836|     51|  fe25519_mul(&tx, &p->x, &zi);
  ------------------
  |  |   85|     51|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1837|     51|  fe25519_mul(&ty, &p->y, &zi);
  ------------------
  |  |   85|     51|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1838|     51|  fe25519_pack(r, &ty);
  ------------------
  |  |   75|     51|#define fe25519_pack         crypto_sign_ed25519_ref_fe25519_pack
  ------------------
 1839|     51|  r[31] ^= fe25519_getparity(&tx) << 7;
  ------------------
  |  |   82|     51|#define fe25519_getparity    crypto_sign_ed25519_ref_fe25519_getparity
  ------------------
 1840|     51|}
ed25519.c:crypto_sign_ed25519_ref_fe25519_invert:
  337|     51|{
  338|     51|	fe25519 z2;
  ------------------
  |  |   72|     51|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  339|     51|	fe25519 z9;
  ------------------
  |  |   72|     51|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  340|     51|	fe25519 z11;
  ------------------
  |  |   72|     51|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  341|     51|	fe25519 z2_5_0;
  ------------------
  |  |   72|     51|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  342|     51|	fe25519 z2_10_0;
  ------------------
  |  |   72|     51|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  343|     51|	fe25519 z2_20_0;
  ------------------
  |  |   72|     51|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  344|     51|	fe25519 z2_50_0;
  ------------------
  |  |   72|     51|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  345|     51|	fe25519 z2_100_0;
  ------------------
  |  |   72|     51|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  346|     51|	fe25519 t0;
  ------------------
  |  |   72|     51|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  347|     51|	fe25519 t1;
  ------------------
  |  |   72|     51|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  348|     51|	int i;
  349|       |
  350|     51|	/* 2 */ fe25519_square(&z2,x);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  351|       |	/* 4 */ fe25519_square(&t1,&z2);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  352|       |	/* 8 */ fe25519_square(&t0,&t1);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  353|       |	/* 9 */ fe25519_mul(&z9,&t0,x);
  ------------------
  |  |   85|     51|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  354|       |	/* 11 */ fe25519_mul(&z11,&z9,&z2);
  ------------------
  |  |   85|     51|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  355|       |	/* 22 */ fe25519_square(&t0,&z11);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  356|       |	/* 2^5 - 2^0 = 31 */ fe25519_mul(&z2_5_0,&t0,&z9);
  ------------------
  |  |   85|     51|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  357|       |
  358|     51|	/* 2^6 - 2^1 */ fe25519_square(&t0,&z2_5_0);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  359|       |	/* 2^7 - 2^2 */ fe25519_square(&t1,&t0);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  360|       |	/* 2^8 - 2^3 */ fe25519_square(&t0,&t1);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  361|       |	/* 2^9 - 2^4 */ fe25519_square(&t1,&t0);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  362|       |	/* 2^10 - 2^5 */ fe25519_square(&t0,&t1);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  363|       |	/* 2^10 - 2^0 */ fe25519_mul(&z2_10_0,&t0,&z2_5_0);
  ------------------
  |  |   85|     51|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  364|       |
  365|     51|	/* 2^11 - 2^1 */ fe25519_square(&t0,&z2_10_0);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  366|       |	/* 2^12 - 2^2 */ fe25519_square(&t1,&t0);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  367|    255|	/* 2^20 - 2^10 */ for (i = 2;i < 10;i += 2) { fe25519_square(&t0,&t1); fe25519_square(&t1,&t0); }
  ------------------
  |  |   86|    204|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
              	/* 2^20 - 2^10 */ for (i = 2;i < 10;i += 2) { fe25519_square(&t0,&t1); fe25519_square(&t1,&t0); }
  ------------------
  |  |   86|    204|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  |  Branch (367:31): [True: 204, False: 51]
  ------------------
  368|       |	/* 2^20 - 2^0 */ fe25519_mul(&z2_20_0,&t1,&z2_10_0);
  ------------------
  |  |   85|     51|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  369|       |
  370|     51|	/* 2^21 - 2^1 */ fe25519_square(&t0,&z2_20_0);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  371|       |	/* 2^22 - 2^2 */ fe25519_square(&t1,&t0);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  372|    510|	/* 2^40 - 2^20 */ for (i = 2;i < 20;i += 2) { fe25519_square(&t0,&t1); fe25519_square(&t1,&t0); }
  ------------------
  |  |   86|    459|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
              	/* 2^40 - 2^20 */ for (i = 2;i < 20;i += 2) { fe25519_square(&t0,&t1); fe25519_square(&t1,&t0); }
  ------------------
  |  |   86|    459|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  |  Branch (372:31): [True: 459, False: 51]
  ------------------
  373|       |	/* 2^40 - 2^0 */ fe25519_mul(&t0,&t1,&z2_20_0);
  ------------------
  |  |   85|     51|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  374|       |
  375|     51|	/* 2^41 - 2^1 */ fe25519_square(&t1,&t0);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  376|       |	/* 2^42 - 2^2 */ fe25519_square(&t0,&t1);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  377|    255|	/* 2^50 - 2^10 */ for (i = 2;i < 10;i += 2) { fe25519_square(&t1,&t0); fe25519_square(&t0,&t1); }
  ------------------
  |  |   86|    204|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
              	/* 2^50 - 2^10 */ for (i = 2;i < 10;i += 2) { fe25519_square(&t1,&t0); fe25519_square(&t0,&t1); }
  ------------------
  |  |   86|    204|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  |  Branch (377:31): [True: 204, False: 51]
  ------------------
  378|       |	/* 2^50 - 2^0 */ fe25519_mul(&z2_50_0,&t0,&z2_10_0);
  ------------------
  |  |   85|     51|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  379|       |
  380|     51|	/* 2^51 - 2^1 */ fe25519_square(&t0,&z2_50_0);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  381|       |	/* 2^52 - 2^2 */ fe25519_square(&t1,&t0);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  382|  1.27k|	/* 2^100 - 2^50 */ for (i = 2;i < 50;i += 2) { fe25519_square(&t0,&t1); fe25519_square(&t1,&t0); }
  ------------------
  |  |   86|  1.22k|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
              	/* 2^100 - 2^50 */ for (i = 2;i < 50;i += 2) { fe25519_square(&t0,&t1); fe25519_square(&t1,&t0); }
  ------------------
  |  |   86|  1.22k|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  |  Branch (382:32): [True: 1.22k, False: 51]
  ------------------
  383|       |	/* 2^100 - 2^0 */ fe25519_mul(&z2_100_0,&t1,&z2_50_0);
  ------------------
  |  |   85|     51|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  384|       |
  385|     51|	/* 2^101 - 2^1 */ fe25519_square(&t1,&z2_100_0);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  386|       |	/* 2^102 - 2^2 */ fe25519_square(&t0,&t1);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  387|  2.55k|	/* 2^200 - 2^100 */ for (i = 2;i < 100;i += 2) { fe25519_square(&t1,&t0); fe25519_square(&t0,&t1); }
  ------------------
  |  |   86|  2.49k|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
              	/* 2^200 - 2^100 */ for (i = 2;i < 100;i += 2) { fe25519_square(&t1,&t0); fe25519_square(&t0,&t1); }
  ------------------
  |  |   86|  2.49k|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  |  Branch (387:33): [True: 2.49k, False: 51]
  ------------------
  388|       |	/* 2^200 - 2^0 */ fe25519_mul(&t1,&t0,&z2_100_0);
  ------------------
  |  |   85|     51|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  389|       |
  390|     51|	/* 2^201 - 2^1 */ fe25519_square(&t0,&t1);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  391|       |	/* 2^202 - 2^2 */ fe25519_square(&t1,&t0);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  392|  1.27k|	/* 2^250 - 2^50 */ for (i = 2;i < 50;i += 2) { fe25519_square(&t0,&t1); fe25519_square(&t1,&t0); }
  ------------------
  |  |   86|  1.22k|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
              	/* 2^250 - 2^50 */ for (i = 2;i < 50;i += 2) { fe25519_square(&t0,&t1); fe25519_square(&t1,&t0); }
  ------------------
  |  |   86|  1.22k|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  |  Branch (392:32): [True: 1.22k, False: 51]
  ------------------
  393|       |	/* 2^250 - 2^0 */ fe25519_mul(&t0,&t1,&z2_50_0);
  ------------------
  |  |   85|     51|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  394|       |
  395|     51|	/* 2^251 - 2^1 */ fe25519_square(&t1,&t0);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  396|       |	/* 2^252 - 2^2 */ fe25519_square(&t0,&t1);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  397|       |	/* 2^253 - 2^3 */ fe25519_square(&t1,&t0);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  398|       |	/* 2^254 - 2^4 */ fe25519_square(&t0,&t1);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  399|       |	/* 2^255 - 2^5 */ fe25519_square(&t1,&t0);
  ------------------
  |  |   86|     51|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
  400|       |	/* 2^255 - 21 */ fe25519_mul(r,&t1,&z11);
  ------------------
  |  |   85|     51|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
  401|     51|}
ed25519.c:crypto_sign_ed25519_ref_fe25519_pack:
  227|     51|{
  228|     51|  int i;
  229|     51|  fe25519 y = *x;
  ------------------
  |  |   72|     51|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
  230|     51|  fe25519_freeze(&y);
  ------------------
  |  |   73|     51|#define fe25519_freeze       crypto_sign_ed25519_ref_fe25519_freeze
  ------------------
  231|  1.68k|  for(i=0;i<32;i++)
  ------------------
  |  Branch (231:11): [True: 1.63k, False: 51]
  ------------------
  232|  1.63k|    r[i] = y.v[i];
  233|     51|}
ed25519.c:crypto_sign_ed25519_ref_sc25519_from64bytes:
  614|     51|{
  615|     51|  int i;
  616|     51|  crypto_uint32 t[64];
  617|  3.31k|  for(i=0;i<64;i++) t[i] = x[i];
  ------------------
  |  Branch (617:11): [True: 3.26k, False: 51]
  ------------------
  618|     51|  barrett_reduce(r, t);
  619|     51|}
ed25519.c:crypto_sign_ed25519_ref_double_scalarmult_vartime:
 1852|     51|{
 1853|     51|  ge25519_p1p1 tp1p1;
 1854|     51|  ge25519_p3 pre[16];
  ------------------
  |  |  771|     51|#define ge25519_p3 ge25519
  |  |  ------------------
  |  |  |  |  724|     51|#define ge25519                           crypto_sign_ed25519_ref_ge25519
  |  |  ------------------
  ------------------
 1855|     51|  unsigned char b[127];
 1856|     51|  int i;
 1857|       |
 1858|       |  /* precomputation                                                        s2 s1 */
 1859|     51|  setneutral(pre);                                                      /* 00 00 */
 1860|     51|  pre[1] = *p1;                                                         /* 00 01 */
 1861|     51|  dbl_p1p1(&tp1p1,(ge25519_p2 *)p1);      p1p1_to_p3( &pre[2], &tp1p1); /* 00 10 */
 1862|     51|  add_p1p1(&tp1p1,&pre[1], &pre[2]);      p1p1_to_p3( &pre[3], &tp1p1); /* 00 11 */
 1863|     51|  pre[4] = *p2;                                                         /* 01 00 */
 1864|     51|  add_p1p1(&tp1p1,&pre[1], &pre[4]);      p1p1_to_p3( &pre[5], &tp1p1); /* 01 01 */
 1865|     51|  add_p1p1(&tp1p1,&pre[2], &pre[4]);      p1p1_to_p3( &pre[6], &tp1p1); /* 01 10 */
 1866|     51|  add_p1p1(&tp1p1,&pre[3], &pre[4]);      p1p1_to_p3( &pre[7], &tp1p1); /* 01 11 */
 1867|     51|  dbl_p1p1(&tp1p1,(ge25519_p2 *)p2);      p1p1_to_p3( &pre[8], &tp1p1); /* 10 00 */
 1868|     51|  add_p1p1(&tp1p1,&pre[1], &pre[8]);      p1p1_to_p3( &pre[9], &tp1p1); /* 10 01 */
 1869|     51|  dbl_p1p1(&tp1p1,(ge25519_p2 *)&pre[5]); p1p1_to_p3(&pre[10], &tp1p1); /* 10 10 */
 1870|     51|  add_p1p1(&tp1p1,&pre[3], &pre[8]);      p1p1_to_p3(&pre[11], &tp1p1); /* 10 11 */
 1871|     51|  add_p1p1(&tp1p1,&pre[4], &pre[8]);      p1p1_to_p3(&pre[12], &tp1p1); /* 11 00 */
 1872|     51|  add_p1p1(&tp1p1,&pre[1],&pre[12]);      p1p1_to_p3(&pre[13], &tp1p1); /* 11 01 */
 1873|     51|  add_p1p1(&tp1p1,&pre[2],&pre[12]);      p1p1_to_p3(&pre[14], &tp1p1); /* 11 10 */
 1874|     51|  add_p1p1(&tp1p1,&pre[3],&pre[12]);      p1p1_to_p3(&pre[15], &tp1p1); /* 11 11 */
 1875|       |
 1876|     51|  sc25519_2interleave2(b,s1,s2);
  ------------------
  |  |  469|     51|#define sc25519_2interleave2     crypto_sign_ed25519_ref_sc25519_2interleave2
  ------------------
 1877|       |
 1878|       |  /* scalar multiplication */
 1879|     51|  *r = pre[b[126]];
 1880|  6.47k|  for(i=125;i>=0;i--)
  ------------------
  |  Branch (1880:13): [True: 6.42k, False: 51]
  ------------------
 1881|  6.42k|  {
 1882|  6.42k|    dbl_p1p1(&tp1p1, (ge25519_p2 *)r);
 1883|  6.42k|    p1p1_to_p2((ge25519_p2 *) r, &tp1p1);
 1884|  6.42k|    dbl_p1p1(&tp1p1, (ge25519_p2 *)r);
 1885|  6.42k|    if(b[i]!=0)
  ------------------
  |  Branch (1885:8): [True: 5.37k, False: 1.05k]
  ------------------
 1886|  5.37k|    {
 1887|  5.37k|      p1p1_to_p3(r, &tp1p1);
 1888|  5.37k|      add_p1p1(&tp1p1, r, &pre[b[i]]);
 1889|  5.37k|    }
 1890|  6.42k|    if(i != 0) p1p1_to_p2((ge25519_p2 *)r, &tp1p1);
  ------------------
  |  Branch (1890:8): [True: 6.37k, False: 51]
  ------------------
 1891|     51|    else p1p1_to_p3(r, &tp1p1);
 1892|  6.42k|  }
 1893|     51|}
ed25519.c:setneutral:
 1773|     51|{
 1774|     51|  fe25519_setzero(&r->x);
  ------------------
  |  |   80|     51|#define fe25519_setzero      crypto_sign_ed25519_ref_fe25519_setzero
  ------------------
 1775|     51|  fe25519_setone(&r->y);
  ------------------
  |  |   79|     51|#define fe25519_setone       crypto_sign_ed25519_ref_fe25519_setone
  ------------------
 1776|     51|  fe25519_setone(&r->z);
  ------------------
  |  |   79|     51|#define fe25519_setone       crypto_sign_ed25519_ref_fe25519_setone
  ------------------
 1777|     51|  fe25519_setzero(&r->t);
  ------------------
  |  |   80|     51|#define fe25519_setzero      crypto_sign_ed25519_ref_fe25519_setzero
  ------------------
 1778|     51|}
ed25519.c:dbl_p1p1:
 1717|  13.0k|{
 1718|  13.0k|  fe25519 a,b,c,d;
  ------------------
  |  |   72|  13.0k|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
 1719|  13.0k|  fe25519_square(&a, &p->x);
  ------------------
  |  |   86|  13.0k|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
 1720|  13.0k|  fe25519_square(&b, &p->y);
  ------------------
  |  |   86|  13.0k|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
 1721|  13.0k|  fe25519_square(&c, &p->z);
  ------------------
  |  |   86|  13.0k|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
 1722|  13.0k|  fe25519_add(&c, &c, &c);
  ------------------
  |  |   83|  13.0k|#define fe25519_add          crypto_sign_ed25519_ref_fe25519_add
  ------------------
 1723|  13.0k|  fe25519_neg(&d, &a);
  ------------------
  |  |   81|  13.0k|#define fe25519_neg          crypto_sign_ed25519_ref_fe25519_neg
  ------------------
 1724|       |
 1725|  13.0k|  fe25519_add(&r->x, &p->x, &p->y);
  ------------------
  |  |   83|  13.0k|#define fe25519_add          crypto_sign_ed25519_ref_fe25519_add
  ------------------
 1726|  13.0k|  fe25519_square(&r->x, &r->x);
  ------------------
  |  |   86|  13.0k|#define fe25519_square       crypto_sign_ed25519_ref_fe25519_square
  ------------------
 1727|  13.0k|  fe25519_sub(&r->x, &r->x, &a);
  ------------------
  |  |   84|  13.0k|#define fe25519_sub          crypto_sign_ed25519_ref_fe25519_sub
  ------------------
 1728|  13.0k|  fe25519_sub(&r->x, &r->x, &b);
  ------------------
  |  |   84|  13.0k|#define fe25519_sub          crypto_sign_ed25519_ref_fe25519_sub
  ------------------
 1729|  13.0k|  fe25519_add(&r->z, &d, &b);
  ------------------
  |  |   83|  13.0k|#define fe25519_add          crypto_sign_ed25519_ref_fe25519_add
  ------------------
 1730|  13.0k|  fe25519_sub(&r->t, &r->z, &c);
  ------------------
  |  |   84|  13.0k|#define fe25519_sub          crypto_sign_ed25519_ref_fe25519_sub
  ------------------
 1731|  13.0k|  fe25519_sub(&r->y, &d, &b);
  ------------------
  |  |   84|  13.0k|#define fe25519_sub          crypto_sign_ed25519_ref_fe25519_sub
  ------------------
 1732|  13.0k|}
ed25519.c:p1p1_to_p3:
 1667|  6.08k|{
 1668|  6.08k|  p1p1_to_p2((ge25519_p2 *)r, p);
 1669|  6.08k|  fe25519_mul(&r->t, &p->x, &p->y);
  ------------------
  |  |   85|  6.08k|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1670|  6.08k|}
ed25519.c:add_p1p1:
 1696|  5.88k|{
 1697|  5.88k|  fe25519 a, b, c, d, t;
  ------------------
  |  |   72|  5.88k|#define fe25519              crypto_sign_ed25519_ref_fe25519
  ------------------
 1698|       |
 1699|  5.88k|  fe25519_sub(&a, &p->y, &p->x); /* A = (Y1-X1)*(Y2-X2) */
  ------------------
  |  |   84|  5.88k|#define fe25519_sub          crypto_sign_ed25519_ref_fe25519_sub
  ------------------
 1700|  5.88k|  fe25519_sub(&t, &q->y, &q->x);
  ------------------
  |  |   84|  5.88k|#define fe25519_sub          crypto_sign_ed25519_ref_fe25519_sub
  ------------------
 1701|  5.88k|  fe25519_mul(&a, &a, &t);
  ------------------
  |  |   85|  5.88k|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1702|  5.88k|  fe25519_add(&b, &p->x, &p->y); /* B = (Y1+X1)*(Y2+X2) */
  ------------------
  |  |   83|  5.88k|#define fe25519_add          crypto_sign_ed25519_ref_fe25519_add
  ------------------
 1703|  5.88k|  fe25519_add(&t, &q->x, &q->y);
  ------------------
  |  |   83|  5.88k|#define fe25519_add          crypto_sign_ed25519_ref_fe25519_add
  ------------------
 1704|  5.88k|  fe25519_mul(&b, &b, &t);
  ------------------
  |  |   85|  5.88k|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1705|  5.88k|  fe25519_mul(&c, &p->t, &q->t); /* C = T1*k*T2 */
  ------------------
  |  |   85|  5.88k|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1706|  5.88k|  fe25519_mul(&c, &c, &ge25519_ec2d);
  ------------------
  |  |   85|  5.88k|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1707|  5.88k|  fe25519_mul(&d, &p->z, &q->z); /* D = Z1*2*Z2 */
  ------------------
  |  |   85|  5.88k|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1708|  5.88k|  fe25519_add(&d, &d, &d);
  ------------------
  |  |   83|  5.88k|#define fe25519_add          crypto_sign_ed25519_ref_fe25519_add
  ------------------
 1709|  5.88k|  fe25519_sub(&r->x, &b, &a); /* E = B-A */
  ------------------
  |  |   84|  5.88k|#define fe25519_sub          crypto_sign_ed25519_ref_fe25519_sub
  ------------------
 1710|  5.88k|  fe25519_sub(&r->t, &d, &c); /* F = D-C */
  ------------------
  |  |   84|  5.88k|#define fe25519_sub          crypto_sign_ed25519_ref_fe25519_sub
  ------------------
 1711|  5.88k|  fe25519_add(&r->z, &d, &c); /* G = D+C */
  ------------------
  |  |   83|  5.88k|#define fe25519_add          crypto_sign_ed25519_ref_fe25519_add
  ------------------
 1712|  5.88k|  fe25519_add(&r->y, &b, &a); /* H = B+A */
  ------------------
  |  |   83|  5.88k|#define fe25519_add          crypto_sign_ed25519_ref_fe25519_add
  ------------------
 1713|  5.88k|}
ed25519.c:crypto_sign_ed25519_ref_sc25519_2interleave2:
  706|     51|{
  707|     51|  int i;
  708|  1.63k|  for(i=0;i<31;i++)
  ------------------
  |  Branch (708:11): [True: 1.58k, False: 51]
  ------------------
  709|  1.58k|  {
  710|  1.58k|    r[4*i]   = ( s1->v[i]       & 3) ^ (( s2->v[i]       & 3) << 2);
  711|  1.58k|    r[4*i+1] = ((s1->v[i] >> 2) & 3) ^ (((s2->v[i] >> 2) & 3) << 2);
  712|  1.58k|    r[4*i+2] = ((s1->v[i] >> 4) & 3) ^ (((s2->v[i] >> 4) & 3) << 2);
  713|  1.58k|    r[4*i+3] = ((s1->v[i] >> 6) & 3) ^ (((s2->v[i] >> 6) & 3) << 2);
  714|  1.58k|  }
  715|     51|  r[124] = ( s1->v[31]       & 3) ^ (( s2->v[31]       & 3) << 2);
  716|     51|  r[125] = ((s1->v[31] >> 2) & 3) ^ (((s2->v[31] >> 2) & 3) << 2);
  717|     51|  r[126] = ((s1->v[31] >> 4) & 3) ^ (((s2->v[31] >> 4) & 3) << 2);
  718|     51|}
ed25519.c:p1p1_to_p2:
 1660|  18.8k|{
 1661|  18.8k|  fe25519_mul(&r->x, &p->x, &p->t);
  ------------------
  |  |   85|  18.8k|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1662|  18.8k|  fe25519_mul(&r->y, &p->y, &p->z);
  ------------------
  |  |   85|  18.8k|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1663|  18.8k|  fe25519_mul(&r->z, &p->z, &p->t);
  ------------------
  |  |   85|  18.8k|#define fe25519_mul          crypto_sign_ed25519_ref_fe25519_mul
  ------------------
 1664|  18.8k|}
ed25519.c:crypto_verify_32:
   30|     51|{
   31|     51|  unsigned int differentbits = 0;
   32|     51|#define F(i) differentbits |= x[i] ^ y[i];
   33|     51|  F(0)
  ------------------
  |  |   32|     51|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   34|     51|  F(1)
  ------------------
  |  |   32|     51|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   35|     51|  F(2)
  ------------------
  |  |   32|     51|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   36|     51|  F(3)
  ------------------
  |  |   32|     51|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   37|     51|  F(4)
  ------------------
  |  |   32|     51|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   38|     51|  F(5)
  ------------------
  |  |   32|     51|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   39|     51|  F(6)
  ------------------
  |  |   32|     51|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   40|     51|  F(7)
  ------------------
  |  |   32|     51|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   41|     51|  F(8)
  ------------------
  |  |   32|     51|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   42|     51|  F(9)
  ------------------
  |  |   32|     51|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   43|     51|  F(10)
  ------------------
  |  |   32|     51|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   44|     51|  F(11)
  ------------------
  |  |   32|     51|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   45|     51|  F(12)
  ------------------
  |  |   32|     51|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   46|     51|  F(13)
  ------------------
  |  |   32|     51|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   47|     51|  F(14)
  ------------------
  |  |   32|     51|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   48|     51|  F(15)
  ------------------
  |  |   32|     51|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   49|     51|  F(16)
  ------------------
  |  |   32|     51|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   50|     51|  F(17)
  ------------------
  |  |   32|     51|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   51|     51|  F(18)
  ------------------
  |  |   32|     51|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   52|     51|  F(19)
  ------------------
  |  |   32|     51|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   53|     51|  F(20)
  ------------------
  |  |   32|     51|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   54|     51|  F(21)
  ------------------
  |  |   32|     51|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   55|     51|  F(22)
  ------------------
  |  |   32|     51|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   56|     51|  F(23)
  ------------------
  |  |   32|     51|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   57|     51|  F(24)
  ------------------
  |  |   32|     51|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   58|     51|  F(25)
  ------------------
  |  |   32|     51|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   59|     51|  F(26)
  ------------------
  |  |   32|     51|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   60|     51|  F(27)
  ------------------
  |  |   32|     51|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   61|     51|  F(28)
  ------------------
  |  |   32|     51|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   62|     51|  F(29)
  ------------------
  |  |   32|     51|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   63|     51|  F(30)
  ------------------
  |  |   32|     51|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   64|     51|  F(31)
  ------------------
  |  |   32|     51|#define F(i) differentbits |= x[i] ^ y[i];
  ------------------
   65|     51|  return (1 & ((differentbits - 1) >> 8)) - 1;
   66|     51|}

crypto_hash_sha512:
   19|     51|{
   20|       |
   21|     51|	if (!EVP_Digest(in, inlen, out, NULL, EVP_sha512(), NULL))
  ------------------
  |  Branch (21:6): [True: 0, False: 51]
  ------------------
   22|      0|		return -1;
   23|     51|	return 0;
   24|     51|}

log_init:
  203|  2.64k|{
  204|       |#if defined(HAVE_OPENLOG_R) && defined(SYSLOG_DATA_INIT)
  205|       |	struct syslog_data sdata = SYSLOG_DATA_INIT;
  206|       |#endif
  207|       |
  208|  2.64k|	argv0 = av0;
  209|       |
  210|  2.64k|	if (log_change_level(level) != 0) {
  ------------------
  |  Branch (210:6): [True: 0, False: 2.64k]
  ------------------
  211|      0|		fprintf(stderr, "Unrecognized internal syslog level code %d\n",
  212|      0|		    (int) level);
  213|      0|		exit(1);
  214|      0|	}
  215|       |
  216|  2.64k|	log_handler = NULL;
  217|  2.64k|	log_handler_ctx = NULL;
  218|       |
  219|  2.64k|	log_on_stderr = on_stderr;
  220|  2.64k|	if (on_stderr)
  ------------------
  |  Branch (220:6): [True: 2.64k, False: 0]
  ------------------
  221|  2.64k|		return;
  222|       |
  223|      0|	switch (facility) {
  224|      0|	case SYSLOG_FACILITY_DAEMON:
  ------------------
  |  Branch (224:2): [True: 0, False: 0]
  ------------------
  225|      0|		log_facility = LOG_DAEMON;
  226|      0|		break;
  227|      0|	case SYSLOG_FACILITY_USER:
  ------------------
  |  Branch (227:2): [True: 0, False: 0]
  ------------------
  228|      0|		log_facility = LOG_USER;
  229|      0|		break;
  230|      0|	case SYSLOG_FACILITY_AUTH:
  ------------------
  |  Branch (230:2): [True: 0, False: 0]
  ------------------
  231|      0|		log_facility = LOG_AUTH;
  232|      0|		break;
  233|      0|#ifdef LOG_AUTHPRIV
  234|      0|	case SYSLOG_FACILITY_AUTHPRIV:
  ------------------
  |  Branch (234:2): [True: 0, False: 0]
  ------------------
  235|      0|		log_facility = LOG_AUTHPRIV;
  236|      0|		break;
  237|      0|#endif
  238|      0|	case SYSLOG_FACILITY_LOCAL0:
  ------------------
  |  Branch (238:2): [True: 0, False: 0]
  ------------------
  239|      0|		log_facility = LOG_LOCAL0;
  240|      0|		break;
  241|      0|	case SYSLOG_FACILITY_LOCAL1:
  ------------------
  |  Branch (241:2): [True: 0, False: 0]
  ------------------
  242|      0|		log_facility = LOG_LOCAL1;
  243|      0|		break;
  244|      0|	case SYSLOG_FACILITY_LOCAL2:
  ------------------
  |  Branch (244:2): [True: 0, False: 0]
  ------------------
  245|      0|		log_facility = LOG_LOCAL2;
  246|      0|		break;
  247|      0|	case SYSLOG_FACILITY_LOCAL3:
  ------------------
  |  Branch (247:2): [True: 0, False: 0]
  ------------------
  248|      0|		log_facility = LOG_LOCAL3;
  249|      0|		break;
  250|      0|	case SYSLOG_FACILITY_LOCAL4:
  ------------------
  |  Branch (250:2): [True: 0, False: 0]
  ------------------
  251|      0|		log_facility = LOG_LOCAL4;
  252|      0|		break;
  253|      0|	case SYSLOG_FACILITY_LOCAL5:
  ------------------
  |  Branch (253:2): [True: 0, False: 0]
  ------------------
  254|      0|		log_facility = LOG_LOCAL5;
  255|      0|		break;
  256|      0|	case SYSLOG_FACILITY_LOCAL6:
  ------------------
  |  Branch (256:2): [True: 0, False: 0]
  ------------------
  257|      0|		log_facility = LOG_LOCAL6;
  258|      0|		break;
  259|      0|	case SYSLOG_FACILITY_LOCAL7:
  ------------------
  |  Branch (259:2): [True: 0, False: 0]
  ------------------
  260|      0|		log_facility = LOG_LOCAL7;
  261|      0|		break;
  262|      0|	default:
  ------------------
  |  Branch (262:2): [True: 0, False: 0]
  ------------------
  263|      0|		fprintf(stderr,
  264|      0|		    "Unrecognized internal syslog facility code %d\n",
  265|      0|		    (int) facility);
  266|      0|		exit(1);
  267|      0|	}
  268|       |
  269|       |	/*
  270|       |	 * If an external library (eg libwrap) attempts to use syslog
  271|       |	 * immediately after reexec, syslog may be pointing to the wrong
  272|       |	 * facility, so we force an open/close of syslog here.
  273|       |	 */
  274|       |#if defined(HAVE_OPENLOG_R) && defined(SYSLOG_DATA_INIT)
  275|       |	openlog_r(argv0 ? argv0 : __progname, LOG_PID, log_facility, &sdata);
  276|       |	closelog_r(&sdata);
  277|       |#else
  278|      0|	openlog(argv0 ? argv0 : __progname, LOG_PID, log_facility);
  ------------------
  |  Branch (278:10): [True: 0, False: 0]
  ------------------
  279|      0|	closelog();
  280|      0|#endif
  281|      0|}
log_change_level:
  285|  2.64k|{
  286|       |	/* no-op if log_init has not been called */
  287|  2.64k|	if (argv0 == NULL)
  ------------------
  |  Branch (287:6): [True: 0, False: 2.64k]
  ------------------
  288|      0|		return 0;
  289|       |
  290|  2.64k|	switch (new_log_level) {
  291|  2.64k|	case SYSLOG_LEVEL_QUIET:
  ------------------
  |  Branch (291:2): [True: 2.64k, False: 0]
  ------------------
  292|  2.64k|	case SYSLOG_LEVEL_FATAL:
  ------------------
  |  Branch (292:2): [True: 0, False: 2.64k]
  ------------------
  293|  2.64k|	case SYSLOG_LEVEL_ERROR:
  ------------------
  |  Branch (293:2): [True: 0, False: 2.64k]
  ------------------
  294|  2.64k|	case SYSLOG_LEVEL_INFO:
  ------------------
  |  Branch (294:2): [True: 0, False: 2.64k]
  ------------------
  295|  2.64k|	case SYSLOG_LEVEL_VERBOSE:
  ------------------
  |  Branch (295:2): [True: 0, False: 2.64k]
  ------------------
  296|  2.64k|	case SYSLOG_LEVEL_DEBUG1:
  ------------------
  |  Branch (296:2): [True: 0, False: 2.64k]
  ------------------
  297|  2.64k|	case SYSLOG_LEVEL_DEBUG2:
  ------------------
  |  Branch (297:2): [True: 0, False: 2.64k]
  ------------------
  298|  2.64k|	case SYSLOG_LEVEL_DEBUG3:
  ------------------
  |  Branch (298:2): [True: 0, False: 2.64k]
  ------------------
  299|  2.64k|		log_level = new_log_level;
  300|  2.64k|		return 0;
  301|      0|	default:
  ------------------
  |  Branch (301:2): [True: 0, False: 2.64k]
  ------------------
  302|      0|		return -1;
  303|  2.64k|	}
  304|  2.64k|}
sshlog:
  436|  9.37k|{
  437|  9.37k|	va_list args;
  438|       |
  439|  9.37k|	va_start(args, fmt);
  440|  9.37k|	sshlogv(file, func, line, showfunc, level, suffix, fmt, args);
  441|  9.37k|	va_end(args);
  442|  9.37k|}
sshlogv:
  473|  9.37k|{
  474|  9.37k|	char tag[128], fmt2[MSGBUFSIZ + 128];
  475|  9.37k|	int forced = 0;
  476|  9.37k|	const char *cp;
  477|  9.37k|	size_t i;
  478|       |
  479|       |	/* short circuit processing early if we're not going to log anything */
  480|  9.37k|	if (nlog_verbose == 0 && level > log_level)
  ------------------
  |  Branch (480:6): [True: 9.37k, False: 0]
  |  Branch (480:27): [True: 9.37k, False: 0]
  ------------------
  481|  9.37k|		return;
  482|       |
  483|      0|	snprintf(tag, sizeof(tag), "%.48s:%.48s():%d (pid=%ld)",
  484|      0|	    (cp = strrchr(file, '/')) == NULL ? file : cp + 1, func, line,
  ------------------
  |  Branch (484:6): [True: 0, False: 0]
  ------------------
  485|      0|	    (long)getpid());
  486|      0|	for (i = 0; i < nlog_verbose; i++) {
  ------------------
  |  Branch (486:14): [True: 0, False: 0]
  ------------------
  487|      0|		if (match_pattern_list(tag, log_verbose[i], 0) == 1) {
  ------------------
  |  Branch (487:7): [True: 0, False: 0]
  ------------------
  488|      0|			forced = 1;
  489|      0|			break;
  490|      0|		}
  491|      0|	}
  492|       |
  493|      0|	if (forced)
  ------------------
  |  Branch (493:6): [True: 0, False: 0]
  ------------------
  494|      0|		snprintf(fmt2, sizeof(fmt2), "%s: %s", tag, fmt);
  495|      0|	else if (showfunc)
  ------------------
  |  Branch (495:11): [True: 0, False: 0]
  ------------------
  496|      0|		snprintf(fmt2, sizeof(fmt2), "%s: %s", func, fmt);
  497|      0|	else
  498|      0|		strlcpy(fmt2, fmt, sizeof(fmt2));
  499|       |
  500|      0|	do_log(level, forced, suffix, fmt2, args);
  501|      0|}

match_pattern:
   58|  4.51k|{
   59|  24.7k|	for (;;) {
   60|       |		/* If at end of pattern, accept if also at end of string. */
   61|  24.7k|		if (!*pattern)
  ------------------
  |  Branch (61:7): [True: 2.20k, False: 22.5k]
  ------------------
   62|  2.20k|			return !*s;
   63|       |
   64|  22.5k|		if (*pattern == '*') {
  ------------------
  |  Branch (64:7): [True: 0, False: 22.5k]
  ------------------
   65|       |			/* Skip this and any consecutive asterisks. */
   66|      0|			while (*pattern == '*')
  ------------------
  |  Branch (66:11): [True: 0, False: 0]
  ------------------
   67|      0|				pattern++;
   68|       |
   69|       |			/* If at end of pattern, accept immediately. */
   70|      0|			if (!*pattern)
  ------------------
  |  Branch (70:8): [True: 0, False: 0]
  ------------------
   71|      0|				return 1;
   72|       |
   73|       |			/* If next character in pattern is known, optimize. */
   74|      0|			if (*pattern != '?' && *pattern != '*') {
  ------------------
  |  Branch (74:8): [True: 0, False: 0]
  |  Branch (74:27): [True: 0, False: 0]
  ------------------
   75|       |				/*
   76|       |				 * Look instances of the next character in
   77|       |				 * pattern, and try to match starting from
   78|       |				 * those.
   79|       |				 */
   80|      0|				for (; *s; s++)
  ------------------
  |  Branch (80:12): [True: 0, False: 0]
  ------------------
   81|      0|					if (*s == *pattern &&
  ------------------
  |  Branch (81:10): [True: 0, False: 0]
  ------------------
   82|      0|					    match_pattern(s + 1, pattern + 1))
  ------------------
  |  Branch (82:10): [True: 0, False: 0]
  ------------------
   83|      0|						return 1;
   84|       |				/* Failed. */
   85|      0|				return 0;
   86|      0|			}
   87|       |			/*
   88|       |			 * Move ahead one character at a time and try to
   89|       |			 * match at each position.
   90|       |			 */
   91|      0|			for (; *s; s++)
  ------------------
  |  Branch (91:11): [True: 0, False: 0]
  ------------------
   92|      0|				if (match_pattern(s, pattern))
  ------------------
  |  Branch (92:9): [True: 0, False: 0]
  ------------------
   93|      0|					return 1;
   94|       |			/* Failed. */
   95|      0|			return 0;
   96|      0|		}
   97|       |		/*
   98|       |		 * There must be at least one more character in the string.
   99|       |		 * If we are at the end, fail.
  100|       |		 */
  101|  22.5k|		if (!*s)
  ------------------
  |  Branch (101:7): [True: 78, False: 22.4k]
  ------------------
  102|     78|			return 0;
  103|       |
  104|       |		/* Check if the next character of the string is acceptable. */
  105|  22.4k|		if (*pattern != '?' && *pattern != *s)
  ------------------
  |  Branch (105:7): [True: 22.4k, False: 0]
  |  Branch (105:26): [True: 2.23k, False: 20.2k]
  ------------------
  106|  2.23k|			return 0;
  107|       |
  108|       |		/* Move to the next character, both in string and in pattern. */
  109|  20.2k|		s++;
  110|  20.2k|		pattern++;
  111|  20.2k|	}
  112|       |	/* NOTREACHED */
  113|  4.51k|}
match_pattern_list:
  123|  2.25k|{
  124|  2.25k|	char sub[1024];
  125|  2.25k|	int negated;
  126|  2.25k|	int got_positive;
  127|  2.25k|	u_int i, subi, len = strlen(pattern);
  128|       |
  129|  2.25k|	got_positive = 0;
  130|  6.76k|	for (i = 0; i < len;) {
  ------------------
  |  Branch (130:14): [True: 4.51k, False: 2.25k]
  ------------------
  131|       |		/* Check if the subpattern is negated. */
  132|  4.51k|		if (pattern[i] == '!') {
  ------------------
  |  Branch (132:7): [True: 0, False: 4.51k]
  ------------------
  133|      0|			negated = 1;
  134|      0|			i++;
  135|      0|		} else
  136|  4.51k|			negated = 0;
  137|       |
  138|       |		/*
  139|       |		 * Extract the subpattern up to a comma or end.  Convert the
  140|       |		 * subpattern to lowercase.
  141|       |		 */
  142|  4.51k|		for (subi = 0;
  143|  31.9k|		    i < len && subi < sizeof(sub) - 1 && pattern[i] != ',';
  ------------------
  |  Branch (143:7): [True: 29.7k, False: 2.25k]
  |  Branch (143:18): [True: 29.7k, False: 0]
  |  Branch (143:44): [True: 27.4k, False: 2.25k]
  ------------------
  144|  27.4k|		    subi++, i++)
  145|  27.4k|			sub[subi] = dolower && isupper((u_char)pattern[i]) ?
  ------------------
  |  Branch (145:16): [True: 0, False: 27.4k]
  ------------------
  146|  27.4k|			    tolower((u_char)pattern[i]) : pattern[i];
  147|       |		/* If subpattern too long, return failure (no match). */
  148|  4.51k|		if (subi >= sizeof(sub) - 1)
  ------------------
  |  Branch (148:7): [True: 0, False: 4.51k]
  ------------------
  149|      0|			return 0;
  150|       |
  151|       |		/* If the subpattern was terminated by a comma, then skip it. */
  152|  4.51k|		if (i < len && pattern[i] == ',')
  ------------------
  |  Branch (152:7): [True: 2.25k, False: 2.25k]
  |  Branch (152:18): [True: 2.25k, False: 0]
  ------------------
  153|  2.25k|			i++;
  154|       |
  155|       |		/* Null-terminate the subpattern. */
  156|  4.51k|		sub[subi] = '\0';
  157|       |
  158|       |		/* Try to match the subpattern against the string. */
  159|  4.51k|		if (match_pattern(string, sub)) {
  ------------------
  |  Branch (159:7): [True: 2.19k, False: 2.31k]
  ------------------
  160|  2.19k|			if (negated)
  ------------------
  |  Branch (160:8): [True: 0, False: 2.19k]
  ------------------
  161|      0|				return -1;		/* Negative */
  162|  2.19k|			else
  163|  2.19k|				got_positive = 1;	/* Positive */
  164|  2.19k|		}
  165|  4.51k|	}
  166|       |
  167|       |	/*
  168|       |	 * Return success if got a positive match.  If there was a negative
  169|       |	 * match, we have already returned -1 and never get here.
  170|       |	 */
  171|  2.25k|	return got_positive;
  172|  2.25k|}

tohex:
 1543|  2.16k|{
 1544|  2.16k|	const u_char *p = (const u_char *)vp;
 1545|  2.16k|	char b[3], *r;
 1546|  2.16k|	size_t i, hl;
 1547|       |
 1548|  2.16k|	if (l > 65536)
  ------------------
  |  Branch (1548:6): [True: 0, False: 2.16k]
  ------------------
 1549|      0|		return xstrdup("tohex: length > 65536");
 1550|       |
 1551|  2.16k|	hl = l * 2 + 1;
 1552|  2.16k|	r = xcalloc(1, hl);
 1553|   109k|	for (i = 0; i < l; i++) {
  ------------------
  |  Branch (1553:14): [True: 107k, False: 2.16k]
  ------------------
 1554|   107k|		snprintf(b, sizeof(b), "%02x", p[i]);
 1555|   107k|		strlcat(r, b, hl);
 1556|   107k|	}
 1557|  2.16k|	return (r);
 1558|  2.16k|}

freezero:
   26|  44.5k|{
   27|  44.5k|	if (ptr == NULL)
  ------------------
  |  Branch (27:6): [True: 15.2k, False: 29.3k]
  ------------------
   28|  15.2k|		return;
   29|  29.3k|	explicit_bzero(ptr, sz);
   30|  29.3k|	free(ptr);
   31|  29.3k|}

recallocarray:
   39|  3.15k|{
   40|  3.15k|	size_t oldsize, newsize;
   41|  3.15k|	void *newptr;
   42|       |
   43|  3.15k|	if (ptr == NULL)
  ------------------
  |  Branch (43:6): [True: 54, False: 3.09k]
  ------------------
   44|     54|		return calloc(newnmemb, size);
   45|       |
   46|  3.09k|	if ((newnmemb >= MUL_NO_OVERFLOW || size >= MUL_NO_OVERFLOW) &&
  ------------------
  |  |   35|  6.19k|#define MUL_NO_OVERFLOW ((size_t)1 << (sizeof(size_t) * 4))
  ------------------
              	if ((newnmemb >= MUL_NO_OVERFLOW || size >= MUL_NO_OVERFLOW) &&
  ------------------
  |  |   35|  3.09k|#define MUL_NO_OVERFLOW ((size_t)1 << (sizeof(size_t) * 4))
  ------------------
  |  Branch (46:7): [True: 0, False: 3.09k]
  |  Branch (46:38): [True: 0, False: 3.09k]
  ------------------
   47|  3.09k|	    newnmemb > 0 && SIZE_MAX / newnmemb < size) {
  ------------------
  |  Branch (47:6): [True: 0, False: 0]
  |  Branch (47:22): [True: 0, False: 0]
  ------------------
   48|      0|		errno = ENOMEM;
   49|      0|		return NULL;
   50|      0|	}
   51|  3.09k|	newsize = newnmemb * size;
   52|       |
   53|  3.09k|	if ((oldnmemb >= MUL_NO_OVERFLOW || size >= MUL_NO_OVERFLOW) &&
  ------------------
  |  |   35|  6.19k|#define MUL_NO_OVERFLOW ((size_t)1 << (sizeof(size_t) * 4))
  ------------------
              	if ((oldnmemb >= MUL_NO_OVERFLOW || size >= MUL_NO_OVERFLOW) &&
  ------------------
  |  |   35|  3.09k|#define MUL_NO_OVERFLOW ((size_t)1 << (sizeof(size_t) * 4))
  ------------------
  |  Branch (53:7): [True: 0, False: 3.09k]
  |  Branch (53:38): [True: 0, False: 3.09k]
  ------------------
   54|  3.09k|	    oldnmemb > 0 && SIZE_MAX / oldnmemb < size) {
  ------------------
  |  Branch (54:6): [True: 0, False: 0]
  |  Branch (54:22): [True: 0, False: 0]
  ------------------
   55|      0|		errno = EINVAL;
   56|      0|		return NULL;
   57|      0|	}
   58|  3.09k|	oldsize = oldnmemb * size;
   59|       |	
   60|       |	/*
   61|       |	 * Don't bother too much if we're shrinking just a bit,
   62|       |	 * we do not shrink for series of small steps, oh well.
   63|       |	 */
   64|  3.09k|	if (newsize <= oldsize) {
  ------------------
  |  Branch (64:6): [True: 52, False: 3.04k]
  ------------------
   65|     52|		size_t d = oldsize - newsize;
   66|       |
   67|     52|		if (d < oldsize / 2 && d < (size_t)getpagesize()) {
  ------------------
  |  Branch (67:7): [True: 0, False: 52]
  |  Branch (67:26): [True: 0, False: 0]
  ------------------
   68|      0|			memset((char *)ptr + newsize, 0, d);
   69|      0|			return ptr;
   70|      0|		}
   71|     52|	}
   72|       |
   73|  3.09k|	newptr = malloc(newsize);
   74|  3.09k|	if (newptr == NULL)
  ------------------
  |  Branch (74:6): [True: 0, False: 3.09k]
  ------------------
   75|      0|		return NULL;
   76|       |
   77|  3.09k|	if (newsize > oldsize) {
  ------------------
  |  Branch (77:6): [True: 3.04k, False: 52]
  ------------------
   78|  3.04k|		memcpy(newptr, ptr, oldsize);
   79|  3.04k|		memset((char *)newptr + oldsize, 0, newsize - oldsize);
   80|  3.04k|	} else
   81|     52|		memcpy(newptr, ptr, newsize);
   82|       |
   83|  3.09k|	explicit_bzero(ptr, oldsize);
   84|  3.09k|	free(ptr);
   85|       |
   86|  3.09k|	return newptr;
   87|  3.09k|}

strlcat:
   36|   107k|{
   37|   107k|	char *d = dst;
   38|   107k|	const char *s = src;
   39|   107k|	size_t n = siz;
   40|   107k|	size_t dlen;
   41|       |
   42|       |	/* Find the end of dst and adjust bytes left but don't go past end */
   43|  5.91M|	while (n-- != 0 && *d != '\0')
  ------------------
  |  Branch (43:9): [True: 5.91M, False: 0]
  |  Branch (43:21): [True: 5.80M, False: 107k]
  ------------------
   44|  5.80M|		d++;
   45|   107k|	dlen = d - dst;
   46|   107k|	n = siz - dlen;
   47|       |
   48|   107k|	if (n == 0)
  ------------------
  |  Branch (48:6): [True: 0, False: 107k]
  ------------------
   49|      0|		return(dlen + strlen(s));
   50|   323k|	while (*s != '\0') {
  ------------------
  |  Branch (50:9): [True: 215k, False: 107k]
  ------------------
   51|   215k|		if (n != 1) {
  ------------------
  |  Branch (51:7): [True: 215k, False: 0]
  ------------------
   52|   215k|			*d++ = *s;
   53|   215k|			n--;
   54|   215k|		}
   55|   215k|		s++;
   56|   215k|	}
   57|   107k|	*d = '\0';
   58|       |
   59|   107k|	return(dlen + (s - src));	/* count does not include NUL */
   60|   107k|}

timingsafe_bcmp:
   25|  4.80k|{
   26|  4.80k|	const unsigned char *p1 = b1, *p2 = b2;
   27|  4.80k|	int ret = 0;
   28|       |
   29|  33.6k|	for (; n > 0; n--)
  ------------------
  |  Branch (29:9): [True: 28.8k, False: 4.80k]
  ------------------
   30|  28.8k|		ret |= *p1++ ^ *p2++;
   31|  4.80k|	return (ret != 0);
   32|  4.80k|}

LLVMFuzzerTestOneInput:
   19|  2.64k|{
   20|  2.64k|  static const char *data = "If everyone started announcing his nose had "
   21|  2.64k|      "run away, I don’t know how it would all end";
   22|  2.64k|  struct sshbuf *signature = sshbuf_from(sig, slen);
   23|  2.64k|  struct sshbuf *message = sshbuf_from(data, strlen(data));
   24|  2.64k|  struct sshkey *k = NULL;
   25|  2.64k|  struct sshkey_sig_details *details = NULL;
   26|  2.64k|  extern char *__progname;
   27|       |
   28|  2.64k|  log_init(__progname, SYSLOG_LEVEL_QUIET, SYSLOG_FACILITY_USER, 1);
   29|  2.64k|  sshsig_verifyb(signature, message, "castle", &k, &details);
   30|  2.64k|  sshkey_sig_details_free(details);
   31|  2.64k|  sshkey_free(k);
   32|  2.64k|  sshbuf_free(signature);
   33|  2.64k|  sshbuf_free(message);
   34|  2.64k|  return 0;
   35|  2.64k|}

ssh-dss.c:ssh_dss_alloc:
   63|    661|{
   64|    661|	if ((k->dsa = DSA_new()) == NULL)
  ------------------
  |  Branch (64:6): [True: 0, False: 661]
  ------------------
   65|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
   66|    661|	return 0;
   67|    661|}
ssh-dss.c:ssh_dss_cleanup:
   71|    661|{
   72|    661|	DSA_free(k->dsa);
   73|    661|	k->dsa = NULL;
   74|    661|}
ssh-dss.c:ssh_dss_deserialize_public:
  203|    661|{
  204|    661|	int ret = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|    661|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  205|    661|	BIGNUM *dsa_p = NULL, *dsa_q = NULL, *dsa_g = NULL, *dsa_pub_key = NULL;
  206|       |
  207|    661|	if (sshbuf_get_bignum2(b, &dsa_p) != 0 ||
  ------------------
  |  Branch (207:6): [True: 68, False: 593]
  ------------------
  208|    661|	    sshbuf_get_bignum2(b, &dsa_q) != 0 ||
  ------------------
  |  Branch (208:6): [True: 35, False: 558]
  ------------------
  209|    661|	    sshbuf_get_bignum2(b, &dsa_g) != 0 ||
  ------------------
  |  Branch (209:6): [True: 12, False: 546]
  ------------------
  210|    661|	    sshbuf_get_bignum2(b, &dsa_pub_key) != 0) {
  ------------------
  |  Branch (210:6): [True: 9, False: 537]
  ------------------
  211|    124|		ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|    124|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  212|    124|		goto out;
  213|    124|	}
  214|    537|	if (!DSA_set0_pqg(key->dsa, dsa_p, dsa_q, dsa_g)) {
  ------------------
  |  Branch (214:6): [True: 0, False: 537]
  ------------------
  215|      0|		ret = SSH_ERR_LIBCRYPTO_ERROR;
  ------------------
  |  |   46|      0|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
  216|      0|		goto out;
  217|      0|	}
  218|    537|	dsa_p = dsa_q = dsa_g = NULL; /* transferred */
  219|    537|	if (!DSA_set0_key(key->dsa, dsa_pub_key, NULL)) {
  ------------------
  |  Branch (219:6): [True: 0, False: 537]
  ------------------
  220|      0|		ret = SSH_ERR_LIBCRYPTO_ERROR;
  ------------------
  |  |   46|      0|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
  221|      0|		goto out;
  222|      0|	}
  223|    537|	dsa_pub_key = NULL; /* transferred */
  224|       |#ifdef DEBUG_PK
  225|       |	DSA_print_fp(stderr, key->dsa, 8);
  226|       |#endif
  227|       |	/* success */
  228|    537|	ret = 0;
  229|    661| out:
  230|    661|	BN_clear_free(dsa_p);
  231|    661|	BN_clear_free(dsa_q);
  232|    661|	BN_clear_free(dsa_g);
  233|    661|	BN_clear_free(dsa_pub_key);
  234|    661|	return ret;
  235|    537|}
ssh-dss.c:ssh_dss_verify:
  333|     99|{
  334|     99|	DSA_SIG *dsig = NULL;
  335|     99|	BIGNUM *sig_r = NULL, *sig_s = NULL;
  336|     99|	u_char digest[SSH_DIGEST_MAX_LENGTH], *sigblob = NULL;
  337|     99|	size_t len, hlen = ssh_digest_bytes(SSH_DIGEST_SHA1);
  ------------------
  |  |   26|     99|#define SSH_DIGEST_SHA1		1
  ------------------
  338|     99|	int ret = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|     99|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  339|     99|	struct sshbuf *b = NULL;
  340|     99|	char *ktype = NULL;
  341|       |
  342|     99|	if (key == NULL || key->dsa == NULL ||
  ------------------
  |  Branch (342:6): [True: 0, False: 99]
  |  Branch (342:21): [True: 0, False: 99]
  ------------------
  343|     99|	    sshkey_type_plain(key->type) != KEY_DSA ||
  ------------------
  |  Branch (343:6): [True: 0, False: 99]
  ------------------
  344|     99|	    sig == NULL || siglen == 0)
  ------------------
  |  Branch (344:6): [True: 0, False: 99]
  |  Branch (344:21): [True: 0, False: 99]
  ------------------
  345|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  346|     99|	if (hlen == 0)
  ------------------
  |  Branch (346:6): [True: 0, False: 99]
  ------------------
  347|      0|		return SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|      0|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  348|       |
  349|       |	/* fetch signature */
  350|     99|	if ((b = sshbuf_from(sig, siglen)) == NULL)
  ------------------
  |  Branch (350:6): [True: 0, False: 99]
  ------------------
  351|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  352|     99|	if (sshbuf_get_cstring(b, &ktype, NULL) != 0 ||
  ------------------
  |  Branch (352:6): [True: 18, False: 81]
  ------------------
  353|     99|	    sshbuf_get_string(b, &sigblob, &len) != 0) {
  ------------------
  |  Branch (353:6): [True: 3, False: 78]
  ------------------
  354|     21|		ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     21|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  355|     21|		goto out;
  356|     21|	}
  357|     78|	if (strcmp("ssh-dss", ktype) != 0) {
  ------------------
  |  Branch (357:6): [True: 65, False: 13]
  ------------------
  358|     65|		ret = SSH_ERR_KEY_TYPE_MISMATCH;
  ------------------
  |  |   37|     65|#define SSH_ERR_KEY_TYPE_MISMATCH		-13
  ------------------
  359|     65|		goto out;
  360|     65|	}
  361|     13|	if (sshbuf_len(b) != 0) {
  ------------------
  |  Branch (361:6): [True: 1, False: 12]
  ------------------
  362|      1|		ret = SSH_ERR_UNEXPECTED_TRAILING_DATA;
  ------------------
  |  |   47|      1|#define SSH_ERR_UNEXPECTED_TRAILING_DATA	-23
  ------------------
  363|      1|		goto out;
  364|      1|	}
  365|       |
  366|     12|	if (len != SIGBLOB_LEN) {
  ------------------
  |  |   48|     12|#define SIGBLOB_LEN	(2*INTBLOB_LEN)
  |  |  ------------------
  |  |  |  |   47|     12|#define INTBLOB_LEN	20
  |  |  ------------------
  ------------------
  |  Branch (366:6): [True: 11, False: 1]
  ------------------
  367|     11|		ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     11|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  368|     11|		goto out;
  369|     11|	}
  370|       |
  371|       |	/* parse signature */
  372|      1|	if ((dsig = DSA_SIG_new()) == NULL ||
  ------------------
  |  Branch (372:6): [True: 0, False: 1]
  ------------------
  373|      1|	    (sig_r = BN_new()) == NULL ||
  ------------------
  |  Branch (373:6): [True: 0, False: 1]
  ------------------
  374|      1|	    (sig_s = BN_new()) == NULL) {
  ------------------
  |  Branch (374:6): [True: 0, False: 1]
  ------------------
  375|      0|		ret = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  376|      0|		goto out;
  377|      0|	}
  378|      1|	if ((BN_bin2bn(sigblob, INTBLOB_LEN, sig_r) == NULL) ||
  ------------------
  |  |   47|      1|#define INTBLOB_LEN	20
  ------------------
  |  Branch (378:6): [True: 0, False: 1]
  ------------------
  379|      1|	    (BN_bin2bn(sigblob + INTBLOB_LEN, INTBLOB_LEN, sig_s) == NULL)) {
  ------------------
  |  |   47|      1|#define INTBLOB_LEN	20
  ------------------
              	    (BN_bin2bn(sigblob + INTBLOB_LEN, INTBLOB_LEN, sig_s) == NULL)) {
  ------------------
  |  |   47|      1|#define INTBLOB_LEN	20
  ------------------
  |  Branch (379:6): [True: 0, False: 1]
  ------------------
  380|      0|		ret = SSH_ERR_LIBCRYPTO_ERROR;
  ------------------
  |  |   46|      0|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
  381|      0|		goto out;
  382|      0|	}
  383|      1|	if (!DSA_SIG_set0(dsig, sig_r, sig_s)) {
  ------------------
  |  Branch (383:6): [True: 0, False: 1]
  ------------------
  384|      0|		ret = SSH_ERR_LIBCRYPTO_ERROR;
  ------------------
  |  |   46|      0|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
  385|      0|		goto out;
  386|      0|	}
  387|      1|	sig_r = sig_s = NULL; /* transferred */
  388|       |
  389|       |	/* sha1 the data */
  390|      1|	if ((ret = ssh_digest_memory(SSH_DIGEST_SHA1, data, dlen,
  ------------------
  |  |   26|      1|#define SSH_DIGEST_SHA1		1
  ------------------
  |  Branch (390:6): [True: 0, False: 1]
  ------------------
  391|      1|	    digest, sizeof(digest))) != 0)
  392|      0|		goto out;
  393|       |
  394|      1|	switch (DSA_do_verify(digest, hlen, dsig, key->dsa)) {
  395|      0|	case 1:
  ------------------
  |  Branch (395:2): [True: 0, False: 1]
  ------------------
  396|      0|		ret = 0;
  397|      0|		break;
  398|      0|	case 0:
  ------------------
  |  Branch (398:2): [True: 0, False: 1]
  ------------------
  399|      0|		ret = SSH_ERR_SIGNATURE_INVALID;
  ------------------
  |  |   45|      0|#define SSH_ERR_SIGNATURE_INVALID		-21
  ------------------
  400|      0|		goto out;
  401|      1|	default:
  ------------------
  |  Branch (401:2): [True: 1, False: 0]
  ------------------
  402|      1|		ret = SSH_ERR_LIBCRYPTO_ERROR;
  ------------------
  |  |   46|      1|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
  403|      1|		goto out;
  404|      1|	}
  405|       |
  406|     99| out:
  407|     99|	explicit_bzero(digest, sizeof(digest));
  408|     99|	DSA_SIG_free(dsig);
  409|     99|	BN_clear_free(sig_r);
  410|     99|	BN_clear_free(sig_s);
  411|     99|	sshbuf_free(b);
  412|     99|	free(ktype);
  413|     99|	if (sigblob != NULL)
  ------------------
  |  Branch (413:6): [True: 78, False: 21]
  ------------------
  414|     78|		freezero(sigblob, len);
  415|     99|	return ret;
  416|      1|}

ssh-ecdsa-sk.c:ssh_ecdsa_sk_cleanup:
   69|      7|{
   70|      7|	sshkey_sk_cleanup(k);
   71|      7|	sshkey_ecdsa_funcs.cleanup(k);
   72|      7|}
ssh-ecdsa-sk.c:ssh_ecdsa_sk_deserialize_public:
  130|      7|{
  131|      7|	int r;
  132|       |
  133|      7|	if ((r = sshkey_ecdsa_funcs.deserialize_public(ktype, b, key)) != 0)
  ------------------
  |  Branch (133:6): [True: 7, False: 0]
  ------------------
  134|      7|		return r;
  135|      0|	if ((r = sshkey_deserialize_sk(b, key)) != 0)
  ------------------
  |  Branch (135:6): [True: 0, False: 0]
  ------------------
  136|      0|		return r;
  137|      0|	return 0;
  138|      0|}

ssh-ecdsa.c:ssh_ecdsa_cleanup:
   67|    226|{
   68|    226|	EC_KEY_free(k->ecdsa);
   69|    226|	k->ecdsa = NULL;
   70|    226|}
ssh-ecdsa.c:ssh_ecdsa_deserialize_public:
  159|    226|{
  160|    226|	int r;
  161|    226|	char *curve = NULL;
  162|       |
  163|    226|	if ((key->ecdsa_nid = sshkey_ecdsa_nid_from_name(ktype)) == -1)
  ------------------
  |  Branch (163:6): [True: 10, False: 216]
  ------------------
  164|     10|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|     10|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  165|    216|	if ((r = sshbuf_get_cstring(b, &curve, NULL)) != 0)
  ------------------
  |  Branch (165:6): [True: 9, False: 207]
  ------------------
  166|      9|		goto out;
  167|    207|	if (key->ecdsa_nid != sshkey_curve_name_to_nid(curve)) {
  ------------------
  |  Branch (167:6): [True: 112, False: 95]
  ------------------
  168|    112|		r = SSH_ERR_EC_CURVE_MISMATCH;
  ------------------
  |  |   39|    112|#define SSH_ERR_EC_CURVE_MISMATCH		-15
  ------------------
  169|    112|		goto out;
  170|    112|	}
  171|     95|	EC_KEY_free(key->ecdsa);
  172|     95|	key->ecdsa = NULL;
  173|     95|	if ((key->ecdsa = EC_KEY_new_by_curve_name(key->ecdsa_nid)) == NULL) {
  ------------------
  |  Branch (173:6): [True: 0, False: 95]
  ------------------
  174|      0|		r = SSH_ERR_LIBCRYPTO_ERROR;
  ------------------
  |  |   46|      0|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
  175|      0|		goto out;
  176|      0|	}
  177|     95|	if ((r = sshbuf_get_eckey(b, key->ecdsa)) != 0)
  ------------------
  |  Branch (177:6): [True: 95, False: 0]
  ------------------
  178|     95|		goto out;
  179|      0|	if (sshkey_ec_validate_public(EC_KEY_get0_group(key->ecdsa),
  ------------------
  |  Branch (179:6): [True: 0, False: 0]
  ------------------
  180|      0|	    EC_KEY_get0_public_key(key->ecdsa)) != 0) {
  181|      0|		r = SSH_ERR_KEY_INVALID_EC_VALUE;
  ------------------
  |  |   44|      0|#define SSH_ERR_KEY_INVALID_EC_VALUE		-20
  ------------------
  182|      0|		goto out;
  183|      0|	}
  184|       |	/* success */
  185|      0|	r = 0;
  186|       |#ifdef DEBUG_PK
  187|       |	sshkey_dump_ec_point(EC_KEY_get0_group(key->ecdsa),
  188|       |	    EC_KEY_get0_public_key(key->ecdsa));
  189|       |#endif
  190|    216| out:
  191|    216|	free(curve);
  192|    216|	if (r != 0) {
  ------------------
  |  Branch (192:6): [True: 216, False: 0]
  ------------------
  193|    216|		EC_KEY_free(key->ecdsa);
  194|    216|		key->ecdsa = NULL;
  195|    216|	}
  196|    216|	return r;
  197|      0|}

ssh-ed25519-sk.c:ssh_ed25519_sk_cleanup:
   43|    152|{
   44|    152|	sshkey_sk_cleanup(k);
   45|    152|	sshkey_ed25519_funcs.cleanup(k);
   46|    152|}
ssh-ed25519-sk.c:ssh_ed25519_sk_deserialize_public:
  101|    151|{
  102|    151|	int r;
  103|       |
  104|    151|	if ((r = sshkey_ed25519_funcs.deserialize_public(ktype, b, key)) != 0)
  ------------------
  |  Branch (104:6): [True: 5, False: 146]
  ------------------
  105|      5|		return r;
  106|    146|	if ((r = sshkey_deserialize_sk(b, key)) != 0)
  ------------------
  |  Branch (106:6): [True: 1, False: 145]
  ------------------
  107|      1|		return r;
  108|    145|	return 0;
  109|    146|}
ssh-ed25519-sk.c:ssh_ed25519_sk_verify:
  129|    140|{
  130|    140|	struct sshbuf *b = NULL;
  131|    140|	struct sshbuf *encoded = NULL;
  132|    140|	char *ktype = NULL;
  133|    140|	const u_char *sigblob;
  134|    140|	const u_char *sm;
  135|    140|	u_char *m = NULL;
  136|    140|	u_char apphash[32];
  137|    140|	u_char msghash[32];
  138|    140|	u_char sig_flags;
  139|    140|	u_int sig_counter;
  140|    140|	size_t len;
  141|    140|	unsigned long long smlen = 0, mlen = 0;
  142|    140|	int r = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|    140|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  143|    140|	int ret;
  144|    140|	struct sshkey_sig_details *details = NULL;
  145|       |
  146|    140|	if (detailsp != NULL)
  ------------------
  |  Branch (146:6): [True: 8, False: 132]
  ------------------
  147|      8|		*detailsp = NULL;
  148|       |
  149|    140|	if (key == NULL ||
  ------------------
  |  Branch (149:6): [True: 0, False: 140]
  ------------------
  150|    140|	    sshkey_type_plain(key->type) != KEY_ED25519_SK ||
  ------------------
  |  Branch (150:6): [True: 0, False: 140]
  ------------------
  151|    140|	    key->ed25519_pk == NULL ||
  ------------------
  |  Branch (151:6): [True: 0, False: 140]
  ------------------
  152|    140|	    sig == NULL || siglen == 0)
  ------------------
  |  Branch (152:6): [True: 0, False: 140]
  |  Branch (152:21): [True: 0, False: 140]
  ------------------
  153|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  154|       |
  155|    140|	if ((b = sshbuf_from(sig, siglen)) == NULL)
  ------------------
  |  Branch (155:6): [True: 0, False: 140]
  ------------------
  156|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  157|    140|	if (sshbuf_get_cstring(b, &ktype, NULL) != 0 ||
  ------------------
  |  Branch (157:6): [True: 3, False: 137]
  ------------------
  158|    140|	    sshbuf_get_string_direct(b, &sigblob, &len) != 0 ||
  ------------------
  |  Branch (158:6): [True: 2, False: 135]
  ------------------
  159|    140|	    sshbuf_get_u8(b, &sig_flags) != 0 ||
  ------------------
  |  Branch (159:6): [True: 2, False: 133]
  ------------------
  160|    140|	    sshbuf_get_u32(b, &sig_counter) != 0) {
  ------------------
  |  Branch (160:6): [True: 1, False: 132]
  ------------------
  161|      8|		r = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      8|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  162|      8|		goto out;
  163|      8|	}
  164|       |#ifdef DEBUG_SK
  165|       |	fprintf(stderr, "%s: data:\n", __func__);
  166|       |	/* sshbuf_dump_data(data, datalen, stderr); */
  167|       |	fprintf(stderr, "%s: sigblob:\n", __func__);
  168|       |	sshbuf_dump_data(sigblob, len, stderr);
  169|       |	fprintf(stderr, "%s: sig_flags = 0x%02x, sig_counter = %u\n",
  170|       |	    __func__, sig_flags, sig_counter);
  171|       |#endif
  172|    132|	if (strcmp(sshkey_ssh_name_plain(key), ktype) != 0) {
  ------------------
  |  Branch (172:6): [True: 107, False: 25]
  ------------------
  173|    107|		r = SSH_ERR_KEY_TYPE_MISMATCH;
  ------------------
  |  |   37|    107|#define SSH_ERR_KEY_TYPE_MISMATCH		-13
  ------------------
  174|    107|		goto out;
  175|    107|	}
  176|     25|	if (sshbuf_len(b) != 0) {
  ------------------
  |  Branch (176:6): [True: 11, False: 14]
  ------------------
  177|     11|		r = SSH_ERR_UNEXPECTED_TRAILING_DATA;
  ------------------
  |  |   47|     11|#define SSH_ERR_UNEXPECTED_TRAILING_DATA	-23
  ------------------
  178|     11|		goto out;
  179|     11|	}
  180|     14|	if (len > crypto_sign_ed25519_BYTES) {
  ------------------
  |  |   37|     14|#define crypto_sign_ed25519_BYTES 64U
  ------------------
  |  Branch (180:6): [True: 1, False: 13]
  ------------------
  181|      1|		r = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      1|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  182|      1|		goto out;
  183|      1|	}
  184|     13|	if (ssh_digest_memory(SSH_DIGEST_SHA256, key->sk_application,
  ------------------
  |  |   27|     13|#define SSH_DIGEST_SHA256	2
  ------------------
  |  Branch (184:6): [True: 0, False: 13]
  ------------------
  185|     13|	    strlen(key->sk_application), apphash, sizeof(apphash)) != 0 ||
  186|     13|	    ssh_digest_memory(SSH_DIGEST_SHA256, data, dlen,
  ------------------
  |  |   27|     13|#define SSH_DIGEST_SHA256	2
  ------------------
  |  Branch (186:6): [True: 0, False: 13]
  ------------------
  187|     13|	    msghash, sizeof(msghash)) != 0) {
  188|      0|		r = SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  189|      0|		goto out;
  190|      0|	}
  191|       |#ifdef DEBUG_SK
  192|       |	fprintf(stderr, "%s: hashed application:\n", __func__);
  193|       |	sshbuf_dump_data(apphash, sizeof(apphash), stderr);
  194|       |	fprintf(stderr, "%s: hashed message:\n", __func__);
  195|       |	sshbuf_dump_data(msghash, sizeof(msghash), stderr);
  196|       |#endif
  197|     13|	if ((details = calloc(1, sizeof(*details))) == NULL) {
  ------------------
  |  Branch (197:6): [True: 0, False: 13]
  ------------------
  198|      0|		r = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  199|      0|		goto out;
  200|      0|	}
  201|     13|	details->sk_counter = sig_counter;
  202|     13|	details->sk_flags = sig_flags;
  203|     13|	if ((encoded = sshbuf_new()) == NULL) {
  ------------------
  |  |   36|     13|#define sshbuf_new() sshbuf_new_label(__func__)
  ------------------
  |  Branch (203:6): [True: 0, False: 13]
  ------------------
  204|      0|		r = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  205|      0|		goto out;
  206|      0|	}
  207|     13|	if (sshbuf_put(encoded, sigblob, len) != 0 ||
  ------------------
  |  Branch (207:6): [True: 0, False: 13]
  ------------------
  208|     13|	    sshbuf_put(encoded, apphash, sizeof(apphash)) != 0 ||
  ------------------
  |  Branch (208:6): [True: 0, False: 13]
  ------------------
  209|     13|	    sshbuf_put_u8(encoded, sig_flags) != 0 ||
  ------------------
  |  Branch (209:6): [True: 0, False: 13]
  ------------------
  210|     13|	    sshbuf_put_u32(encoded, sig_counter) != 0 ||
  ------------------
  |  Branch (210:6): [True: 0, False: 13]
  ------------------
  211|     13|	    sshbuf_put(encoded, msghash, sizeof(msghash)) != 0) {
  ------------------
  |  Branch (211:6): [True: 0, False: 13]
  ------------------
  212|      0|		r = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  213|      0|		goto out;
  214|      0|	}
  215|       |#ifdef DEBUG_SK
  216|       |	fprintf(stderr, "%s: signed buf:\n", __func__);
  217|       |	sshbuf_dump(encoded, stderr);
  218|       |#endif
  219|     13|	sm = sshbuf_ptr(encoded);
  220|     13|	smlen = sshbuf_len(encoded);
  221|     13|	mlen = smlen;
  222|     13|	if ((m = malloc(smlen)) == NULL) {
  ------------------
  |  Branch (222:6): [True: 0, False: 13]
  ------------------
  223|      0|		r = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  224|      0|		goto out;
  225|      0|	}
  226|     13|	if ((ret = crypto_sign_ed25519_open(m, &mlen, sm, smlen,
  ------------------
  |  Branch (226:6): [True: 12, False: 1]
  ------------------
  227|     13|	    key->ed25519_pk)) != 0) {
  228|     12|		debug2_f("crypto_sign_ed25519_open failed: %d", ret);
  ------------------
  |  |  101|     12|#define debug2_f(...)		sshlog(__FILE__, __func__, __LINE__, 1, SYSLOG_LEVEL_DEBUG2, NULL, __VA_ARGS__)
  ------------------
  229|     12|	}
  230|     13|	if (ret != 0 || mlen != smlen - len) {
  ------------------
  |  Branch (230:6): [True: 12, False: 1]
  |  Branch (230:18): [True: 0, False: 1]
  ------------------
  231|     12|		r = SSH_ERR_SIGNATURE_INVALID;
  ------------------
  |  |   45|     12|#define SSH_ERR_SIGNATURE_INVALID		-21
  ------------------
  232|     12|		goto out;
  233|     12|	}
  234|       |	/* XXX compare 'm' and 'sm + len' ? */
  235|       |	/* success */
  236|      1|	r = 0;
  237|      1|	if (detailsp != NULL) {
  ------------------
  |  Branch (237:6): [True: 0, False: 1]
  ------------------
  238|      0|		*detailsp = details;
  239|      0|		details = NULL;
  240|      0|	}
  241|    140| out:
  242|    140|	if (m != NULL)
  ------------------
  |  Branch (242:6): [True: 13, False: 127]
  ------------------
  243|     13|		freezero(m, smlen); /* NB mlen may be invalid if r != 0 */
  244|    140|	sshkey_sig_details_free(details);
  245|    140|	sshbuf_free(b);
  246|    140|	sshbuf_free(encoded);
  247|    140|	free(ktype);
  248|    140|	return r;
  249|      1|}

ssh-ed25519.c:ssh_ed25519_cleanup:
   37|    758|{
   38|    758|	freezero(k->ed25519_pk, ED25519_PK_SZ);
  ------------------
  |  |  159|    758|#define	ED25519_PK_SZ	crypto_sign_ed25519_PUBLICKEYBYTES
  |  |  ------------------
  |  |  |  |   36|    758|#define crypto_sign_ed25519_PUBLICKEYBYTES 32U
  |  |  ------------------
  ------------------
   39|    758|	freezero(k->ed25519_sk, ED25519_SK_SZ);
  ------------------
  |  |  158|    758|#define	ED25519_SK_SZ	crypto_sign_ed25519_SECRETKEYBYTES
  |  |  ------------------
  |  |  |  |   35|    758|#define crypto_sign_ed25519_SECRETKEYBYTES 64U
  |  |  ------------------
  ------------------
   40|    758|	k->ed25519_pk = NULL;
   41|    758|	k->ed25519_sk = NULL;
   42|    758|}
ssh-ed25519.c:ssh_ed25519_deserialize_public:
  105|    756|{
  106|    756|	u_char *pk = NULL;
  107|    756|	size_t len = 0;
  108|    756|	int r;
  109|       |
  110|    756|	if ((r = sshbuf_get_string(b, &pk, &len)) != 0)
  ------------------
  |  Branch (110:6): [True: 7, False: 749]
  ------------------
  111|      7|		return r;
  112|    749|	if (len != ED25519_PK_SZ) {
  ------------------
  |  |  159|    749|#define	ED25519_PK_SZ	crypto_sign_ed25519_PUBLICKEYBYTES
  |  |  ------------------
  |  |  |  |   36|    749|#define crypto_sign_ed25519_PUBLICKEYBYTES 32U
  |  |  ------------------
  ------------------
  |  Branch (112:6): [True: 16, False: 733]
  ------------------
  113|     16|		freezero(pk, len);
  114|     16|		return SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     16|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  115|     16|	}
  116|    733|	key->ed25519_pk = pk;
  117|    733|	return 0;
  118|    749|}
ssh-ed25519.c:ssh_ed25519_verify:
  209|    205|{
  210|    205|	struct sshbuf *b = NULL;
  211|    205|	char *ktype = NULL;
  212|    205|	const u_char *sigblob;
  213|    205|	u_char *sm = NULL, *m = NULL;
  214|    205|	size_t len;
  215|    205|	unsigned long long smlen = 0, mlen = 0;
  216|    205|	int r, ret;
  217|       |
  218|    205|	if (key == NULL ||
  ------------------
  |  Branch (218:6): [True: 0, False: 205]
  ------------------
  219|    205|	    sshkey_type_plain(key->type) != KEY_ED25519 ||
  ------------------
  |  Branch (219:6): [True: 0, False: 205]
  ------------------
  220|    205|	    key->ed25519_pk == NULL ||
  ------------------
  |  Branch (220:6): [True: 0, False: 205]
  ------------------
  221|    205|	    dlen >= INT_MAX - crypto_sign_ed25519_BYTES ||
  ------------------
  |  |   37|    410|#define crypto_sign_ed25519_BYTES 64U
  ------------------
  |  Branch (221:6): [True: 0, False: 205]
  ------------------
  222|    205|	    sig == NULL || siglen == 0)
  ------------------
  |  Branch (222:6): [True: 0, False: 205]
  |  Branch (222:21): [True: 0, False: 205]
  ------------------
  223|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  224|       |
  225|    205|	if ((b = sshbuf_from(sig, siglen)) == NULL)
  ------------------
  |  Branch (225:6): [True: 0, False: 205]
  ------------------
  226|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  227|    205|	if ((r = sshbuf_get_cstring(b, &ktype, NULL)) != 0 ||
  ------------------
  |  Branch (227:6): [True: 21, False: 184]
  ------------------
  228|    205|	    (r = sshbuf_get_string_direct(b, &sigblob, &len)) != 0)
  ------------------
  |  Branch (228:6): [True: 4, False: 180]
  ------------------
  229|     25|		goto out;
  230|    180|	if (strcmp("ssh-ed25519", ktype) != 0) {
  ------------------
  |  Branch (230:6): [True: 96, False: 84]
  ------------------
  231|     96|		r = SSH_ERR_KEY_TYPE_MISMATCH;
  ------------------
  |  |   37|     96|#define SSH_ERR_KEY_TYPE_MISMATCH		-13
  ------------------
  232|     96|		goto out;
  233|     96|	}
  234|     84|	if (sshbuf_len(b) != 0) {
  ------------------
  |  Branch (234:6): [True: 17, False: 67]
  ------------------
  235|     17|		r = SSH_ERR_UNEXPECTED_TRAILING_DATA;
  ------------------
  |  |   47|     17|#define SSH_ERR_UNEXPECTED_TRAILING_DATA	-23
  ------------------
  236|     17|		goto out;
  237|     17|	}
  238|     67|	if (len > crypto_sign_ed25519_BYTES) {
  ------------------
  |  |   37|     67|#define crypto_sign_ed25519_BYTES 64U
  ------------------
  |  Branch (238:6): [True: 3, False: 64]
  ------------------
  239|      3|		r = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      3|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  240|      3|		goto out;
  241|      3|	}
  242|     64|	if (dlen >= SIZE_MAX - len) {
  ------------------
  |  Branch (242:6): [True: 0, False: 64]
  ------------------
  243|      0|		r = SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  244|      0|		goto out;
  245|      0|	}
  246|     64|	smlen = len + dlen;
  247|     64|	mlen = smlen;
  248|     64|	if ((sm = malloc(smlen)) == NULL || (m = malloc(mlen)) == NULL) {
  ------------------
  |  Branch (248:6): [True: 0, False: 64]
  |  Branch (248:38): [True: 0, False: 64]
  ------------------
  249|      0|		r = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  250|      0|		goto out;
  251|      0|	}
  252|     64|	memcpy(sm, sigblob, len);
  253|     64|	memcpy(sm+len, data, dlen);
  254|     64|	if ((ret = crypto_sign_ed25519_open(m, &mlen, sm, smlen,
  ------------------
  |  Branch (254:6): [True: 57, False: 7]
  ------------------
  255|     64|	    key->ed25519_pk)) != 0) {
  256|     57|		debug2_f("crypto_sign_ed25519_open failed: %d", ret);
  ------------------
  |  |  101|     57|#define debug2_f(...)		sshlog(__FILE__, __func__, __LINE__, 1, SYSLOG_LEVEL_DEBUG2, NULL, __VA_ARGS__)
  ------------------
  257|     57|	}
  258|     64|	if (ret != 0 || mlen != dlen) {
  ------------------
  |  Branch (258:6): [True: 57, False: 7]
  |  Branch (258:18): [True: 3, False: 4]
  ------------------
  259|     60|		r = SSH_ERR_SIGNATURE_INVALID;
  ------------------
  |  |   45|     60|#define SSH_ERR_SIGNATURE_INVALID		-21
  ------------------
  260|     60|		goto out;
  261|     60|	}
  262|       |	/* XXX compare 'm' and 'data' ? */
  263|       |	/* success */
  264|      4|	r = 0;
  265|    205| out:
  266|    205|	if (sm != NULL)
  ------------------
  |  Branch (266:6): [True: 64, False: 141]
  ------------------
  267|     64|		freezero(sm, smlen);
  268|    205|	if (m != NULL)
  ------------------
  |  Branch (268:6): [True: 64, False: 141]
  ------------------
  269|     64|		freezero(m, smlen); /* NB mlen may be invalid if r != 0 */
  270|    205|	sshbuf_free(b);
  271|    205|	free(ktype);
  272|    205|	return r;
  273|      4|}

ssh-rsa.c:ssh_rsa_alloc:
   54|    310|{
   55|    310|	if ((k->rsa = RSA_new()) == NULL)
  ------------------
  |  Branch (55:6): [True: 0, False: 310]
  ------------------
   56|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
   57|    310|	return 0;
   58|    310|}
ssh-rsa.c:ssh_rsa_cleanup:
   62|    310|{
   63|    310|	RSA_free(k->rsa);
   64|    310|	k->rsa = NULL;
   65|    310|}
ssh-rsa.c:ssh_rsa_deserialize_public:
  188|    310|{
  189|    310|	int ret = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|    310|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  190|    310|	BIGNUM *rsa_n = NULL, *rsa_e = NULL;
  191|       |
  192|    310|	if (sshbuf_get_bignum2(b, &rsa_e) != 0 ||
  ------------------
  |  Branch (192:6): [True: 12, False: 298]
  ------------------
  193|    310|	    sshbuf_get_bignum2(b, &rsa_n) != 0) {
  ------------------
  |  Branch (193:6): [True: 12, False: 286]
  ------------------
  194|     24|		ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     24|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  195|     24|		goto out;
  196|     24|	}
  197|    286|	if (!RSA_set0_key(key->rsa, rsa_n, rsa_e, NULL)) {
  ------------------
  |  Branch (197:6): [True: 0, False: 286]
  ------------------
  198|      0|		ret = SSH_ERR_LIBCRYPTO_ERROR;
  ------------------
  |  |   46|      0|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
  199|      0|		goto out;
  200|      0|	}
  201|    286|	rsa_n = rsa_e = NULL; /* transferred */
  202|    286|	if ((ret = sshkey_check_rsa_length(key, 0)) != 0)
  ------------------
  |  Branch (202:6): [True: 25, False: 261]
  ------------------
  203|     25|		goto out;
  204|       |#ifdef DEBUG_PK
  205|       |	RSA_print_fp(stderr, key->rsa, 8);
  206|       |#endif
  207|       |	/* success */
  208|    261|	ret = 0;
  209|    310| out:
  210|    310|	BN_clear_free(rsa_n);
  211|    310|	BN_clear_free(rsa_e);
  212|    310|	return ret;
  213|    261|}
ssh-rsa.c:rsa_hash_id_from_ident:
  289|    232|{
  290|    232|	if (strcmp(ident, "ssh-rsa") == 0)
  ------------------
  |  Branch (290:6): [True: 10, False: 222]
  ------------------
  291|     10|		return SSH_DIGEST_SHA1;
  ------------------
  |  |   26|     10|#define SSH_DIGEST_SHA1		1
  ------------------
  292|    222|	if (strcmp(ident, "rsa-sha2-256") == 0)
  ------------------
  |  Branch (292:6): [True: 15, False: 207]
  ------------------
  293|     15|		return SSH_DIGEST_SHA256;
  ------------------
  |  |   27|     15|#define SSH_DIGEST_SHA256	2
  ------------------
  294|    207|	if (strcmp(ident, "rsa-sha2-512") == 0)
  ------------------
  |  Branch (294:6): [True: 16, False: 191]
  ------------------
  295|     16|		return SSH_DIGEST_SHA512;
  ------------------
  |  |   29|     16|#define SSH_DIGEST_SHA512	4
  ------------------
  296|    191|	return -1;
  297|    207|}
ssh-rsa.c:ssh_rsa_verify:
  478|    244|{
  479|    244|	const BIGNUM *rsa_n;
  480|    244|	char *sigtype = NULL;
  481|    244|	int hash_alg, want_alg, ret = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|    244|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  482|    244|	size_t len = 0, diff, modlen, hlen;
  483|    244|	struct sshbuf *b = NULL;
  484|    244|	u_char digest[SSH_DIGEST_MAX_LENGTH], *osigblob, *sigblob = NULL;
  485|       |
  486|    244|	if (key == NULL || key->rsa == NULL ||
  ------------------
  |  Branch (486:6): [True: 0, False: 244]
  |  Branch (486:21): [True: 0, False: 244]
  ------------------
  487|    244|	    sshkey_type_plain(key->type) != KEY_RSA ||
  ------------------
  |  Branch (487:6): [True: 0, False: 244]
  ------------------
  488|    244|	    sig == NULL || siglen == 0)
  ------------------
  |  Branch (488:6): [True: 0, False: 244]
  |  Branch (488:21): [True: 0, False: 244]
  ------------------
  489|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  490|    244|	RSA_get0_key(key->rsa, &rsa_n, NULL, NULL);
  491|    244|	if (BN_num_bits(rsa_n) < SSH_RSA_MINIMUM_MODULUS_SIZE)
  ------------------
  |  |   53|    244|#define SSH_RSA_MINIMUM_MODULUS_SIZE	1024
  ------------------
  |  Branch (491:6): [True: 0, False: 244]
  ------------------
  492|      0|		return SSH_ERR_KEY_LENGTH;
  ------------------
  |  |   80|      0|#define SSH_ERR_KEY_LENGTH			-56
  ------------------
  493|       |
  494|    244|	if ((b = sshbuf_from(sig, siglen)) == NULL)
  ------------------
  |  Branch (494:6): [True: 0, False: 244]
  ------------------
  495|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  496|    244|	if (sshbuf_get_cstring(b, &sigtype, NULL) != 0) {
  ------------------
  |  Branch (496:6): [True: 12, False: 232]
  ------------------
  497|     12|		ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     12|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  498|     12|		goto out;
  499|     12|	}
  500|    232|	if ((hash_alg = rsa_hash_id_from_ident(sigtype)) == -1) {
  ------------------
  |  Branch (500:6): [True: 191, False: 41]
  ------------------
  501|    191|		ret = SSH_ERR_KEY_TYPE_MISMATCH;
  ------------------
  |  |   37|    191|#define SSH_ERR_KEY_TYPE_MISMATCH		-13
  ------------------
  502|    191|		goto out;
  503|    191|	}
  504|       |	/*
  505|       |	 * Allow ssh-rsa-cert-v01 certs to generate SHA2 signatures for
  506|       |	 * legacy reasons, but otherwise the signature type should match.
  507|       |	 */
  508|     41|	if (alg != NULL && strcmp(alg, "ssh-rsa-cert-v01@openssh.com") != 0) {
  ------------------
  |  Branch (508:6): [True: 0, False: 41]
  |  Branch (508:21): [True: 0, False: 0]
  ------------------
  509|      0|		if ((want_alg = rsa_hash_id_from_keyname(alg)) == -1) {
  ------------------
  |  Branch (509:7): [True: 0, False: 0]
  ------------------
  510|      0|			ret = SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  511|      0|			goto out;
  512|      0|		}
  513|      0|		if (hash_alg != want_alg) {
  ------------------
  |  Branch (513:7): [True: 0, False: 0]
  ------------------
  514|      0|			ret = SSH_ERR_SIGNATURE_INVALID;
  ------------------
  |  |   45|      0|#define SSH_ERR_SIGNATURE_INVALID		-21
  ------------------
  515|      0|			goto out;
  516|      0|		}
  517|      0|	}
  518|     41|	if (sshbuf_get_string(b, &sigblob, &len) != 0) {
  ------------------
  |  Branch (518:6): [True: 7, False: 34]
  ------------------
  519|      7|		ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      7|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  520|      7|		goto out;
  521|      7|	}
  522|     34|	if (sshbuf_len(b) != 0) {
  ------------------
  |  Branch (522:6): [True: 2, False: 32]
  ------------------
  523|      2|		ret = SSH_ERR_UNEXPECTED_TRAILING_DATA;
  ------------------
  |  |   47|      2|#define SSH_ERR_UNEXPECTED_TRAILING_DATA	-23
  ------------------
  524|      2|		goto out;
  525|      2|	}
  526|       |	/* RSA_verify expects a signature of RSA_size */
  527|     32|	modlen = RSA_size(key->rsa);
  528|     32|	if (len > modlen) {
  ------------------
  |  Branch (528:6): [True: 10, False: 22]
  ------------------
  529|     10|		ret = SSH_ERR_KEY_BITS_MISMATCH;
  ------------------
  |  |   35|     10|#define SSH_ERR_KEY_BITS_MISMATCH		-11
  ------------------
  530|     10|		goto out;
  531|     22|	} else if (len < modlen) {
  ------------------
  |  Branch (531:13): [True: 21, False: 1]
  ------------------
  532|     21|		diff = modlen - len;
  533|     21|		osigblob = sigblob;
  534|     21|		if ((sigblob = realloc(sigblob, modlen)) == NULL) {
  ------------------
  |  Branch (534:7): [True: 0, False: 21]
  ------------------
  535|      0|			sigblob = osigblob; /* put it back for clear/free */
  536|      0|			ret = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  537|      0|			goto out;
  538|      0|		}
  539|     21|		memmove(sigblob + diff, sigblob, len);
  540|     21|		explicit_bzero(sigblob, diff);
  541|     21|		len = modlen;
  542|     21|	}
  543|     22|	if ((hlen = ssh_digest_bytes(hash_alg)) == 0) {
  ------------------
  |  Branch (543:6): [True: 0, False: 22]
  ------------------
  544|      0|		ret = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|      0|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  545|      0|		goto out;
  546|      0|	}
  547|     22|	if ((ret = ssh_digest_memory(hash_alg, data, dlen,
  ------------------
  |  Branch (547:6): [True: 0, False: 22]
  ------------------
  548|     22|	    digest, sizeof(digest))) != 0)
  549|      0|		goto out;
  550|       |
  551|     22|	ret = openssh_RSA_verify(hash_alg, digest, hlen, sigblob, len,
  552|     22|	    key->rsa);
  553|    244| out:
  554|    244|	freezero(sigblob, len);
  555|    244|	free(sigtype);
  556|    244|	sshbuf_free(b);
  557|    244|	explicit_bzero(digest, sizeof(digest));
  558|    244|	return ret;
  559|     22|}
ssh-rsa.c:openssh_RSA_verify:
  635|     22|{
  636|     22|	size_t rsasize = 0, oidlen = 0, hlen = 0;
  637|     22|	int ret, len, oidmatch, hashmatch;
  638|     22|	const u_char *oid = NULL;
  639|     22|	u_char *decrypted = NULL;
  640|       |
  641|     22|	if ((ret = rsa_hash_alg_oid(hash_alg, &oid, &oidlen)) != 0)
  ------------------
  |  Branch (641:6): [True: 0, False: 22]
  ------------------
  642|      0|		return ret;
  643|     22|	ret = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|     22|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  644|     22|	hlen = ssh_digest_bytes(hash_alg);
  645|     22|	if (hashlen != hlen) {
  ------------------
  |  Branch (645:6): [True: 0, False: 22]
  ------------------
  646|      0|		ret = SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  647|      0|		goto done;
  648|      0|	}
  649|     22|	rsasize = RSA_size(rsa);
  650|     22|	if (rsasize <= 0 || rsasize > SSHBUF_MAX_BIGNUM ||
  ------------------
  |  |   33|     44|#define SSHBUF_MAX_BIGNUM	(16384 / 8)	/* Max bignum *bytes* */
  ------------------
  |  Branch (650:6): [True: 0, False: 22]
  |  Branch (650:22): [True: 0, False: 22]
  ------------------
  651|     22|	    siglen == 0 || siglen > rsasize) {
  ------------------
  |  Branch (651:6): [True: 0, False: 22]
  |  Branch (651:21): [True: 0, False: 22]
  ------------------
  652|      0|		ret = SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  653|      0|		goto done;
  654|      0|	}
  655|     22|	if ((decrypted = malloc(rsasize)) == NULL) {
  ------------------
  |  Branch (655:6): [True: 0, False: 22]
  ------------------
  656|      0|		ret = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  657|      0|		goto done;
  658|      0|	}
  659|     22|	if ((len = RSA_public_decrypt(siglen, sigbuf, decrypted, rsa,
  ------------------
  |  Branch (659:6): [True: 22, False: 0]
  ------------------
  660|     22|	    RSA_PKCS1_PADDING)) < 0) {
  661|     22|		ret = SSH_ERR_LIBCRYPTO_ERROR;
  ------------------
  |  |   46|     22|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
  662|     22|		goto done;
  663|     22|	}
  664|      0|	if (len < 0 || (size_t)len != hlen + oidlen) {
  ------------------
  |  Branch (664:6): [True: 0, False: 0]
  |  Branch (664:17): [True: 0, False: 0]
  ------------------
  665|      0|		ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      0|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  666|      0|		goto done;
  667|      0|	}
  668|      0|	oidmatch = timingsafe_bcmp(decrypted, oid, oidlen) == 0;
  669|      0|	hashmatch = timingsafe_bcmp(decrypted + oidlen, hash, hlen) == 0;
  670|      0|	if (!oidmatch || !hashmatch) {
  ------------------
  |  Branch (670:6): [True: 0, False: 0]
  |  Branch (670:19): [True: 0, False: 0]
  ------------------
  671|      0|		ret = SSH_ERR_SIGNATURE_INVALID;
  ------------------
  |  |   45|      0|#define SSH_ERR_SIGNATURE_INVALID		-21
  ------------------
  672|      0|		goto done;
  673|      0|	}
  674|      0|	ret = 0;
  675|     22|done:
  676|     22|	freezero(decrypted, rsasize);
  677|     22|	return ret;
  678|      0|}
ssh-rsa.c:rsa_hash_alg_oid:
  612|     22|{
  613|     22|	switch (hash_alg) {
  614|      2|	case SSH_DIGEST_SHA1:
  ------------------
  |  |   26|      2|#define SSH_DIGEST_SHA1		1
  ------------------
  |  Branch (614:2): [True: 2, False: 20]
  ------------------
  615|      2|		*oidp = id_sha1;
  616|      2|		*oidlenp = sizeof(id_sha1);
  617|      2|		break;
  618|     13|	case SSH_DIGEST_SHA256:
  ------------------
  |  |   27|     13|#define SSH_DIGEST_SHA256	2
  ------------------
  |  Branch (618:2): [True: 13, False: 9]
  ------------------
  619|     13|		*oidp = id_sha256;
  620|     13|		*oidlenp = sizeof(id_sha256);
  621|     13|		break;
  622|      7|	case SSH_DIGEST_SHA512:
  ------------------
  |  |   29|      7|#define SSH_DIGEST_SHA512	4
  ------------------
  |  Branch (622:2): [True: 7, False: 15]
  ------------------
  623|      7|		*oidp = id_sha512;
  624|      7|		*oidlenp = sizeof(id_sha512);
  625|      7|		break;
  626|      0|	default:
  ------------------
  |  Branch (626:2): [True: 0, False: 22]
  ------------------
  627|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  628|     22|	}
  629|     22|	return 0;
  630|     22|}

ssh-xmss.c:ssh_xmss_cleanup:
   44|    390|{
   45|    390|	freezero(k->xmss_pk, sshkey_xmss_pklen(k));
   46|    390|	freezero(k->xmss_sk, sshkey_xmss_sklen(k));
   47|    390|	sshkey_xmss_free_state(k);
   48|    390|	free(k->xmss_name);
   49|    390|	free(k->xmss_filename);
   50|    390|	k->xmss_pk = NULL;
   51|    390|	k->xmss_sk = NULL;
   52|    390|	k->xmss_name = NULL;
   53|    390|	k->xmss_filename = NULL;
   54|    390|}
ssh-xmss.c:ssh_xmss_deserialize_public:
  134|    389|{
  135|    389|	size_t len = 0;
  136|    389|	char *xmss_name = NULL;
  137|    389|	u_char *pk = NULL;
  138|    389|	int ret = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|    389|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  139|       |
  140|    389|	if ((ret = sshbuf_get_cstring(b, &xmss_name, NULL)) != 0)
  ------------------
  |  Branch (140:6): [True: 2, False: 387]
  ------------------
  141|      2|		goto out;
  142|    387|	if ((ret = sshkey_xmss_init(key, xmss_name)) != 0)
  ------------------
  |  Branch (142:6): [True: 147, False: 240]
  ------------------
  143|    147|		goto out;
  144|    240|	if ((ret = sshbuf_get_string(b, &pk, &len)) != 0)
  ------------------
  |  Branch (144:6): [True: 6, False: 234]
  ------------------
  145|      6|		goto out;
  146|    234|	if (len == 0 || len != sshkey_xmss_pklen(key)) {
  ------------------
  |  Branch (146:6): [True: 1, False: 233]
  |  Branch (146:18): [True: 40, False: 193]
  ------------------
  147|     41|		ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     41|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  148|     41|		goto out;
  149|     41|	}
  150|    193|	key->xmss_pk = pk;
  151|    193|	pk = NULL;
  152|    193|	if (!sshkey_is_cert(key) &&
  ------------------
  |  Branch (152:6): [True: 187, False: 6]
  ------------------
  153|    193|	    (ret = sshkey_xmss_deserialize_pk_info(key, b)) != 0)
  ------------------
  |  Branch (153:6): [True: 22, False: 165]
  ------------------
  154|     22|		goto out;
  155|       |	/* success */
  156|    171|	ret = 0;
  157|    389| out:
  158|    389|	free(xmss_name);
  159|    389|	freezero(pk, len);
  160|    389|	return ret;
  161|    171|}
ssh-xmss.c:ssh_xmss_verify:
  281|    158|{
  282|    158|	struct sshbuf *b = NULL;
  283|    158|	char *ktype = NULL;
  284|    158|	const u_char *sigblob;
  285|    158|	u_char *sm = NULL, *m = NULL;
  286|    158|	size_t len, required_siglen;
  287|    158|	unsigned long long smlen = 0, mlen = 0;
  288|    158|	int r, ret;
  289|       |
  290|    158|	if (key == NULL ||
  ------------------
  |  Branch (290:6): [True: 0, False: 158]
  ------------------
  291|    158|	    sshkey_type_plain(key->type) != KEY_XMSS ||
  ------------------
  |  Branch (291:6): [True: 0, False: 158]
  ------------------
  292|    158|	    key->xmss_pk == NULL ||
  ------------------
  |  Branch (292:6): [True: 0, False: 158]
  ------------------
  293|    158|	    sshkey_xmss_params(key) == NULL ||
  ------------------
  |  Branch (293:6): [True: 0, False: 158]
  ------------------
  294|    158|	    sig == NULL || siglen == 0)
  ------------------
  |  Branch (294:6): [True: 0, False: 158]
  |  Branch (294:21): [True: 0, False: 158]
  ------------------
  295|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  296|    158|	if ((r = sshkey_xmss_siglen(key, &required_siglen)) != 0)
  ------------------
  |  Branch (296:6): [True: 0, False: 158]
  ------------------
  297|      0|		return r;
  298|    158|	if (dlen >= INT_MAX - required_siglen)
  ------------------
  |  Branch (298:6): [True: 0, False: 158]
  ------------------
  299|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  300|       |
  301|    158|	if ((b = sshbuf_from(sig, siglen)) == NULL)
  ------------------
  |  Branch (301:6): [True: 0, False: 158]
  ------------------
  302|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  303|    158|	if ((r = sshbuf_get_cstring(b, &ktype, NULL)) != 0 ||
  ------------------
  |  Branch (303:6): [True: 17, False: 141]
  ------------------
  304|    158|	    (r = sshbuf_get_string_direct(b, &sigblob, &len)) != 0)
  ------------------
  |  Branch (304:6): [True: 3, False: 138]
  ------------------
  305|     20|		goto out;
  306|    138|	if (strcmp("ssh-xmss@openssh.com", ktype) != 0) {
  ------------------
  |  Branch (306:6): [True: 122, False: 16]
  ------------------
  307|    122|		r = SSH_ERR_KEY_TYPE_MISMATCH;
  ------------------
  |  |   37|    122|#define SSH_ERR_KEY_TYPE_MISMATCH		-13
  ------------------
  308|    122|		goto out;
  309|    122|	}
  310|     16|	if (sshbuf_len(b) != 0) {
  ------------------
  |  Branch (310:6): [True: 9, False: 7]
  ------------------
  311|      9|		r = SSH_ERR_UNEXPECTED_TRAILING_DATA;
  ------------------
  |  |   47|      9|#define SSH_ERR_UNEXPECTED_TRAILING_DATA	-23
  ------------------
  312|      9|		goto out;
  313|      9|	}
  314|      7|	if (len != required_siglen) {
  ------------------
  |  Branch (314:6): [True: 7, False: 0]
  ------------------
  315|      7|		r = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      7|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  316|      7|		goto out;
  317|      7|	}
  318|      0|	if (dlen >= SIZE_MAX - len) {
  ------------------
  |  Branch (318:6): [True: 0, False: 0]
  ------------------
  319|      0|		r = SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  320|      0|		goto out;
  321|      0|	}
  322|      0|	smlen = len + dlen;
  323|      0|	mlen = smlen;
  324|      0|	if ((sm = malloc(smlen)) == NULL || (m = malloc(mlen)) == NULL) {
  ------------------
  |  Branch (324:6): [True: 0, False: 0]
  |  Branch (324:38): [True: 0, False: 0]
  ------------------
  325|      0|		r = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  326|      0|		goto out;
  327|      0|	}
  328|      0|	memcpy(sm, sigblob, len);
  329|      0|	memcpy(sm+len, data, dlen);
  330|      0|	if ((ret = xmss_sign_open(m, &mlen, sm, smlen,
  ------------------
  |  Branch (330:6): [True: 0, False: 0]
  ------------------
  331|      0|	    key->xmss_pk, sshkey_xmss_params(key))) != 0) {
  332|      0|		debug2_f("xmss_sign_open failed: %d", ret);
  ------------------
  |  |  101|      0|#define debug2_f(...)		sshlog(__FILE__, __func__, __LINE__, 1, SYSLOG_LEVEL_DEBUG2, NULL, __VA_ARGS__)
  ------------------
  333|      0|	}
  334|      0|	if (ret != 0 || mlen != dlen) {
  ------------------
  |  Branch (334:6): [True: 0, False: 0]
  |  Branch (334:18): [True: 0, False: 0]
  ------------------
  335|      0|		r = SSH_ERR_SIGNATURE_INVALID;
  ------------------
  |  |   45|      0|#define SSH_ERR_SIGNATURE_INVALID		-21
  ------------------
  336|      0|		goto out;
  337|      0|	}
  338|       |	/* XXX compare 'm' and 'data' ? */
  339|       |	/* success */
  340|      0|	r = 0;
  341|    158| out:
  342|    158|	if (sm != NULL)
  ------------------
  |  Branch (342:6): [True: 0, False: 158]
  ------------------
  343|      0|		freezero(sm, smlen);
  344|    158|	if (m != NULL)
  ------------------
  |  Branch (344:6): [True: 0, False: 158]
  ------------------
  345|      0|		freezero(m, smlen);
  346|    158|	sshbuf_free(b);
  347|    158|	free(ktype);
  348|    158|	return r;
  349|      0|}

sshbuf_get_u64:
   49|  2.04k|{
   50|  2.04k|	const u_char *p = sshbuf_ptr(buf);
   51|  2.04k|	int r;
   52|       |
   53|  2.04k|	if ((r = sshbuf_consume(buf, 8)) < 0)
  ------------------
  |  Branch (53:6): [True: 24, False: 2.01k]
  ------------------
   54|     24|		return r;
   55|  2.01k|	if (valp != NULL)
  ------------------
  |  Branch (55:6): [True: 2.01k, False: 0]
  ------------------
   56|  2.01k|		*valp = PEEK_U64(p);
  ------------------
  |  |  335|  2.01k|	(((u_int64_t)(((const u_char *)(p))[0]) << 56) | \
  |  |  336|  2.01k|	 ((u_int64_t)(((const u_char *)(p))[1]) << 48) | \
  |  |  337|  2.01k|	 ((u_int64_t)(((const u_char *)(p))[2]) << 40) | \
  |  |  338|  2.01k|	 ((u_int64_t)(((const u_char *)(p))[3]) << 32) | \
  |  |  339|  2.01k|	 ((u_int64_t)(((const u_char *)(p))[4]) << 24) | \
  |  |  340|  2.01k|	 ((u_int64_t)(((const u_char *)(p))[5]) << 16) | \
  |  |  341|  2.01k|	 ((u_int64_t)(((const u_char *)(p))[6]) << 8) | \
  |  |  342|  2.01k|	  (u_int64_t)(((const u_char *)(p))[7]))
  ------------------
   57|  2.01k|	return 0;
   58|  2.04k|}
sshbuf_get_u32:
   62|  5.65k|{
   63|  5.65k|	const u_char *p = sshbuf_ptr(buf);
   64|  5.65k|	int r;
   65|       |
   66|  5.65k|	if ((r = sshbuf_consume(buf, 4)) < 0)
  ------------------
  |  Branch (66:6): [True: 10, False: 5.64k]
  ------------------
   67|     10|		return r;
   68|  5.64k|	if (valp != NULL)
  ------------------
  |  Branch (68:6): [True: 5.64k, False: 0]
  ------------------
   69|  5.64k|		*valp = PEEK_U32(p);
  ------------------
  |  |  344|  5.64k|	(((u_int32_t)(((const u_char *)(p))[0]) << 24) | \
  |  |  345|  5.64k|	 ((u_int32_t)(((const u_char *)(p))[1]) << 16) | \
  |  |  346|  5.64k|	 ((u_int32_t)(((const u_char *)(p))[2]) << 8) | \
  |  |  347|  5.64k|	  (u_int32_t)(((const u_char *)(p))[3]))
  ------------------
   70|  5.64k|	return 0;
   71|  5.65k|}
sshbuf_get_u8:
   88|    160|{
   89|    160|	const u_char *p = sshbuf_ptr(buf);
   90|    160|	int r;
   91|       |
   92|    160|	if ((r = sshbuf_consume(buf, 1)) < 0)
  ------------------
  |  Branch (92:6): [True: 2, False: 158]
  ------------------
   93|      2|		return r;
   94|    158|	if (valp != NULL)
  ------------------
  |  Branch (94:6): [True: 158, False: 0]
  ------------------
   95|    158|		*valp = (u_int8_t)*p;
   96|    158|	return 0;
   97|    160|}
sshbuf_get_string:
  188|  4.74k|{
  189|  4.74k|	const u_char *val;
  190|  4.74k|	size_t len;
  191|  4.74k|	int r;
  192|       |
  193|  4.74k|	if (valp != NULL)
  ------------------
  |  Branch (193:6): [True: 1.74k, False: 3.00k]
  ------------------
  194|  1.74k|		*valp = NULL;
  195|  4.74k|	if (lenp != NULL)
  ------------------
  |  Branch (195:6): [True: 1.74k, False: 3.00k]
  ------------------
  196|  1.74k|		*lenp = 0;
  197|  4.74k|	if ((r = sshbuf_get_string_direct(buf, &val, &len)) < 0)
  ------------------
  |  Branch (197:6): [True: 106, False: 4.64k]
  ------------------
  198|    106|		return r;
  199|  4.64k|	if (valp != NULL) {
  ------------------
  |  Branch (199:6): [True: 1.71k, False: 2.92k]
  ------------------
  200|  1.71k|		if ((*valp = malloc(len + 1)) == NULL) {
  ------------------
  |  Branch (200:7): [True: 0, False: 1.71k]
  ------------------
  201|      0|			SSHBUF_DBG(("SSH_ERR_ALLOC_FAIL"));
  202|      0|			return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  203|      0|		}
  204|  1.71k|		if (len != 0)
  ------------------
  |  Branch (204:7): [True: 1.42k, False: 292]
  ------------------
  205|  1.42k|			memcpy(*valp, val, len);
  206|  1.71k|		(*valp)[len] = '\0';
  207|  1.71k|	}
  208|  4.64k|	if (lenp != NULL)
  ------------------
  |  Branch (208:6): [True: 1.71k, False: 2.92k]
  ------------------
  209|  1.71k|		*lenp = len;
  210|  4.64k|	return 0;
  211|  4.64k|}
sshbuf_get_string_direct:
  215|  30.5k|{
  216|  30.5k|	size_t len;
  217|  30.5k|	const u_char *p;
  218|  30.5k|	int r;
  219|       |
  220|  30.5k|	if (valp != NULL)
  ------------------
  |  Branch (220:6): [True: 5.75k, False: 24.7k]
  ------------------
  221|  5.75k|		*valp = NULL;
  222|  30.5k|	if (lenp != NULL)
  ------------------
  |  Branch (222:6): [True: 5.75k, False: 24.7k]
  ------------------
  223|  5.75k|		*lenp = 0;
  224|  30.5k|	if ((r = sshbuf_peek_string_direct(buf, &p, &len)) < 0)
  ------------------
  |  Branch (224:6): [True: 389, False: 30.1k]
  ------------------
  225|    389|		return r;
  226|  30.1k|	if (valp != NULL)
  ------------------
  |  Branch (226:6): [True: 5.64k, False: 24.4k]
  ------------------
  227|  5.64k|		*valp = p;
  228|  30.1k|	if (lenp != NULL)
  ------------------
  |  Branch (228:6): [True: 5.64k, False: 24.4k]
  ------------------
  229|  5.64k|		*lenp = len;
  230|  30.1k|	if (sshbuf_consume(buf, len + 4) != 0) {
  ------------------
  |  Branch (230:6): [True: 0, False: 30.1k]
  ------------------
  231|       |		/* Shouldn't happen */
  232|      0|		SSHBUF_DBG(("SSH_ERR_INTERNAL_ERROR"));
  233|      0|		SSHBUF_ABORT();
  234|      0|		return SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|      0|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  235|      0|	}
  236|  30.1k|	return 0;
  237|  30.1k|}
sshbuf_peek_string_direct:
  242|  49.4k|{
  243|  49.4k|	u_int32_t len;
  244|  49.4k|	const u_char *p = sshbuf_ptr(buf);
  245|       |
  246|  49.4k|	if (valp != NULL)
  ------------------
  |  Branch (246:6): [True: 49.4k, False: 0]
  ------------------
  247|  49.4k|		*valp = NULL;
  248|  49.4k|	if (lenp != NULL)
  ------------------
  |  Branch (248:6): [True: 49.4k, False: 0]
  ------------------
  249|  49.4k|		*lenp = 0;
  250|  49.4k|	if (sshbuf_len(buf) < 4) {
  ------------------
  |  Branch (250:6): [True: 304, False: 49.1k]
  ------------------
  251|    304|		SSHBUF_DBG(("SSH_ERR_MESSAGE_INCOMPLETE"));
  252|    304|		return SSH_ERR_MESSAGE_INCOMPLETE;
  ------------------
  |  |   27|    304|#define SSH_ERR_MESSAGE_INCOMPLETE		-3
  ------------------
  253|    304|	}
  254|  49.1k|	len = PEEK_U32(p);
  ------------------
  |  |  344|  49.1k|	(((u_int32_t)(((const u_char *)(p))[0]) << 24) | \
  |  |  345|  49.1k|	 ((u_int32_t)(((const u_char *)(p))[1]) << 16) | \
  |  |  346|  49.1k|	 ((u_int32_t)(((const u_char *)(p))[2]) << 8) | \
  |  |  347|  49.1k|	  (u_int32_t)(((const u_char *)(p))[3]))
  ------------------
  255|  49.1k|	if (len > SSHBUF_SIZE_MAX - 4) {
  ------------------
  |  |   31|  49.1k|#define SSHBUF_SIZE_MAX		0x8000000	/* Hard maximum size 128MB */
  ------------------
  |  Branch (255:6): [True: 215, False: 48.9k]
  ------------------
  256|    215|		SSHBUF_DBG(("SSH_ERR_STRING_TOO_LARGE"));
  257|    215|		return SSH_ERR_STRING_TOO_LARGE;
  ------------------
  |  |   30|    215|#define SSH_ERR_STRING_TOO_LARGE		-6
  ------------------
  258|    215|	}
  259|  48.9k|	if (sshbuf_len(buf) - 4 < len) {
  ------------------
  |  Branch (259:6): [True: 362, False: 48.5k]
  ------------------
  260|    362|		SSHBUF_DBG(("SSH_ERR_MESSAGE_INCOMPLETE"));
  261|    362|		return SSH_ERR_MESSAGE_INCOMPLETE;
  ------------------
  |  |   27|    362|#define SSH_ERR_MESSAGE_INCOMPLETE		-3
  ------------------
  262|    362|	}
  263|  48.5k|	if (valp != NULL)
  ------------------
  |  Branch (263:6): [True: 48.5k, False: 0]
  ------------------
  264|  48.5k|		*valp = p + 4;
  265|  48.5k|	if (lenp != NULL)
  ------------------
  |  Branch (265:6): [True: 48.5k, False: 0]
  ------------------
  266|  48.5k|		*lenp = len;
  267|  48.5k|	return 0;
  268|  48.9k|}
sshbuf_get_cstring:
  272|  11.0k|{
  273|  11.0k|	size_t len;
  274|  11.0k|	const u_char *p, *z;
  275|  11.0k|	int r;
  276|       |
  277|  11.0k|	if (valp != NULL)
  ------------------
  |  Branch (277:6): [True: 11.0k, False: 0]
  ------------------
  278|  11.0k|		*valp = NULL;
  279|  11.0k|	if (lenp != NULL)
  ------------------
  |  Branch (279:6): [True: 725, False: 10.3k]
  ------------------
  280|    725|		*lenp = 0;
  281|  11.0k|	if ((r = sshbuf_peek_string_direct(buf, &p, &len)) != 0)
  ------------------
  |  Branch (281:6): [True: 257, False: 10.8k]
  ------------------
  282|    257|		return r;
  283|       |	/* Allow a \0 only at the end of the string */
  284|  10.8k|	if (len > 0 &&
  ------------------
  |  Branch (284:6): [True: 8.09k, False: 2.75k]
  ------------------
  285|  10.8k|	    (z = memchr(p , '\0', len)) != NULL && z < p + len - 1) {
  ------------------
  |  Branch (285:6): [True: 1.24k, False: 6.85k]
  |  Branch (285:45): [True: 10, False: 1.23k]
  ------------------
  286|     10|		SSHBUF_DBG(("SSH_ERR_INVALID_FORMAT"));
  287|     10|		return SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     10|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  288|     10|	}
  289|  10.8k|	if ((r = sshbuf_skip_string(buf)) != 0)
  ------------------
  |  |  237|  10.8k|#define sshbuf_skip_string(buf) sshbuf_get_string_direct(buf, NULL, NULL)
  ------------------
  |  Branch (289:6): [True: 0, False: 10.8k]
  ------------------
  290|      0|		return -1;
  291|  10.8k|	if (valp != NULL) {
  ------------------
  |  Branch (291:6): [True: 10.8k, False: 0]
  ------------------
  292|  10.8k|		if ((*valp = malloc(len + 1)) == NULL) {
  ------------------
  |  Branch (292:7): [True: 0, False: 10.8k]
  ------------------
  293|      0|			SSHBUF_DBG(("SSH_ERR_ALLOC_FAIL"));
  294|      0|			return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  295|      0|		}
  296|  10.8k|		if (len != 0)
  ------------------
  |  Branch (296:7): [True: 8.08k, False: 2.75k]
  ------------------
  297|  8.08k|			memcpy(*valp, p, len);
  298|  10.8k|		(*valp)[len] = '\0';
  299|  10.8k|	}
  300|  10.8k|	if (lenp != NULL)
  ------------------
  |  Branch (300:6): [True: 714, False: 10.1k]
  ------------------
  301|    714|		*lenp = (size_t)len;
  302|  10.8k|	return 0;
  303|  10.8k|}
sshbuf_put:
  327|  6.14k|{
  328|  6.14k|	u_char *p;
  329|  6.14k|	int r;
  330|       |
  331|  6.14k|	if ((r = sshbuf_reserve(buf, len, &p)) < 0)
  ------------------
  |  Branch (331:6): [True: 0, False: 6.14k]
  ------------------
  332|      0|		return r;
  333|  6.14k|	if (len != 0)
  ------------------
  |  Branch (333:6): [True: 5.20k, False: 938]
  ------------------
  334|  5.20k|		memcpy(p, v, len);
  335|  6.14k|	return 0;
  336|  6.14k|}
sshbuf_putb:
  340|  1.77k|{
  341|  1.77k|	if (v == NULL)
  ------------------
  |  Branch (341:6): [True: 0, False: 1.77k]
  ------------------
  342|      0|		return 0;
  343|  1.77k|	return sshbuf_put(buf, sshbuf_ptr(v), sshbuf_len(v));
  344|  1.77k|}
sshbuf_put_u32:
  405|     13|{
  406|     13|	u_char *p;
  407|     13|	int r;
  408|       |
  409|     13|	if ((r = sshbuf_reserve(buf, 4, &p)) < 0)
  ------------------
  |  Branch (409:6): [True: 0, False: 13]
  ------------------
  410|      0|		return r;
  411|     13|	POKE_U32(p, val);
  ------------------
  |  |  365|     13|	do { \
  |  |  366|     13|		const u_int32_t __v = (v); \
  |  |  367|     13|		((u_char *)(p))[0] = (__v >> 24) & 0xff; \
  |  |  368|     13|		((u_char *)(p))[1] = (__v >> 16) & 0xff; \
  |  |  369|     13|		((u_char *)(p))[2] = (__v >> 8) & 0xff; \
  |  |  370|     13|		((u_char *)(p))[3] = __v & 0xff; \
  |  |  371|     13|	} while (0)
  |  |  ------------------
  |  |  |  Branch (371:11): [Folded - Ignored]
  |  |  ------------------
  ------------------
  412|     13|	return 0;
  413|     13|}
sshbuf_put_u8:
  429|     13|{
  430|     13|	u_char *p;
  431|     13|	int r;
  432|       |
  433|     13|	if ((r = sshbuf_reserve(buf, 1, &p)) < 0)
  ------------------
  |  Branch (433:6): [True: 0, False: 13]
  ------------------
  434|      0|		return r;
  435|     13|	p[0] = val;
  436|     13|	return 0;
  437|     13|}
sshbuf_put_string:
  515|  8.65k|{
  516|  8.65k|	u_char *d;
  517|  8.65k|	int r;
  518|       |
  519|  8.65k|	if (len > SSHBUF_SIZE_MAX - 4) {
  ------------------
  |  |   31|  8.65k|#define SSHBUF_SIZE_MAX		0x8000000	/* Hard maximum size 128MB */
  ------------------
  |  Branch (519:6): [True: 0, False: 8.65k]
  ------------------
  520|      0|		SSHBUF_DBG(("SSH_ERR_NO_BUFFER_SPACE"));
  521|      0|		return SSH_ERR_NO_BUFFER_SPACE;
  ------------------
  |  |   33|      0|#define SSH_ERR_NO_BUFFER_SPACE			-9
  ------------------
  522|      0|	}
  523|  8.65k|	if ((r = sshbuf_reserve(buf, len + 4, &d)) < 0)
  ------------------
  |  Branch (523:6): [True: 0, False: 8.65k]
  ------------------
  524|      0|		return r;
  525|  8.65k|	POKE_U32(d, len);
  ------------------
  |  |  365|  8.65k|	do { \
  |  |  366|  8.65k|		const u_int32_t __v = (v); \
  |  |  367|  8.65k|		((u_char *)(p))[0] = (__v >> 24) & 0xff; \
  |  |  368|  8.65k|		((u_char *)(p))[1] = (__v >> 16) & 0xff; \
  |  |  369|  8.65k|		((u_char *)(p))[2] = (__v >> 8) & 0xff; \
  |  |  370|  8.65k|		((u_char *)(p))[3] = __v & 0xff; \
  |  |  371|  8.65k|	} while (0)
  |  |  ------------------
  |  |  |  Branch (371:11): [Folded - Ignored]
  |  |  ------------------
  ------------------
  526|  8.65k|	if (len != 0)
  ------------------
  |  Branch (526:6): [True: 6.48k, False: 2.16k]
  ------------------
  527|  6.48k|		memcpy(d + 4, v, len);
  528|  8.65k|	return 0;
  529|  8.65k|}
sshbuf_put_cstring:
  533|  4.32k|{
  534|  4.32k|	return sshbuf_put_string(buf, v, v == NULL ? 0 : strlen(v));
  ------------------
  |  Branch (534:35): [True: 0, False: 4.32k]
  ------------------
  535|  4.32k|}
sshbuf_put_stringb:
  539|  2.16k|{
  540|  2.16k|	if (v == NULL)
  ------------------
  |  Branch (540:6): [True: 0, False: 2.16k]
  ------------------
  541|      0|		return sshbuf_put_string(buf, NULL, 0);
  542|       |
  543|  2.16k|	return sshbuf_put_string(buf, sshbuf_ptr(v), sshbuf_len(v));
  544|  2.16k|}
sshbuf_froms:
  548|  4.78k|{
  549|  4.78k|	const u_char *p;
  550|  4.78k|	size_t len;
  551|  4.78k|	struct sshbuf *ret;
  552|  4.78k|	int r;
  553|       |
  554|  4.78k|	if (buf == NULL || bufp == NULL)
  ------------------
  |  Branch (554:6): [True: 0, False: 4.78k]
  |  Branch (554:21): [True: 0, False: 4.78k]
  ------------------
  555|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  556|  4.78k|	*bufp = NULL;
  557|  4.78k|	if ((r = sshbuf_peek_string_direct(buf, &p, &len)) != 0)
  ------------------
  |  Branch (557:6): [True: 67, False: 4.72k]
  ------------------
  558|     67|		return r;
  559|  4.72k|	if ((ret = sshbuf_from(p, len)) == NULL)
  ------------------
  |  Branch (559:6): [True: 0, False: 4.72k]
  ------------------
  560|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  561|  4.72k|	if ((r = sshbuf_consume(buf, len + 4)) != 0 ||  /* Shouldn't happen */
  ------------------
  |  Branch (561:6): [True: 0, False: 4.72k]
  ------------------
  562|  4.72k|	    (r = sshbuf_set_parent(ret, buf)) != 0) {
  ------------------
  |  Branch (562:6): [True: 0, False: 4.72k]
  ------------------
  563|      0|		sshbuf_free(ret);
  564|      0|		return r;
  565|      0|	}
  566|  4.72k|	*bufp = ret;
  567|  4.72k|	return 0;
  568|  4.72k|}
sshbuf_get_bignum2_bytes_direct:
  602|  2.96k|{
  603|  2.96k|	const u_char *d;
  604|  2.96k|	size_t len, olen;
  605|  2.96k|	int r;
  606|       |
  607|  2.96k|	if ((r = sshbuf_peek_string_direct(buf, &d, &olen)) < 0)
  ------------------
  |  Branch (607:6): [True: 118, False: 2.84k]
  ------------------
  608|    118|		return r;
  609|  2.84k|	len = olen;
  610|       |	/* Refuse negative (MSB set) bignums */
  611|  2.84k|	if ((len != 0 && (*d & 0x80) != 0))
  ------------------
  |  Branch (611:7): [True: 743, False: 2.10k]
  |  Branch (611:19): [True: 12, False: 731]
  ------------------
  612|     12|		return SSH_ERR_BIGNUM_IS_NEGATIVE;
  ------------------
  |  |   29|     12|#define SSH_ERR_BIGNUM_IS_NEGATIVE		-5
  ------------------
  613|       |	/* Refuse overlong bignums, allow prepended \0 to avoid MSB set */
  614|  2.83k|	if (len > SSHBUF_MAX_BIGNUM + 1 ||
  ------------------
  |  |   33|  2.83k|#define SSHBUF_MAX_BIGNUM	(16384 / 8)	/* Max bignum *bytes* */
  ------------------
  |  Branch (614:6): [True: 12, False: 2.82k]
  ------------------
  615|  2.83k|	    (len == SSHBUF_MAX_BIGNUM + 1 && *d != 0))
  ------------------
  |  |   33|  2.82k|#define SSHBUF_MAX_BIGNUM	(16384 / 8)	/* Max bignum *bytes* */
  ------------------
  |  Branch (615:7): [True: 16, False: 2.80k]
  |  Branch (615:39): [True: 6, False: 10]
  ------------------
  616|     18|		return SSH_ERR_BIGNUM_TOO_LARGE;
  ------------------
  |  |   31|     18|#define SSH_ERR_BIGNUM_TOO_LARGE		-7
  ------------------
  617|       |	/* Trim leading zeros */
  618|  5.08k|	while (len > 0 && *d == 0x00) {
  ------------------
  |  Branch (618:9): [True: 2.88k, False: 2.20k]
  |  Branch (618:20): [True: 2.26k, False: 618]
  ------------------
  619|  2.26k|		d++;
  620|  2.26k|		len--;
  621|  2.26k|	}
  622|  2.81k|	if (valp != NULL)
  ------------------
  |  Branch (622:6): [True: 2.81k, False: 0]
  ------------------
  623|  2.81k|		*valp = d;
  624|  2.81k|	if (lenp != NULL)
  ------------------
  |  Branch (624:6): [True: 2.81k, False: 0]
  ------------------
  625|  2.81k|		*lenp = len;
  626|  2.81k|	if (sshbuf_consume(buf, olen + 4) != 0) {
  ------------------
  |  Branch (626:6): [True: 0, False: 2.81k]
  ------------------
  627|       |		/* Shouldn't happen */
  628|      0|		SSHBUF_DBG(("SSH_ERR_INTERNAL_ERROR"));
  629|      0|		SSHBUF_ABORT();
  630|      0|		return SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|      0|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  631|      0|	}
  632|  2.81k|	return 0;
  633|  2.81k|}

sshbuf_get_bignum2:
   37|  2.96k|{
   38|  2.96k|	BIGNUM *v;
   39|  2.96k|	const u_char *d;
   40|  2.96k|	size_t len;
   41|  2.96k|	int r;
   42|       |
   43|  2.96k|	if (valp != NULL)
  ------------------
  |  Branch (43:6): [True: 2.96k, False: 0]
  ------------------
   44|  2.96k|		*valp = NULL;
   45|  2.96k|	if ((r = sshbuf_get_bignum2_bytes_direct(buf, &d, &len)) != 0)
  ------------------
  |  Branch (45:6): [True: 148, False: 2.81k]
  ------------------
   46|    148|		return r;
   47|  2.81k|	if (valp != NULL) {
  ------------------
  |  Branch (47:6): [True: 2.81k, False: 0]
  ------------------
   48|  2.81k|		if ((v = BN_new()) == NULL ||
  ------------------
  |  Branch (48:7): [True: 0, False: 2.81k]
  ------------------
   49|  2.81k|		    BN_bin2bn(d, len, v) == NULL) {
  ------------------
  |  Branch (49:7): [True: 0, False: 2.81k]
  ------------------
   50|      0|			BN_clear_free(v);
   51|      0|			return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
   52|      0|		}
   53|  2.81k|		*valp = v;
   54|  2.81k|	}
   55|  2.81k|	return 0;
   56|  2.81k|}
sshbuf_get_eckey:
   96|     95|{
   97|     95|	EC_POINT *pt = EC_POINT_new(EC_KEY_get0_group(v));
   98|     95|	int r;
   99|     95|	const u_char *d;
  100|     95|	size_t len;
  101|       |
  102|     95|	if (pt == NULL) {
  ------------------
  |  Branch (102:6): [True: 0, False: 95]
  ------------------
  103|      0|		SSHBUF_DBG(("SSH_ERR_ALLOC_FAIL"));
  104|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  105|      0|	}
  106|     95|	if ((r = sshbuf_peek_string_direct(buf, &d, &len)) < 0) {
  ------------------
  |  Branch (106:6): [True: 50, False: 45]
  ------------------
  107|     50|		EC_POINT_free(pt);
  108|     50|		return r;
  109|     50|	}
  110|     45|	if ((r = get_ec(d, len, pt, EC_KEY_get0_group(v))) != 0) {
  ------------------
  |  Branch (110:6): [True: 45, False: 0]
  ------------------
  111|     45|		EC_POINT_free(pt);
  112|     45|		return r;
  113|     45|	}
  114|      0|	if (EC_KEY_set_public_key(v, pt) != 1) {
  ------------------
  |  Branch (114:6): [True: 0, False: 0]
  ------------------
  115|      0|		EC_POINT_free(pt);
  116|      0|		return SSH_ERR_ALLOC_FAIL; /* XXX assumption */
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  117|      0|	}
  118|      0|	EC_POINT_free(pt);
  119|       |	/* Skip string */
  120|      0|	if (sshbuf_get_string_direct(buf, NULL, NULL) != 0) {
  ------------------
  |  Branch (120:6): [True: 0, False: 0]
  ------------------
  121|       |		/* Shouldn't happen */
  122|      0|		SSHBUF_DBG(("SSH_ERR_INTERNAL_ERROR"));
  123|      0|		SSHBUF_ABORT();
  124|      0|		return SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|      0|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  125|      0|	}
  126|      0|	return 0;
  127|      0|}
sshbuf-getput-crypto.c:get_ec:
   61|     45|{
   62|       |	/* Refuse overlong bignums */
   63|     45|	if (len == 0 || len > SSHBUF_MAX_ECPOINT)
  ------------------
  |  |   34|     40|#define SSHBUF_MAX_ECPOINT	((528 * 2 / 8) + 1) /* Max EC point *bytes* */
  ------------------
  |  Branch (63:6): [True: 5, False: 40]
  |  Branch (63:18): [True: 15, False: 25]
  ------------------
   64|     20|		return SSH_ERR_ECPOINT_TOO_LARGE;
  ------------------
  |  |   32|     20|#define SSH_ERR_ECPOINT_TOO_LARGE		-8
  ------------------
   65|       |	/* Only handle uncompressed points */
   66|     25|	if (*d != POINT_CONVERSION_UNCOMPRESSED)
  ------------------
  |  Branch (66:6): [True: 23, False: 2]
  ------------------
   67|     23|		return SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     23|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
   68|      2|	if (v != NULL && EC_POINT_oct2point(g, v, d, len, NULL) != 1)
  ------------------
  |  Branch (68:6): [True: 2, False: 0]
  |  Branch (68:19): [True: 2, False: 0]
  ------------------
   69|      2|		return SSH_ERR_INVALID_FORMAT; /* XXX assumption */
  ------------------
  |  |   28|      2|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
   70|      0|	return 0;
   71|      2|}

sshbuf_cmp:
  240|  4.80k|{
  241|  4.80k|	if (sshbuf_ptr(b) == NULL)
  ------------------
  |  Branch (241:6): [True: 0, False: 4.80k]
  ------------------
  242|      0|		return SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|      0|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  243|  4.80k|	if (offset > SSHBUF_SIZE_MAX || len > SSHBUF_SIZE_MAX || len == 0)
  ------------------
  |  |   31|  9.60k|#define SSHBUF_SIZE_MAX		0x8000000	/* Hard maximum size 128MB */
  ------------------
              	if (offset > SSHBUF_SIZE_MAX || len > SSHBUF_SIZE_MAX || len == 0)
  ------------------
  |  |   31|  9.60k|#define SSHBUF_SIZE_MAX		0x8000000	/* Hard maximum size 128MB */
  ------------------
  |  Branch (243:6): [True: 0, False: 4.80k]
  |  Branch (243:34): [True: 0, False: 4.80k]
  |  Branch (243:59): [True: 0, False: 4.80k]
  ------------------
  244|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  245|  4.80k|	if (offset + len > sshbuf_len(b))
  ------------------
  |  Branch (245:6): [True: 4, False: 4.80k]
  ------------------
  246|      4|		return SSH_ERR_MESSAGE_INCOMPLETE;
  ------------------
  |  |   27|      4|#define SSH_ERR_MESSAGE_INCOMPLETE		-3
  ------------------
  247|  4.80k|	if (timingsafe_bcmp(sshbuf_ptr(b) + offset, s, len) != 0)
  ------------------
  |  Branch (247:6): [True: 12, False: 4.78k]
  ------------------
  248|     12|		return SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     12|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  249|  4.78k|	return 0;
  250|  4.80k|}

sshbuf_new_label:
  117|  6.63k|{
  118|  6.63k|	struct sshbuf *ret;
  119|       |
  120|  6.63k|	if ((ret = calloc(sizeof(*ret), 1)) == NULL)
  ------------------
  |  Branch (120:6): [True: 0, False: 6.63k]
  ------------------
  121|      0|		return NULL;
  122|  6.63k|	ret->alloc = SSHBUF_SIZE_INIT;
  ------------------
  |  |  405|  6.63k|# define SSHBUF_SIZE_INIT	256		/* Initial allocation */
  ------------------
  123|  6.63k|	ret->max_size = SSHBUF_SIZE_MAX;
  ------------------
  |  |   31|  6.63k|#define SSHBUF_SIZE_MAX		0x8000000	/* Hard maximum size 128MB */
  ------------------
  124|  6.63k|	ret->readonly = 0;
  125|  6.63k|	ret->refcount = 1;
  126|  6.63k|	ret->parent = NULL;
  127|  6.63k|	if (label != NULL)
  ------------------
  |  Branch (127:6): [True: 6.63k, False: 0]
  ------------------
  128|  6.63k|		strncpy(ret->label, label, MAX_LABEL_LEN-1);
  ------------------
  |  |   35|  6.63k|#define MAX_LABEL_LEN           64 /*maximum size of sshbuf label */
  ------------------
  129|  6.63k|	if ((ret->cd = ret->d = calloc(1, ret->alloc)) == NULL) {
  ------------------
  |  Branch (129:6): [True: 0, False: 6.63k]
  ------------------
  130|      0|		free(ret);
  131|      0|		return NULL;
  132|      0|	}
  133|  6.63k|	return ret;
  134|  6.63k|}
sshbuf_from:
  138|  16.1k|{
  139|  16.1k|	struct sshbuf *ret;
  140|       |
  141|  16.1k|	if (blob == NULL || len > SSHBUF_SIZE_MAX ||
  ------------------
  |  |   31|  32.2k|#define SSHBUF_SIZE_MAX		0x8000000	/* Hard maximum size 128MB */
  ------------------
  |  Branch (141:6): [True: 0, False: 16.1k]
  |  Branch (141:22): [True: 0, False: 16.1k]
  ------------------
  142|  16.1k|	    (ret = calloc(sizeof(*ret), 1)) == NULL)
  ------------------
  |  Branch (142:6): [True: 0, False: 16.1k]
  ------------------
  143|      0|		return NULL;
  144|  16.1k|	ret->alloc = ret->size = ret->max_size = len;
  145|  16.1k|	ret->readonly = 1;
  146|  16.1k|	ret->refcount = 1;
  147|  16.1k|	ret->parent = NULL;
  148|  16.1k|	ret->cd = blob;
  149|  16.1k|	ret->d = NULL;
  150|  16.1k|	return ret;
  151|  16.1k|}
sshbuf_set_parent:
  155|  9.96k|{
  156|  9.96k|	int r;
  157|       |
  158|  9.96k|	if ((r = sshbuf_check_sanity(child)) != 0 ||
  ------------------
  |  Branch (158:6): [True: 0, False: 9.96k]
  ------------------
  159|  9.96k|	    (r = sshbuf_check_sanity(parent)) != 0)
  ------------------
  |  Branch (159:6): [True: 0, False: 9.96k]
  ------------------
  160|      0|		return r;
  161|  9.96k|	if (child->parent != NULL && child->parent != parent)
  ------------------
  |  Branch (161:6): [True: 0, False: 9.96k]
  |  Branch (161:31): [True: 0, False: 0]
  ------------------
  162|      0|		return SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|      0|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  163|  9.96k|	child->parent = parent;
  164|  9.96k|	child->parent->refcount++;
  165|  9.96k|	return 0;
  166|  9.96k|}
sshbuf_fromb:
  170|  5.24k|{
  171|  5.24k|	struct sshbuf *ret;
  172|       |
  173|  5.24k|	if (sshbuf_check_sanity(buf) != 0)
  ------------------
  |  Branch (173:6): [True: 0, False: 5.24k]
  ------------------
  174|      0|		return NULL;
  175|  5.24k|	if ((ret = sshbuf_from(sshbuf_ptr(buf), sshbuf_len(buf))) == NULL)
  ------------------
  |  Branch (175:6): [True: 0, False: 5.24k]
  ------------------
  176|      0|		return NULL;
  177|  5.24k|	if (sshbuf_set_parent(ret, buf) != 0) {
  ------------------
  |  Branch (177:6): [True: 0, False: 5.24k]
  ------------------
  178|      0|		sshbuf_free(ret);
  179|      0|		return NULL;
  180|      0|	}
  181|  5.24k|	return ret;
  182|  5.24k|}
sshbuf_free:
  186|  50.7k|{
  187|  50.7k|	if (buf == NULL)
  ------------------
  |  Branch (187:6): [True: 18.0k, False: 32.7k]
  ------------------
  188|  18.0k|		return;
  189|       |	/*
  190|       |	 * The following will leak on insane buffers, but this is the safest
  191|       |	 * course of action - an invalid pointer or already-freed pointer may
  192|       |	 * have been passed to us and continuing to scribble over memory would
  193|       |	 * be bad.
  194|       |	 */
  195|  32.7k|	if (sshbuf_check_sanity(buf) != 0)
  ------------------
  |  Branch (195:6): [True: 0, False: 32.7k]
  ------------------
  196|      0|		return;
  197|       |
  198|       |	/*
  199|       |	 * If we are a parent with still-extant children, then don't free just
  200|       |	 * yet. The last child's call to sshbuf_free should decrement our
  201|       |	 * refcount to 0 and trigger the actual free.
  202|       |	 */
  203|  32.7k|	buf->refcount--;
  204|  32.7k|	if (buf->refcount > 0)
  ------------------
  |  Branch (204:6): [True: 9.96k, False: 22.7k]
  ------------------
  205|  9.96k|		return;
  206|       |
  207|       |	/*
  208|       |	 * If we are a child, the free our parent to decrement its reference
  209|       |	 * count and possibly free it.
  210|       |	 */
  211|  22.7k|	sshbuf_free(buf->parent);
  212|  22.7k|	buf->parent = NULL;
  213|       |
  214|  22.7k|	if (!buf->readonly) {
  ------------------
  |  Branch (214:6): [True: 6.63k, False: 16.1k]
  ------------------
  215|  6.63k|		explicit_bzero(buf->d, buf->alloc);
  216|  6.63k|		free(buf->d);
  217|  6.63k|	}
  218|  22.7k|	freezero(buf, sizeof(*buf));
  219|  22.7k|}
sshbuf_reset:
  223|     79|{
  224|     79|	u_char *d;
  225|       |
  226|     79|	if (buf->readonly || buf->refcount > 1) {
  ------------------
  |  Branch (226:6): [True: 0, False: 79]
  |  Branch (226:23): [True: 0, False: 79]
  ------------------
  227|       |		/* Nonsensical. Just make buffer appear empty */
  228|      0|		buf->off = buf->size;
  229|      0|		return;
  230|      0|	}
  231|     79|	if (sshbuf_check_sanity(buf) != 0)
  ------------------
  |  Branch (231:6): [True: 0, False: 79]
  ------------------
  232|      0|		return;
  233|     79|	buf->off = buf->size = 0;
  234|     79|	if (buf->alloc != SSHBUF_SIZE_INIT) {
  ------------------
  |  |  405|     79|# define SSHBUF_SIZE_INIT	256		/* Initial allocation */
  ------------------
  |  Branch (234:6): [True: 52, False: 27]
  ------------------
  235|     52|		if ((d = recallocarray(buf->d, buf->alloc, SSHBUF_SIZE_INIT,
  ------------------
  |  |  405|     52|# define SSHBUF_SIZE_INIT	256		/* Initial allocation */
  ------------------
  |  Branch (235:7): [True: 52, False: 0]
  ------------------
  236|     52|		    1)) != NULL) {
  237|     52|			buf->cd = buf->d = d;
  238|     52|			buf->alloc = SSHBUF_SIZE_INIT;
  ------------------
  |  |  405|     52|# define SSHBUF_SIZE_INIT	256		/* Initial allocation */
  ------------------
  239|     52|		}
  240|     52|	}
  241|     79|	explicit_bzero(buf->d, buf->alloc);
  242|     79|}
sshbuf_len:
  308|   177k|{
  309|   177k|	if (sshbuf_check_sanity(buf) != 0)
  ------------------
  |  Branch (309:6): [True: 0, False: 177k]
  ------------------
  310|      0|		return 0;
  311|   177k|	return buf->size - buf->off;
  312|   177k|}
sshbuf_ptr:
  335|  79.1k|{
  336|  79.1k|	if (sshbuf_check_sanity(buf) != 0)
  ------------------
  |  Branch (336:6): [True: 0, False: 79.1k]
  ------------------
  337|      0|		return NULL;
  338|  79.1k|	return buf->cd + buf->off;
  339|  79.1k|}
sshbuf_check_reserve:
  351|  15.2k|{
  352|  15.2k|	int r;
  353|       |
  354|  15.2k|	if ((r = sshbuf_check_sanity(buf)) != 0)
  ------------------
  |  Branch (354:6): [True: 0, False: 15.2k]
  ------------------
  355|      0|		return r;
  356|  15.2k|	if (buf->readonly || buf->refcount > 1)
  ------------------
  |  Branch (356:6): [True: 0, False: 15.2k]
  |  Branch (356:23): [True: 0, False: 15.2k]
  ------------------
  357|      0|		return SSH_ERR_BUFFER_READ_ONLY;
  ------------------
  |  |   73|      0|#define SSH_ERR_BUFFER_READ_ONLY		-49
  ------------------
  358|  15.2k|	SSHBUF_TELL("check");
  359|       |	/* Check that len is reasonable and that max_size + available < len */
  360|  15.2k|	if (len > buf->max_size || buf->max_size - len < buf->size - buf->off)
  ------------------
  |  Branch (360:6): [True: 0, False: 15.2k]
  |  Branch (360:29): [True: 0, False: 15.2k]
  ------------------
  361|      0|		return SSH_ERR_NO_BUFFER_SPACE;
  ------------------
  |  |   33|      0|#define SSH_ERR_NO_BUFFER_SPACE			-9
  ------------------
  362|  15.2k|	return 0;
  363|  15.2k|}
sshbuf_allocate:
  367|  14.8k|{
  368|  14.8k|	size_t rlen, need;
  369|  14.8k|	u_char *dp;
  370|  14.8k|	int r;
  371|       |
  372|  14.8k|	SSHBUF_DBG(("allocate buf = %p len = %zu", buf, len));
  373|  14.8k|	if ((r = sshbuf_check_reserve(buf, len)) != 0)
  ------------------
  |  Branch (373:6): [True: 0, False: 14.8k]
  ------------------
  374|      0|		return r;
  375|       |	/*
  376|       |	 * If the requested allocation appended would push us past max_size
  377|       |	 * then pack the buffer, zeroing buf->off.
  378|       |	 */
  379|  14.8k|	sshbuf_maybe_pack(buf, buf->size + len > buf->max_size);
  380|  14.8k|	SSHBUF_TELL("allocate");
  381|  14.8k|	if (len + buf->size <= buf->alloc)
  ------------------
  |  Branch (381:6): [True: 14.3k, False: 474]
  ------------------
  382|  14.3k|		return 0; /* already have it. */
  383|       |
  384|       |	/*
  385|       |	 * Prefer to alloc in SSHBUF_SIZE_INC units, but
  386|       |	 * allocate less if doing so would overflow max_size.
  387|       |	 */
  388|    474|	need = len + buf->size - buf->alloc;
  389|    474|	rlen = ROUNDUP(buf->alloc + need, SSHBUF_SIZE_INC);
  ------------------
  |  |  237|    474|#define ROUNDUP(x, y)   ((((x)+((y)-1))/(y))*(y))
  ------------------
  390|       |	/* With the changes in 8.9 the output buffer end up growing pretty
  391|       |	 * slowly. It's knows that it needs to grow but it only does so 32K
  392|       |	 * at a time. This means a lot of calls to realloc and memcpy which
  393|       |	 * kills performance until the buffer reaches some maximum size.
  394|       |	 * So we explicitly test for a buffer that's trying to grow and
  395|       |	 * if it is then we push the growth by 4MB at a time. This can result in
  396|       |	 * the buffer being over allocated (in terms of actual needs) but the
  397|       |	 * process is fast. This significantly reduces overhead
  398|       |	 * and improves performance. In this case we look for a buffer that is trying
  399|       |	 * to grow larger than BUF_WATERSHED (256*1024 taken from PACKET_MAX_SIZE)
  400|       |	 * and explcitly check that the buffer is being used for inbound outbound
  401|       |	 * channel buffering.
  402|       |	 * Updated for 18.4.1 -cjr 04/20/24
  403|       |	 */
  404|    474|	if (rlen > BUF_WATERSHED && (buf->type == BUF_CHANNEL_OUTPUT || buf->type == BUF_CHANNEL_INPUT)) {
  ------------------
  |  |   32|    948|#define BUF_WATERSHED 256*1024
  ------------------
  |  Branch (404:6): [True: 10, False: 464]
  |  Branch (404:31): [True: 10, False: 0]
  |  Branch (404:66): [True: 0, False: 0]
  ------------------
  405|       |		/* debug_f ("Prior: label: %s, %p, rlen is %zu need is %zu max_size is %zu",
  406|       |		   buf->label, buf, rlen, need, buf->max_size); */
  407|       |		/* easiest thing to do is grow the nuffer by 4MB each time. It might end
  408|       |		 * up being somewhat overallocated but works quickly */
  409|     10|		need = (4*1024*1024);
  410|     10|		rlen = ROUNDUP(buf->alloc + need, SSHBUF_SIZE_INC);
  ------------------
  |  |  237|     10|#define ROUNDUP(x, y)   ((((x)+((y)-1))/(y))*(y))
  ------------------
  411|       |		/* debug_f ("Post: label: %s, %p, rlen is %zu need is %zu max_size is %zu", */
  412|       |		/* 	 buf->label, buf, rlen, need, buf->max_size); */
  413|     10|	}
  414|    474|	SSHBUF_DBG(("need %zu initial rlen %zu", need, rlen));
  415|       |
  416|       |	/* rlen might be above the max allocation */
  417|    474|	if (rlen > buf->max_size)
  ------------------
  |  Branch (417:6): [True: 0, False: 474]
  ------------------
  418|      0|		rlen = buf->max_size;
  419|       |
  420|    474|	SSHBUF_DBG(("adjusted rlen %zu", rlen));
  421|    474|	if ((dp = recallocarray(buf->d, buf->alloc, rlen, 1)) == NULL) {
  ------------------
  |  Branch (421:6): [True: 0, False: 474]
  ------------------
  422|      0|		SSHBUF_DBG(("realloc fail"));
  423|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  424|      0|	}
  425|    474|	buf->alloc = rlen;
  426|    474|	buf->cd = buf->d = dp;
  427|    474|	if ((r = sshbuf_check_reserve(buf, len)) < 0) {
  ------------------
  |  Branch (427:6): [True: 0, False: 474]
  ------------------
  428|       |		/* shouldn't fail */
  429|      0|		return r;
  430|      0|	}
  431|    474|	SSHBUF_TELL("done");
  432|    474|	return 0;
  433|    474|}
sshbuf_reserve:
  437|  14.8k|{
  438|  14.8k|	u_char *dp;
  439|  14.8k|	int r;
  440|       |
  441|  14.8k|	if (dpp != NULL)
  ------------------
  |  Branch (441:6): [True: 14.8k, False: 0]
  ------------------
  442|  14.8k|		*dpp = NULL;
  443|       |
  444|  14.8k|	SSHBUF_DBG(("reserve buf = %p len = %zu", buf, len));
  445|  14.8k|	if ((r = sshbuf_allocate(buf, len)) != 0)
  ------------------
  |  Branch (445:6): [True: 0, False: 14.8k]
  ------------------
  446|      0|		return r;
  447|       |
  448|  14.8k|	dp = buf->d + buf->size;
  449|  14.8k|	buf->size += len;
  450|  14.8k|	if (dpp != NULL)
  ------------------
  |  Branch (450:6): [True: 14.8k, False: 0]
  ------------------
  451|  14.8k|		*dpp = dp;
  452|  14.8k|	return 0;
  453|  14.8k|}
sshbuf_consume:
  457|  50.3k|{
  458|  50.3k|	int r;
  459|       |
  460|  50.3k|	SSHBUF_DBG(("len = %zu", len));
  461|  50.3k|	if ((r = sshbuf_check_sanity(buf)) != 0)
  ------------------
  |  Branch (461:6): [True: 0, False: 50.3k]
  ------------------
  462|      0|		return r;
  463|  50.3k|	if (len == 0)
  ------------------
  |  Branch (463:6): [True: 0, False: 50.3k]
  ------------------
  464|      0|		return 0;
  465|  50.3k|	if (len > sshbuf_len(buf))
  ------------------
  |  Branch (465:6): [True: 36, False: 50.2k]
  ------------------
  466|     36|		return SSH_ERR_MESSAGE_INCOMPLETE;
  ------------------
  |  |   27|     36|#define SSH_ERR_MESSAGE_INCOMPLETE		-3
  ------------------
  467|  50.2k|	buf->off += len;
  468|       |	/* deal with empty buffer */
  469|  50.2k|	if (buf->off == buf->size)
  ------------------
  |  Branch (469:6): [True: 4.86k, False: 45.4k]
  ------------------
  470|  4.86k|		buf->off = buf->size = 0;
  471|  50.2k|	SSHBUF_TELL("done");
  472|  50.2k|	return 0;
  473|  50.3k|}
sshbuf.c:sshbuf_check_sanity:
   80|   380k|{
   81|   380k|	SSHBUF_TELL("sanity");
   82|   380k|	if (__predict_false(buf == NULL ||
  ------------------
  |  |  924|  6.49M|#  define __predict_false(exp)    __builtin_expect(((exp) != 0), 0)
  |  |  ------------------
  |  |  |  Branch (924:35): [True: 0, False: 380k]
  |  |  |  Branch (924:54): [True: 30.4k, False: 349k]
  |  |  |  Branch (924:54): [True: 0, False: 30.4k]
  |  |  |  Branch (924:54): [True: 0, False: 380k]
  |  |  |  Branch (924:54): [True: 0, False: 380k]
  |  |  |  Branch (924:54): [True: 0, False: 380k]
  |  |  |  Branch (924:54): [True: 0, False: 380k]
  |  |  |  Branch (924:54): [True: 0, False: 380k]
  |  |  |  Branch (924:54): [True: 0, False: 380k]
  |  |  |  Branch (924:54): [True: 0, False: 380k]
  |  |  |  Branch (924:54): [True: 0, False: 380k]
  |  |  ------------------
  ------------------
   83|   380k|	    (!buf->readonly && buf->d != buf->cd) ||
   84|   380k|	    buf->refcount < 1 || buf->refcount > SSHBUF_REFS_MAX ||
   85|   380k|	    buf->cd == NULL ||
   86|   380k|	    buf->max_size > SSHBUF_SIZE_MAX ||
   87|   380k|	    buf->alloc > buf->max_size ||
   88|   380k|	    buf->size > buf->alloc ||
   89|   380k|	    buf->off > buf->size)) {
   90|       |		/* Do not try to recover from corrupted buffer internals */
   91|      0|		SSHBUF_DBG(("SSH_ERR_INTERNAL_ERROR"));
   92|      0|		ssh_signal(SIGSEGV, SIG_DFL);
   93|      0|		raise(SIGSEGV);
   94|      0|		return SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|      0|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
   95|      0|	}
   96|   380k|	return 0;
   97|   380k|}
sshbuf.c:sshbuf_maybe_pack:
  101|  14.8k|{
  102|  14.8k|	SSHBUF_DBG(("force %d", force));
  103|  14.8k|	SSHBUF_TELL("pre-pack");
  104|  14.8k|	if (buf->off == 0 || buf->readonly || buf->refcount > 1)
  ------------------
  |  Branch (104:6): [True: 14.8k, False: 0]
  |  Branch (104:23): [True: 0, False: 0]
  |  Branch (104:40): [True: 0, False: 0]
  ------------------
  105|  14.8k|		return;
  106|      0|	if (force ||
  ------------------
  |  Branch (106:6): [True: 0, False: 0]
  ------------------
  107|      0|	    (buf->off >= SSHBUF_PACK_MIN && buf->off >= buf->size / 2)) {
  ------------------
  |  |  407|      0|# define SSHBUF_PACK_MIN	8192		/* Minimum packable offset */
  ------------------
  |  Branch (107:7): [True: 0, False: 0]
  |  Branch (107:38): [True: 0, False: 0]
  ------------------
  108|      0|		memmove(buf->d, buf->d + buf->off, buf->size - buf->off);
  109|      0|		buf->size -= buf->off;
  110|      0|		buf->off = 0;
  111|      0|		SSHBUF_TELL("packed");
  112|      0|	}
  113|      0|}

ssh_err:
   24|  2.47k|{
   25|  2.47k|	switch (n) {
   26|      0|	case SSH_ERR_SUCCESS:
  ------------------
  |  |   24|      0|#define SSH_ERR_SUCCESS				0
  ------------------
  |  Branch (26:2): [True: 0, False: 2.47k]
  ------------------
   27|      0|		return "success";
   28|      0|	case SSH_ERR_INTERNAL_ERROR:
  ------------------
  |  |   25|      0|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  |  Branch (28:2): [True: 0, False: 2.47k]
  ------------------
   29|      0|		return "unexpected internal error";
   30|      0|	case SSH_ERR_ALLOC_FAIL:
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  |  Branch (30:2): [True: 0, False: 2.47k]
  ------------------
   31|      0|		return "memory allocation failed";
   32|    375|	case SSH_ERR_MESSAGE_INCOMPLETE:
  ------------------
  |  |   27|    375|#define SSH_ERR_MESSAGE_INCOMPLETE		-3
  ------------------
  |  Branch (32:2): [True: 375, False: 2.10k]
  ------------------
   33|    375|		return "incomplete message";
   34|    584|	case SSH_ERR_INVALID_FORMAT:
  ------------------
  |  |   28|    584|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  |  Branch (34:2): [True: 584, False: 1.89k]
  ------------------
   35|    584|		return "invalid format";
   36|      0|	case SSH_ERR_BIGNUM_IS_NEGATIVE:
  ------------------
  |  |   29|      0|#define SSH_ERR_BIGNUM_IS_NEGATIVE		-5
  ------------------
  |  Branch (36:2): [True: 0, False: 2.47k]
  ------------------
   37|      0|		return "bignum is negative";
   38|     87|	case SSH_ERR_STRING_TOO_LARGE:
  ------------------
  |  |   30|     87|#define SSH_ERR_STRING_TOO_LARGE		-6
  ------------------
  |  Branch (38:2): [True: 87, False: 2.38k]
  ------------------
   39|     87|		return "string is too large";
   40|      0|	case SSH_ERR_BIGNUM_TOO_LARGE:
  ------------------
  |  |   31|      0|#define SSH_ERR_BIGNUM_TOO_LARGE		-7
  ------------------
  |  Branch (40:2): [True: 0, False: 2.47k]
  ------------------
   41|      0|		return "bignum is too large";
   42|     20|	case SSH_ERR_ECPOINT_TOO_LARGE:
  ------------------
  |  |   32|     20|#define SSH_ERR_ECPOINT_TOO_LARGE		-8
  ------------------
  |  Branch (42:2): [True: 20, False: 2.45k]
  ------------------
   43|     20|		return "elliptic curve point is too large";
   44|      0|	case SSH_ERR_NO_BUFFER_SPACE:
  ------------------
  |  |   33|      0|#define SSH_ERR_NO_BUFFER_SPACE			-9
  ------------------
  |  Branch (44:2): [True: 0, False: 2.47k]
  ------------------
   45|      0|		return "insufficient buffer space";
   46|     34|	case SSH_ERR_INVALID_ARGUMENT:
  ------------------
  |  |   34|     34|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  |  Branch (46:2): [True: 34, False: 2.44k]
  ------------------
   47|     34|		return "invalid argument";
   48|     10|	case SSH_ERR_KEY_BITS_MISMATCH:
  ------------------
  |  |   35|     10|#define SSH_ERR_KEY_BITS_MISMATCH		-11
  ------------------
  |  Branch (48:2): [True: 10, False: 2.46k]
  ------------------
   49|     10|		return "key bits do not match";
   50|      0|	case SSH_ERR_EC_CURVE_INVALID:
  ------------------
  |  |   36|      0|#define SSH_ERR_EC_CURVE_INVALID		-12
  ------------------
  |  Branch (50:2): [True: 0, False: 2.47k]
  ------------------
   51|      0|		return "invalid elliptic curve";
   52|    581|	case SSH_ERR_KEY_TYPE_MISMATCH:
  ------------------
  |  |   37|    581|#define SSH_ERR_KEY_TYPE_MISMATCH		-13
  ------------------
  |  Branch (52:2): [True: 581, False: 1.89k]
  ------------------
   53|    581|		return "key type does not match";
   54|    350|	case SSH_ERR_KEY_TYPE_UNKNOWN:
  ------------------
  |  |   38|    350|#define SSH_ERR_KEY_TYPE_UNKNOWN		-14 /* XXX UNSUPPORTED? */
  ------------------
  |  Branch (54:2): [True: 350, False: 2.12k]
  ------------------
   55|    350|		return "unknown or unsupported key type";
   56|    112|	case SSH_ERR_EC_CURVE_MISMATCH:
  ------------------
  |  |   39|    112|#define SSH_ERR_EC_CURVE_MISMATCH		-15
  ------------------
  |  Branch (56:2): [True: 112, False: 2.36k]
  ------------------
   57|    112|		return "elliptic curve does not match";
   58|      0|	case SSH_ERR_EXPECTED_CERT:
  ------------------
  |  |   40|      0|#define SSH_ERR_EXPECTED_CERT			-16
  ------------------
  |  Branch (58:2): [True: 0, False: 2.47k]
  ------------------
   59|      0|		return "plain key provided where certificate required";
   60|      0|	case SSH_ERR_KEY_LACKS_CERTBLOB:
  ------------------
  |  |   41|      0|#define SSH_ERR_KEY_LACKS_CERTBLOB		-17
  ------------------
  |  Branch (60:2): [True: 0, False: 2.47k]
  ------------------
   61|      0|		return "key lacks certificate data";
   62|     62|	case SSH_ERR_KEY_CERT_UNKNOWN_TYPE:
  ------------------
  |  |   42|     62|#define SSH_ERR_KEY_CERT_UNKNOWN_TYPE		-18
  ------------------
  |  Branch (62:2): [True: 62, False: 2.41k]
  ------------------
   63|     62|		return "unknown/unsupported certificate type";
   64|     42|	case SSH_ERR_KEY_CERT_INVALID_SIGN_KEY:
  ------------------
  |  |   43|     42|#define SSH_ERR_KEY_CERT_INVALID_SIGN_KEY	-19
  ------------------
  |  Branch (64:2): [True: 42, False: 2.43k]
  ------------------
   65|     42|		return "invalid certificate signing key";
   66|      0|	case SSH_ERR_KEY_INVALID_EC_VALUE:
  ------------------
  |  |   44|      0|#define SSH_ERR_KEY_INVALID_EC_VALUE		-20
  ------------------
  |  Branch (66:2): [True: 0, False: 2.47k]
  ------------------
   67|      0|		return "invalid elliptic curve value";
   68|     72|	case SSH_ERR_SIGNATURE_INVALID:
  ------------------
  |  |   45|     72|#define SSH_ERR_SIGNATURE_INVALID		-21
  ------------------
  |  Branch (68:2): [True: 72, False: 2.40k]
  ------------------
   69|     72|		return "incorrect signature";
   70|     23|	case SSH_ERR_LIBCRYPTO_ERROR:
  ------------------
  |  |   46|     23|#define SSH_ERR_LIBCRYPTO_ERROR			-22
  ------------------
  |  Branch (70:2): [True: 23, False: 2.45k]
  ------------------
   71|     23|		return "error in libcrypto";  /* XXX fetch and return */
   72|     40|	case SSH_ERR_UNEXPECTED_TRAILING_DATA:
  ------------------
  |  |   47|     40|#define SSH_ERR_UNEXPECTED_TRAILING_DATA	-23
  ------------------
  |  Branch (72:2): [True: 40, False: 2.43k]
  ------------------
   73|     40|		return "unexpected bytes remain after decoding";
   74|      0|	case SSH_ERR_SYSTEM_ERROR:
  ------------------
  |  |   48|      0|#define SSH_ERR_SYSTEM_ERROR			-24
  ------------------
  |  Branch (74:2): [True: 0, False: 2.47k]
  ------------------
   75|      0|		return strerror(errno);
   76|      0|	case SSH_ERR_KEY_CERT_INVALID:
  ------------------
  |  |   49|      0|#define SSH_ERR_KEY_CERT_INVALID		-25
  ------------------
  |  Branch (76:2): [True: 0, False: 2.47k]
  ------------------
   77|      0|		return "invalid certificate";
   78|      0|	case SSH_ERR_AGENT_COMMUNICATION:
  ------------------
  |  |   50|      0|#define SSH_ERR_AGENT_COMMUNICATION		-26
  ------------------
  |  Branch (78:2): [True: 0, False: 2.47k]
  ------------------
   79|      0|		return "communication with agent failed";
   80|      0|	case SSH_ERR_AGENT_FAILURE:
  ------------------
  |  |   51|      0|#define SSH_ERR_AGENT_FAILURE			-27
  ------------------
  |  Branch (80:2): [True: 0, False: 2.47k]
  ------------------
   81|      0|		return "agent refused operation";
   82|      0|	case SSH_ERR_DH_GEX_OUT_OF_RANGE:
  ------------------
  |  |   52|      0|#define SSH_ERR_DH_GEX_OUT_OF_RANGE		-28
  ------------------
  |  Branch (82:2): [True: 0, False: 2.47k]
  ------------------
   83|      0|		return "DH GEX group out of range";
   84|      0|	case SSH_ERR_DISCONNECTED:
  ------------------
  |  |   53|      0|#define SSH_ERR_DISCONNECTED			-29
  ------------------
  |  Branch (84:2): [True: 0, False: 2.47k]
  ------------------
   85|      0|		return "disconnected";
   86|      0|	case SSH_ERR_MAC_INVALID:
  ------------------
  |  |   54|      0|#define SSH_ERR_MAC_INVALID			-30
  ------------------
  |  Branch (86:2): [True: 0, False: 2.47k]
  ------------------
   87|      0|		return "message authentication code incorrect";
   88|      0|	case SSH_ERR_NO_CIPHER_ALG_MATCH:
  ------------------
  |  |   55|      0|#define SSH_ERR_NO_CIPHER_ALG_MATCH		-31
  ------------------
  |  Branch (88:2): [True: 0, False: 2.47k]
  ------------------
   89|      0|		return "no matching cipher found";
   90|      0|	case SSH_ERR_NO_MAC_ALG_MATCH:
  ------------------
  |  |   56|      0|#define SSH_ERR_NO_MAC_ALG_MATCH		-32
  ------------------
  |  Branch (90:2): [True: 0, False: 2.47k]
  ------------------
   91|      0|		return "no matching MAC found";
   92|      0|	case SSH_ERR_NO_COMPRESS_ALG_MATCH:
  ------------------
  |  |   57|      0|#define SSH_ERR_NO_COMPRESS_ALG_MATCH		-33
  ------------------
  |  Branch (92:2): [True: 0, False: 2.47k]
  ------------------
   93|      0|		return "no matching compression method found";
   94|      0|	case SSH_ERR_NO_KEX_ALG_MATCH:
  ------------------
  |  |   58|      0|#define SSH_ERR_NO_KEX_ALG_MATCH		-34
  ------------------
  |  Branch (94:2): [True: 0, False: 2.47k]
  ------------------
   95|      0|		return "no matching key exchange method found";
   96|      0|	case SSH_ERR_NO_HOSTKEY_ALG_MATCH:
  ------------------
  |  |   59|      0|#define SSH_ERR_NO_HOSTKEY_ALG_MATCH		-35
  ------------------
  |  Branch (96:2): [True: 0, False: 2.47k]
  ------------------
   97|      0|		return "no matching host key type found";
   98|      0|	case SSH_ERR_PROTOCOL_MISMATCH:
  ------------------
  |  |   61|      0|#define SSH_ERR_PROTOCOL_MISMATCH		-37
  ------------------
  |  Branch (98:2): [True: 0, False: 2.47k]
  ------------------
   99|      0|		return "protocol version mismatch";
  100|      0|	case SSH_ERR_NO_PROTOCOL_VERSION:
  ------------------
  |  |   62|      0|#define SSH_ERR_NO_PROTOCOL_VERSION		-38
  ------------------
  |  Branch (100:2): [True: 0, False: 2.47k]
  ------------------
  101|      0|		return "could not read protocol version";
  102|      0|	case SSH_ERR_NO_HOSTKEY_LOADED:
  ------------------
  |  |   60|      0|#define SSH_ERR_NO_HOSTKEY_LOADED		-36
  ------------------
  |  Branch (102:2): [True: 0, False: 2.47k]
  ------------------
  103|      0|		return "could not load host key";
  104|      0|	case SSH_ERR_NEED_REKEY:
  ------------------
  |  |   63|      0|#define SSH_ERR_NEED_REKEY			-39
  ------------------
  |  Branch (104:2): [True: 0, False: 2.47k]
  ------------------
  105|      0|		return "rekeying not supported by peer";
  106|      0|	case SSH_ERR_PASSPHRASE_TOO_SHORT:
  ------------------
  |  |   64|      0|#define SSH_ERR_PASSPHRASE_TOO_SHORT		-40
  ------------------
  |  Branch (106:2): [True: 0, False: 2.47k]
  ------------------
  107|      0|		return "passphrase is too short (minimum five characters)";
  108|      0|	case SSH_ERR_FILE_CHANGED:
  ------------------
  |  |   65|      0|#define SSH_ERR_FILE_CHANGED			-41
  ------------------
  |  Branch (108:2): [True: 0, False: 2.47k]
  ------------------
  109|      0|		return "file changed while reading";
  110|      0|	case SSH_ERR_KEY_UNKNOWN_CIPHER:
  ------------------
  |  |   66|      0|#define SSH_ERR_KEY_UNKNOWN_CIPHER		-42
  ------------------
  |  Branch (110:2): [True: 0, False: 2.47k]
  ------------------
  111|      0|		return "key encrypted using unsupported cipher";
  112|      0|	case SSH_ERR_KEY_WRONG_PASSPHRASE:
  ------------------
  |  |   67|      0|#define SSH_ERR_KEY_WRONG_PASSPHRASE		-43
  ------------------
  |  Branch (112:2): [True: 0, False: 2.47k]
  ------------------
  113|      0|		return "incorrect passphrase supplied to decrypt private key";
  114|      0|	case SSH_ERR_KEY_BAD_PERMISSIONS:
  ------------------
  |  |   68|      0|#define SSH_ERR_KEY_BAD_PERMISSIONS		-44
  ------------------
  |  Branch (114:2): [True: 0, False: 2.47k]
  ------------------
  115|      0|		return "bad permissions";
  116|      0|	case SSH_ERR_KEY_CERT_MISMATCH:
  ------------------
  |  |   69|      0|#define SSH_ERR_KEY_CERT_MISMATCH		-45
  ------------------
  |  Branch (116:2): [True: 0, False: 2.47k]
  ------------------
  117|      0|		return "certificate does not match key";
  118|      0|	case SSH_ERR_KEY_NOT_FOUND:
  ------------------
  |  |   70|      0|#define SSH_ERR_KEY_NOT_FOUND			-46
  ------------------
  |  Branch (118:2): [True: 0, False: 2.47k]
  ------------------
  119|      0|		return "key not found";
  120|      0|	case SSH_ERR_AGENT_NOT_PRESENT:
  ------------------
  |  |   71|      0|#define SSH_ERR_AGENT_NOT_PRESENT		-47
  ------------------
  |  Branch (120:2): [True: 0, False: 2.47k]
  ------------------
  121|      0|		return "agent not present";
  122|      0|	case SSH_ERR_AGENT_NO_IDENTITIES:
  ------------------
  |  |   72|      0|#define SSH_ERR_AGENT_NO_IDENTITIES		-48
  ------------------
  |  Branch (122:2): [True: 0, False: 2.47k]
  ------------------
  123|      0|		return "agent contains no identities";
  124|      0|	case SSH_ERR_BUFFER_READ_ONLY:
  ------------------
  |  |   73|      0|#define SSH_ERR_BUFFER_READ_ONLY		-49
  ------------------
  |  Branch (124:2): [True: 0, False: 2.47k]
  ------------------
  125|      0|		return "internal error: buffer is read-only";
  126|      0|	case SSH_ERR_KRL_BAD_MAGIC:
  ------------------
  |  |   74|      0|#define SSH_ERR_KRL_BAD_MAGIC			-50
  ------------------
  |  Branch (126:2): [True: 0, False: 2.47k]
  ------------------
  127|      0|		return "KRL file has invalid magic number";
  128|      0|	case SSH_ERR_KEY_REVOKED:
  ------------------
  |  |   75|      0|#define SSH_ERR_KEY_REVOKED			-51
  ------------------
  |  Branch (128:2): [True: 0, False: 2.47k]
  ------------------
  129|      0|		return "Key is revoked";
  130|      0|	case SSH_ERR_CONN_CLOSED:
  ------------------
  |  |   76|      0|#define SSH_ERR_CONN_CLOSED			-52
  ------------------
  |  Branch (130:2): [True: 0, False: 2.47k]
  ------------------
  131|      0|		return "Connection closed";
  132|      0|	case SSH_ERR_CONN_TIMEOUT:
  ------------------
  |  |   77|      0|#define SSH_ERR_CONN_TIMEOUT			-53
  ------------------
  |  Branch (132:2): [True: 0, False: 2.47k]
  ------------------
  133|      0|		return "Connection timed out";
  134|      0|	case SSH_ERR_CONN_CORRUPT:
  ------------------
  |  |   78|      0|#define SSH_ERR_CONN_CORRUPT			-54
  ------------------
  |  Branch (134:2): [True: 0, False: 2.47k]
  ------------------
  135|      0|		return "Connection corrupted";
  136|      0|	case SSH_ERR_PROTOCOL_ERROR:
  ------------------
  |  |   79|      0|#define SSH_ERR_PROTOCOL_ERROR			-55
  ------------------
  |  Branch (136:2): [True: 0, False: 2.47k]
  ------------------
  137|      0|		return "Protocol error";
  138|     23|	case SSH_ERR_KEY_LENGTH:
  ------------------
  |  |   80|     23|#define SSH_ERR_KEY_LENGTH			-56
  ------------------
  |  Branch (138:2): [True: 23, False: 2.45k]
  ------------------
  139|     23|		return "Invalid key length";
  140|      0|	case SSH_ERR_NUMBER_TOO_LARGE:
  ------------------
  |  |   81|      0|#define SSH_ERR_NUMBER_TOO_LARGE		-57
  ------------------
  |  Branch (140:2): [True: 0, False: 2.47k]
  ------------------
  141|      0|		return "number is too large";
  142|     61|	case SSH_ERR_SIGN_ALG_UNSUPPORTED:
  ------------------
  |  |   82|     61|#define SSH_ERR_SIGN_ALG_UNSUPPORTED		-58
  ------------------
  |  Branch (142:2): [True: 61, False: 2.41k]
  ------------------
  143|     61|		return "signature algorithm not supported";
  144|      0|	case SSH_ERR_FEATURE_UNSUPPORTED:
  ------------------
  |  |   83|      0|#define SSH_ERR_FEATURE_UNSUPPORTED		-59
  ------------------
  |  Branch (144:2): [True: 0, False: 2.47k]
  ------------------
  145|      0|		return "requested feature not supported";
  146|      0|	case SSH_ERR_DEVICE_NOT_FOUND:
  ------------------
  |  |   84|      0|#define SSH_ERR_DEVICE_NOT_FOUND		-60
  ------------------
  |  Branch (146:2): [True: 0, False: 2.47k]
  ------------------
  147|      0|		return "device not found";
  148|      0|	default:
  ------------------
  |  Branch (148:2): [True: 0, False: 2.47k]
  ------------------
  149|      0|		return "unknown error";
  150|  2.47k|	}
  151|  2.47k|}

sshkey_xmss_init:
   96|    387|{
   97|    387|	struct ssh_xmss_state *state;
   98|       |
   99|    387|	if (key->xmss_state != NULL)
  ------------------
  |  Branch (99:6): [True: 0, False: 387]
  ------------------
  100|      0|		return SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      0|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  101|    387|	if (name == NULL)
  ------------------
  |  Branch (101:6): [True: 0, False: 387]
  ------------------
  102|      0|		return SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      0|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  103|    387|	state = calloc(sizeof(struct ssh_xmss_state), 1);
  104|    387|	if (state == NULL)
  ------------------
  |  Branch (104:6): [True: 0, False: 387]
  ------------------
  105|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  106|    387|	if (strcmp(name, XMSS_SHA2_256_W16_H10_NAME) == 0) {
  ------------------
  |  |   28|    387|#define XMSS_SHA2_256_W16_H10_NAME	"XMSS_SHA2-256_W16_H10"
  ------------------
  |  Branch (106:6): [True: 96, False: 291]
  ------------------
  107|     96|		state->n = 32;
  108|     96|		state->w = 16;
  109|     96|		state->h = 10;
  110|    291|	} else if (strcmp(name, XMSS_SHA2_256_W16_H16_NAME) == 0) {
  ------------------
  |  |   29|    291|#define XMSS_SHA2_256_W16_H16_NAME	"XMSS_SHA2-256_W16_H16"
  ------------------
  |  Branch (110:13): [True: 63, False: 228]
  ------------------
  111|     63|		state->n = 32;
  112|     63|		state->w = 16;
  113|     63|		state->h = 16;
  114|    228|	} else if (strcmp(name, XMSS_SHA2_256_W16_H20_NAME) == 0) {
  ------------------
  |  |   30|    228|#define XMSS_SHA2_256_W16_H20_NAME	"XMSS_SHA2-256_W16_H20"
  ------------------
  |  Branch (114:13): [True: 81, False: 147]
  ------------------
  115|     81|		state->n = 32;
  116|     81|		state->w = 16;
  117|     81|		state->h = 20;
  118|    147|	} else {
  119|    147|		free(state);
  120|    147|		return SSH_ERR_KEY_TYPE_UNKNOWN;
  ------------------
  |  |   38|    147|#define SSH_ERR_KEY_TYPE_UNKNOWN		-14 /* XXX UNSUPPORTED? */
  ------------------
  121|    147|	}
  122|    240|	if ((key->xmss_name = strdup(name)) == NULL) {
  ------------------
  |  Branch (122:6): [True: 0, False: 240]
  ------------------
  123|      0|		free(state);
  124|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  125|      0|	}
  126|    240|	state->k = 2;	/* XXX hardcoded */
  127|    240|	state->lockfd = -1;
  128|    240|	if (xmss_set_params(&state->params, state->n, state->h, state->w,
  ------------------
  |  Branch (128:6): [True: 0, False: 240]
  ------------------
  129|    240|	    state->k) != 0) {
  130|      0|		free(state);
  131|      0|		return SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      0|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  132|      0|	}
  133|    240|	key->xmss_state = state;
  134|    240|	return 0;
  135|    240|}
sshkey_xmss_free_state:
  139|    390|{
  140|    390|	struct ssh_xmss_state *state = key->xmss_state;
  141|       |
  142|    390|	sshkey_xmss_free_bds(key);
  143|    390|	if (state) {
  ------------------
  |  Branch (143:6): [True: 240, False: 150]
  ------------------
  144|    240|		if (state->enc_keyiv) {
  ------------------
  |  Branch (144:7): [True: 0, False: 240]
  ------------------
  145|      0|			explicit_bzero(state->enc_keyiv, state->enc_keyiv_len);
  146|      0|			free(state->enc_keyiv);
  147|      0|		}
  148|    240|		free(state->enc_ciphername);
  149|    240|		free(state);
  150|    240|	}
  151|    390|	key->xmss_state = NULL;
  152|    390|}
sshkey_xmss_free_bds:
  191|    390|{
  192|    390|	struct ssh_xmss_state *state = key->xmss_state;
  193|       |
  194|    390|	if (state == NULL)
  ------------------
  |  Branch (194:6): [True: 150, False: 240]
  ------------------
  195|    150|		return;
  196|    240|	free(state->stack);
  197|    240|	free(state->stacklevels);
  198|    240|	free(state->auth);
  199|    240|	free(state->keep);
  200|    240|	free(state->th_nodes);
  201|    240|	free(state->retain);
  202|    240|	free(state->treehash);
  203|    240|	state->stack = NULL;
  204|    240|	state->stacklevels = NULL;
  205|    240|	state->auth = NULL;
  206|    240|	state->keep = NULL;
  207|    240|	state->th_nodes = NULL;
  208|    240|	state->retain = NULL;
  209|    240|	state->treehash = NULL;
  210|    240|}
sshkey_xmss_params:
  214|    158|{
  215|    158|	struct ssh_xmss_state *state = key->xmss_state;
  216|       |
  217|    158|	if (state == NULL)
  ------------------
  |  Branch (217:6): [True: 0, False: 158]
  ------------------
  218|      0|		return NULL;
  219|    158|	return &state->params;
  220|    158|}
sshkey_xmss_siglen:
  234|    158|{
  235|    158|	struct ssh_xmss_state *state = key->xmss_state;
  236|       |
  237|    158|	if (lenp == NULL)
  ------------------
  |  Branch (237:6): [True: 0, False: 158]
  ------------------
  238|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  239|    158|	if (state == NULL)
  ------------------
  |  Branch (239:6): [True: 0, False: 158]
  ------------------
  240|      0|		return SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      0|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  241|    158|	*lenp = 4 + state->n +
  242|    158|	    state->params.wots_par.keysize +
  243|    158|	    state->h * state->n;
  244|    158|	return 0;
  245|    158|}
sshkey_xmss_pklen:
  249|    623|{
  250|    623|	struct ssh_xmss_state *state = key->xmss_state;
  251|       |
  252|    623|	if (state == NULL)
  ------------------
  |  Branch (252:6): [True: 150, False: 473]
  ------------------
  253|    150|		return 0;
  254|    473|	return state->n * 2;
  255|    623|}
sshkey_xmss_sklen:
  259|    390|{
  260|    390|	struct ssh_xmss_state *state = key->xmss_state;
  261|       |
  262|    390|	if (state == NULL)
  ------------------
  |  Branch (262:6): [True: 150, False: 240]
  ------------------
  263|    150|		return 0;
  264|    240|	return state->n * 4 + 4;
  265|    390|}
sshkey_xmss_deserialize_pk_info:
  347|    187|{
  348|    187|	struct ssh_xmss_state *state = k->xmss_state;
  349|    187|	u_char have_info;
  350|    187|	int r;
  351|       |
  352|    187|	if (state == NULL)
  ------------------
  |  Branch (352:6): [True: 0, False: 187]
  ------------------
  353|      0|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      0|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  354|       |	/* optional */
  355|    187|	if (sshbuf_len(b) == 0)
  ------------------
  |  Branch (355:6): [True: 162, False: 25]
  ------------------
  356|    162|		return 0;
  357|     25|	if ((r = sshbuf_get_u8(b, &have_info)) != 0)
  ------------------
  |  Branch (357:6): [True: 0, False: 25]
  ------------------
  358|      0|		return r;
  359|     25|	if (have_info != 1)
  ------------------
  |  Branch (359:6): [True: 19, False: 6]
  ------------------
  360|     19|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|     19|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
  361|      6|	if ((r = sshbuf_get_u32(b, &state->idx)) != 0 ||
  ------------------
  |  Branch (361:6): [True: 1, False: 5]
  ------------------
  362|      6|	    (r = sshbuf_get_u32(b, &state->maxidx)) != 0)
  ------------------
  |  Branch (362:6): [True: 2, False: 3]
  ------------------
  363|      3|		return r;
  364|      3|	return 0;
  365|      6|}

sshkey_type_is_cert:
  230|  9.35k|{
  231|  9.35k|	const struct sshkey_impl *impl;
  232|       |
  233|  9.35k|	if ((impl = sshkey_impl_from_type(type)) == NULL)
  ------------------
  |  Branch (233:6): [True: 2, False: 9.35k]
  ------------------
  234|      2|		return 0;
  235|  9.35k|	return impl->cert;
  236|  9.35k|}
sshkey_ssh_name_plain:
  246|    132|{
  247|    132|	return sshkey_ssh_name_from_type_nid(sshkey_type_plain(k->type),
  248|    132|	    k->ecdsa_nid);
  249|    132|}
sshkey_type_from_name:
  253|  2.55k|{
  254|  2.55k|	int i;
  255|  2.55k|	const struct sshkey_impl *impl;
  256|       |
  257|  31.1k|	for (i = 0; keyimpls[i] != NULL; i++) {
  ------------------
  |  Branch (257:14): [True: 30.9k, False: 206]
  ------------------
  258|  30.9k|		impl = keyimpls[i];
  259|       |		/* Only allow shortname matches for plain key types */
  260|  30.9k|		if ((impl->name != NULL && strcmp(name, impl->name) == 0) ||
  ------------------
  |  Branch (260:8): [True: 30.9k, False: 0]
  |  Branch (260:30): [True: 1.33k, False: 29.5k]
  ------------------
  261|  30.9k|		    (!impl->cert && strcasecmp(impl->shortname, name) == 0))
  ------------------
  |  Branch (261:8): [True: 16.4k, False: 13.1k]
  |  Branch (261:23): [True: 1.01k, False: 15.4k]
  ------------------
  262|  2.34k|			return impl->type;
  263|  30.9k|	}
  264|    206|	return KEY_UNSPEC;
  265|  2.55k|}
sshkey_ecdsa_nid_from_name:
  282|    226|{
  283|    226|	int i;
  284|       |
  285|  1.71k|	for (i = 0; keyimpls[i] != NULL; i++) {
  ------------------
  |  Branch (285:14): [True: 1.70k, False: 10]
  ------------------
  286|  1.70k|		if (!key_type_is_ecdsa_variant(keyimpls[i]->type))
  ------------------
  |  Branch (286:7): [True: 1.00k, False: 702]
  ------------------
  287|  1.00k|			continue;
  288|    702|		if (keyimpls[i]->name != NULL &&
  ------------------
  |  Branch (288:7): [True: 702, False: 0]
  ------------------
  289|    702|		    strcmp(name, keyimpls[i]->name) == 0)
  ------------------
  |  Branch (289:7): [True: 216, False: 486]
  ------------------
  290|    216|			return keyimpls[i]->nid;
  291|    702|	}
  292|     10|	return -1;
  293|    226|}
sshkey_is_cert:
  415|  6.58k|{
  416|  6.58k|	if (k == NULL)
  ------------------
  |  Branch (416:6): [True: 0, False: 6.58k]
  ------------------
  417|      0|		return 0;
  418|  6.58k|	return sshkey_type_is_cert(k->type);
  419|  6.58k|}
sshkey_type_plain:
  438|  1.43k|{
  439|  1.43k|	switch (type) {
  440|      0|	case KEY_RSA_CERT:
  ------------------
  |  Branch (440:2): [True: 0, False: 1.43k]
  ------------------
  441|      0|		return KEY_RSA;
  442|      3|	case KEY_DSA_CERT:
  ------------------
  |  Branch (442:2): [True: 3, False: 1.42k]
  ------------------
  443|      3|		return KEY_DSA;
  444|      0|	case KEY_ECDSA_CERT:
  ------------------
  |  Branch (444:2): [True: 0, False: 1.43k]
  ------------------
  445|      0|		return KEY_ECDSA;
  446|      0|	case KEY_ECDSA_SK_CERT:
  ------------------
  |  Branch (446:2): [True: 0, False: 1.43k]
  ------------------
  447|      0|		return KEY_ECDSA_SK;
  448|      0|	case KEY_ED25519_CERT:
  ------------------
  |  Branch (448:2): [True: 0, False: 1.43k]
  ------------------
  449|      0|		return KEY_ED25519;
  450|      0|	case KEY_ED25519_SK_CERT:
  ------------------
  |  Branch (450:2): [True: 0, False: 1.43k]
  ------------------
  451|      0|		return KEY_ED25519_SK;
  452|      0|	case KEY_XMSS_CERT:
  ------------------
  |  Branch (452:2): [True: 0, False: 1.43k]
  ------------------
  453|      0|		return KEY_XMSS;
  454|  1.42k|	default:
  ------------------
  |  Branch (454:2): [True: 1.42k, False: 3]
  ------------------
  455|  1.42k|		return type;
  456|  1.43k|	}
  457|  1.43k|}
sshkey_curve_name_to_nid:
  487|    207|{
  488|    207|	if (strcmp(name, "nistp256") == 0)
  ------------------
  |  Branch (488:6): [True: 36, False: 171]
  ------------------
  489|     36|		return NID_X9_62_prime256v1;
  490|    171|	else if (strcmp(name, "nistp384") == 0)
  ------------------
  |  Branch (490:11): [True: 50, False: 121]
  ------------------
  491|     50|		return NID_secp384r1;
  492|    121|# ifdef OPENSSL_HAS_NISTP521
  493|    121|	else if (strcmp(name, "nistp521") == 0)
  ------------------
  |  Branch (493:11): [True: 13, False: 108]
  ------------------
  494|     13|		return NID_secp521r1;
  495|    108|# endif /* OPENSSL_HAS_NISTP521 */
  496|    108|	else
  497|    108|		return -1;
  498|    207|}
sshkey_new:
  610|  2.34k|{
  611|  2.34k|	struct sshkey *k;
  612|  2.34k|	const struct sshkey_impl *impl = NULL;
  613|       |
  614|  2.34k|	if (type != KEY_UNSPEC &&
  ------------------
  |  Branch (614:6): [True: 2.34k, False: 0]
  ------------------
  615|  2.34k|	    (impl = sshkey_impl_from_type(type)) == NULL)
  ------------------
  |  Branch (615:6): [True: 0, False: 2.34k]
  ------------------
  616|      0|		return NULL;
  617|       |
  618|       |	/* All non-certificate types may act as CAs */
  619|  2.34k|	if ((k = calloc(1, sizeof(*k))) == NULL)
  ------------------
  |  Branch (619:6): [True: 0, False: 2.34k]
  ------------------
  620|      0|		return NULL;
  621|  2.34k|	k->type = type;
  622|  2.34k|	k->ecdsa_nid = -1;
  623|  2.34k|	if (impl != NULL && impl->funcs->alloc != NULL) {
  ------------------
  |  Branch (623:6): [True: 2.34k, False: 0]
  |  Branch (623:22): [True: 971, False: 1.37k]
  ------------------
  624|    971|		if (impl->funcs->alloc(k) != 0) {
  ------------------
  |  Branch (624:7): [True: 0, False: 971]
  ------------------
  625|      0|			free(k);
  626|      0|			return NULL;
  627|      0|		}
  628|    971|	}
  629|  2.34k|	if (sshkey_is_cert(k)) {
  ------------------
  |  Branch (629:6): [True: 766, False: 1.57k]
  ------------------
  630|    766|		if ((k->cert = cert_new()) == NULL) {
  ------------------
  |  Branch (630:7): [True: 0, False: 766]
  ------------------
  631|      0|			sshkey_free(k);
  632|      0|			return NULL;
  633|      0|		}
  634|    766|	}
  635|       |
  636|  2.34k|	return k;
  637|  2.34k|}
sshkey_sk_cleanup:
  642|    159|{
  643|    159|	free(k->sk_application);
  644|    159|	sshbuf_free(k->sk_key_handle);
  645|    159|	sshbuf_free(k->sk_reserved);
  646|    159|	k->sk_application = NULL;
  647|    159|	k->sk_key_handle = k->sk_reserved = NULL;
  648|    159|}
sshkey_free:
  668|  8.17k|{
  669|  8.17k|	sshkey_free_contents(k);
  670|  8.17k|	freezero(k, sizeof(*k));
  671|  8.17k|}
sshkey_check_rsa_length:
 1332|    286|{
 1333|    286|#ifdef WITH_OPENSSL
 1334|    286|	const BIGNUM *rsa_n;
 1335|    286|	int nbits;
 1336|       |
 1337|    286|	if (k == NULL || k->rsa == NULL ||
  ------------------
  |  Branch (1337:6): [True: 0, False: 286]
  |  Branch (1337:19): [True: 0, False: 286]
  ------------------
 1338|    286|	    (k->type != KEY_RSA && k->type != KEY_RSA_CERT))
  ------------------
  |  Branch (1338:7): [True: 6, False: 280]
  |  Branch (1338:29): [True: 0, False: 6]
  ------------------
 1339|      0|		return 0;
 1340|    286|	RSA_get0_key(k->rsa, &rsa_n, NULL, NULL);
 1341|    286|	nbits = BN_num_bits(rsa_n);
 1342|    286|	if (nbits < SSH_RSA_MINIMUM_MODULUS_SIZE ||
  ------------------
  |  |   53|    572|#define SSH_RSA_MINIMUM_MODULUS_SIZE	1024
  ------------------
  |  Branch (1342:6): [True: 25, False: 261]
  ------------------
 1343|    286|	    (min_size > 0 && nbits < min_size))
  ------------------
  |  Branch (1343:7): [True: 0, False: 261]
  |  Branch (1343:23): [True: 0, False: 0]
  ------------------
 1344|     25|		return SSH_ERR_KEY_LENGTH;
  ------------------
  |  |   80|     25|#define SSH_ERR_KEY_LENGTH			-56
  ------------------
 1345|    261|#endif /* WITH_OPENSSL */
 1346|    261|	return 0;
 1347|    286|}
sshkey_deserialize_sk:
 1891|    146|{
 1892|       |	/* Parse additional security-key application string */
 1893|    146|	if (sshbuf_get_cstring(b, &key->sk_application, NULL) != 0)
  ------------------
  |  Branch (1893:6): [True: 1, False: 145]
  ------------------
 1894|      1|		return SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      1|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
 1895|    145|	return 0;
 1896|    146|}
sshkey_froms:
 1986|  2.16k|{
 1987|  2.16k|	struct sshbuf *b;
 1988|  2.16k|	int r;
 1989|       |
 1990|  2.16k|	if ((r = sshbuf_froms(buf, &b)) != 0)
  ------------------
  |  Branch (1990:6): [True: 0, False: 2.16k]
  ------------------
 1991|      0|		return r;
 1992|  2.16k|	r = sshkey_from_blob_internal(b, keyp, 1);
 1993|  2.16k|	sshbuf_free(b);
 1994|  2.16k|	return r;
 1995|  2.16k|}
sshkey_get_sigtype:
 1999|     38|{
 2000|     38|	int r;
 2001|     38|	struct sshbuf *b = NULL;
 2002|     38|	char *sigtype = NULL;
 2003|       |
 2004|     38|	if (sigtypep != NULL)
  ------------------
  |  Branch (2004:6): [True: 38, False: 0]
  ------------------
 2005|     38|		*sigtypep = NULL;
 2006|     38|	if ((b = sshbuf_from(sig, siglen)) == NULL)
  ------------------
  |  Branch (2006:6): [True: 0, False: 38]
  ------------------
 2007|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
 2008|     38|	if ((r = sshbuf_get_cstring(b, &sigtype, NULL)) != 0)
  ------------------
  |  Branch (2008:6): [True: 2, False: 36]
  ------------------
 2009|      2|		goto out;
 2010|       |	/* success */
 2011|     36|	if (sigtypep != NULL) {
  ------------------
  |  Branch (2011:6): [True: 36, False: 0]
  ------------------
 2012|     36|		*sigtypep = sigtype;
 2013|     36|		sigtype = NULL;
 2014|     36|	}
 2015|     36|	r = 0;
 2016|     38| out:
 2017|     38|	free(sigtype);
 2018|     38|	sshbuf_free(b);
 2019|     38|	return r;
 2020|     36|}
sshkey_verify:
 2134|    852|{
 2135|    852|	const struct sshkey_impl *impl;
 2136|       |
 2137|    852|	if (detailsp != NULL)
  ------------------
  |  Branch (2137:6): [True: 451, False: 401]
  ------------------
 2138|    451|		*detailsp = NULL;
 2139|    852|	if (siglen == 0 || dlen > SSH_KEY_MAX_SIGN_DATA_SIZE)
  ------------------
  |  |   54|    846|#define SSH_KEY_MAX_SIGN_DATA_SIZE	(1 << 20)
  ------------------
  |  Branch (2139:6): [True: 6, False: 846]
  |  Branch (2139:21): [True: 0, False: 846]
  ------------------
 2140|      6|		return SSH_ERR_INVALID_ARGUMENT;
  ------------------
  |  |   34|      6|#define SSH_ERR_INVALID_ARGUMENT		-10
  ------------------
 2141|    846|	if ((impl = sshkey_impl_from_key(key)) == NULL)
  ------------------
  |  Branch (2141:6): [True: 0, False: 846]
  ------------------
 2142|      0|		return SSH_ERR_KEY_TYPE_UNKNOWN;
  ------------------
  |  |   38|      0|#define SSH_ERR_KEY_TYPE_UNKNOWN		-14 /* XXX UNSUPPORTED? */
  ------------------
 2143|    846|	return impl->funcs->verify(key, sig, siglen, data, dlen,
 2144|    846|	    alg, compat, detailsp);
 2145|    846|}
sshkey_sig_details_free:
 3622|  2.78k|{
 3623|  2.78k|	freezero(details, sizeof(*details));
 3624|  2.78k|}
sshkey.c:sshkey_impl_from_key:
  202|    846|{
  203|    846|	if (k == NULL)
  ------------------
  |  Branch (203:6): [True: 0, False: 846]
  ------------------
  204|      0|		return NULL;
  205|    846|	return sshkey_impl_from_type_nid(k->type, k->ecdsa_nid);
  206|    846|}
sshkey.c:sshkey_impl_from_type_nid:
  189|    978|{
  190|    978|	int i;
  191|       |
  192|  9.78k|	for (i = 0; keyimpls[i] != NULL; i++) {
  ------------------
  |  Branch (192:14): [True: 9.78k, False: 0]
  ------------------
  193|  9.78k|		if (keyimpls[i]->type == type &&
  ------------------
  |  Branch (193:7): [True: 978, False: 8.81k]
  ------------------
  194|  9.78k|		    (keyimpls[i]->nid == 0 || keyimpls[i]->nid == nid))
  ------------------
  |  Branch (194:8): [True: 978, False: 0]
  |  Branch (194:33): [True: 0, False: 0]
  ------------------
  195|    978|			return keyimpls[i];
  196|  9.78k|	}
  197|      0|	return NULL;
  198|    978|}
sshkey.c:sshkey_impl_from_type:
  177|  16.9k|{
  178|  16.9k|	int i;
  179|       |
  180|   189k|	for (i = 0; keyimpls[i] != NULL; i++) {
  ------------------
  |  Branch (180:14): [True: 189k, False: 208]
  ------------------
  181|   189k|		if (keyimpls[i]->type == type)
  ------------------
  |  Branch (181:7): [True: 16.7k, False: 172k]
  ------------------
  182|  16.7k|			return keyimpls[i];
  183|   189k|	}
  184|    208|	return NULL;
  185|  16.9k|}
sshkey.c:sshkey_ssh_name_from_type_nid:
  220|    132|{
  221|    132|	const struct sshkey_impl *impl;
  222|       |
  223|    132|	if ((impl = sshkey_impl_from_type_nid(type, nid)) == NULL)
  ------------------
  |  Branch (223:6): [True: 0, False: 132]
  ------------------
  224|      0|		return "ssh-unknown";
  225|    132|	return impl->name;
  226|    132|}
sshkey.c:key_type_is_ecdsa_variant:
  269|  1.70k|{
  270|  1.70k|	switch (type) {
  ------------------
  |  Branch (270:10): [True: 1.00k, False: 702]
  ------------------
  271|    436|	case KEY_ECDSA:
  ------------------
  |  Branch (271:2): [True: 436, False: 1.27k]
  ------------------
  272|    667|	case KEY_ECDSA_CERT:
  ------------------
  |  Branch (272:2): [True: 231, False: 1.47k]
  ------------------
  273|    691|	case KEY_ECDSA_SK:
  ------------------
  |  Branch (273:2): [True: 24, False: 1.68k]
  ------------------
  274|    702|	case KEY_ECDSA_SK_CERT:
  ------------------
  |  Branch (274:2): [True: 11, False: 1.69k]
  ------------------
  275|    702|		return 1;
  276|  1.70k|	}
  277|  1.00k|	return 0;
  278|  1.70k|}
sshkey.c:cert_new:
  590|    766|{
  591|    766|	struct sshkey_cert *cert;
  592|       |
  593|    766|	if ((cert = calloc(1, sizeof(*cert))) == NULL)
  ------------------
  |  Branch (593:6): [True: 0, False: 766]
  ------------------
  594|      0|		return NULL;
  595|    766|	if ((cert->certblob = sshbuf_new()) == NULL ||
  ------------------
  |  |   36|    766|#define sshbuf_new() sshbuf_new_label(__func__)
  ------------------
  |  Branch (595:6): [True: 0, False: 766]
  ------------------
  596|    766|	    (cert->critical = sshbuf_new()) == NULL ||
  ------------------
  |  |   36|    766|#define sshbuf_new() sshbuf_new_label(__func__)
  ------------------
  |  Branch (596:6): [True: 0, False: 766]
  ------------------
  597|    766|	    (cert->extensions = sshbuf_new()) == NULL) {
  ------------------
  |  |   36|    766|#define sshbuf_new() sshbuf_new_label(__func__)
  ------------------
  |  Branch (597:6): [True: 0, False: 766]
  ------------------
  598|      0|		cert_free(cert);
  599|      0|		return NULL;
  600|      0|	}
  601|    766|	cert->key_id = NULL;
  602|    766|	cert->principals = NULL;
  603|    766|	cert->signature_key = NULL;
  604|    766|	cert->signature_type = NULL;
  605|    766|	return cert;
  606|    766|}
sshkey.c:sshkey_free_contents:
  652|  8.17k|{
  653|  8.17k|	const struct sshkey_impl *impl;
  654|       |
  655|  8.17k|	if (k == NULL)
  ------------------
  |  Branch (655:6): [True: 5.83k, False: 2.34k]
  ------------------
  656|  5.83k|		return;
  657|  2.34k|	if ((impl = sshkey_impl_from_type(k->type)) != NULL &&
  ------------------
  |  Branch (657:6): [True: 2.34k, False: 0]
  ------------------
  658|  2.34k|	    impl->funcs->cleanup != NULL)
  ------------------
  |  Branch (658:6): [True: 2.34k, False: 0]
  ------------------
  659|  2.34k|		impl->funcs->cleanup(k);
  660|  2.34k|	if (sshkey_is_cert(k))
  ------------------
  |  Branch (660:6): [True: 766, False: 1.57k]
  ------------------
  661|    766|		cert_free(k->cert);
  662|  2.34k|	freezero(k->shielded_private, k->shielded_len);
  663|  2.34k|	freezero(k->shield_prekey, k->shield_prekey_len);
  664|  2.34k|}
sshkey.c:cert_free:
  571|    766|{
  572|    766|	u_int i;
  573|       |
  574|    766|	if (cert == NULL)
  ------------------
  |  Branch (574:6): [True: 0, False: 766]
  ------------------
  575|      0|		return;
  576|    766|	sshbuf_free(cert->certblob);
  577|    766|	sshbuf_free(cert->critical);
  578|    766|	sshbuf_free(cert->extensions);
  579|    766|	free(cert->key_id);
  580|  3.39k|	for (i = 0; i < cert->nprincipals; i++)
  ------------------
  |  Branch (580:14): [True: 2.62k, False: 766]
  ------------------
  581|  2.62k|		free(cert->principals[i]);
  582|    766|	free(cert->principals);
  583|    766|	sshkey_free(cert->signature_key);
  584|    766|	free(cert->signature_type);
  585|    766|	freezero(cert, sizeof(*cert));
  586|    766|}
sshkey.c:sshkey_from_blob_internal:
 1901|  2.60k|{
 1902|  2.60k|	int type, ret = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|  2.60k|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
 1903|  2.60k|	char *ktype = NULL;
 1904|  2.60k|	struct sshkey *key = NULL;
 1905|  2.60k|	struct sshbuf *copy;
 1906|  2.60k|	const struct sshkey_impl *impl;
 1907|       |
 1908|       |#ifdef DEBUG_PK /* XXX */
 1909|       |	sshbuf_dump(b, stderr);
 1910|       |#endif
 1911|  2.60k|	if (keyp != NULL)
  ------------------
  |  Branch (1911:6): [True: 2.60k, False: 0]
  ------------------
 1912|  2.60k|		*keyp = NULL;
 1913|  2.60k|	if ((copy = sshbuf_fromb(b)) == NULL) {
  ------------------
  |  Branch (1913:6): [True: 0, False: 2.60k]
  ------------------
 1914|      0|		ret = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
 1915|      0|		goto out;
 1916|      0|	}
 1917|  2.60k|	if (sshbuf_get_cstring(b, &ktype, NULL) != 0) {
  ------------------
  |  Branch (1917:6): [True: 52, False: 2.55k]
  ------------------
 1918|     52|		ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     52|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
 1919|     52|		goto out;
 1920|     52|	}
 1921|       |
 1922|  2.55k|	type = sshkey_type_from_name(ktype);
 1923|  2.55k|	if (!allow_cert && sshkey_type_is_cert(type)) {
  ------------------
  |  Branch (1923:6): [True: 424, False: 2.13k]
  |  Branch (1923:21): [True: 3, False: 421]
  ------------------
 1924|      3|		ret = SSH_ERR_KEY_CERT_INVALID_SIGN_KEY;
  ------------------
  |  |   43|      3|#define SSH_ERR_KEY_CERT_INVALID_SIGN_KEY	-19
  ------------------
 1925|      3|		goto out;
 1926|      3|	}
 1927|  2.55k|	if ((impl = sshkey_impl_from_type(type)) == NULL) {
  ------------------
  |  Branch (1927:6): [True: 206, False: 2.34k]
  ------------------
 1928|    206|		ret = SSH_ERR_KEY_TYPE_UNKNOWN;
  ------------------
  |  |   38|    206|#define SSH_ERR_KEY_TYPE_UNKNOWN		-14 /* XXX UNSUPPORTED? */
  ------------------
 1929|    206|		goto out;
 1930|    206|	}
 1931|  2.34k|	if ((key = sshkey_new(type)) == NULL) {
  ------------------
  |  Branch (1931:6): [True: 0, False: 2.34k]
  ------------------
 1932|      0|		ret = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
 1933|      0|		goto out;
 1934|      0|	}
 1935|  2.34k|	if (sshkey_type_is_cert(type)) {
  ------------------
  |  Branch (1935:6): [True: 766, False: 1.57k]
  ------------------
 1936|       |		/* Skip nonce that precedes all certificates */
 1937|    766|		if (sshbuf_get_string_direct(b, NULL, NULL) != 0) {
  ------------------
  |  Branch (1937:7): [True: 3, False: 763]
  ------------------
 1938|      3|			ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      3|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
 1939|      3|			goto out;
 1940|      3|		}
 1941|    766|	}
 1942|  2.34k|	if ((ret = impl->funcs->deserialize_public(ktype, b, key)) != 0)
  ------------------
  |  Branch (1942:6): [True: 641, False: 1.70k]
  ------------------
 1943|    641|		goto out;
 1944|       |
 1945|       |	/* Parse certificate potion */
 1946|  1.70k|	if (sshkey_is_cert(key) && (ret = cert_parse(b, key, copy)) != 0)
  ------------------
  |  Branch (1946:6): [True: 735, False: 966]
  |  Branch (1946:29): [True: 731, False: 4]
  ------------------
 1947|    731|		goto out;
 1948|       |
 1949|    970|	if (key != NULL && sshbuf_len(b) != 0) {
  ------------------
  |  Branch (1949:6): [True: 970, False: 0]
  |  Branch (1949:21): [True: 21, False: 949]
  ------------------
 1950|     21|		ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     21|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
 1951|     21|		goto out;
 1952|     21|	}
 1953|    949|	ret = 0;
 1954|    949|	if (keyp != NULL) {
  ------------------
  |  Branch (1954:6): [True: 949, False: 0]
  ------------------
 1955|    949|		*keyp = key;
 1956|    949|		key = NULL;
 1957|    949|	}
 1958|  2.60k| out:
 1959|  2.60k|	sshbuf_free(copy);
 1960|  2.60k|	sshkey_free(key);
 1961|  2.60k|	free(ktype);
 1962|  2.60k|	return ret;
 1963|    949|}
sshkey.c:cert_parse:
 1765|    735|{
 1766|    735|	struct sshbuf *principals = NULL, *crit = NULL;
 1767|    735|	struct sshbuf *exts = NULL, *ca = NULL;
 1768|    735|	u_char *sig = NULL;
 1769|    735|	size_t signed_len = 0, slen = 0, kidlen = 0;
 1770|    735|	int ret = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|    735|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
 1771|       |
 1772|       |	/* Copy the entire key blob for verification and later serialisation */
 1773|    735|	if ((ret = sshbuf_putb(key->cert->certblob, certbuf)) != 0)
  ------------------
  |  Branch (1773:6): [True: 0, False: 735]
  ------------------
 1774|      0|		return ret;
 1775|       |
 1776|       |	/* Parse body of certificate up to signature */
 1777|    735|	if ((ret = sshbuf_get_u64(b, &key->cert->serial)) != 0 ||
  ------------------
  |  Branch (1777:6): [True: 8, False: 727]
  ------------------
 1778|    735|	    (ret = sshbuf_get_u32(b, &key->cert->type)) != 0 ||
  ------------------
  |  Branch (1778:6): [True: 2, False: 725]
  ------------------
 1779|    735|	    (ret = sshbuf_get_cstring(b, &key->cert->key_id, &kidlen)) != 0 ||
  ------------------
  |  Branch (1779:6): [True: 11, False: 714]
  ------------------
 1780|    735|	    (ret = sshbuf_froms(b, &principals)) != 0 ||
  ------------------
  |  Branch (1780:6): [True: 55, False: 659]
  ------------------
 1781|    735|	    (ret = sshbuf_get_u64(b, &key->cert->valid_after)) != 0 ||
  ------------------
  |  Branch (1781:6): [True: 12, False: 647]
  ------------------
 1782|    735|	    (ret = sshbuf_get_u64(b, &key->cert->valid_before)) != 0 ||
  ------------------
  |  Branch (1782:6): [True: 4, False: 643]
  ------------------
 1783|    735|	    (ret = sshbuf_froms(b, &crit)) != 0 ||
  ------------------
  |  Branch (1783:6): [True: 4, False: 639]
  ------------------
 1784|    735|	    (ret = sshbuf_froms(b, &exts)) != 0 ||
  ------------------
  |  Branch (1784:6): [True: 6, False: 633]
  ------------------
 1785|    735|	    (ret = sshbuf_get_string_direct(b, NULL, NULL)) != 0 ||
  ------------------
  |  Branch (1785:6): [True: 4, False: 629]
  ------------------
 1786|    735|	    (ret = sshbuf_froms(b, &ca)) != 0) {
  ------------------
  |  Branch (1786:6): [True: 2, False: 627]
  ------------------
 1787|       |		/* XXX debug print error for ret */
 1788|    108|		ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|    108|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
 1789|    108|		goto out;
 1790|    108|	}
 1791|       |
 1792|       |	/* Signature is left in the buffer so we can calculate this length */
 1793|    627|	signed_len = sshbuf_len(key->cert->certblob) - sshbuf_len(b);
 1794|       |
 1795|    627|	if ((ret = sshbuf_get_string(b, &sig, &slen)) != 0) {
  ------------------
  |  Branch (1795:6): [True: 5, False: 622]
  ------------------
 1796|      5|		ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      5|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
 1797|      5|		goto out;
 1798|      5|	}
 1799|       |
 1800|    622|	if (key->cert->type != SSH2_CERT_TYPE_USER &&
  ------------------
  |  |  179|  1.24k|#define SSH2_CERT_TYPE_USER				1
  ------------------
  |  Branch (1800:6): [True: 363, False: 259]
  ------------------
 1801|    622|	    key->cert->type != SSH2_CERT_TYPE_HOST) {
  ------------------
  |  |  180|    363|#define SSH2_CERT_TYPE_HOST				2
  ------------------
  |  Branch (1801:6): [True: 62, False: 301]
  ------------------
 1802|     62|		ret = SSH_ERR_KEY_CERT_UNKNOWN_TYPE;
  ------------------
  |  |   42|     62|#define SSH_ERR_KEY_CERT_UNKNOWN_TYPE		-18
  ------------------
 1803|     62|		goto out;
 1804|     62|	}
 1805|       |
 1806|       |	/* Parse principals section */
 1807|  3.18k|	while (sshbuf_len(principals) > 0) {
  ------------------
  |  Branch (1807:9): [True: 2.66k, False: 522]
  ------------------
 1808|  2.66k|		char *principal = NULL;
 1809|  2.66k|		char **oprincipals = NULL;
 1810|       |
 1811|  2.66k|		if (key->cert->nprincipals >= SSHKEY_CERT_MAX_PRINCIPALS) {
  ------------------
  |  |  108|  2.66k|#define SSHKEY_CERT_MAX_PRINCIPALS	256
  ------------------
  |  Branch (1811:7): [True: 1, False: 2.66k]
  ------------------
 1812|      1|			ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|      1|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
 1813|      1|			goto out;
 1814|      1|		}
 1815|  2.66k|		if ((ret = sshbuf_get_cstring(principals, &principal,
  ------------------
  |  Branch (1815:7): [True: 37, False: 2.62k]
  ------------------
 1816|  2.66k|		    NULL)) != 0) {
 1817|     37|			ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     37|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
 1818|     37|			goto out;
 1819|     37|		}
 1820|  2.62k|		oprincipals = key->cert->principals;
 1821|  2.62k|		key->cert->principals = recallocarray(key->cert->principals,
 1822|  2.62k|		    key->cert->nprincipals, key->cert->nprincipals + 1,
 1823|  2.62k|		    sizeof(*key->cert->principals));
 1824|  2.62k|		if (key->cert->principals == NULL) {
  ------------------
  |  Branch (1824:7): [True: 0, False: 2.62k]
  ------------------
 1825|      0|			free(principal);
 1826|      0|			key->cert->principals = oprincipals;
 1827|      0|			ret = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
 1828|      0|			goto out;
 1829|      0|		}
 1830|  2.62k|		key->cert->principals[key->cert->nprincipals++] = principal;
 1831|  2.62k|	}
 1832|       |
 1833|       |	/*
 1834|       |	 * Stash a copies of the critical options and extensions sections
 1835|       |	 * for later use.
 1836|       |	 */
 1837|    522|	if ((ret = sshbuf_putb(key->cert->critical, crit)) != 0 ||
  ------------------
  |  Branch (1837:6): [True: 0, False: 522]
  ------------------
 1838|    522|	    (exts != NULL &&
  ------------------
  |  Branch (1838:7): [True: 522, False: 0]
  ------------------
 1839|    522|	    (ret = sshbuf_putb(key->cert->extensions, exts)) != 0))
  ------------------
  |  Branch (1839:6): [True: 0, False: 522]
  ------------------
 1840|      0|		goto out;
 1841|       |
 1842|       |	/*
 1843|       |	 * Validate critical options and extensions sections format.
 1844|       |	 */
 1845|  2.25k|	while (sshbuf_len(crit) != 0) {
  ------------------
  |  Branch (1845:9): [True: 1.78k, False: 471]
  ------------------
 1846|  1.78k|		if ((ret = sshbuf_get_string_direct(crit, NULL, NULL)) != 0 ||
  ------------------
  |  Branch (1846:7): [True: 31, False: 1.75k]
  ------------------
 1847|  1.78k|		    (ret = sshbuf_get_string_direct(crit, NULL, NULL)) != 0) {
  ------------------
  |  Branch (1847:7): [True: 20, False: 1.73k]
  ------------------
 1848|     51|			sshbuf_reset(key->cert->critical);
 1849|     51|			ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     51|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
 1850|     51|			goto out;
 1851|     51|		}
 1852|  1.78k|	}
 1853|  1.26k|	while (exts != NULL && sshbuf_len(exts) != 0) {
  ------------------
  |  Branch (1853:9): [True: 1.26k, False: 0]
  |  Branch (1853:25): [True: 818, False: 443]
  ------------------
 1854|    818|		if ((ret = sshbuf_get_string_direct(exts, NULL, NULL)) != 0 ||
  ------------------
  |  Branch (1854:7): [True: 20, False: 798]
  ------------------
 1855|    818|		    (ret = sshbuf_get_string_direct(exts, NULL, NULL)) != 0) {
  ------------------
  |  Branch (1855:7): [True: 8, False: 790]
  ------------------
 1856|     28|			sshbuf_reset(key->cert->extensions);
 1857|     28|			ret = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     28|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
 1858|     28|			goto out;
 1859|     28|		}
 1860|    818|	}
 1861|       |
 1862|       |	/* Parse CA key and check signature */
 1863|    443|	if (sshkey_from_blob_internal(ca, &key->cert->signature_key, 0) != 0) {
  ------------------
  |  Branch (1863:6): [True: 42, False: 401]
  ------------------
 1864|     42|		ret = SSH_ERR_KEY_CERT_INVALID_SIGN_KEY;
  ------------------
  |  |   43|     42|#define SSH_ERR_KEY_CERT_INVALID_SIGN_KEY	-19
  ------------------
 1865|     42|		goto out;
 1866|     42|	}
 1867|    401|	if (!sshkey_type_is_valid_ca(key->cert->signature_key->type)) {
  ------------------
  |  Branch (1867:6): [True: 0, False: 401]
  ------------------
 1868|      0|		ret = SSH_ERR_KEY_CERT_INVALID_SIGN_KEY;
  ------------------
  |  |   43|      0|#define SSH_ERR_KEY_CERT_INVALID_SIGN_KEY	-19
  ------------------
 1869|      0|		goto out;
 1870|      0|	}
 1871|    401|	if ((ret = sshkey_verify(key->cert->signature_key, sig, slen,
  ------------------
  |  Branch (1871:6): [True: 397, False: 4]
  ------------------
 1872|    401|	    sshbuf_ptr(key->cert->certblob), signed_len, NULL, 0, NULL)) != 0)
 1873|    397|		goto out;
 1874|      4|	if ((ret = sshkey_get_sigtype(sig, slen,
  ------------------
  |  Branch (1874:6): [True: 0, False: 4]
  ------------------
 1875|      4|	    &key->cert->signature_type)) != 0)
 1876|      0|		goto out;
 1877|       |
 1878|       |	/* Success */
 1879|      4|	ret = 0;
 1880|    735| out:
 1881|    735|	sshbuf_free(ca);
 1882|    735|	sshbuf_free(crit);
 1883|    735|	sshbuf_free(exts);
 1884|    735|	sshbuf_free(principals);
 1885|    735|	free(sig);
 1886|    735|	return ret;
 1887|      4|}
sshkey.c:sshkey_type_is_valid_ca:
  404|    401|{
  405|    401|	const struct sshkey_impl *impl;
  406|       |
  407|    401|	if ((impl = sshkey_impl_from_type(type)) == NULL)
  ------------------
  |  Branch (407:6): [True: 0, False: 401]
  ------------------
  408|      0|		return 0;
  409|       |	/* All non-certificate types may act as CAs */
  410|    401|	return !impl->cert;
  411|    401|}

sshsig_verifyb:
  473|  2.64k|{
  474|  2.64k|	struct sshbuf *b = NULL;
  475|  2.64k|	int r = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|  2.64k|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  476|  2.64k|	char *hashalg = NULL;
  477|       |
  478|  2.64k|	if (sig_details != NULL)
  ------------------
  |  Branch (478:6): [True: 2.64k, False: 0]
  ------------------
  479|  2.64k|		*sig_details = NULL;
  480|  2.64k|	if (sign_keyp != NULL)
  ------------------
  |  Branch (480:6): [True: 2.64k, False: 0]
  ------------------
  481|  2.64k|		*sign_keyp = NULL;
  482|  2.64k|	if ((r = sshsig_peek_hashalg(signature, &hashalg)) != 0)
  ------------------
  |  Branch (482:6): [True: 417, False: 2.22k]
  ------------------
  483|    417|		return r;
  484|  2.22k|	debug_f("signature made with hash \"%s\"", hashalg);
  ------------------
  |  |  102|  2.22k|#define debug_f(...)		sshlog(__FILE__, __func__, __LINE__, 1, SYSLOG_LEVEL_DEBUG1, NULL, __VA_ARGS__)
  ------------------
  485|  2.22k|	if ((r = hash_buffer(message, hashalg, &b)) != 0) {
  ------------------
  |  Branch (485:6): [True: 61, False: 2.16k]
  ------------------
  486|     61|		error_fr(r, "hash buffer");
  ------------------
  |  |  127|     61|#define error_fr(r, ...)	sshlog(__FILE__, __func__, __LINE__, 1, SYSLOG_LEVEL_ERROR, ssh_err(r), __VA_ARGS__)
  ------------------
  487|     61|		goto out;
  488|     61|	}
  489|  2.16k|	if ((r = sshsig_wrap_verify(signature, hashalg, b, expect_namespace,
  ------------------
  |  Branch (489:6): [True: 2.16k, False: 1]
  ------------------
  490|  2.16k|	    sign_keyp, sig_details)) != 0)
  491|  2.16k|		goto out;
  492|       |	/* success */
  493|      1|	r = 0;
  494|  2.22k| out:
  495|  2.22k|	sshbuf_free(b);
  496|  2.22k|	free(hashalg);
  497|  2.22k|	return r;
  498|      1|}
sshsig.c:hash_buffer:
  402|  2.22k|{
  403|  2.22k|	char *hex, hash[SSH_DIGEST_MAX_LENGTH];
  404|  2.22k|	int alg, r = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|  2.22k|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  405|  2.22k|	struct sshbuf *b = NULL;
  406|       |
  407|  2.22k|	*bp = NULL;
  408|  2.22k|	memset(hash, 0, sizeof(hash));
  409|       |
  410|  2.22k|	if ((r = sshsig_check_hashalg(hashalg)) != 0)
  ------------------
  |  Branch (410:6): [True: 61, False: 2.16k]
  ------------------
  411|     61|		return r;
  412|  2.16k|	if ((alg = ssh_digest_alg_by_name(hashalg)) == -1) {
  ------------------
  |  Branch (412:6): [True: 0, False: 2.16k]
  ------------------
  413|      0|		error_f("can't look up hash algorithm %s", hashalg);
  ------------------
  |  |  105|      0|#define error_f(...)		sshlog(__FILE__, __func__, __LINE__, 1, SYSLOG_LEVEL_ERROR, NULL, __VA_ARGS__)
  ------------------
  414|      0|		return SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|      0|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  415|      0|	}
  416|  2.16k|	if ((r = ssh_digest_buffer(alg, m, hash, sizeof(hash))) != 0) {
  ------------------
  |  Branch (416:6): [True: 0, False: 2.16k]
  ------------------
  417|      0|		error_fr(r, "ssh_digest_buffer");
  ------------------
  |  |  127|      0|#define error_fr(r, ...)	sshlog(__FILE__, __func__, __LINE__, 1, SYSLOG_LEVEL_ERROR, ssh_err(r), __VA_ARGS__)
  ------------------
  418|      0|		return r;
  419|      0|	}
  420|  2.16k|	if ((hex = tohex(hash, ssh_digest_bytes(alg))) != NULL) {
  ------------------
  |  Branch (420:6): [True: 2.16k, False: 0]
  ------------------
  421|  2.16k|		debug3_f("final hash: %s", hex);
  ------------------
  |  |  100|  2.16k|#define debug3_f(...)		sshlog(__FILE__, __func__, __LINE__, 1, SYSLOG_LEVEL_DEBUG3, NULL, __VA_ARGS__)
  ------------------
  422|  2.16k|		freezero(hex, strlen(hex));
  423|  2.16k|	}
  424|  2.16k|	if ((b = sshbuf_new()) == NULL) {
  ------------------
  |  |   36|  2.16k|#define sshbuf_new() sshbuf_new_label(__func__)
  ------------------
  |  Branch (424:6): [True: 0, False: 2.16k]
  ------------------
  425|      0|		r = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  426|      0|		goto out;
  427|      0|	}
  428|  2.16k|	if ((r = sshbuf_put(b, hash, ssh_digest_bytes(alg))) != 0) {
  ------------------
  |  Branch (428:6): [True: 0, False: 2.16k]
  ------------------
  429|      0|		error_fr(r, "sshbuf_put");
  ------------------
  |  |  127|      0|#define error_fr(r, ...)	sshlog(__FILE__, __func__, __LINE__, 1, SYSLOG_LEVEL_ERROR, ssh_err(r), __VA_ARGS__)
  ------------------
  430|      0|		goto out;
  431|      0|	}
  432|  2.16k|	*bp = b;
  433|  2.16k|	b = NULL; /* transferred */
  434|       |	/* success */
  435|  2.16k|	r = 0;
  436|  2.16k| out:
  437|  2.16k|	sshbuf_free(b);
  438|  2.16k|	explicit_bzero(hash, sizeof(hash));
  439|  2.16k|	return r;
  440|  2.16k|}
sshsig.c:sshsig_check_hashalg:
  259|  2.22k|{
  260|  2.22k|	if (hashalg == NULL ||
  ------------------
  |  Branch (260:6): [True: 0, False: 2.22k]
  ------------------
  261|  2.22k|	    match_pattern_list(hashalg, HASHALG_ALLOWED, 0) == 1)
  ------------------
  |  |   46|  2.22k|#define HASHALG_ALLOWED		"sha256,sha512"
  ------------------
  |  Branch (261:6): [True: 2.16k, False: 61]
  ------------------
  262|  2.16k|		return 0;
  263|     61|	error_f("unsupported hash algorithm \"%.100s\"", hashalg);
  ------------------
  |  |  105|     61|#define error_f(...)		sshlog(__FILE__, __func__, __LINE__, 1, SYSLOG_LEVEL_ERROR, NULL, __VA_ARGS__)
  ------------------
  264|     61|	return SSH_ERR_SIGN_ALG_UNSUPPORTED;
  ------------------
  |  |   82|     61|#define SSH_ERR_SIGN_ALG_UNSUPPORTED		-58
  ------------------
  265|  2.22k|}
sshsig.c:sshsig_peek_hashalg:
  269|  2.64k|{
  270|  2.64k|	struct sshbuf *buf = NULL;
  271|  2.64k|	char *hashalg = NULL;
  272|  2.64k|	int r = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|  2.64k|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  273|       |
  274|  2.64k|	if (hashalgp != NULL)
  ------------------
  |  Branch (274:6): [True: 2.64k, False: 0]
  ------------------
  275|  2.64k|		*hashalgp = NULL;
  276|  2.64k|	if ((buf = sshbuf_fromb(signature)) == NULL)
  ------------------
  |  Branch (276:6): [True: 0, False: 2.64k]
  ------------------
  277|      0|		return SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  278|  2.64k|	if ((r = sshsig_parse_preamble(buf)) != 0)
  ------------------
  |  Branch (278:6): [True: 70, False: 2.57k]
  ------------------
  279|     70|		goto done;
  280|  2.57k|	if ((r = sshbuf_get_string_direct(buf, NULL, NULL)) != 0 ||
  ------------------
  |  Branch (280:6): [True: 64, False: 2.50k]
  ------------------
  281|  2.57k|	    (r = sshbuf_get_string_direct(buf, NULL, NULL)) != 0 ||
  ------------------
  |  Branch (281:6): [True: 52, False: 2.45k]
  ------------------
  282|  2.57k|	    (r = sshbuf_get_string(buf, NULL, NULL)) != 0 ||
  ------------------
  |  Branch (282:6): [True: 78, False: 2.37k]
  ------------------
  283|  2.57k|	    (r = sshbuf_get_cstring(buf, &hashalg, NULL)) != 0 ||
  ------------------
  |  Branch (283:6): [True: 81, False: 2.29k]
  ------------------
  284|  2.57k|	    (r = sshbuf_get_string_direct(buf, NULL, NULL)) != 0) {
  ------------------
  |  Branch (284:6): [True: 72, False: 2.22k]
  ------------------
  285|    347|		error_fr(r, "parse signature object");
  ------------------
  |  |  127|    347|#define error_fr(r, ...)	sshlog(__FILE__, __func__, __LINE__, 1, SYSLOG_LEVEL_ERROR, ssh_err(r), __VA_ARGS__)
  ------------------
  286|    347|		goto done;
  287|    347|	}
  288|       |
  289|       |	/* success */
  290|  2.22k|	r = 0;
  291|  2.22k|	*hashalgp = hashalg;
  292|  2.22k|	hashalg = NULL;
  293|  2.64k| done:
  294|  2.64k|	free(hashalg);
  295|  2.64k|	sshbuf_free(buf);
  296|  2.64k|	return r;
  297|  2.22k|}
sshsig.c:sshsig_wrap_verify:
  303|  2.16k|{
  304|  2.16k|	int r = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|  2.16k|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  305|  2.16k|	struct sshbuf *buf = NULL, *toverify = NULL;
  306|  2.16k|	struct sshkey *key = NULL;
  307|  2.16k|	const u_char *sig;
  308|  2.16k|	char *got_namespace = NULL, *sigtype = NULL, *sig_hashalg = NULL;
  309|  2.16k|	size_t siglen;
  310|       |
  311|  2.16k|	debug_f("verify message length %zu", sshbuf_len(h_message));
  ------------------
  |  |  102|  2.16k|#define debug_f(...)		sshlog(__FILE__, __func__, __LINE__, 1, SYSLOG_LEVEL_DEBUG1, NULL, __VA_ARGS__)
  ------------------
  312|  2.16k|	if (sig_details != NULL)
  ------------------
  |  Branch (312:6): [True: 2.16k, False: 0]
  ------------------
  313|  2.16k|		*sig_details = NULL;
  314|  2.16k|	if (sign_keyp != NULL)
  ------------------
  |  Branch (314:6): [True: 2.16k, False: 0]
  ------------------
  315|  2.16k|		*sign_keyp = NULL;
  316|       |
  317|  2.16k|	if ((toverify = sshbuf_new()) == NULL) {
  ------------------
  |  |   36|  2.16k|#define sshbuf_new() sshbuf_new_label(__func__)
  ------------------
  |  Branch (317:6): [True: 0, False: 2.16k]
  ------------------
  318|      0|		error_f("sshbuf_new failed");
  ------------------
  |  |  105|      0|#define error_f(...)		sshlog(__FILE__, __func__, __LINE__, 1, SYSLOG_LEVEL_ERROR, NULL, __VA_ARGS__)
  ------------------
  319|      0|		r = SSH_ERR_ALLOC_FAIL;
  ------------------
  |  |   26|      0|#define SSH_ERR_ALLOC_FAIL			-2
  ------------------
  320|      0|		goto done;
  321|      0|	}
  322|  2.16k|	if ((r = sshbuf_put(toverify, MAGIC_PREAMBLE,
  ------------------
  |  |   39|  2.16k|#define MAGIC_PREAMBLE		"SSHSIG"
  ------------------
  |  Branch (322:6): [True: 0, False: 2.16k]
  ------------------
  323|  2.16k|	    MAGIC_PREAMBLE_LEN)) != 0 ||
  ------------------
  |  |   40|  2.16k|#define MAGIC_PREAMBLE_LEN	(sizeof(MAGIC_PREAMBLE) - 1)
  |  |  ------------------
  |  |  |  |   39|  2.16k|#define MAGIC_PREAMBLE		"SSHSIG"
  |  |  ------------------
  ------------------
  324|  2.16k|	    (r = sshbuf_put_cstring(toverify, expect_namespace)) != 0 ||
  ------------------
  |  Branch (324:6): [True: 0, False: 2.16k]
  ------------------
  325|  2.16k|	    (r = sshbuf_put_string(toverify, NULL, 0)) != 0 || /* reserved */
  ------------------
  |  Branch (325:6): [True: 0, False: 2.16k]
  ------------------
  326|  2.16k|	    (r = sshbuf_put_cstring(toverify, hashalg)) != 0 ||
  ------------------
  |  Branch (326:6): [True: 0, False: 2.16k]
  ------------------
  327|  2.16k|	    (r = sshbuf_put_stringb(toverify, h_message)) != 0) {
  ------------------
  |  Branch (327:6): [True: 0, False: 2.16k]
  ------------------
  328|      0|		error_fr(r, "assemble message to verify");
  ------------------
  |  |  127|      0|#define error_fr(r, ...)	sshlog(__FILE__, __func__, __LINE__, 1, SYSLOG_LEVEL_ERROR, ssh_err(r), __VA_ARGS__)
  ------------------
  329|      0|		goto done;
  330|      0|	}
  331|       |
  332|  2.16k|	if ((r = sshsig_parse_preamble(signature)) != 0)
  ------------------
  |  Branch (332:6): [True: 0, False: 2.16k]
  ------------------
  333|      0|		goto done;
  334|       |
  335|  2.16k|	if ((r = sshkey_froms(signature, &key)) != 0 ||
  ------------------
  |  Branch (335:6): [True: 1.61k, False: 548]
  ------------------
  336|  2.16k|	    (r = sshbuf_get_cstring(signature, &got_namespace, NULL)) != 0 ||
  ------------------
  |  Branch (336:6): [True: 1, False: 547]
  ------------------
  337|  2.16k|	    (r = sshbuf_get_string(signature, NULL, NULL)) != 0 ||
  ------------------
  |  Branch (337:6): [True: 0, False: 547]
  ------------------
  338|  2.16k|	    (r = sshbuf_get_cstring(signature, &sig_hashalg, NULL)) != 0 ||
  ------------------
  |  Branch (338:6): [True: 0, False: 547]
  ------------------
  339|  2.16k|	    (r = sshbuf_get_string_direct(signature, &sig, &siglen)) != 0) {
  ------------------
  |  Branch (339:6): [True: 0, False: 547]
  ------------------
  340|  1.61k|		error_fr(r, "parse signature object");
  ------------------
  |  |  127|  1.61k|#define error_fr(r, ...)	sshlog(__FILE__, __func__, __LINE__, 1, SYSLOG_LEVEL_ERROR, ssh_err(r), __VA_ARGS__)
  ------------------
  341|  1.61k|		goto done;
  342|  1.61k|	}
  343|       |
  344|    547|	if (sshbuf_len(signature) != 0) {
  ------------------
  |  Branch (344:6): [True: 35, False: 512]
  ------------------
  345|     35|		error("Signature contains trailing data");
  ------------------
  |  |   93|     35|#define error(...)		sshlog(__FILE__, __func__, __LINE__, 0, SYSLOG_LEVEL_ERROR, NULL, __VA_ARGS__)
  ------------------
  346|     35|		r = SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     35|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  347|     35|		goto done;
  348|     35|	}
  349|       |
  350|    512|	if (strcmp(expect_namespace, got_namespace) != 0) {
  ------------------
  |  Branch (350:6): [True: 58, False: 454]
  ------------------
  351|     58|		error("Couldn't verify signature: namespace does not match");
  ------------------
  |  |   93|     58|#define error(...)		sshlog(__FILE__, __func__, __LINE__, 0, SYSLOG_LEVEL_ERROR, NULL, __VA_ARGS__)
  ------------------
  352|     58|		debug_f("expected namespace \"%s\" received \"%s\"",
  ------------------
  |  |  102|     58|#define debug_f(...)		sshlog(__FILE__, __func__, __LINE__, 1, SYSLOG_LEVEL_DEBUG1, NULL, __VA_ARGS__)
  ------------------
  353|     58|		    expect_namespace, got_namespace);
  354|     58|		r = SSH_ERR_SIGNATURE_INVALID;
  ------------------
  |  |   45|     58|#define SSH_ERR_SIGNATURE_INVALID		-21
  ------------------
  355|     58|		goto done;
  356|     58|	}
  357|    454|	if (strcmp(hashalg, sig_hashalg) != 0) {
  ------------------
  |  Branch (357:6): [True: 0, False: 454]
  ------------------
  358|      0|		error("Couldn't verify signature: hash algorithm mismatch");
  ------------------
  |  |   93|      0|#define error(...)		sshlog(__FILE__, __func__, __LINE__, 0, SYSLOG_LEVEL_ERROR, NULL, __VA_ARGS__)
  ------------------
  359|      0|		debug_f("expected algorithm \"%s\" received \"%s\"",
  ------------------
  |  |  102|      0|#define debug_f(...)		sshlog(__FILE__, __func__, __LINE__, 1, SYSLOG_LEVEL_DEBUG1, NULL, __VA_ARGS__)
  ------------------
  360|      0|		    hashalg, sig_hashalg);
  361|      0|		r = SSH_ERR_SIGNATURE_INVALID;
  ------------------
  |  |   45|      0|#define SSH_ERR_SIGNATURE_INVALID		-21
  ------------------
  362|      0|		goto done;
  363|      0|	}
  364|       |	/* Ensure that RSA keys use an acceptable signature algorithm */
  365|    454|	if (sshkey_type_plain(key->type) == KEY_RSA) {
  ------------------
  |  Branch (365:6): [True: 34, False: 420]
  ------------------
  366|     34|		if ((r = sshkey_get_sigtype(sig, siglen, &sigtype)) != 0) {
  ------------------
  |  Branch (366:7): [True: 2, False: 32]
  ------------------
  367|      2|			error_r(r, "Couldn't verify signature: unable to get "
  ------------------
  |  |  117|      2|#define error_r(r, ...)		sshlog(__FILE__, __func__, __LINE__, 0, SYSLOG_LEVEL_ERROR, ssh_err(r), __VA_ARGS__)
  ------------------
  368|      2|			    "signature type");
  369|      2|			goto done;
  370|      2|		}
  371|     32|		if (match_pattern_list(sigtype, RSA_SIGN_ALLOWED, 0) != 1) {
  ------------------
  |  |   44|     32|#define RSA_SIGN_ALLOWED	"rsa-sha2-512,rsa-sha2-256"
  ------------------
  |  Branch (371:7): [True: 1, False: 31]
  ------------------
  372|      1|			error("Couldn't verify signature: unsupported RSA "
  ------------------
  |  |   93|      1|#define error(...)		sshlog(__FILE__, __func__, __LINE__, 0, SYSLOG_LEVEL_ERROR, NULL, __VA_ARGS__)
  ------------------
  373|      1|			    "signature algorithm %s", sigtype);
  374|      1|			r = SSH_ERR_SIGN_ALG_UNSUPPORTED;
  ------------------
  |  |   82|      1|#define SSH_ERR_SIGN_ALG_UNSUPPORTED		-58
  ------------------
  375|      1|			goto done;
  376|      1|		}
  377|     32|	}
  378|    451|	if ((r = sshkey_verify(key, sig, siglen, sshbuf_ptr(toverify),
  ------------------
  |  Branch (378:6): [True: 450, False: 1]
  ------------------
  379|    451|	    sshbuf_len(toverify), NULL, 0, sig_details)) != 0) {
  380|    450|		error_r(r, "Signature verification failed");
  ------------------
  |  |  117|    450|#define error_r(r, ...)		sshlog(__FILE__, __func__, __LINE__, 0, SYSLOG_LEVEL_ERROR, ssh_err(r), __VA_ARGS__)
  ------------------
  381|    450|		goto done;
  382|    450|	}
  383|       |
  384|       |	/* success */
  385|      1|	r = 0;
  386|      1|	if (sign_keyp != NULL) {
  ------------------
  |  Branch (386:6): [True: 1, False: 0]
  ------------------
  387|      1|		*sign_keyp = key;
  388|      1|		key = NULL; /* transferred */
  389|      1|	}
  390|  2.16k|done:
  391|  2.16k|	free(got_namespace);
  392|  2.16k|	free(sigtype);
  393|  2.16k|	free(sig_hashalg);
  394|  2.16k|	sshbuf_free(buf);
  395|  2.16k|	sshbuf_free(toverify);
  396|  2.16k|	sshkey_free(key);
  397|  2.16k|	return r;
  398|      1|}
sshsig.c:sshsig_parse_preamble:
  238|  4.80k|{
  239|  4.80k|	int r = SSH_ERR_INTERNAL_ERROR;
  ------------------
  |  |   25|  4.80k|#define SSH_ERR_INTERNAL_ERROR			-1
  ------------------
  240|  4.80k|	uint32_t sversion;
  241|       |
  242|  4.80k|	if ((r = sshbuf_cmp(buf, 0, MAGIC_PREAMBLE, MAGIC_PREAMBLE_LEN)) != 0 ||
  ------------------
  |  |   39|  4.80k|#define MAGIC_PREAMBLE		"SSHSIG"
  ------------------
              	if ((r = sshbuf_cmp(buf, 0, MAGIC_PREAMBLE, MAGIC_PREAMBLE_LEN)) != 0 ||
  ------------------
  |  |   40|  4.80k|#define MAGIC_PREAMBLE_LEN	(sizeof(MAGIC_PREAMBLE) - 1)
  |  |  ------------------
  |  |  |  |   39|  4.80k|#define MAGIC_PREAMBLE		"SSHSIG"
  |  |  ------------------
  ------------------
  |  Branch (242:6): [True: 16, False: 4.78k]
  ------------------
  243|  4.80k|	    (r = sshbuf_consume(buf, (sizeof(MAGIC_PREAMBLE)-1))) != 0 ||
  ------------------
  |  |   39|  4.78k|#define MAGIC_PREAMBLE		"SSHSIG"
  ------------------
  |  Branch (243:6): [True: 0, False: 4.78k]
  ------------------
  244|  4.80k|	    (r = sshbuf_get_u32(buf, &sversion)) != 0) {
  ------------------
  |  Branch (244:6): [True: 4, False: 4.78k]
  ------------------
  245|     20|		error("Couldn't verify signature: invalid format");
  ------------------
  |  |   93|     20|#define error(...)		sshlog(__FILE__, __func__, __LINE__, 0, SYSLOG_LEVEL_ERROR, NULL, __VA_ARGS__)
  ------------------
  246|     20|		return r;
  247|     20|	}
  248|       |
  249|  4.78k|	if (sversion > SIG_VERSION) {
  ------------------
  |  |   38|  4.78k|#define SIG_VERSION		0x01
  ------------------
  |  Branch (249:6): [True: 50, False: 4.73k]
  ------------------
  250|     50|		error("Signature version %lu is larger than supported "
  ------------------
  |  |   93|     50|#define error(...)		sshlog(__FILE__, __func__, __LINE__, 0, SYSLOG_LEVEL_ERROR, NULL, __VA_ARGS__)
  ------------------
  251|     50|		    "version %u", (unsigned long)sversion, SIG_VERSION);
  252|     50|		return SSH_ERR_INVALID_FORMAT;
  ------------------
  |  |   28|     50|#define SSH_ERR_INVALID_FORMAT			-4
  ------------------
  253|     50|	}
  254|  4.73k|	return 0;
  255|  4.78k|}

xcalloc:
   48|  2.16k|{
   49|  2.16k|	void *ptr;
   50|       |
   51|  2.16k|	if (size == 0 || nmemb == 0)
  ------------------
  |  Branch (51:6): [True: 0, False: 2.16k]
  |  Branch (51:19): [True: 0, False: 2.16k]
  ------------------
   52|      0|		fatal("xcalloc: zero size");
  ------------------
  |  |   94|      0|#define fatal(...)		sshfatal(__FILE__, __func__, __LINE__, 0, SYSLOG_LEVEL_FATAL, NULL, __VA_ARGS__)
  ------------------
   53|  2.16k|	if (SIZE_MAX / nmemb < size)
  ------------------
  |  Branch (53:6): [True: 0, False: 2.16k]
  ------------------
   54|      0|		fatal("xcalloc: nmemb * size > SIZE_MAX");
  ------------------
  |  |   94|      0|#define fatal(...)		sshfatal(__FILE__, __func__, __LINE__, 0, SYSLOG_LEVEL_FATAL, NULL, __VA_ARGS__)
  ------------------
   55|  2.16k|	ptr = calloc(nmemb, size);
   56|  2.16k|	if (ptr == NULL)
  ------------------
  |  Branch (56:6): [True: 0, False: 2.16k]
  ------------------
   57|      0|		fatal("xcalloc: out of memory (allocating %zu bytes)",
  ------------------
  |  |   94|      0|#define fatal(...)		sshfatal(__FILE__, __func__, __LINE__, 0, SYSLOG_LEVEL_FATAL, NULL, __VA_ARGS__)
  ------------------
   58|  2.16k|		    size * nmemb);
   59|  2.16k|	return ptr;
   60|  2.16k|}

xmss_set_params:
   54|    240|{
   55|    240|  if (k >= h || k < 2 || (h - k) % 2) {
  ------------------
  |  Branch (55:7): [True: 0, False: 240]
  |  Branch (55:17): [True: 0, False: 240]
  |  Branch (55:26): [True: 0, False: 240]
  ------------------
   56|      0|    fprintf(stderr, "For BDS traversal, H - K must be even, with H > K >= 2!\n");
   57|      0|    return 1;
   58|      0|  }
   59|    240|  params->h = h;
   60|    240|  params->n = n;
   61|    240|  params->k = k;
   62|    240|  wots_params wots_par;
   63|    240|  wots_set_params(&wots_par, n, w);
   64|    240|  params->wots_par = wots_par;
   65|    240|  return 0;
   66|    240|}

wots_set_params:
   39|    240|{
   40|    240|  params->n = n;
   41|    240|  params->w = w;
   42|    240|  params->log_w = wots_log2(params->w);
   43|    240|  params->len_1 = (CHAR_BIT * n) / params->log_w;
   44|    240|  params->len_2 = (wots_log2(params->len_1 * (w - 1)) / params->log_w) + 1;
   45|    240|  params->len = params->len_1 + params->len_2;
   46|    240|  params->keysize = params->len * params->n;
   47|    240|}
xmss_wots.c:wots_log2:
   26|    480|{
   27|    480|  int      b;
   28|       |
   29|  12.2k|  for (b = sizeof (v) * CHAR_BIT - 1; b >= 0; b--) {
  ------------------
  |  Branch (29:39): [True: 12.2k, False: 0]
  ------------------
   30|  12.2k|    if ((1U << b) & v) {
  ------------------
  |  Branch (30:9): [True: 480, False: 11.7k]
  ------------------
   31|    480|      return b;
   32|    480|    }
   33|  12.2k|  }
   34|      0|  return 0;
   35|    480|}

